CPA · CISA · CISM · CDPSE · CCSE · MBA
Security analyst conducting a NIST cybersecurity framework risk assessment for a California business

Cybersecurity Risk Assessment and Framework Readiness

NIST, ISO 27001, PCI DSS and CMMC assessment, with findings expressed as business exposure rather than a severity count.

What makes a cybersecurity risk assessment in California worth acting on?

Findings expressed as business exposure rather than a severity count. The usual output is several hundred rated findings, no sense of which would actually cost money, and no order in which to address them. Starting instead from what a material incident would cost this specific company, in lost revenue, notification and legal exposure, produces a sequence someone can fund. Frameworks covered are NIST, ISO 27001, PCI DSS and CMMC.

A cybersecurity risk assessment in California is commissioned for one of two audiences, and which one it is ought to decide what the document contains: a board that has to fund something, or a customer's security questionnaire that has to be answered.

Assessments here are built for the first audience and they survive the second. Frameworks are used as a checklist of what to examine rather than as the structure of the report, because PCI DSS, ISO 27001 and CMMC all describe controls well and none of them tells a board which control to buy this quarter.

Frameworks a cybersecurity risk assessment in California is measured against

NIST Cybersecurity Framework. The most useful general-purpose framework for a company with no specific regulatory driver. Its function-level structure maps well to how executives think about the problem, and the maturity tiers give a defensible way to express where you are and where you should be.

NIST SP 800-53 and 800-171. Relevant to federal contractors and their supply chain, where the control set is prescribed rather than chosen.

ISO 27001 and 27002. Where an international customer base or a certification requirement makes a formal ISMS worth the overhead. Assessment and readiness here; certification itself requires an accredited certification body.

PCI DSS. For card-accepting businesses, where scoping is the entire game. Most PCI cost is incurred by organisations that never properly reduced their cardholder data environment and are therefore assessing systems that need not be in scope at all.

CMMC. For the defence supply chain, where the level required depends on the information handled and the assessment route differs accordingly.

FFIEC. For financial institutions, drawing on twenty years of auditing banks, insurers and mortgage companies, and on knowing what an examiner actually opens first.

These overlap substantially. A company pursuing SOC 2 and ISO 27001 and preparing for a customer security questionnaire is usually documenting the same controls three times. Mapping once and testing once is where the cost comes out.

Translating technical findings into financial exposure

This is the part that distinguishes the work, and it comes from the CPA side rather than the security side.

A finding that "MFA is not enforced on the VPN" tells a board nothing actionable. The same finding expressed as: this permits credential-based access to the finance systems; the systems hold the payment approval function; a business email compromise in a comparable company in this sector costs a six-figure sum on average; the compensating control is a call-back verification that currently exists as an informal habit rather than a required step; that is a decision a board can make.

Constructing that translation requires knowing what the systems do financially, what the fraud patterns actually are, and what an incident costs when the notification obligations, the forensic engagement and the customer attrition are all counted. It is the reason this assessment sits inside a CPA practice rather than a security consultancy.

Third-party and vendor risk

For most mid-market companies the largest realistic exposure is not their own infrastructure; it is the twenty to two hundred SaaS vendors and service providers holding their data, of which finance can typically name a dozen.

Work here covers building an actual inventory (usually via expense analysis and SSO logs, since the vendor list nobody maintains is always incomplete), tiering by data sensitivity and business dependency, obtaining and reading SOC 2 or ISO certificates for the material ones, mapping complementary user entity controls to an owner, and reviewing contractual security and breach-notification terms.

The finding that recurs: a critical vendor with no security documentation, no contractual breach notification obligation, and a contract that renewed automatically four times.

What is deliberately not offered

This is an assessment and advisory practice, not a security operations provider. There is no penetration testing performed in-house, no managed detection and response, no endpoint or firewall management, no 24/7 monitoring.

Where penetration testing is required (and for SOC 2 or PCI it generally is) the work is scoped and a specialist firm is engaged, with their findings integrated into the assessment. Several capable MSSPs operate in Thousand Oaks and across Ventura County for the operational side.

Stating the boundary matters because the assessment's value depends on independence from the remediation. An assessor selling the tools they recommend is not assessing.

Reporting for two audiences

Every engagement produces two documents, because the audiences need different things and combining them serves neither.

The technical findings register goes to IT: specific, evidenced, with a remediation approach and the sequence dependencies noted.

The executive report runs to a handful of pages: what the material exposures are in business terms, what remediation would cost, what residual risk remains after it, and what the board is being asked to accept. Where useful this is presented directly to the board, which pairs with the oversight work described on the governance advisory page.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Framework-based control assessment (NIST CSF, 800-171, ISO 27001, PCI DSS, CMMC or FFIEC)
  • Business impact analysis quantifying incident exposure in financial terms
  • Third-party and vendor risk inventory with tiering and documentation review
  • Complementary user entity control mapping with named owners
  • Technical findings register with evidence and remediation approach
  • Executive and board report expressing exposure in business terms
  • Prioritised remediation roadmap sequenced by dependency and impact
  • Multi-framework control mapping to eliminate duplicated compliance effort
  • Penetration test scoping and vendor selection support

How a typical engagement runs

  1. Establish what matters

    What data the business holds, which systems it cannot operate without, and what a material incident would actually cost. Everything downstream is ranked against this.

  2. Assess

    Control assessment against the chosen framework using documentation review, configuration inspection and interviews with the people who operate the controls day to day.

  3. Quantify

    Findings translated into exposure, what each one enables, how likely it is, what compensating controls exist, and what the consequence would be in dollars.

  4. Sequence and report

    A remediation roadmap ordered by exposure reduction per unit of effort, plus separate technical and executive reporting.

Cybersecurity Risk Assessment across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

Cybersecurity Risk Assessment: questions we are asked

Not answered here? Ask Javed directly

Which framework should we use?

If nothing external is dictating the answer, NIST CSF. It is free, well-structured, maps cleanly to executive conversation, and gives a defensible maturity target.

Otherwise the requirement chooses for you: PCI DSS if you take cards, CMMC or 800-171 for defence supply chain, ISO 27001 where a customer or an international market demands certification, FFIEC if you are a financial institution, and SOC 2 where enterprise customers are asking; which is a different kind of instrument, covered on the SOC 2 page.

Do you perform penetration testing?

No, and that is deliberate. Penetration testing is a specialist discipline and it should be performed by someone independent of the party assessing and advising on remediation.

What is provided is scoping (defining what should be tested and to what depth) selection support, and integration of the results into the wider risk assessment so the findings are ranked alongside everything else rather than sitting in a separate report.

How often should an assessment be repeated?

Annually for the framework assessment where a compliance obligation exists, or every two years where the environment is stable and no external requirement applies.

More usefully, reassess on change rather than on calendar: a significant new system, a cloud migration, an acquisition, a shift to remote working, or a new category of data. Those events change the exposure far more than twelve months of ordinary operation.

Our IT is fully outsourced. Is this still our responsibility?

Yes. Outsourcing the function does not transfer the accountability, regulators, customers and courts hold the data controller responsible, not the provider.

What changes is where the assessment looks. It examines what your provider is contracted to do versus what they actually do, whether their own security posture is documented, whether contractual breach-notification terms exist and are workable, and (most commonly missed) which controls the provider assumes you are performing. That last item is where the gaps usually sit, because both parties assume the other has it covered.

What does an assessment cost and how long does it take?

A NIST CSF assessment for a single-site company with straightforward infrastructure typically runs three to four weeks. ISO 27001 or PCI DSS readiness runs longer because the control sets are more prescriptive and the evidence expectations higher.

The main cost variables are the number of systems and locations, whether an existing assessment exists to build on, and the size of the vendor population, since third-party review scales directly with the number of material vendors.

Related services

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about cybersecurity risk assessment

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a cybersecurity risk assessment engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now