Risk assessment

Know exactly where you stand — before they do.

Most businesses don't know what they don't know. A KIS risk assessment gives you a clear, honest picture of your vulnerabilities, your exposure, and what to do about it — in a report you can actually read and act on. We assess against both NIST CSF 2.0 and ISO 27001 controls, as well as the NZ Information Security Manual, so findings are meaningful and independently verifiable.

What's included
  • Comprehensive review of your systems, policies, and practices
  • Threat modelling specific to your industry and business size
  • Assessment against NIST CSF 2.0, ISO 27001 controls, and NZISM
  • Plain-English report with findings ranked by risk level
  • Prioritised remediation roadmap with effort and cost estimates
  • 60-minute walkthrough session with your team
  • 12-month reassessment to track progress
Methodology: We use NIST CSF 2.0 as our primary assessment framework — covering Govern, Identify, Protect, Detect, Respond, and Recover. Findings are also mapped to ISO 27001 Annex A controls so they're immediately useful for businesses pursuing certification.
Book a risk assessment →
3 Average critical risks found per KIS SMB assessment Based on internal KIS engagement data
68% Of findings fixable at no or low cost — configuration changes only Based on internal KIS engagement data
1–2 wk Typical delivery time for SMB engagements Standard KIS SMB engagement timeline