cybersecurity
What a Cybersecurity Assessment Includes for a Hampton Roads Small Business
What a cybersecurity assessment covers for a Portsmouth or Hampton Roads small business, how it differs from a pentest, how long it takes, and what a real report costs.
Someone told you to get a cybersecurity assessment. Maybe it was your cyber insurance renewal. Maybe a prime contractor’s vendor questionnaire before a Navy or maritime subcontract clears. Maybe an IT consultant used the phrase and you nodded like you knew exactly what came next.
You don’t, and that’s fine. Most Hampton Roads business owners have never sat through one.
A cybersecurity assessment, sometimes called a cybersecurity risk assessment, is a structured review of how your business protects its systems and data, measured against a defined set of controls, and it ends with a report that ranks your gaps by risk. That’s the whole concept. The rest of this article is what actually happens between “you’re told you need one” and “you get the report,” written for the Portsmouth, Norfolk, and Chesapeake businesses that keep asking us this question.
I’m going to walk through what it looks at, how it differs from the penetration test people confuse it with, how long it takes, what the deliverable looks like, what triggers the request in the first place, and what it should cost. If you decide afterward to run it yourself or hire someone other than Helix Stax, that’s a fine outcome. The point of this piece is that you understand what you’re buying.
What is a cybersecurity assessment, exactly?
A cybersecurity assessment is a structured evaluation of your organization’s security controls, measured against an established framework, that produces a prioritized list of gaps and recommendations. It is not a single tool or scan. It’s a process: someone reviews your systems, your access controls, your policies, and your practices, then tells you where you stand and what to fix first.
Frameworks vary. Some assessors work from the CIS Controls, which rank security actions by priority. Others use the NIST Cybersecurity Framework (CSF), organized around five functions: Identify, Protect, Detect, Respond, Recover. Government contractors usually get measured against NIST SP 800-171, the 110-control standard behind CMMC. None of these frameworks are secret. You can read all of them for free, and a competent assessor should tell you which one they’re using and why.
What an assessment is not: it is not a penetration test (more on that below), it is not an insurance requirement in itself (though insurers often want one), and it is not a one-time fix. It’s a snapshot, taken against a ruler, that tells you where the gaps are today.
If you’ve read our cybersecurity for small business guide or worked through our small business cybersecurity checklist, you already know the controls that usually matter most: MFA, access cleanup, backup testing, patching, and training. An assessment is the formal process of checking whether those controls actually exist, at what strength, and where they’re missing. It turns “we think we’re okay” into a specific list.
What does a cybersecurity assessment actually look at?
A thorough assessment covers five areas, and a good one covers all five even if your gut says only one matters.
Identity and access. Who has an account, who has admin rights, whether MFA is required, whether former employees still have access to anything. This is usually where the most damage lives and the cheapest fixes are found.
Endpoints and devices. Laptops, desktops, servers, and mobile devices: are they patched, encrypted, managed, and running current operating systems. An assessor will ask how many devices exist before they ask how they’re protected, because you can’t secure what you haven’t counted.
Network and infrastructure. Firewall configuration, Wi-Fi segmentation, VPN and remote access setup, and whether anyone still remembers what the guest network password does.
Data protection and backups. Where sensitive data lives, who can reach it, whether backups exist, and whether anyone has actually tested a restore. A backup that has never been restored is a belief, not a control.
Policies and processes. Written (or missing) policies for password management, incident response, vendor access, and employee onboarding and offboarding. This is the part owners skip past mentally and the part an insurer or prime contractor reads first.

A network security assessment specifically zeroes in on that third bucket: firewalls, segmentation, wireless, and remote access configuration. If someone asked for a “network security assessment” rather than a full cybersecurity assessment, they may only need that slice. Ask what they actually require before you pay for the whole five-bucket review.
What this looks like varies by industry, and Hampton Roads has a specific mix. A marine repair shop or port services vendor working with the Port of Virginia usually has the network and infrastructure bucket flagged first, because remote monitoring on cranes, gate systems, or fleet tracking creates more entry points than the owner realizes. A dental or family medicine practice in Portsmouth almost always has gaps in data protection, since patient records sit under HIPAA whether or not anyone’s checked the backup and encryption story lately. A defense subcontractor supporting the shipyard usually already assumes identity and access is fine and is surprised to learn former employees still have VPN access six months after leaving. The five buckets are the same everywhere. Which one bites first depends on what you actually do.
The output of all this is a prioritized gap list, sometimes called a cybersecurity gap analysis: a side-by-side comparison of where you are against where the framework says you should be, with each gap tagged by severity. That gap list is the actual product. Everything before it is data collection.
How is a cybersecurity assessment different from a penetration test?
A cybersecurity assessment reviews your controls and configuration. A penetration test tries to break in.
An assessment asks: do you have MFA, is your firewall configured correctly, are your backups tested, does your access control policy match reality. A pentest asks: can I actually get into your network, your email, your VPN, or your application right now, using the same techniques a real attacker would use.
Think of it as the difference between a home inspector and a burglar you hired. The inspector checks the locks, the wiring, the foundation, and tells you what’s out of code. The burglar tries the windows, tests the alarm, and tells you whether they could actually get in tonight.
Both have value, and they’re not interchangeable. Most small businesses should start with an assessment, not a pentest, because a pentest against a business with obvious, unpatched gaps mostly just confirms what an assessment would have told you for less money and less risk of disruption. Pentests earn their cost once your baseline controls are solid and you want to validate them under real attack conditions, or when a compliance framework specifically requires one.

If your cyber insurer or a prime contractor asked for a “security assessment,” don’t quietly upgrade that in your head to “penetration test.” They are priced differently, scoped differently, and answer different questions. Ask which one is actually required before you sign a statement of work.
How long does an assessment take for a small business?
For a business with 10 to 50 employees and a fairly ordinary IT setup (Microsoft 365 or Google Workspace, a handful of cloud apps, maybe a file server, no unusual regulatory scope), a cybersecurity assessment typically runs one to three weeks from kickoff to report.
That includes a discovery session (an hour or two, walking through your systems, users, and vendors), a review period (the assessor is in your environment, in your documentation, and asking follow-up questions), and a reporting phase where findings get written up and ranked.
The timeline moves for a few reasons. More locations, more systems, or multiple business units stretch the discovery phase. Regulatory scope, like a NIST 800-171 assessment for a defense contractor, adds a control-by-control mapping exercise that a general assessment skips. And responsiveness matters: an assessment that depends on your team answering questions and pulling documentation moves at the speed of your team, not the assessor’s calendar.
A NIST 800-171 assessment in particular, done for CMMC readiness, tends to run longer because it isn’t measuring general best practice, it’s measuring against 110 specific controls across 14 control families, each of which needs evidence, not just a yes or no answer. If you’re a Hampton Roads contractor sorting out where CUI lives in your environment, budget more time for that step alone, before the control mapping even starts.
What do you get at the end (what does the report look like)?
A real assessment report has three parts, and if a report you’re evaluating is missing one of them, ask why.
An executive summary. A page or two, plain language, that says roughly: here’s your overall posture, here are the two or three things that matter most, here’s the risk if nothing changes. This is what you hand to a partner, a board, or an insurer who isn’t going to read 40 pages of findings.
The findings, ranked by risk. Not a checklist of everything scanned. A ranked list: this gap is high risk because it’s exploitable and the data behind it matters; this one is lower risk because it’s inconvenient but contained. Ranking is the actual expertise being paid for. Anyone can run a scanner and dump the output.
A remediation roadmap. What to fix first, what can wait, and roughly what each fix requires: a policy change, a configuration change, a new tool, a vendor conversation. A good roadmap tells you the sequence and the reasoning, not just a task list. You should be able to hand this section to any competent IT provider, including one that isn’t Helix Stax, and have them execute against it.
If you’re pursuing compliance (CMMC, HIPAA, a specific insurer requirement), the report should map findings to the specific controls in that framework, not just general best practice. A NIST 800-171 assessment report, for instance, should reference the specific control family (access control, audit and accountability, configuration management, and so on) each finding falls under. That’s what a prime contractor or a C3PAO assessor will expect to see later.
What usually triggers the need for a cybersecurity assessment?
Five situations come up again and again.
A cyber insurance application or renewal. Carriers have gotten more specific about what they ask, and “we have antivirus” doesn’t satisfy a modern questionnaire. An assessment gives you documented answers instead of guesses, and it often surfaces the gap between what you assumed was true and what’s actually configured. See our cyber insurance requirements guide for the specific questions carriers tend to ask.
A prime contractor’s vendor questionnaire. If you do business with a larger company or a government prime, their security team eventually asks about yours. This is common for Hampton Roads subcontractors feeding into shipyard and Navy work, where the prime’s security office reviews vendors before, not after, a subcontract clears. An assessment gives you something concrete to send back instead of a policy document nobody’s updated since 2019.
A compliance deadline. CMMC, HIPAA, PCI, or a state privacy law creates a specific control requirement with a timeline attached. The assessment is step one of getting there, not the whole journey. See our CMMC requirements guide if that’s your specific trigger.
Growth or a merger. A company that added 20 employees, opened a second office, or absorbed another business through acquisition usually has security controls that were fine for the smaller version of itself and haven’t been re-checked since.
An incident, or a near-miss. Nothing focuses attention like a phishing email that almost worked, or a vendor that got breached and used your billing contact to send a fake invoice. An assessment after an incident is reactive, but it’s still the right move; it tells you whether the near-miss was luck or a real gap.
If none of these apply to you and someone is pushing an assessment anyway, ask what specifically they’re worried about. A good assessor, including us, should be able to answer that in one sentence.
What should you expect to pay for a cybersecurity assessment?
Cybersecurity assessment pricing for small businesses commonly runs from around $2,000 for a narrow, single-location review to $15,000 or more for a multi-location business with compliance scope like CMMC or HIPAA layered in. That’s a wide range because the price follows the same variables that drive the timeline: number of systems and users, number of locations, whether a specific compliance framework is in scope, and how much documentation already exists versus needs to be built from scratch.
A general assessment against the CIS Controls or NIST CSF for a single-location business under 50 employees tends to land toward the lower end of that range. A NIST 800-171 assessment for CMMC readiness costs more, because it’s measuring against 110 specific controls with evidence requirements, not general best practice; for context, the eventual CMMC C3PAO certification audit itself runs $25,000 to $150,000-plus on top of the readiness work, which is a separate cost most people don’t realize is coming. (See our CMMC vs. NIST 800-171 explainer and our CMMC compliance cost breakdown for how those costs stack.)
Be skeptical of two things at opposite ends of the market. A free assessment is usually a sales pitch wearing a report’s clothes, built to justify whatever tool the vendor already sells. And a six-figure assessment quote for a 20-person company with no unusual compliance scope is priced for a business ten times your size. Ask what framework is being used, what the deliverable looks like, and who’s actually doing the work before you accept either extreme.
Whatever you spend, you should walk away owning the report. It should be usable by any IT provider you choose, not just the one who wrote it. If an assessor’s pricing or contract implies the findings are proprietary or only actionable through them, that’s worth questioning before you sign anything.
If you want a starting point without committing to a full paid engagement first, our Free IT Assessment covers the basics in about sixty minutes and tells you whether a deeper, paid assessment is actually warranted. It’s genuinely free, not a scanner report with a sales call attached, and it’s how most Portsmouth and Hampton Roads businesses we work with started. If Helix Stax isn’t the right fit for the full engagement, you still leave with a clearer list than you walked in with. We’re based in Portsmouth and work across Hampton Roads, so if a follow-up conversation makes sense, it’s a local one.
FAQ
Do you need a cybersecurity assessment before applying for cyber insurance?
Most carriers will ask you to fill out a security questionnaire before they quote you, and an assessment is how you answer it honestly instead of guessing. If you already know your MFA coverage, backup status, and access controls, the application takes an afternoon. If you do not, the carrier’s questions become the first time anyone has actually checked.
Is a cybersecurity assessment the same as a CMMC gap analysis?
No. A general cybersecurity assessment measures your security posture against broad best practices like the CIS Controls or NIST CSF. A CMMC gap analysis measures a specific set of systems against NIST SP 800-171’s 110 controls because a DoD contract requires it. The methods overlap, but a CMMC gap analysis has a stricter scope, a specific control list, and a paper trail an assessor can review.
How often should a small business get a cybersecurity assessment?
Once a year is a reasonable baseline for most small businesses, with a re-check any time something material changes: new office, new line-of-business software, a merger, a new compliance requirement, or a security incident. Contractors under CMMC or similar frameworks usually need continuous monitoring between formal assessments, not just an annual snapshot.
Is a free cybersecurity assessment worth doing?
It depends on what’s actually being offered. A free 60-minute review that tells you whether you need a deeper paid engagement is useful and honest. A free assessment that arrives with a pre-written recommendation for a specific tool or contract is a sales pitch, not an assessment. Ask upfront what the free version covers and what happens with the findings afterward.
Frequently asked questions about Helix Stax managed IT services
Most carriers will ask you to fill out a security questionnaire before they quote you, and an assessment is how you answer it honestly instead of guessing. If you already know your MFA coverage, backup status, and access controls, the application takes an afternoon. If you do not, the carrier's questions become the first time anyone has actually checked.
No. A general cybersecurity assessment measures your security posture against broad best practices like the CIS Controls or NIST CSF. A CMMC gap analysis measures a specific set of systems against NIST SP 800-171's 110 controls because a DoD contract requires it. The methods overlap, but a CMMC gap analysis has a stricter scope, a specific control list, and a paper trail an assessor can review.
Once a year is a reasonable baseline for most small businesses, with a re-check any time something material changes: new office, new line-of-business software, a merger, a new compliance requirement, or a security incident. Contractors under CMMC or similar frameworks usually need continuous monitoring between formal assessments, not just an annual snapshot.
It depends on what's actually being offered. A free 60-minute review that tells you whether you need a deeper paid engagement is useful and honest. A free assessment that arrives with a pre-written recommendation for a specific tool or contract is a sales pitch, not an assessment. Ask upfront what the free version covers and what happens with the findings afterward.