---
title: "Full Cybersecurity Assessment | EFROS"
description: "Authenticated review of internal infrastructure, identity, endpoints, and policies. Goes beyond a passive external scan. Board-level report with prioritized remediation roadmap."
canonical: https://efros.com/services/cybersecurity-assessment/
---

- [Home](https://efros.com/)
- /[Services](https://efros.com/services/)
- /Cybersecurity Assessment

By [Stefan Efros](https://www.linkedin.com/in/stefanefros-cyberdefense/), CEO & Founder, EFROS

Updated · August 6, 2026

Service · Cybersecurity Assessment

# Beyond the external scan, a full authenticated assessment.

The free passive external scan gives a score in 60 seconds. The full assessment authenticates against your tenant, validates with evidence, and produces a roadmap your board can approve.

[Run Free Security Score](https://efros.com/free-security-assessment/) [Book a 20-Minute Call](https://efros.com/contact/?type=consultation)

Who this is for

Companies preparing for cyber-insurance renewal, vendor security review, M&A due diligence, or a SOC 2 / HIPAA / PCI audit. Also a strong fit before any major MSSP engagement. Produces the baseline that makes the first ninety days operational instead of exploratory.

## What's included in a full assessment

### Authenticated identity review

Microsoft Entra / Okta / Google Workspace. Conditional Access, MFA coverage, privileged access, service accounts, guest sprawl, sign-in risk.

### Endpoint posture sampling

Live agent telemetry from EDR, OS version, patch state, disk encryption, application allowlisting. Sampled across user, server, and BYO tiers.

### Email + DNS deep-dive

SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI maturity. Plus message-trace forensics, anti-phishing policy, attachment filtering, impersonation rules.

### Policy + procedure review

Acceptable use, BYOD, vendor management, incident response, data classification, retention. Compared against your industry baseline.

### Findings register with evidence

Each finding has a unique ID, evidence hash, severity, likelihood, business impact, technical impact, recommended remediation, estimated effort, validation steps.

### Prioritized remediation roadmap with budget

Remediation priority bands: P1 (≤7 days) · P2 (≤30 days) · P3 (30-90 days) · P4 (90-180 days). These are remediation windows for closing findings, not incident-response SLAs. For IR severity bands and response timing see the canonical SLA matrix at efros.com/trust/#sla. Each item costed against typical implementation effort.

What this engagement does not cover

Items below sit outside the scope of this service. Some are handled by separate EFROS engagements; others belong with your existing partners or in-house team.
- ×Active penetration testing or exploitation (separate authorized engagement)
- ×Remediation work. The assessment identifies findings; ongoing remediation runs under Managed IT or MSSP scope
- ×Third-party vendor audits beyond standard vendor risk questionnaires
- ×Source-code review or application-level security testing

Security impact

Surfaces the misconfigurations, identity exposures, and policy gaps that determine whether an attacker's first foothold becomes a contained incident or a tenant-wide compromise. The roadmap prioritizes by exploit likelihood × business impact rather than by tool-default severity.

Compliance & cyber-insurance relevance

The findings register maps directly to SOC 2 TSC, ISO 27001 Annex A, HIPAA Security Rule, PCI-DSS v4.0.1 §11, and CMMC L2 controls. Auditors and cyber-insurance reviewers accept it as the gap-analysis artifact for the corresponding controls.

## How the engagement runs

Week 1

### Scope + authorization
- ·Rules of engagement signed
- ·Read-only tenant access provisioned
- ·Asset list and crown-jewel review
- ·Communication channels and escalation contacts

Week 2-3

### Evidence collection
- ·Configuration export from tenants
- ·Endpoint sampling
- ·DNS, email, and web posture validation
- ·Policy and procedure review

Week 4

### Synthesis + draft report
- ·Findings register with evidence hashes
- ·MITRE ATT&CK mapping where applicable
- ·Standards mapping (NIST CSF, ISO 27001, CIS Controls)
- ·Internal peer review of critical / high findings

Week 5

### Delivery + handoff
- ·Executive presentation
- ·Dual-layer PDF report (Executive + Technical)
- ·Remediation roadmap with budget
- ·Re-test plan and validation criteria

● Visible proof

## What the deliverable looks like

Per-category scores, an overall posture grade, a prioritized finding example. Sample shown, anonymized.

EFROS Passive Assessment · Sample · Anonymized

v1.0 · Letter

Overall security score

86 Grade B out of 100

Posture

Above-average for industry · 3 priority remediations

Domain A

DNSSEC · CAA 89/100

Email Auth B

SPF · DKIM · DMARC 72/100

Web Security A

HSTS · CSP 91/100

Brand A+

Typosquats · BIMI 96/100

Infrastructure A+

DNSBL · CDN 100/100

Compliance C

GDPR · security.txt 65/100

P2 F-007 · Medium CVSS 6.1 · Confirmed

DMARC policy at p=none allows spoofed mail through

Recommended: move to p=quarantine within 14 days after a 30-day aggregate-report review, then to p=reject. Owner: IT lead. Effort: 2 hours.

Page 3 · 14 CONFIDENTIAL · SAMPLE · COPY-A1F2B3

Standards and frameworks referenced

NIST SP 800-53 Rev. 5 NIST CSF 2.0 ISO/IEC 27001:2022 CIS Controls v8.1 OWASP ASVS 5.0.0 MITRE ATT&CK

Standard versions should be verified from the official source before contractual reliance.

Frequently asked

## Questions before we start.

How is this different from the free 60-second scan? + The free scan is passive and external: public DNS, mail, and TLS only. The full assessment authenticates against your tenant, samples endpoints, reviews policies, and maps findings to compliance frameworks with evidence. The free scan gives a score. The full assessment gives a defensible report.

Do you exploit anything during the assessment? + No exploitation is attempted in a standard assessment engagement. Further validation requires written authorization. If exploitation is in scope, that's a separate red-team engagement with explicit rules of engagement.

What credentials do you need? + Read-only auditor or global-reader equivalent on the tenants in scope. Sample-level endpoint access via your existing EDR or MDM. We never request, store, or use end-user passwords.

Will the findings hold up in front of an auditor? + Every finding is anchored to a specific evidence ID and SHA-256. Reproduction steps in the report can be re-run independently from the recorded artifacts at any time. This is the same standard that survives SOC 2 Type II and ISO 27001 audit cycles.

## Start with your domain.

Free passive external assessment. 60 seconds. No signup to start.

[Run Free Security Score](https://efros.com/free-security-assessment/) [Book a 20-Minute Call](https://efros.com/book/)

Related EFROS resources

## Related EFROS services

[### Managed Detection & Response 24/7 SOC with pre-authorized containment — the operational layer for any service.Open→](https://efros.com/security/mdr/) [### Virtual CISO Fractional executive security leadership with quarterly board reporting.Open→](https://efros.com/security/vciso/) [### Zero Trust NIST SP 800-207 implementation across identity, device, network, app, data.Open→](https://efros.com/security/zero-trust/) [### AI Governance NIST AI RMF + ISO/IEC 42001 + SR 11-7 operating program.Open→](https://efros.com/services/ai-governance/) [### Full services catalog MSP, MSSP, system integration, AI governance under one accountable SLA.Open→](https://efros.com/services/) [### Security service catalog Complete cybersecurity service overview.Open→](https://efros.com/security/)
