Interconnekt
Posture Audit

CIS Gap Analysis

The CIS Controls are the most practical 'do this' security baseline there is: 18 controls, 153 safeguards, tiered into Implementation Groups so a small business starts with the essentials. We assess where you actually sit, score you against your target group, and hand back a roadmap keyed to risk - not a 153-line checklist you'll never action.

Next step

Ready to scope CIS Gap Analysis for your business?

What’s included

Scope that’s actually defined.

Every inclusion below is documented, delivered, and renewable under our standard agreement. No surprise scope. No silent exclusions.

Controls assessment, all 18

We assess your environment against every CIS Control v8.1 - asset and software inventory, data protection, access control, logging, recovery, service-provider management, awareness training, incident response - down to the safeguard.

Implementation Group scoring

Scored against your target Implementation Group - IG1 'essential cyber hygiene' (56 safeguards) for most SMBs, IG2 (74) where data sensitivity or contracts demand it.

Evidence-based, not a survey

We review live configuration, not just ask you questions. Where it helps we use CIS CSAT for the controls assessment and CIS-CAT against the CIS Benchmarks for the technical config layer - you get both.

Framework mapping

Your CIS posture mapped across to NIST CSF 2.0 and ISO 27001 controls, so one assessment answers several compliance questions at once.

Prioritised roadmap

The gaps ranked by risk and Implementation Group, with the 20% of work that delivers most of the uplift flagged. You keep the report and the raw data.

What’s not included

The boundaries, stated up front.

Knowing where a service stops matters as much as knowing what it covers. Here’s what sits outside this engagement - so there are no awkward surprises later.

Remediation of what we find

The gap analysis tells you where you stand and what to fix. Closing the gaps is a separate engagement - usually the Compliance Foundation Programme - so you're free to action it yourself or with us.

A CIS certification

CIS doesn't issue a pass/fail certificate, and we won't imply one. You get an honest score against your target Implementation Group, amber findings included.

ISO 27001 or SOC 2 certification

We map your CIS posture to those frameworks, but the formal ISO or SOC audit and certificate come from an accredited certification body, which we'll scope and partner on rather than overclaim.

How we deliver

A sequence you can hold us to.

Every engagement runs the same four steps. You always know which one we’re in and what comes next.

  1. 01

    Scope

    We map your current state and agree exactly what's in and out, in writing, before any work or invoice. No surprise scope, no silent exclusions.

  2. 02

    Plan

    A documented plan with milestones, owners, and success criteria you can hold us to - so you know what good looks like before we start.

  3. 03

    Implement

    We do the work with change control and your sign-off at each gate. You see progress against the plan, not a black box.

  4. 04

    Operate

    Ongoing management, published performance, and a quarterly review that keeps the work honest and the roadmap current.

Frequently asked

The questions we get most.

CIS or Essential Eight - which do we need?
Different jobs. The Essential Eight is the narrow, Microsoft-centric Australian baseline that primes and insurers ask about. CIS is the broad international management framework that covers the governance, process, and people controls the Essential Eight deliberately leaves out - training, incident response, service-provider risk, data management - and it maps onto NIST and ISO. Many businesses are Essential Eight aligned and still have real CIS gaps. We often run both.
Which Implementation Group should we target?
Start at IG1 - it's the essential cyber hygiene every business should have, and it defends against the common, non-targeted attacks. IG2 is for businesses handling more sensitive data across multiple functions. IG3 is for mature, regulated enterprises. We'll recommend a target based on your data and contracts, not sell you the highest tier.
How long does it take?
A focused IG1 gap analysis for a typical SMB is a couple of weeks end to end - assessment, validation, and reporting. Broader scope or an IG2 target takes longer.
Do you keep the report?
You get the report, the evidence, and the raw data. We don't hold your posture hostage - you should be able to walk it across the road if we ever disappoint you.
Ready when you are

Leave the MSP that doesn’t pick up.

Tell us what your current setup looks like. We’ll send back a quote, a transition plan, and a firm date you’d be onboarded - within 48 hours.

Response
Within 48 hours
Format
Written quote
Discovery call
Not required
Contracts
No lock-in terms

We’ll respond within 48 business hours. No spam, ever.