Validate Your Defences

A CIS 18 assessment may be the wake-up call you need

Does your business have a mix of technical controls and management processes? Firewalls, policies, MFA, risk assessments, audits? All of these have value. But here is the uncomfortable truth: you need to make sure they perform in a real attack.

This is where an assessment that gives weight to both technology and GRC becomes useful.

What is CIS 18?

CIS 18 is a framework, currently at V8, and it focuses on a simple idea: stop guessing how secure you are, and start testing it.

  • It is not a technical exercise where somebody runs a tool and dumps the results
  • It is not management slides, and it is not compliance theatre

CIS 18 sits in the middle, where realistic security meets practical decisions.

What we see when we run them

When we carry out CIS 18 assessments with clients, a pattern shows up.

A bar chart titled Implementation Group Scores, with eighteen bars numbered 1 to 18 whose values range from 15 to 90 per cent
Each of the eighteen controls gets its own score, and the spread between them is usually where the conversation starts.

We find technical gaps that policies never reveal. An old privilege, a misconfiguration, or a service nobody has touched in years.

There are management controls that work in theory but not in practice. Incident response plans nobody has tested. Procedures that do not match reality. Tools nobody is watching.

And there are service providers doing good work which, for one reason or another, does not fit your risk appetite, or even what you thought you had bought.

How we approach it

The PB Security approach to CIS 18 is simple and balanced.

  • First a scoping session, to understand your environment
  • Then an interview that assesses your maturity, verification of your existing controls, and a real test of your technical setup, where we attempt to compromise you
  • Finally a review aimed at management, and a technical walkthrough for your IT team. Our reporting contains a clear overview of the items you need to act on

If you need help building a remediation plan, or fixing the problems themselves, PB Security can be useful there too.

Who should consider one?

It is a sensible move if you:

  • Are unsure about your current security posture
  • Rely on cloud or hybrid setups
  • Need to validate recent security investments
  • Are preparing for NIS2 or other customer requirements

Fundamentally: if you depend on security controls, you should test them.

One last thought

CIS 18 is valuable because it is balanced. It does not get lost in technical noise, and it does not drift away into management buzzwords.

It is an opportunity to see your security the way an attacker would, and to improve based on protecting what actually matters.

← All articles

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us