Evaluation

An evaluation executed against the organization’s real environment.

The evaluation period operates on production infrastructure rather than a demonstration environment. At its conclusion, the organization holds the security index, the list of critical risks identified, and the recommended action for each item, irrespective of the contracting decision.

  • No credit card required
  • Activated in one business day
  • Scope recorded in contract

Register for the evaluation

Optional field. Shortens the time to schedule the scoping meeting.

Step by step

Stages of the evaluation process

  1. Day 1

    Registration

    Registration of contact and organization details. No credit card is required at any stage of the evaluation period.

  2. Day 2

    Scoping meeting

    A thirty-minute session to survey the environment, formally define the monitoring scope, and grant the access required for execution.

  3. First week

    Scan execution

    Delivery of the initial security index and the prioritized risk queue, with asset identification and a recommended action for each record.

  4. Conclusion

    Contracting decision

    The decision is taken on the basis of results obtained in the organization’s own environment. The technical report for the period remains with the organization.

Scope

Boundaries of the evaluation period.

The purpose of the evaluation is to establish the organization’s security position, not to present a tour of features.

Included in scope

  • Platform access in line with the scope defined at implementation
  • A scan of the organization’s external surface
  • Vulnerability scanning across the agreed assets
  • Security index and prioritized remediation queue
  • Artificial intelligence assistant in operation
  • Executive report of findings for the period
  • Support from the CyberSeven team throughout the evaluation

Not included in scope

  • Execution of corrections in the environment without formal approval
  • Response to an incident in progress, which constitutes a distinct service
  • Issuing a certificate or compliance seal
  • Integration with third-party tools outside the agreed scope

On your side

Requirements from the organization

Conditions necessary to execute the evaluation, recorded in advance.

Technical point of contact

A professional with basic knowledge of the infrastructure, from the internal IT team or the vendor responsible for administering the environment.

Formal authorization

Executing a security scan requires authorization from whoever is legally accountable for the organization, recorded before any verification takes place.

Calendar availability

Thirty minutes for the scoping meeting. Subsequent follow-up is conducted by the platform itself.

Questions

Frequently asked questions about the evaluation

Does the evaluation require software installation?

Monitoring the external surface requires no installation, since verification is executed from outside the perimeter. Monitoring the internal network requires an agent installed on a machine in the network, carried out jointly with the organization during the scoping meeting.

Can scanning affect system availability?

Scans are parameterised to operate without impact on availability, and both the scope and the execution window are agreed in advance. Sensitive equipment, such as medical devices and industrial control systems, is handled through passive verification.

How long does the evaluation period last?

The term is defined at the scoping meeting, together with the breadth of monitoring. The commitment given is delivery of the initial security index and the prioritized queue within the first week.

What conditions apply if the organization does not proceed?

Platform access is terminated and the technical report of findings remains with the organization. There is no penalty, retroactive charge, or minimum term, since the evaluation precedes any contractual commitment.

How frequent is contact during the evaluation?

The process provides for the scoping meeting, one interim contact for clarifications, and a closing contact. The organization may elect to conduct communication exclusively by email.