Begin with consequence
Cyber risk becomes useful when leaders can act on it.
Many cybersecurity assessments produce a long list of alerts, vulnerabilities and product recommendations without explaining which business operations are most exposed. A useful assessment starts with what the organisation must protect and the consequence if access, confidentiality, integrity or availability is lost.
Secure State uses a human-governed approach to AI-assisted cybersecurity. AI may help organise evidence, identify patterns and accelerate triage, but authorised people define scope, validate findings, decide priorities and approve every material action.
The assessment should connect identities, endpoints, email, cloud services, vulnerabilities, suppliers, connected systems and incident readiness into a single view of practical risk. It should then convert that view into owned actions and measurable evidence.
This guide is an operational framework, not a certification or statement of compliance. Legal, regulatory and sector-specific requirements must be confirmed for the organisation and assessment scope.
Decision guide
Eight areas that reveal material cyber risk.
Assess the organisation as a connected operating environment rather than a collection of unrelated security products.
Critical operations and assets
Begin with the services, information, systems and operational dependencies the organisation cannot afford to lose. Asset importance gives technical findings their business context.
Identity and privileged access
Review how users, administrators, service accounts and third parties authenticate, obtain privileges and lose access. Weak identity control can bypass otherwise strong technical protection.
Endpoint and server exposure
Assess device inventory, configuration, patching, endpoint protection, encryption, local privilege and monitoring across workstations, servers and mobile endpoints.
Email, cloud and collaboration
Examine common attack paths around business email, shared documents, cloud administration, external sharing, applications and recovery of compromised accounts.
Vulnerabilities and attack paths
Do not treat every finding equally. Connect weaknesses into realistic attack paths and prioritise them by exploitability, exposure, business consequence and available control.
Detection and response
Confirm which events are logged, who reviews alerts, how incidents are declared and what containment, communication, evidence and recovery actions are available.
Third parties and connected systems
Suppliers, remote support, managed services, operational technology and physical-security systems can extend risk beyond the traditional IT boundary. Ownership and access must remain clear.
AI governance and assurance
AI may improve analysis and triage, but its data access, prompts, outputs, actions, limitations and human approval points must be governed. Automation should not create uncontrolled authority.
A controlled pathway
From exposure to accountable improvement.
A repeatable assessment pathway keeps evidence, judgement, priorities and human authority connected.
Frame
Agree the business scope, critical operations, decision-makers, evidence sources and assessment boundaries.
Discover
Build a practical view of assets, identities, data, dependencies, existing controls and known concerns.
Assess
Test the evidence, identify material gaps and connect technical exposure to realistic operational consequence.
Prioritise
Separate urgent containment, high-value improvements, planned remediation and accepted residual risk.
Govern and review
Assign owners, dates and evidence, then review progress and changing exposure rather than filing a static report.
Before approval
Expect these assessment outcomes.
Important: cybersecurity risk changes with people, systems, suppliers and threats. The assessment should lead to controlled implementation and recurring review, not a one-time claim of complete security.
Official references
Check the current authority position.
Frequently asked
Clear answers before commitment.
What is an AI-assisted cybersecurity risk assessment?+
It is a human-led assessment that may use governed analytics and AI to organise evidence, identify patterns and support prioritisation. Accountable people still define scope, validate findings, decide risk and approve action.
Does AI replace a cybersecurity consultant?+
No. AI can accelerate analysis but may miss context, produce incorrect conclusions or expose sensitive information if poorly governed. Experienced people must validate evidence and remain responsible for decisions.
What should the final assessment provide?+
It should provide a clear scope, evidence basis, material risks, affected operations, existing controls, priority, recommended actions, owners, target dates, dependencies and residual-risk decisions.
Can the assessment include cloud, email and endpoints?+
Yes. The agreed scope can include identities, endpoints, servers, email, collaboration, cloud services, network exposure, vulnerabilities, backups, logging and incident-response readiness.
Can physical-security systems be included?+
Yes. Connected CCTV, access control, intercom and building systems may introduce network, identity, supplier and data risks. Secure State can include them when access, ownership and assessment authority are confirmed.
Does a risk assessment guarantee that the organisation is secure?+
No. Absolute security cannot be guaranteed. A good assessment improves visibility, prioritisation and accountable action, but resilience requires implementation, monitoring, testing and recurring review.
