All Posts
Cybersecurity
9 min read

Cybersecurity Risk Assessment: What Yours Must Uncover

A risk assessment is only worth the calendar time if it produces evidence, owners, and dates. Here is what yours has to uncover.

By Centaris Team

Two business leaders reviewing prioritized findings on a glass wall during a cybersecurity risk assessment planning session.

Most organizations do not have a security problem they can see. They have one they never went looking for.

Key Takeaways

A cybersecurity risk assessment is only worth the calendar time if it produces evidence, a ranked list of gaps, and a remediation plan with names attached.

If you cannot name the person who owns patching, backup verification, and offboarding today, that is your first finding.

Almost every organization that gets breached had a warning it did not act on. Sometimes the warning was an audit finding. More often it was quieter: a server that stopped reporting to the patch console, a departed contractor whose account stayed live, a backup job that had been failing silently since spring. None of that shows up in a board report. All of it shows up in an incident timeline.

The stakes are moving in the wrong direction. IBM's 2026 Cost of a Data Breach Report put the global average breach cost at a record 4.99 million dollars, with United States organizations averaging 11.5 million, more than double the global figure. For a 200-person manufacturer or a regional health system, those numbers are existential.

A cybersecurity risk assessment exists to close the gap between what leadership believes about its environment and what is actually true. Done well, it is the highest-leverage security investment a mid-sized organization can make, because every dollar spent afterward is either aimed at a real gap or aimed at nothing. If you are evaluating Michigan IT and cybersecurity support, the assessment is where the conversation should start, not where it should end.

What Does a Cybersecurity Risk Assessment Actually Tell You?

A real assessment answers three questions: where sensitive data and critical systems live, which controls protecting them are actually working, and what an attacker could reach from a single foothold. Anything that answers fewer than all three is a partial picture sold as a complete one.

The distinction matters because the market is crowded with things that look like assessments. An automated scan produces a list of unpatched software. A questionnaire produces a list of what your team believes is in place. Neither one tells you whether the belief and the reality match. That gap is where incidents live.

Inventory Comes Before Opinion

You cannot assess what you have not found. Discovery covers endpoints, servers, cloud tenants, identity providers, network segments, SaaS applications purchased outside IT, and the data classes flowing through each. The surprise is usually a system nobody has thought about in three years that still holds production data.

Add AI tools to that inventory. Employees are already pasting contracts, patient summaries, and engineering drawings into assistants nobody approved. The goal is governed adoption with clear acceptable-use boundaries, not a ban that drives the same behavior underground.

Evidence Beats Attestation

The difference between a checklist and a cybersecurity risk assessment is proof. "Backups are running" is an attestation. A documented restore test with a recorded recovery time is evidence. "MFA is enforced" is an attestation. A conditional access policy export showing which accounts and which legacy protocols are exempt is evidence. Ask for the second kind on every finding that matters.

Infographic comparing three security attestations against the documented evidence a cybersecurity risk assessment should require.

How Does the Assessment Process Work, Stage by Stage?

It moves from discovery through validation to a ranked report, and each stage should produce an artifact you can hand to someone else. If a stage generates no document, it did not happen.

The last stage matters most. A 90-page technical appendix nobody reads is a deliverable. A one-page ranked roadmap the leadership team argues over is a result.

What Gaps Do Assessments Find Most Often?

The findings a cybersecurity risk assessment surfaces repeat with remarkable consistency across manufacturers, health systems, and professional firms throughout the Great Lakes region. Six show up again and again.

CISA's Cross-Sector Cybersecurity Performance Goals, updated to version 2.0 in December 2025, offer a useful sanity check against this list. They are deliberately short and deliberately basic, which is the point: most incidents exploit the fundamentals, not the exotic.

Three business leaders reviewing printed security assessment findings together around a conference table.

How Do Compliance Requirements Shape the Assessment?

Compliance frameworks do not replace a cybersecurity risk assessment. Several of them mandate one, and regulators have started treating its absence as the finding.

In healthcare, the HIPAA Security Rule has always required an accurate and thorough risk analysis. The Department of Health and Human Services Office for Civil Rights has spent the last two years making that requirement expensive to ignore. In April 2026 alone, OCR announced four ransomware settlements, marking 19 completed ransomware investigations and 13 resolutions under its Risk Analysis Initiative. The pattern across those cases is consistent: the enforcement action targets what was missing before the attack, not the attack. That makes a current compliance assessment a legal position as much as a security one for any Michigan healthcare organization handling ePHI.

Defense manufacturing has been through a different kind of whiplash. The Defense Department Chief Information Officer suspended the November 2026 transition to CMMC Phase 2 in July 2026, pausing the requirement for third-party Level 2 assessments while a reform task force reviews the program. Read the memo carefully before you exhale. Phase 1 self-assessment requirements remain in force, DFARS 252.204-7012 and FAR 52.204-21 are untouched, and the Department continues to enforce NIST SP 800-171 Revision 2 through self-assessment and government-led review. The deadline moved. The obligation did not. For manufacturers in the defense supply chain, the honest read is that the pause bought preparation time, not relief.

One clarification worth keeping straight: no IT provider certifies anyone. Accredited third parties perform CMMC certification. A technology partner assesses, prepares, remediates, and coordinates the evidence. Anyone who tells you otherwise is selling something they cannot deliver.

What Does an Unaddressed Gap Cost?

The cost is rarely the ransom. It is the days of stopped output, the overtime spent catching up, and the customer who quietly moves the next order elsewhere.

Consider a manufacturer with 220 employees and 50 million dollars in annual revenue across roughly 250 production days. That is about 200,000 dollars of output per day. A ransomware event that halts production for four days costs approximately 800,000 dollars in lost output before a single invoice arrives from incident response, outside counsel, or forensics, and before any contractual penalty for a missed delivery window. Run that math for your own operation. The number is usually larger than the entire annual security budget being debated.

Business continuity belongs inside the assessment for exactly this reason. Recovery time objectives that have never been tested are aspirations. If leadership believes the plant can be running again in eight hours and the last restore test took three days, the assessment has just found the most expensive gap in the organization.

Key statistics on breach costs, unremediated critical vulnerabilities, and HIPAA risk analysis enforcement actions.

How Do You Turn a Cybersecurity Risk Assessment Into a Remediation Plan?

You rank the findings by what an attacker would reach first, assign each one an owner and a date, and accept that some items will be deferred deliberately rather than forgotten accidentally.

The fourth item is the one most organizations skip, and it is the one auditors and regulators look for. Documented acceptance of a known risk is a defensible governance decision. Undocumented acceptance is negligence with better paperwork.

Capacity is usually the real constraint. Internal teams typically know what needs to happen and are already consumed by the ticket queue, which is how a report becomes shelfware. Targeted cybersecurity consulting or co-managed IT support earns its keep by owning specific workstreams your team will otherwise never reach.

Frequently Asked Questions

A few questions come up in nearly every assessment conversation. The short answers are below.

How often should an assessment be repeated, and what triggers an early one?

Annually at minimum, and immediately after any significant change: an acquisition, a major system migration, a move to a new facility, or a security incident. Environments drift faster than most teams expect, and a two-year-old assessment describes a network that no longer exists.

Is a vulnerability scan the same as a risk assessment?

No. A scan identifies technical weaknesses in systems it can reach, and a security audit measures conformance against a defined standard at a point in time. A risk assessment adds business context, control validation, framework mapping, and prioritization across all of it. The scan and the audit are inputs, not substitutes.

Does an assessment make an organization compliant?

No. A compliance assessment identifies gaps against a framework and produces the remediation plan that closes them. Certification under CMMC, TISAX, or similar programs is performed by accredited third parties, and no technology provider can grant it.

What does an assessment require from the internal team?

Expect several hours of interviews with IT, operations, and compliance stakeholders, read-only access for technical discovery, and documentation review. Most engagements need far less internal time than teams fear, and the interviews frequently surface the most useful findings.

A business leader at an office window overlooking a Midwestern skyline after reviewing security assessment results.

Find Out Where You Actually Stand

Every one of the gaps described above is fixable. The organizations that get breached are rarely the ones that lacked the budget. They are the ones that never produced an honest picture of their own environment, so every security dollar went somewhere plausible instead of somewhere necessary.

Centaris is an IT and cybersecurity partner working with manufacturers, healthcare organizations, and other regulated businesses across Michigan and the Great Lakes region. Our approach starts with assessment because recommending controls before understanding exposure is guesswork, however confident it sounds. We show you what we find, explain what it means for your operation and your regulatory position, and let you decide what to address and in what order.

Schedule a no-obligation assessment and find out what is actually running in your environment.

Ready to Talk?

Schedule a no-obligation assessment and get clarity on your environment.

Schedule an Assessment →