Direct answer: An enterprise security review is a point-in-time assessment of your whole security posture across people, process and technology, and its output is a risk-ranked roadmap rather than a pass or a fail. It is not an audit, because nobody signs an attestation at the end. It is not a penetration test, because it is far broader than one application. It is the step that tells you where you stand across the organization so you can decide what to fix and in what order, with the expensive problems at the top.
What it is, and what it is not
The phrase gets used loosely, so it is worth being exact. An enterprise security review looks at your security programme as a whole and reports a prioritised view of your risk. It does not produce a SOC 2 report or an ISO 27001 certificate, which only a licensed CPA firm or an accredited certification body can issue. It is not a penetration test, which goes deep on one application or network to find exploitable flaws. And it is broader than a framework gap assessment, which measures you against one standard. A review can take the frameworks into account, but its job is to tell you the truth about your posture, not to score you against a single rulebook.
People
Security is mostly people, so the review starts there. It looks at how security is owned and whether anyone senior is actually accountable for it. It looks at awareness and whether training runs and lands. And it looks hard at the access lifecycle: how people get access, whether privilege is controlled, and whether access is removed when someone leaves. Offboarding is the recurring finding, because the account that was never disabled is both the easiest thing to fix and the most common way in.
Process
The process layer is where posture is either real or performative. The review covers your policies and whether they describe what you actually do, how you manage risk and whether anything is recorded, your incident response plan and whether it has ever been exercised, how you manage vendors and the data you hand them, how changes reach production, and whether you could recover the business if a site or a system went down. The common pattern is a stack of well-written policies with no evidence anyone operates them, which is a process finding, not a documentation one.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
Technology
The technology layer is the one people expect, and it is the easiest to over-index on. The review looks at identity and whether MFA is enforced, endpoint protection and coverage, cloud configuration against sane baselines, network boundaries, logging and whether anyone would notice an incident, backups and whether they have been restore-tested, and the security of the applications you build. The point is breadth, not depth on any one thing. A review that finds unenforced MFA, public cloud storage and backups nobody has restored has found more real risk than a narrow look at a single service would.
The deliverable: a risk-ranked roadmap
The value of a review is entirely in its output, and a weak one is easy to spot. A scanner export with a logo on it lists hundreds of findings with no judgement about which ones matter, and hands the prioritisation back to you. A real review does the opposite. Each finding is scored by impact and likelihood, so a theoretical issue on an internal tool does not outrank an unenforced admin login on a production system. The findings are then sequenced into a roadmap with owners and a sense of effort, so the first thing you read is what to do on Monday, not a list of three hundred things ordered by the tool that found them. The test of a review is whether a founder or a board can act on page one without a translator.
Who buys one and when
Reviews cluster around moments of change. Before a fundraise, when an investor will run technical due diligence and you would rather find the problems first. After an incident, when you need an honest account of what else is exposed. When a new security leader starts and wants a baseline they did not inherit the blind spots of. Before committing to a framework, to decide whether SOC 2 or ISO 27001 is even the right next spend. And when a board starts asking security questions that the team cannot currently answer with evidence. In each case the review is the cheap step that stops you spending on the wrong fix.
How it differs from the two-phase readiness model
If you have looked at our compliance work you will know we scope it in two phases: a Phase 1 gap assessment that sets scope and produces a findings register, then a Phase 2 remediation priced from those findings. An enterprise security review is related but broader. A gap assessment measures you against one framework. A review measures your whole posture and is not tied to a standard, which makes it the better first purchase when you do not yet know which framework, or whether a framework is even the question. The honest version of pricing both is the same: remediation is scoped after the review, not before, because until the review is done nobody knows what the gaps are. Any firm that quotes you a fixed fix-everything number before looking is guessing.
The review is led by a practitioner rather than handed to a checklist. Our Principal, Jacob Masse, has five published CVEs on our research page, which is the kind of credential worth asking any reviewer for, because a review is only as good as the judgement ranking the findings. If you want a lighter, free starting point before committing to a full review, our security programme scorecard gives you a quick self-assessment across the same three layers.
Is an enterprise security review an audit?
No. An audit ends in an attestation signed by an independent licensed firm. A review ends in a roadmap you own and act on. They answer different questions: an audit proves a position to a third party, a review tells you what your position actually is.
How is it different from a penetration test?
A penetration test goes deep on one application or network to find exploitable vulnerabilities. A review goes wide across people, process and technology. Most organizations need both eventually, but the review is usually the better first step because it tells you whether the pentest is even where your risk is.
What do we get at the end?
A written report with findings scored by impact and likelihood, sequenced into a roadmap with owners and effort, and a readout that a non-technical board or investor can follow. The roadmap, not the finding count, is the thing you are buying.
Want a clear read on your posture? An enterprise security review across people, process and technology, from $7,500, ending in a risk-ranked roadmap you can hand to your board and act on.
Enterprise security reviewOr book a call