Security Assessments

Choosing a Security Assessment Partner: What to Look For and What to Ask

Two proposals with the same title can describe wildly different levels of work. Here's what a real assessment includes — and the questions to ask before you sign.

W. Scott Montgomery

Choosing a Security Assessment Partner: What to Look For and What to Ask
Choosing a Security Assessment Partner: What to Look For and What to Ask

If you're reading this, you've probably already decided that your organization needs an independent look at its security posture. Maybe an examiner or auditor is asking for evidence. Maybe your cyber insurance carrier wants a recent assessment. Or maybe you simply want a straight answer to a question every leadership team eventually asks: how exposed are we, really?

The harder decision isn't whether to get a security assessment — it's who should perform it. The market is crowded, the terminology is inconsistent, and two proposals with the same title can describe wildly different levels of work. One vendor's "security assessment" is a single automated scan with a canned PDF. Another's is a genuine, multi-layered evaluation of your network, identity systems, cloud environment, and physical controls, delivered with analysis you can actually act on.

At Digital Elevation, we've spent decades on both sides of this conversation. This post shares what we believe a quality security assessment should include — and, just as importantly, the questions you should be asking any vendor (including us) before you sign an engagement.

What a complete security assessment should cover

A meaningful assessment looks at your environment from multiple angles, because attackers do. When you compare proposals, check whether each of the following areas is explicitly in scope.

1. Full network discovery — before anything gets scanned

You can't assess what you haven't found. A quality engagement begins with systematic discovery and mapping of every computing asset in your environment. At Digital Elevation, we use advanced NMAP-based footprinting to build a complete picture of your network before any vulnerability analysis begins. Unknown and unmanaged devices are among the most common findings we uncover — and often the most dangerous.

2. Vulnerability scanning from three perspectives

Not all scans are equal, and a single scan type tells only part of the story. A thorough assessment should include:

  • Detailed (non-authenticated) scanning — scans that reveal what an attacker on your network would see, using policies tuned for comprehensive results with minimal network impact.
  • Authenticated scanning — deep, credentialed inspection of Windows workstations and servers from the inside out, to identify missing patches, misconfigurations, and weaknesses invisible to an outside-in scan.
  • External scanning — assessment of your public IP space to identify what the entire internet can see and probe.

We perform all three using customized Tenable Nessus Professional policies. If a vendor only offers one perspective, you're getting a partial picture.

3. Your Microsoft environment: on-premises and cloud

For most mid-market organizations, identity is the new perimeter. Active Directory and Microsoft 365 are where attackers go first, so your assessment should go there too. Look for explicit coverage of domain configuration, user account security, group policy, and administrative privilege; in-depth password security analysis, including identification of weak or compromised credentials; and a full Entra ID and M365 security audit covering cloud identity, access management, and security posture. An assessment that ignores your cloud tenant is assessing the organization you were five years ago.

4. The areas that often get skipped

Wireless security, network infrastructure (firewalls, routers, switches, segmentation), physical access controls, and exposure to current malware, zero-day vulnerabilities, and publicly available exploits are the domains that separate a checkbox exercise from a real evaluation. Digital Elevation includes them because breaches don't respect scope boundaries.

As a result, we also conduct penetration testing: ethical, real-world attack simulation that validates whether identified vulnerabilities are actually exploitable and whether your security controls hold up under pressure.

5. Reporting your whole organization can use

An assessment is only as valuable as the decisions it enables. Insist on reporting tailored to different audiences. Your board needs a clear executive summary and security ratings they can govern from. Your IT team needs technical detail — vulnerabilities by device, by severity, by public exploit availability — plus a solutions report with concrete remediation guidance and an exception tracking checklist. And if this isn't your first assessment, ask for historical comparison and trend analysis so you can demonstrate measurable improvement and ROI on your security investments. A vendor who hands everyone the same 400-page scanner export hasn't finished the job.

Not a commodity. Not a leap of faith.

A security assessment shouldn't be either one. Ask hard questions. Demand specific answers. Any vendor worth engaging will welcome the scrutiny.

Ten questions to ask any security assessment vendor

Whether you're evaluating Digital Elevation or anyone else, these questions will quickly separate genuine security practitioners from report resellers.

1. How do you discover assets before you scan? What happens when you find devices we didn't know about?
Why it matters: Vendors who scan only the IP ranges you hand them will miss the shadow IT and forgotten systems that cause real breaches. Discovery should be systematic, not assumed.

2. Do you perform authenticated (credentialed) scanning, or only unauthenticated scans?
Why it matters: Unauthenticated scans alone miss the majority of internal weaknesses. Credentialed scanning of workstations and servers is where the substantive findings live — and it requires a vendor you can trust with that access.

3. Is our external, internet-facing footprint explicitly in scope?
Why it matters: Your public exposure is what opportunistic attackers probe first. If external scanning is an add-on or an afterthought, ask why.

4. How deeply do you assess Active Directory, Entra ID, and Microsoft 365?
Why it matters: Identity compromise drives most modern attacks. A vendor who can't articulate their methodology for privilege review, password analysis, and cloud tenant configuration isn't assessing your real risk.

5. What scanning tools and policies do you use, and how are they tuned for our environment?
Why it matters: Default scanner policies can disrupt production systems or drown you in noise. Look for customized policies designed for thorough results with minimal business impact — and a vendor willing to name their tooling.

6. What report formats will we receive, and for which audiences?
Why it matters: Ask to see sanitized samples. You should expect board-level and executive reporting, detailed technical breakdowns, prioritized remediation guidance, and a mechanism for tracking exceptions to closure.

7. How do you prioritize findings — and will you tell us what to fix first?
Why it matters: A list of 500 vulnerabilities is data, not intelligence. The deliverable should focus your team's remediation effort where it matters most, including flagging vulnerabilities with publicly available exploits.

8. Can you compare results against our previous assessments to show trends?
Why it matters: Security programs are judged over time. Trend analysis lets you demonstrate improvement to your board, your examiners, and your insurers — and shows that the assessment paid for itself.

9. What happens after the report is delivered?
Why it matters: The best vendors offer remediation guidance, answer questions during your cleanup, and provide follow-up assessments to verify progress. If the relationship ends when the PDF arrives, keep looking.

10. How do you protect our data during and after the engagement?
Why it matters: An assessment vendor sees your organization at its most exposed. Ask about confidentiality protocols, credential handling, and how findings are stored and destroyed. The answers should be specific and confident.

Where Digital Elevation stands

We built our Security Assessment Services (SAS) offering to answer every one of these questions — because they're the same questions we'd ask if we were sitting on your side of the table.

  • Expertise you can trust — a team with extensive, real-world experience in vulnerability assessment, penetration testing, and security architecture.
  • Minimal business disruption — customized scanning policies engineered for thorough coverage without disrupting your network or your business.
  • Actionable intelligence — clear, prioritized recommendations that tell your team exactly where to focus first.
  • Comprehensive coverage — network, cloud, wireless, physical, and identity; your entire security posture, not a slice of it.
  • Ongoing support — detailed documentation, remediation guidance, and follow-up assessments that track your improvement over time.
  • Confidentiality guaranteed — strict confidentiality protocols from kickoff through closeout. Your data stays secure and private.

Ready to pressure-test a proposal?

Bring us the ten questions. Bring us someone else's proposal. We'll answer honestly either way.

Start the conversation arrow_forward

W. Scott Montgomery is Director of Security at Digital Elevation, where he leads the firm's security assessment and advisory practice. With more than 40 years of IT experience, Scott helps mid-market organizations, credit unions, and healthcare firms build practical, defensible security programs — from vulnerability management and examination readiness to compliance across frameworks including NIST CSF, FFIEC, GLBA, and HIPAA.

Share this post