Security Gap Assessment

Measure your security posture against industry frameworks. Identify gaps, quantify risk, and build a prioritized roadmap to close the vulnerabilities that matter most.

You Cannot Fix What You Cannot Measure

Mjolnir Security's Gap Assessment provides an objective, evidence-based evaluation of your security posture against the frameworks that matter to your organization and industry. We do not just check boxes — we assess the actual operational effectiveness of your controls, interview the teams who operate them, and validate findings through technical testing where appropriate.

The output is not a generic report full of theoretical recommendations. It is a prioritized, actionable roadmap that aligns security investments with business risk and gives your leadership team the data they need to make informed decisions about resource allocation.

Frameworks We Assess Against

NIST Cybersecurity Framework (CSF)

The NIST CSF provides a comprehensive, risk-based approach to cybersecurity organized around five core functions — Identify, Protect, Detect, Respond, and Recover. We assess your implementation tier across all categories and subcategories, establishing both current state and target state maturity levels:

ISO 27001

For organizations pursuing or maintaining ISO 27001 certification, we perform readiness assessments that identify gaps in your Information Security Management System (ISMS) against every control in Annex A. Our assessment helps you prepare for certification audits with confidence, avoiding costly surprises during the formal audit process.

CIS Controls

The CIS Critical Security Controls provide a prioritized, prescriptive set of actions that address the most common attack vectors. We assess your implementation across all 18 control families, with particular attention to Implementation Group mapping that matches the controls to your organizational risk profile and capabilities.

Additional Frameworks

We also assess against PCI DSS, SOC 2 Trust Services Criteria, HIPAA Security Rule, PHIPA, OSFI B-13, and sector-specific frameworks as required by your regulatory environment.

Emerging Regulatory Requirements

Canadian organizations face a rapidly evolving regulatory landscape. Our GAP Assessment includes readiness evaluation for Bill C-26 (Critical Cyber Systems Protection Act) obligations for critical infrastructure operators, Quebec's Law 25 privacy requirements, and the growing security control expectations from cyber insurance carriers. Understanding these gaps now prevents compliance scrambles later.

Assessment Methodology

Our assessment combines multiple evidence-gathering techniques to provide a complete picture:

Maturity Modeling & Roadmapping

We score each control domain on a maturity model (typically 1-5, from Initial to Optimized) and map your current state against your target state. The gap between the two drives our prioritized remediation roadmap, which sequences initiatives based on risk reduction impact, implementation cost, dependency relationships, and quick-win opportunities that demonstrate early progress.

📏

Multi-Framework Analysis

Assess against NIST CSF, ISO 27001, CIS Controls, PCI DSS, SOC 2, and industry-specific frameworks — with cross-mapping to eliminate duplicate effort.

🎯

Prioritized Roadmap

A sequenced remediation plan that prioritizes by risk impact, implementation cost, and quick-win potential — not just a list of findings without context.

📊

Maturity Scoring

Visual maturity scorecards across every control domain, showing current state vs. target state and progress tracking for board and executive reporting.

Related Services

Know Where You Stand

A clear-eyed assessment today prevents costly surprises tomorrow. Start with the facts, then build your security program on solid ground.