Report an Incident Become a Partner Careers Contact
Book a Demo

A compromise assessment asks who is already inside.

It reviews your logs, systems and data for evidence that an attacker is present or has been, then gives you a report you can remediate from — mapped to the standards you are measured against.

A compromise assessment reading an estate's own logs A dense field of log lines. Three entries are already marked before anything happens. A band of light passes across the field and makes those three legible. The assessment does not create the findings — it reveals what the logs already held.

What is a compromise assessment?

Adopt a proactive approach
to cyber security

A compromise assessment is a review of an organisation’s logs, systems and data for evidence that an attacker is already present, or has been. It differs from testing, which looks for routes in that nobody has used yet: an assessment looks for the ones somebody already has.

Most organisations find out they were compromised from somebody else — a bank, a customer, a regulator, or the attacker. The evidence was usually in their own logs the whole time.

It is common for organisations to lack the time to proactively deal with vulnerabilities, leading to breaches and a costly post-attack clean-up and remediation process.

At Wizard Cyber we believe the only way to secure your organisation against cyber attacks is to adopt a proactive approach to cyber security development and improvement. Our compromise assessment service is designed to help you do that.

By collecting the necessary logs, handling the encryption and upload, and analysing every piece of data against our cyber threat models, we produce a report that details the vulnerabilities present within your system. The report is mapped to industry standards such as ISO 27001, so your team can build a remediation plan from it directly.

The service is designed to work alongside the security tooling you already run, including your SIEM and endpoint protection.

Four different questions, four different engagements

These get used interchangeably and they are not interchangeable. Buying the wrong one is the most expensive mistake in this part of the market.

Is somebody already in, or have they been?

Compromise assessment

Looks backwards and inwards, through logs and systems, for evidence of a presence you have not noticed.

Could somebody get in?

Penetration test

Looks forwards and outwards, for routes that exist but nobody has used yet. It tests the locks; an assessment looks for footprints.

What is unpatched or misconfigured?

Vulnerability scan

An inventory of known weaknesses. It is a component of an assessment rather than an alternative to one — step 03 below.

Something has happened. What now?

Incident response

Begins once you already know. An assessment is what you run when you do not.

Use cases

When a compromise assessment
earns its place

Five situations where an assessment is the right thing to buy. The first two are the ones nothing else on this site speaks to.

Cyber insurance

Cyber policies are still largely priced from self-assessment questionnaires, which ask an organisation to report on controls nobody has independently looked at. An assessment replaces that with evidence: what is actually deployed, what is actually logged, and whether anything is already inside. For an underwriter that changes the basis of the decision. For a buyer it is often the difference between a quoted premium and a declined submission.

Mergers and acquisitions

Cyber diligence in a transaction usually happens on a deadline, against an estate the buyer has never seen and the seller has every reason to present well. An assessment is the part that does not rely on either side’s account of it. What it finds can move a valuation, reshape the warranties, or occasionally stop a deal — and finding it after completion means you have bought it.

Breach and compromise detection

When investigating a suspected breach, a full review highlights current or historical compromise you may be unaware of, and identifies the weaknesses that allowed it.

Regulatory and compliance evidence

The documentation produced can be used in regulatory assessments and contributes to vulnerability management requirements.

Third-party risk evaluation

Demonstrates due diligence to partners and collaborators. Regular assessments show you are not carrying unnecessary exposure on their behalf.

The process

How an assessment
actually runs

Six steps, in order. The shape is fixed; the depth of each is scoped with you at the first meeting.

Initial meeting

The process Step 01 of 06

A consultant works through your current security measures with you. The first call is where we understand the organisation, introduce the people who will do the work, and agree the timeline.

Technical controls assessment

The process Step 02 of 06

A review of the controls in place, on site or remotely as needed. Interviews with senior managers identify how people, process and technology actually relate to one another — which is rarely how the documentation says they do.

Vulnerability assessment

The process Step 03 of 06

Internal and external, scoped from the questionnaire completed at the first meeting. External scans run from our premises; internal scans are usually remote, with an on-site visit where the estate requires it.

Intelligence gathering

The process Step 04 of 06

Our team, threat intelligence feeds and tooling gather what can be found about your organisation and its people from outside it. If we can find something that presents a risk, it is fair to assume somebody else can too.

Threat modelling

The process Step 05 of 06

A model built from real-world observation, showing which parts of the organisation are exposed to which kinds of attack — so you can see where the gaps are rather than being told there are some.

Results meeting

The process Step 06 of 06

A report documenting the status of each measure and the level of risk against each vulnerability, with the actions recommended to reduce it. Delivered in a meeting rather than emailed, so the findings can be argued with. What you end up holding is a picture of your estate built from evidence rather than recollection.

Key benefits

What an assessment
gives you

Beyond finding what is already there, an assessment sets a baseline and a direction for everything that follows.

Finds what is already inside

This is the part an organisation cannot easily do for itself, and not because it lacks the skill. Monitoring reports on what it was configured to notice, from the moment it was switched on. An assessment looks at what is already there — including the months before anyone was watching, and the log sources nobody thought to connect. Most of what it finds has been sitting in data the organisation already owned.

Sets a security baseline

A documented position rather than an impression. Most organisations describe their security posture from memory, a spreadsheet somebody exported, and the last thing that went wrong. The report replaces that with a dated, evidenced statement of where you actually are — which is the thing a second assessment measures against. Without it, “better than last year” is a feeling rather than a finding.

Frees your in-house team

Your IT or security team does not have to run the assessment themselves, which leaves their time for the improvements it identifies.

Sharpens the decisions that follow

One card, not two. The data gathered gives your team something concrete to prioritise and plan against, rather than a ranked list of assumptions.

Builds a proactive habit

A regular assessment is what turns security from something you do after an incident into something you do before one.

What drives the scope

It depends on the estate,
and we will tell you how

There is no standard size, and a number before the first conversation would be a guess. Four things move the work, and all four are settled with you at the start rather than discovered halfway through.

How many systems, and how much log

The volume and variety of log sources is the single biggest driver. Collecting, encrypting and uploading is our side of it; how much there is to collect is yours.

Whether the internal scan needs a visit

External scanning runs from our premises. Internal scanning is usually remote, and an on-site visit is only needed where the estate requires it.

How many people we need to talk to

The controls assessment depends on interviews with the people who actually run things, which is rarely the number named on the org chart.

Whether it is once or a cycle

A first assessment sets the baseline. A repeat one measures against it, and is a different and smaller piece of work.

Questions

Compromise assessment, answered.

What is a compromise assessment?

A compromise assessment is a review of an organisation’s logs, systems and data for evidence that an attacker is already present, or has been. It differs from testing, which looks for routes in that nobody has used yet: an assessment looks for the ones somebody already has.

How is it different from a penetration test?

A penetration test asks whether somebody could get in. A compromise assessment asks whether somebody already has. A test examines the locks; an assessment looks for footprints. Both are useful and they answer different questions, which is why buying one when you needed the other is an expensive mistake.

How is it different from incident response?

Incident response begins once you know something has happened. A compromise assessment is what you run when you do not know — and if it finds something, incident response is what follows.

What do you need from us?

Logs from the systems in scope, access for internal and external scanning, and time with the people who run the estate. Collecting the logs, handling the encryption and managing the upload are our side of the work rather than yours.

What do we actually get at the end?

A report documenting the status of each security measure and the level of risk against each vulnerability found, mapped to standards such as ISO 27001 so your team can build a remediation plan directly from it. It is delivered in a meeting rather than emailed, so the findings can be questioned.

If you find something, do we have to buy monitoring from you?

No. An assessment is a fixed piece of work with an end, and the report is yours whatever you do next. If it finds something active, incident response is what follows — and you are free to run that with us, with somebody else, or with your own team.

We already have a SOC and a SIEM. Is this still worth doing?

Usually, yes — because the two answer different questions. Monitoring tells you about what it was configured to notice, from the moment it was switched on. An assessment looks at what is already there, including the period before anyone was watching and the sources nobody thought to connect. It is designed to work alongside the tooling you run rather than replace it.

Will it disrupt our operations?

The process is built to avoid it. Scans are typically performed remotely, and an on-site visit happens only where the internal scan requires one. The parts that take your people’s time — the first meeting, the interviews and the results meeting — are scheduled with you rather than sprung on you.

Where to start

Find out what is already
inside your estate.

The first conversation is a scoping one: what you run, what you log, and how much of it is in scope. It costs you an hour and tells you whether an assessment is the right thing to buy at all.