OneCloud IT Solutions502-268-8844Talk to OneCloud
Home / Services / Security Risk Assessments
Security risk assessments

You cannot prioritize a risk you have never written down.

A useful assessment does not hand leadership a list of vulnerabilities. It answers a business question: of everything that could go wrong here, what should we fix first, and what will it cost?

The lifecycle

Identify → Assess → Prioritize → Remediate → Reassess

An assessment is not an event. Environments change, staff change, vendors change, and a finding closed last year can quietly reopen.

1. Identify

What systems matter, what information matters, where it lives, and how it moves. Most organizations have never written this down, and it is the foundation everything else rests on.

2. Assess

What threats are realistic for an organization of this size and type, what weaknesses exist, and what controls are already working — credit where controls are genuinely in place.

3. Prioritize

Rated by likelihood and business impact, so a long list becomes a short sequence. Leadership decides what to fund; the assessment makes that decision informed.

4. Remediate

A plan with owners, effort and cost — including items we do not do and items that belong to another vendor or to the organization itself.

5. Reassess

Annually, and again whenever the environment changes materially. A stale assessment is treated as no assessment by auditors, insurers and regulators alike.

Scope

What we actually examine

  • Identity and MFA coverage
  • Administrative and privileged access
  • User access and offboarding
  • Endpoints and patching
  • Servers and infrastructure
  • Email security
  • Networking and firewalls
  • Wi-Fi and segmentation
  • Remote access
  • Backup and recovery
  • Restore testing evidence
  • Vendor and third-party access
  • Security awareness and training records
  • Policies and documentation
  • Incident response readiness
  • Physical security
For healthcare organizations

A security risk analysis is a foundational HIPAA Security Rule requirement, and a missing or outdated one is among the most commonly cited findings in enforcement. We produce a document formatted to be handed to your compliance officer, your counsel or your cyber insurer — but the assessment supports your obligations rather than discharging them. Compliance remains the organization’s responsibility.

Questions

Common questions

How often should we do this?

Annually at minimum, and again after any material change — a new location, an EHR migration, a server replacement, a change of IT provider, or a security incident.

The most common failure is not doing one badly. It is doing one well, once, and never revisiting it.

Is this the same as a penetration test?

No, and the two are often confused. A penetration test attempts to exploit specific weaknesses to prove they are real. A risk assessment is broader — it looks at the whole environment, including policy, training, vendors and recovery, and produces a prioritized plan. Most organizations need the assessment first; the pen test is more useful once the obvious gaps are closed.

What do we actually receive?

A written report: an inventory of systems and information, a data flow description, findings against each area above, risk ratings with reasoning, and a remediation plan with owners, effort and indicative cost. Written to be read by leadership, not only by an engineer.

Do we have to use you for the remediation?

No. The report is yours regardless, and it includes items another vendor or your own team may be better placed to handle. An assessment that only ever recommends the assessor’s own services is a sales document, not an assessment.

Start with a clear picture

An assessment tells you where you stand and what to do about it — in a sequence you can actually fund.