Find what matters
Find the gaps that change your decisions—not just the ones a scanner can count.
Find the material gaps across your technology, process, and governance, then turn your findings into sequenced action.
Assessment trace / 02
Public reference route
Assessments
- 01Function
Protect / PR.AA
- 02Evidence
PR.AA-01 · identities + credentials
- 03Review
PR.AA-05 · permissions + least privilege
- 04Decision
Maintain · change · exception
- Reference
- NIST CSF 2.0
- Category
- PR.AA · Identity + access
- Output
- Evidence-backed access decision
When this path is useful
Start when pressure stops producing clarity.
- 01
You need a credible baseline before making your next investment
- 02
You have findings, but your priorities and ownership remain unclear
- 03
Your customer, board, insurer, or regulator is asking harder questions
You may be here because
Start from the moment that put the question on the table.
Security entered diligence
A fixed transaction date, a growing evidence request, and no agreed security position.
The insurance renewal got harder
Specific attestations, real consequences, one signature.
A customer sent a security questionnaire
The answers are due this week; the deal is standing behind them.
Representative scope
Work products that make the next decision easier.
Exact scope follows the organization’s stage and obligations. These are representative outputs, not fixed promises or legal, audit, or regulatory advice.
- 01Scope and decision criteria
- 02Current-control and exposure view
- 03Risk-ranked findings
- 04Leadership briefing
- 05Sequenced remediation plan
- 06Ownership and follow-through checkpoints
Engagement rhythm
A short path from context to cadence.
01
Frame
Define what the assessment must help the business decide and which systems and obligations matter most.
02
Examine
Evaluate the agreed scope across technology, process, people, and governance.
03
Prioritize
Translate findings into an owned sequence of decisions and remediation work.
Scope questions
Know what this work is—and is not.
Does every assessment include penetration testing?
No. The testing method follows the decision, scope, and systems involved. Ackatec defines that scope before work begins.
Will we receive a list of findings?
Yes, where findings are part of the agreed scope, but the emphasis is on materiality, ownership, and the sequence of action—not volume.
Begin with the decision
