Most estates are not short of sensors and not short of analysts. What is missing is a single picture of where exposure actually sits, how long a decision takes to travel from first signal to the person with authority to act, and which gaps live between systems rather than inside any one of them.
Not a maturity grade and not a framework checklist. A description of your own operation that the people who run it recognize as accurate, with the gaps stated plainly.
The actors, vectors and scenarios that apply to this estate, this sector and this geography, grounded in current reporting rather than a generic list carried in from another engagement.
Where time is lost between an event arriving and a person with authority acting on it, traced through the routing, queues and handoffs you actually use, not the ones on the procedure diagram.
What is visible across cyber and control systems, physical security, insider risk and operations, and what falls between the consoles that watch them. The seam is usually in the gaps, not the tools.
The same findings written for a board and an executive committee, in the language of exposure and obligation rather than tooling, so the decision to act can be taken by the people who hold it.
Facilitated scenario work that stresses the current posture, so coordination failures and slow handoffs surface in a room with the right people in it rather than during an actual event.
A sequenced plan for closing what was found, covering technology, process and organizational structure, with a named owner and an agreed success test against each item.
The work is done with the people who hold the watch, in the rooms where they hold it. Scope, participants and scheduling are agreed at the start rather than assumed from a template.
We agree the boundary of the estate, the scenarios in scope and who takes part, and we collect what already exists: escalation procedures, source inventories, prior assessments, org charts.
Interviews with the operators, analysts and watch officers who do this work now, walk-throughs of the consoles in use, and tracing of real past events from first signal to the person who acted.
A facilitated tabletop against scenarios drawn from this estate. The purpose is to find where the handoffs break and where ownership is unclear, not to grade the people in the room.
We write up the gaps, the decision path with its delays marked, and the coverage picture, including what no system in the current stack sees at all.
Findings go to the leadership group and, where asked, to the board. The engagement closes with a sequenced roadmap, each item carrying an owner and a success test.
Each deliverable names its sources and states what it does not cover. Where a finding rests on one interview, it says so.
The assessment does not commit you to anything.
Nothing in this engagement requires a platform decision, and organizations use it to decide whether to buy anything at all. Where the findings do point at a platform, the asset inventory, the source list and the agreed policy questions that come out of this work are the same inputs a deployment would otherwise have to assemble from a standing start.
What you will not get back is a scored maturity grade against someone else's model. Where we cannot see something, the assessment says so rather than filling the space with an inference.
We walk one real convergence case from your estate and agree what an assessment would have to cover to be worth running.