Under attack right now? Active incident line — +1 480-999-0030 · Report an incident

SVC-RA · Comprehensive risk assessment

Know exactly where you stand. In writing.

The starting point for most engagements: a comprehensive cybersecurity risk assessment covering your technology, your people, and your obligations, with findings you own whether or not you engage us further.

What we examine

Technology, people, and obligations, reviewed as a whole

Infrastructure and platform documentation

We map what you actually run: Google Workspace or Microsoft 365 tenant configuration, devices, practice management systems, file storage, backups, and the vendors touching client data. Many firms discover systems they didn't know were still connected.

Roles, responsibilities, and access review

Who can access what, and should they? Departed-employee accounts, over-broad permissions, shared logins, and administrative rights that accumulated over years are the findings that show up in almost every assessment, and in almost every breach.

Vulnerability and risk analysis

Technical gaps are weighed against what they mean for your business: client confidentiality, wire-fraud exposure, uptime commitments, and the obligations in your engagement letters, customer contracts, and insurance policy, not a generic severity score.

Prioritized, plain-language recommendations

The report ranks what to fix in the order it reduces risk, in language a managing partner can act on. No jargon walls, no hundred-page appendix designed to justify a retainer.

Common questions

What firms ask before an assessment

What does a cybersecurity risk assessment actually include?

Four things: documentation of your infrastructure and platforms as they exist today; a review of roles, responsibilities, and who can access what; analysis of vulnerabilities and the risks they create for your specific practice; and a prioritized set of recommendations in plain language, ranked by what reduces the most risk soonest.

How long does an assessment take?

For most small and mid-sized organizations, two to four weeks from kickoff to the written report. Most of it is low-touch document review and interviews, scheduled around your operations.

Are we obligated to engage Panthryx afterward?

No. The assessment stands on its own: you keep the documentation and recommendations whether or not you engage us for anything else. You can hand the findings to your IT provider, implement them internally, or ask us to.

Will the assessment satisfy a client or insurer asking about our security?

It's usually exactly what they're asking for: an independent review led by a certified auditor, with a deliverable that carries weight with whoever asked. If they require attestation against a specific framework such as SOC 2 or ISO 27001, the assessment feeds directly into our compliance and audit services.

Getting started

One conversation. A fixed scope. Findings you keep.

Tell us about your firm and we'll put the timeline, price, and deliverable in writing before you commit to anything.