October is Cybersecurity Awareness Month, and rather than post a list of "top 10 security tips" that you'll skim and forget, we're doing something different. This is Part 1 of a six-part series that walks through building a complete security program - from knowing where you stand today to creating a security culture that outlasts the month of October.
We're starting here because this is where almost everyone gets it wrong. They jump straight to buying tools. Firewalls. Endpoint protection. Email filtering. All good things. But they're buying solutions before they've diagnosed the problem. It's like going to the pharmacy before going to the doctor.
What a Security Assessment Actually Is
A security assessment isn't a penetration test (that comes later, if needed). It's a structured evaluation of your current security posture across people, processes, and technology. It answers a simple question: where are we, and where are the gaps?
When we conduct security assessments for Utah businesses - from 10-person startups in Lehi to 200-employee firms in downtown Salt Lake - the process typically covers five domains:
- Asset inventory. What do you actually have? How many endpoints, servers, cloud services, network devices, mobile devices, and SaaS applications exist in your environment? You'd be stunned how many businesses can't answer this question accurately. We've walked into assessments where the client said they had 30 computers and we found 47. Those 17 unaccounted-for devices? Unpatched, unmonitored, unmanaged.
- Identity and access. Who has access to what? Are there former employees with active accounts? Shared admin credentials? Service accounts with passwords that haven't been rotated in three years? MFA enabled on some accounts but not others? This is consistently the messiest area we find. Every single assessment.
- Data protection. Where does your sensitive data live? Is it encrypted at rest and in transit? Who can access it? Is it being backed up? How long would it take to restore? If someone dropped a ransomware payload right now, what would your recovery actually look like - not theoretically, but specifically?
- Network and endpoint security. Firewall configurations, endpoint protection status, patching cadence, network segmentation, wireless security, remote access methods. The technical infrastructure layer that either supports or undermines everything else.
- Policies and procedures. Do you have an acceptable use policy? An incident response plan? A data retention policy? Business continuity documentation? And the critical follow-up question: do the people who need to follow these policies actually know they exist?
The Gap Analysis
The assessment produces findings. The gap analysis turns those findings into a prioritized action plan. Not everything is equally urgent. A domain admin account with no MFA is a higher priority than updating your acceptable use policy. An unpatched internet-facing server is more critical than improving password complexity requirements. Triage matters.
We score gaps on two axes: likelihood and impact. A vulnerability that's easy to exploit and would cause significant damage goes to the top. A theoretical weakness that requires physical access and would have limited impact goes to the bottom. This isn't complicated, but it's the step that most businesses skip - they either try to fix everything at once (overwhelming and unsustainable) or fix whatever feels most urgent in the moment (reactive and haphazard).
Here's what a simplified risk matrix looks like:
| Low Impact | Medium Impact | High Impact | |
|---|---|---|---|
| High Likelihood | Medium Priority | High Priority | Critical |
| Medium Likelihood | Low Priority | Medium Priority | High Priority |
| Low Likelihood | Accept/Monitor | Low Priority | Medium Priority |
What Auditors and Insurers Are Looking For
If your business is subject to compliance requirements - HIPAA, PCI-DSS, CMMC, SOC 2, or even just a cyber insurance application - assessments aren't optional. They're expected. And the bar is rising. Cyber insurance applications in 2026 are asking specific technical questions that many businesses can't answer without an assessment:
- Do you have MFA on all remote access and email accounts?
- Do you maintain an asset inventory?
- What is your mean time to patch critical vulnerabilities?
- Do you have endpoint detection and response on all endpoints?
- Do you have a tested incident response plan?
- Do you perform regular vulnerability scans?
- Do you have a business continuity/disaster recovery plan?
Answering these questions inaccurately on an insurance application doesn't just risk a denied claim - it can constitute fraud. An assessment gives you accurate answers. Sometimes those answers are uncomfortable, but uncomfortable is better than wrong.
Common Findings We See in Utah Businesses
After conducting hundreds of assessments across businesses along the Wasatch Front, patterns emerge. These are the findings that show up in nearly every first-time assessment:
- Stale accounts. Former employees, contractors, or vendors with active directory or cloud accounts that were never disabled. Average: 3-5 per organization. We once found 23 active accounts for people who hadn't worked at the company in over two years.
- Inconsistent MFA. MFA enabled on Microsoft 365 but not on the VPN. Or on admin accounts but not standard users. Or on email but not the accounting software that holds all the financial data. Partial MFA creates a false sense of security.
- No backup testing. Backups are running. Nobody has tested a restore in the past year. When we test, roughly 1 in 5 backup sets has an issue - corrupted data, missing databases, expired credentials on the backup agent. Backups that can't restore aren't backups.
- Flat networks. One network, everything on it. The receptionist's computer, the accounting server, the security cameras, the IoT thermostat, and the guest Wi-Fi - all on the same network segment. No segmentation means that a compromised device has line-of-sight to everything.
- Shadow IT. Cloud services that employees signed up for without IT knowledge. Dropbox accounts syncing company files. Personal Google Drives with shared company documents. Project management tools with client data. None monitored, none backed up, none governed by policy.
DIY vs. Professional Assessment
Can you assess yourself? Partially. Microsoft Secure Score gives you a decent baseline for your M365 environment. You can audit your Active Directory for stale accounts. You can check your backup logs. But a thorough assessment requires perspective that's hard to get from the inside. You don't know what you don't know. An IT team that built the environment has blind spots about the environment - that's human nature, not a criticism.
Professional assessments also carry weight with auditors, insurers, and leadership that internal self-assessments don't. When a board asks "how's our security?" and the answer is "we assessed ourselves and we're fine," that's not reassuring. When the answer is "we had a third-party assessment, here are the findings, here's the remediation plan, and here's our progress" - that's a different conversation entirely.
What Comes Next
An assessment without action is just an expensive document. The output should be a prioritized remediation roadmap - the top 5-10 things that will have the most impact on your security posture, with realistic timelines and resource requirements. Not a 200-item checklist that paralyzes your team, but a focused plan that moves the needle.
In Part 2 of this series, we'll dive into identity and access management - because in almost every assessment we conduct, identity is where the biggest gaps live. If you want to get a head start and understand where your business actually stands before the rest of this series publishes, our team is available for a security assessment conversation. No sales pitch, just an honest look at where you are.
