
Security Assessment with Implementation
No shelf reports. Assessment with measures.
Know where you stand, then do the right things
Most companies have done a security assessment at some point. The result sits on a hard drive. What is missing is someone who translates the findings into measures and supports the implementation. An assessment without implementation is an expensive inventory. An assessment with implementation is a measurable security gain.
Why it matters:
An 80-page PDF that no one reads improves nothing. We deliver a prioritized inventory with an action plan that actually gets implemented. Prioritized by business risk, not by technical elegance, and sized to the real risk, not to a vendor's product catalog.
What you receive:
- Current-state review: technology, processes, organization, compliance
- Gap analysis against relevant standards (ISO 27001, NIST CSF, CIS Controls, ISG)
- Prioritization by business risk
- Implementation support for the top measures, with partners where needed
- Follow-up check: is the improvement measurable?
How it works
From current-state review to measured improvement.

Current-state review & gap analysis
Where do you really stand, measured against relevant standards?
- Technology, processes, organization
- Gap against ISO 27001, NIST CSF, CIS
- Interviews and configuration review
- Benchmark

Prioritization by risk
Not everything at once, but the most important first.
- Prioritization by business risk
- Cost-benefit assessment
- Action roadmap
- Management report with KPIs

Implementation & follow-up
We stay until the measures take effect.
- Implementation support for top measures
- Partners for specialist topics
- Follow-up check and measurement
- Documented progress
A frequent focus: Microsoft 365
We review licenses, configuration, Conditional Access, Defender, and hardening. Often it turns out that existing licenses already provide the protection needed and only have to be configured correctly, instead of buying something new.
The ODCUS difference
We do not just assess, we implement. When existing tools already do the job and are only misconfigured, we say so. Even when the recommendation is: spend less.
Who this fits
- Companies that want to know where they stand before they invest
- After a security incident or audit finding
- An old assessment exists, none of it implemented
- The feeling of spending too much on security without an overview
- Cyber insurance renewal with new requirements
Proof from practice
- Gap assessment vs. CIS Critical Security Controls at a 3,600-employee industrial company: interviews, questionnaires, benchmark, priority roadmap, implementation support, management report with KPIs
- M365 tenant review and security hardening at more than 10 companies (various industries and sizes)
- Assessment led to an Intune project, acquired and delivered with a partner
- SOC built (Microsoft Sentinel, Defender XDR, KQL detection rules, MITRE framework)
What sets your assessment apart from a penetration test?
A pentest looks for technical vulnerabilities in a defined scope. Our assessment evaluates the entire security posture, technology, processes, and organization, against relevant standards and delivers a prioritized action plan with implementation.
Do we just get a report?
No, that is the whole point. The report is the beginning. We support the implementation of the most important measures and verify afterward whether the improvement is measurable.
How long does an assessment take?
Depending on size, two to six weeks for the assessment, after which implementation support runs for as long as the prioritized measures take.
Security assessment, audit or security review, what is the difference?
The terms are often used synonymously. An audit checks against a specific standard, an assessment captures the overall picture. We deliver both with implementation: a structured IT security review with prioritized measures.
Which standards do you assess against?
Depending on the goal, ISO 27001, NIST CSF, CIS Controls or the ISG requirements. We choose the framework that fits your industry and your customer requirements.
Does an assessment make sense for Microsoft 365 too?
Yes, that is a frequent focus. We review licenses, conditional access, Defender and hardening. Often existing licenses already provide the necessary protection and only need to be configured correctly.
"With ODCUS, we have a partner by our side who not only understands our IT but also tackles our challenges with us."
Assessment that turns into measures
Discuss without obligation where your security stands and what to do first. In 30 minutes you know where you stand.



