ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
AlvorAdvisory
Assess→Architect→Build→Operate

01/The diagnostic

Know exactly where you stand, and what to fix first.

We measure your current state against the framework and the maturity models that apply to you, then hand you a prioritised picture of the gap. The clearest way to start, with a defined scope and a defined deliverable.

Book a consultationSee the full lifecycle
IdentifyProtectDetectRespondRecoverMATURITY3.1/ 5.0
NIST CSF 2.0 · C2M2ISO 27001 · SOC 2The flagship diagnostic

The engagements

Thirteen ways to start with Assess.

Some assess the whole program, others a single function within it. Each is scoped on its own. Start with one, or run several together.

Alvor Advisory · AssessAS-01

Security Program Assessment

Know exactly where you stand, and what to fix first.

You walk away with

Maturity scorecardPrioritised gap registerRisk-ranked exposure pictureRemediation roadmap

Program-wide·Typically 3–4 weeks

Scope of workp. 2

Includes

  • Current-state review of the whole program against the framework you answer to
  • Maturity scoring on a recognised whole-program model (NIST CSF 2.0 or C2M2)
  • Risk analysis across the enterprise, your cloud, and your vendors
  • A prioritised, risk-ranked gap register with a remediation roadmap

Best for a first, complete read of where the program stands.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-02

Compliance Readiness Assessment

See the exact distance to certification before you commit to the audit.

You walk away with

Readiness reportGap-to-certification registerRemediation priorities

Program-wide·Typically 2–3 weeks

Scope of workp. 2

Includes

  • Gap assessment of the program against one named standard: ISO 27001, SOC 2, or a sector regime
  • Control-by-control review of what is in place against what the standard requires
  • An honest read on the time and effort to certification

Best for teams heading into a first certification or surveillance audit.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-03

Domain Maturity Assessment

Score a single security function against the model built for it.

You walk away with

Function maturity scorecardCapability gap analysisTargeted improvement roadmap

Targeted·Typically 2–3 weeks

Scope of workp. 2

Includes

  • Vulnerability management, scored against the SANS VMMM
  • Application security, scored against BSIMM or OWASP SAMM
  • Security operations, scored against the SOC-CMM
  • A focused, function-level maturity rating and improvement path

Best for a deep read of one capability, not the whole program.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-04

AI Security and Governance Assessment

See where AI is already in your business, and what it exposes.

You walk away with

AI usage inventoryExposure findings reportAI governance gap register

Function: AI governance·Typically 2–4 weeks

Scope of workp. 2

Includes

  • Shadow-AI discovery: the tools, models, and assistants already in use
  • Data and model-pipeline exposure review, from training data to outputs
  • Third-party AI risk across the vendors and features you already rely on
  • Findings mapped to ISO/IEC 42001 and the NIST AI RMF

Best for organisations whose AI adoption is running ahead of governance.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-05

Incident Response and Resilience Readiness

Know the plan holds before you ever need it.

You walk away with

IR readiness reportTabletop findingsRecovery gap register

Function: Resilience·Typically 2–3 weeks

Scope of workp. 2

Includes

  • IR plan and playbook review against how your organisation actually runs
  • A tabletop exercise with your leadership and technical teams
  • Recovery validation: backups, continuity, and the path back to normal
  • A clear read on insurer and reportable-incident expectations

Best for teams whose IR plan has never been rehearsed.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-06

Cloud Security Posture Review

Find what your cloud is actually exposing.

You walk away with

Posture findings reportPrioritised remediation order

Function: Cloud security·Typically 2–4 weeks, sized to the estate

Scope of workp. 2

Includes

  • Configuration and posture assessed against the CIS Benchmarks and the CSA Cloud Controls Matrix
  • Identity, network, and data-exposure review across your accounts
  • ISO 27017 and 27018 in scope where the cloud handles personal data
  • Findings ranked by exploitability and blast radius

Best for cloud-first teams unsure what their accounts expose.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-07

Third-Party Risk Assessment

Understand the risk you inherit from the vendors you depend on.

You walk away with

Third-party risk registerVendor tiering model

Function: Third-party risk·Typically 2–4 weeks

Scope of workp. 2

Includes

  • Inventory and tiering of your vendors by the access and data they hold
  • Risk review of your critical and high-tier suppliers
  • A repeatable scoring method you can keep using

Best for organisations with a growing or unmapped vendor estate.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-08

Penetration Test and Control Validation

Confirm the controls you rely on actually hold.

You walk away with

Test report with severity ratingsValidated control findingsRetest on fixes

Function: Technical assurance·Typically 1–3 weeks per scope

Scope of workp. 2

Includes

  • Hands-on testing of network, application, or cloud, scoped to your estate
  • Run to recognised methodologies: OWASP for applications, PTES and MITRE ATT&CK for adversary emulation
  • Delivered by certified offensive-security practitioners
  • Findings with clear reproduction steps and remediation guidance

Best for teams needing technical proof, not just a paper review.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-09

Identity and Access Management Assessment

Map who and what can reach your systems, and where that access goes wrong.

You walk away with

Identity and access current-state reportPrivileged-access and entitlement findingsPrioritised IAM gap register

Function: Identity & access·Typically 2–4 weeks

Scope of workp. 2

Includes

  • Current-state review of human and machine identity: joiners, movers, and leavers, privileged access, service accounts, and standing entitlements
  • Access read against least privilege and segregation of duties, with the dormant, excess, and orphaned accounts surfaced
  • Posture measured against the controls that bind you: the Essential Eight strategies for restricting admin privileges and enforcing MFA, APRA CPS 234 access management, and ISO 27001 Annex A identity controls
  • A prioritised view of the gap between today's access model and the target state

Best for teams where identity has sprawled faster than anyone has governed it.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-10

Essential Eight Maturity Assessment

Know your Essential Eight maturity level, and what it takes to reach the next one.

You walk away with

Essential Eight maturity scorecardPer-strategy gap analysisUplift roadmap

Program-wide·Typically 2–3 weeks

Scope of workp. 2

Includes

  • Each of the eight mitigation strategies assessed against the ACSC Maturity Model, scored Maturity Level Zero to Three
  • Evidence-based review across application control, patching, macro settings, application hardening, administrative privileges, MFA, and backups
  • Alignment to the broader ACSC Information Security Manual where it applies to you
  • A clear path to the target maturity level you actually need, not Level Three for its own sake

Best for Australian teams holding themselves to the ACSC baseline.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-11

APRA CPS 234 Information Security Readiness

Meet the prudential standard your board attests to, with the evidence to prove it.

You walk away with

CPS 234 readiness reportControl-testing gap registerBoard-ready assurance summary

Program-wide·Typically 3–4 weeks

Scope of workp. 2

Includes

  • Information-security capability assessed against each CPS 234 requirement, from policy to control testing
  • Information-security roles defined and the board's ultimate accountability mapped
  • The classification of information assets by criticality and sensitivity reviewed
  • Third-party and related-party arrangements tested against the standard's reach into your supply chain

Best for APRA-regulated entities and the providers who serve them.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-12

APRA CPS 230 Operational Resilience Readiness

Show you can keep critical operations running through disruption, and that your providers can too.

You walk away with

CPS 230 readiness reportCritical-operations and tolerance registerService-provider risk map

Program-wide·Typically 3–5 weeks

Scope of workp. 2

Includes

  • Critical operations identified, with tolerance levels for disruption set and tested
  • Operational risk and business-continuity capability reviewed against CPS 230
  • Material service-provider arrangements mapped, with concentration and exit risk surfaced
  • Scenario testing of severe-but-plausible disruption against your tolerances

Best for APRA-regulated entities preparing for CPS 230.

Scope this engagementRead the full page

Alvor Advisory · AssessAS-13

SOCI Risk Management Program Readiness

Stand up the risk-management program the SOCI Act requires, across all four hazard domains.

You walk away with

CIRMP gap assessmentFour-domain hazard registerIncident-reporting readiness check

Program-wide·Typically 3–5 weeks

Scope of workp. 2

Includes

  • Your obligations confirmed: which assets are covered, and whether enhanced obligations for systems of national significance apply
  • A Critical Infrastructure Risk Management Program reviewed across the cyber, physical, personnel, and supply-chain hazard domains
  • Cyber hazard maturity assessed against a recognised ACSC framework (the Essential Eight or the ISM), as the rules contemplate
  • Incident-reporting readiness against the mandatory 12-hour and 72-hour timeframes

Best for responsible entities for assets covered by the SOCI Act.

Scope this engagementRead the full page

The catalogue, mapped

One flagship. Twelve ways to go deeper.

Inner orbit · program-wideOuter orbit · targetedSelect a node to open its report

What you walk away with

It resolves to one maturity scorecard and a single prioritised, risk-ranked gap register, so the diagnosis and the remediation roadmap are the same artefact.

  1. 01Maturity scorecard
  2. 02Prioritised gap register
  3. 03Risk-ranked exposure picture
  4. 04Remediation roadmap

The decision is yours

The flagship assessment stands on its own. Its roadmap is the scoped proposal for Architect, and the next move is yours.

Next trackArchitectDecide what good looks like before a single control is built.
AlvorAdvisory

Start where it makes sense for you.

A short conversation is the fastest way to scope Assess and see where it fits across the lifecycle.

Book a consultationBack to the advisory
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security, Simplified.

Platform

  • Overview
  • AI Assistant
  • Security Architecture
  • Assets
  • Components
  • Dependency Mapping
  • Data Governance
  • Secure by Design
  • Security Design Review
  • Threat Modeling
  • Risk
  • Compliance
  • Policy
  • Program
  • Business Continuity
  • TPRM

Solutions

  • Startups
  • Mid-Market
  • Enterprise

Company

  • About
  • Advisory
  • Compliance
  • Blog
  • Security
  • Pricing
  • Compare

Legal

  • Privacy
  • Cookie Policy
  • Terms
  • Disclosure

© 2026 Alvor, Inc. All rights reserved.

LinkedIn