Step-by-step process to evaluate and improve your organization's cybersecurity posture
TechnologyInitial cybersecurity assessment planning
Start day
Define audit scope and objectives
+2 days after start
Create inventory of IT assets
+5 days after start
Review current security policies
+8 days after start
Identify regulatory compliance requirements
+11 days after start
Conduct vulnerability scanning
+14 days after start
Perform network security assessment
+17 days after start
Evaluate access control systems
+20 days after start
Review password policies and practices
+23 days after start
Assess data backup procedures
+26 days after start
Review incident response plan
+29 days after start
Evaluate employee security awareness
+32 days after start
Check physical security controls
+35 days after start
Compile audit findings
+38 days after start
Prioritize security issues
+41 days after start
Create remediation action plan
+45 days after start
Present findings to stakeholders
+50 days after start
Using this template will create a new list with all the items shown above. You can rename the list, and optionally add due dates counted from a start date you choose.
17 tasks covering a full security review of an organisation: scope, asset inventory, policy review, vulnerability scanning, access control, backups, incident response, and the reporting that turns findings into work. It's written for an internal audit — someone responsible for security at a small or mid-sized company — rather than a formal certification exercise, though it maps onto most frameworks well enough to prepare for one.
The asset inventory task looks like busywork and is the foundation of everything after it. You cannot assess what you don't know you have, and the gap between the systems people think are running and the systems actually running is where most real incidents start — the forgotten server, the contractor's account, the SaaS tool one team bought on a card.
Budget more time for this step than seems reasonable. It's normal for it to take longer than the scanning.
A scan will return more issues than anyone can fix. The prioritisation task is what makes the audit useful: sorting by exploitability and blast radius rather than by the severity score the tool printed. A medium-severity flaw on an internet-facing system usually outranks a critical one on an isolated internal box.
The backup task means restoring something. An untested backup is a belief, not a control, and the restore is where people discover the retention window is shorter than they thought.
Six to eight weeks for a first audit. Turn on due dates — the offsets pace it so it doesn't stall after the scanning phase, which is where these usually die.