Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

What an Enterprise Security Review Covers

Direct answer: An enterprise security review is a point-in-time assessment of your whole security posture across people, process and technology, and its output is a risk-ranked roadmap rather than a pass or a fail. It is not an audit, because nobody signs an attestation at the end. It is not a penetration test, because it is far broader than one application. It is the step that tells you where you stand across the organization so you can decide what to fix and in what order, with the expensive problems at the top.

What it is, and what it is not

The phrase gets used loosely, so it is worth being exact. An enterprise security review looks at your security programme as a whole and reports a prioritised view of your risk. It does not produce a SOC 2 report or an ISO 27001 certificate, which only a licensed CPA firm or an accredited certification body can issue. It is not a penetration test, which goes deep on one application or network to find exploitable flaws. And it is broader than a framework gap assessment, which measures you against one standard. A review can take the frameworks into account, but its job is to tell you the truth about your posture, not to score you against a single rulebook.

People

Security is mostly people, so the review starts there. It looks at how security is owned and whether anyone senior is actually accountable for it. It looks at awareness and whether training runs and lands. And it looks hard at the access lifecycle: how people get access, whether privilege is controlled, and whether access is removed when someone leaves. Offboarding is the recurring finding, because the account that was never disabled is both the easiest thing to fix and the most common way in.

Process

The process layer is where posture is either real or performative. The review covers your policies and whether they describe what you actually do, how you manage risk and whether anything is recorded, your incident response plan and whether it has ever been exercised, how you manage vendors and the data you hand them, how changes reach production, and whether you could recover the business if a site or a system went down. The common pattern is a stack of well-written policies with no evidence anyone operates them, which is a process finding, not a documentation one.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Technology

The technology layer is the one people expect, and it is the easiest to over-index on. The review looks at identity and whether MFA is enforced, endpoint protection and coverage, cloud configuration against sane baselines, network boundaries, logging and whether anyone would notice an incident, backups and whether they have been restore-tested, and the security of the applications you build. The point is breadth, not depth on any one thing. A review that finds unenforced MFA, public cloud storage and backups nobody has restored has found more real risk than a narrow look at a single service would.

Want to know where you actually stand? An enterprise security review gives you a point-in-time read across people, process and technology and a risk-ranked roadmap, from $7,500. Enterprise security review

The deliverable: a risk-ranked roadmap

The value of a review is entirely in its output, and a weak one is easy to spot. A scanner export with a logo on it lists hundreds of findings with no judgement about which ones matter, and hands the prioritisation back to you. A real review does the opposite. Each finding is scored by impact and likelihood, so a theoretical issue on an internal tool does not outrank an unenforced admin login on a production system. The findings are then sequenced into a roadmap with owners and a sense of effort, so the first thing you read is what to do on Monday, not a list of three hundred things ordered by the tool that found them. The test of a review is whether a founder or a board can act on page one without a translator.

Who buys one and when

Reviews cluster around moments of change. Before a fundraise, when an investor will run technical due diligence and you would rather find the problems first. After an incident, when you need an honest account of what else is exposed. When a new security leader starts and wants a baseline they did not inherit the blind spots of. Before committing to a framework, to decide whether SOC 2 or ISO 27001 is even the right next spend. And when a board starts asking security questions that the team cannot currently answer with evidence. In each case the review is the cheap step that stops you spending on the wrong fix.

How it differs from the two-phase readiness model

If you have looked at our compliance work you will know we scope it in two phases: a Phase 1 gap assessment that sets scope and produces a findings register, then a Phase 2 remediation priced from those findings. An enterprise security review is related but broader. A gap assessment measures you against one framework. A review measures your whole posture and is not tied to a standard, which makes it the better first purchase when you do not yet know which framework, or whether a framework is even the question. The honest version of pricing both is the same: remediation is scoped after the review, not before, because until the review is done nobody knows what the gaps are. Any firm that quotes you a fixed fix-everything number before looking is guessing.

The review is led by a practitioner rather than handed to a checklist. Our Principal, Jacob Masse, has five published CVEs on our research page, which is the kind of credential worth asking any reviewer for, because a review is only as good as the judgement ranking the findings. If you want a lighter, free starting point before committing to a full review, our security programme scorecard gives you a quick self-assessment across the same three layers.

Is an enterprise security review an audit?

No. An audit ends in an attestation signed by an independent licensed firm. A review ends in a roadmap you own and act on. They answer different questions: an audit proves a position to a third party, a review tells you what your position actually is.

How is it different from a penetration test?

A penetration test goes deep on one application or network to find exploitable vulnerabilities. A review goes wide across people, process and technology. Most organizations need both eventually, but the review is usually the better first step because it tells you whether the pentest is even where your risk is.

What do we get at the end?

A written report with findings scored by impact and likelihood, sequenced into a roadmap with owners and effort, and a readout that a non-technical board or investor can follow. The roadmap, not the finding count, is the thing you are buying.

Want a clear read on your posture? An enterprise security review across people, process and technology, from $7,500, ending in a risk-ranked roadmap you can hand to your board and act on.

Enterprise security reviewOr book a call

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.