
Security Risk Assessments
A security risk assessment you can operate — not a 60-page shelfware PDF.
A SAINT security risk assessment is a scoped review of how your identity, email, endpoints, backup, and network actually run — mapped to NIST CSF language and the questionnaire in front of you (cyber insurance, HIPAA-readiness, CMMC, board). You leave with must-fix / should-fix / later, owners, and a written plan. It is not a pentest, not a compliance certificate, and not a Huntress (or Guardz) sales call. If you want us to operate the fixes afterward, we pick Huntress or Guardz as the cyber stack — one or the other — after the report, not as the backbone of the assessment itself.
Identity, email, endpoints, backup, network — documented current state
Written roadmap; optional operate-it engagement after
Estimate-only catalog tile exists; labor and electrical are not in retail planning totals

Capabilities
What this engagement covers
Showing Current-state inventory: Modern glass-walled office corridor with track lighting and a breakroom kitchen
Standards we reference — alignment, not certification
These are the languages we write the report in. We are not selling a certified-assessor badge for any of them.
- 01NIST Cybersecurity FrameworkPrimary Identify / Protect / Detect / Respond / Recover mappingReference
- 02CIS ControlsPractical safeguard set — IG language where it fits SMB opsReference
- 03CISA Cyber Performance GoalsBaseline goals carriers and civic buyers increasingly ask aboutReference
- 04MITRE ATT&CKDetection-coverage language when we talk about what you’d actually catchReference
Frequently asked
Is this the same as a vCISO engagement?+
No. This is a time-boxed assessment and written plan. vCISO is ongoing fractional leadership. Many clients start here and only retain vCISO if they need someone on the insurance and board cadence. See /risk-advisory-vciso.
Do I have to buy Huntress or Guardz?+
Is the catalog price a binding quote?+
No. The Security Risk Assessment tile on /products/services is SAINT retail for planning. Labor is not included in those totals. A formal proposal follows discovery. See /pricing for how we bill.
Will you certify us against NIST, CIS, HIPAA, or CMMC?+
No. We align and evidence. Auditors, carriers, and C3PAOs determine outcomes. We will not sell a fake certificate.
Lincoln or Omaha — is this remote or on-site?+
Both, sized to the environment. Lincoln is a short drive from Hickman; Omaha-metro is scheduled on-site when walking the office adds value. No storefront. Hubs: /locations/lincoln-ne · /locations/omaha-ne.
Lincoln & Omaha — how this actually shows up locally
Lincoln, NE
Lincoln, NE hubLincoln security risk assessments — clinics, offices, civic-adjacent.
Haymarket professional offices, independent clinics, and small-municipal environments get a written gap list mapped to the questionnaire they actually have — not a coastal PDF mill. Hickman-based; no Lincoln storefront.
Omaha, NE
Omaha, NE hubOmaha-metro assessments for multi-site identity and email risk.
Omaha work is often several buildings and one messy tenant. We assess identity, email, and backup as one surface — then you decide whether Huntress, Guardz, or neither is the operate-it path. Scheduled on-site; no Omaha HQ.
Related
Keep going.
- 01Assessments hubOpen
- 02vCISO / risk advisoryOpen
- 03CybersecurityOpen
- 04Vendor assessmentsOpen
- 05Physical assessmentsOpen
- 06Critical infrastructureOpen
- 07Assessment guide (blog)Open
- 08Insurability checkOpen
- 09How we priceOpen
- 10HealthcareOpen
- 11ManufacturingOpen
- 12Municipal governmentOpen
- 13Professional servicesOpen
- 14Huntress partnerOpen
- 15Guardz partnerOpen
- 16Lincoln, NEOpen
- 17Omaha, NEOpen

Ready to see where you stand?
A short call, an honest assessment, and a written plan. No pressure to switch providers if you’re already in good hands.
15 minutes. NIST-aligned report. No obligation.





