
Most organizations do not have a security problem they can see. They have one they never went looking for.
Key Takeaways
A cybersecurity risk assessment is only worth the calendar time if it produces evidence, a ranked list of gaps, and a remediation plan with names attached.
Assessments that stop at a tool inventory miss what actually causes incidents: patching no one owns, backups no one has restored, accounts no one closed.
Regulators in healthcare and defense manufacturing increasingly treat a missing or stale risk analysis as the violation itself, separate from the breach that exposed it.
Breach costs hit a record in 2026, and the gap between the global average and the United States average keeps widening.
Findings without an owner and a deadline change nothing. Most organizations already know two or three of their gaps and have not closed them.
If you cannot name the person who owns patching, backup verification, and offboarding today, that is your first finding.
Almost every organization that gets breached had a warning it did not act on. Sometimes the warning was an audit finding. More often it was quieter: a server that stopped reporting to the patch console, a departed contractor whose account stayed live, a backup job that had been failing silently since spring. None of that shows up in a board report. All of it shows up in an incident timeline.
The stakes are moving in the wrong direction. IBM's 2026 Cost of a Data Breach Report put the global average breach cost at a record 4.99 million dollars, with United States organizations averaging 11.5 million, more than double the global figure. For a 200-person manufacturer or a regional health system, those numbers are existential.
A cybersecurity risk assessment exists to close the gap between what leadership believes about its environment and what is actually true. Done well, it is the highest-leverage security investment a mid-sized organization can make, because every dollar spent afterward is either aimed at a real gap or aimed at nothing. If you are evaluating Michigan IT and cybersecurity support, the assessment is where the conversation should start, not where it should end.
What Does a Cybersecurity Risk Assessment Actually Tell You?
A real assessment answers three questions: where sensitive data and critical systems live, which controls protecting them are actually working, and what an attacker could reach from a single foothold. Anything that answers fewer than all three is a partial picture sold as a complete one.
The distinction matters because the market is crowded with things that look like assessments. An automated scan produces a list of unpatched software. A questionnaire produces a list of what your team believes is in place. Neither one tells you whether the belief and the reality match. That gap is where incidents live.
Inventory Comes Before Opinion
You cannot assess what you have not found. Discovery covers endpoints, servers, cloud tenants, identity providers, network segments, SaaS applications purchased outside IT, and the data classes flowing through each. The surprise is usually a system nobody has thought about in three years that still holds production data.
Add AI tools to that inventory. Employees are already pasting contracts, patient summaries, and engineering drawings into assistants nobody approved. The goal is governed adoption with clear acceptable-use boundaries, not a ban that drives the same behavior underground.
Evidence Beats Attestation
The difference between a checklist and a cybersecurity risk assessment is proof. "Backups are running" is an attestation. A documented restore test with a recorded recovery time is evidence. "MFA is enforced" is an attestation. A conditional access policy export showing which accounts and which legacy protocols are exempt is evidence. Ask for the second kind on every finding that matters.

How Does the Assessment Process Work, Stage by Stage?
It moves from discovery through validation to a ranked report, and each stage should produce an artifact you can hand to someone else. If a stage generates no document, it did not happen.
Discovery and scoping. What it examines: Assets, data locations, identity sources, network boundaries, third-party and AI tool usage. What you should receive: A current asset and data-flow inventory.
Technical testing. What it examines: External exposure, internal vulnerabilities, configuration drift, endpoint posture. What you should receive: Findings ranked by exploitability rather than severity score alone.
Control validation. What it examines: Whether documented controls are enforced in practice, including MFA, logging, backup restores, offboarding. What you should receive: Evidence for each control, with exceptions named.
Framework mapping. What it examines: Alignment to the standard that governs you, such as NIST SP 800-171, the HIPAA Security Rule, or TISAX. What you should receive: A gap register tied to specific control requirements.
Risk ranking and reporting. What it examines: Business impact, likelihood, and remediation effort for each finding. What you should receive: A prioritized roadmap with owners and target dates.
The last stage matters most. A 90-page technical appendix nobody reads is a deliverable. A one-page ranked roadmap the leadership team argues over is a result.
What Gaps Do Assessments Find Most Often?
The findings a cybersecurity risk assessment surfaces repeat with remarkable consistency across manufacturers, health systems, and professional firms throughout the Great Lakes region. Six show up again and again.
Patching that nobody owns. Verizon's 2026 Data Breach Investigations Report found that only 26 percent of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog were fully remediated in 2025, with the median time to full resolution stretching to 43 days. Exploitation of vulnerabilities has now overtaken credential abuse as the leading way attackers get in, and in manufacturing it accounts for 38 percent of breaches. The tooling usually exists. The accountability does not.
Backups nobody has restored. Backup jobs report success far more reliably than they restore data. If the last full restore test is undated, assume the capability is unproven.
Identity sprawl. Former employees, dormant service accounts, and shared administrative credentials accumulate quietly. A managed cybersecurity services review typically finds active accounts belonging to people who left more than a year ago.
Multi-factor authentication with holes in it. Partial enforcement is the norm. Legacy authentication protocols, break-glass accounts, and VPN paths that bypass conditional access are the exceptions attackers look for first.
Flat networks connecting the office to the plant floor or the clinical environment. In manufacturing, a compromised front-office workstation should not be able to reach an HMI. In healthcare, it should not reach imaging systems. Segmentation is the control most often assumed and least often verified.
Vendor access nobody reviews. Remote support tunnels for machine builders, EHR vendors, and managed print providers frequently outlive the projects that created them.
CISA's Cross-Sector Cybersecurity Performance Goals, updated to version 2.0 in December 2025, offer a useful sanity check against this list. They are deliberately short and deliberately basic, which is the point: most incidents exploit the fundamentals, not the exotic.

How Do Compliance Requirements Shape the Assessment?
Compliance frameworks do not replace a cybersecurity risk assessment. Several of them mandate one, and regulators have started treating its absence as the finding.
In healthcare, the HIPAA Security Rule has always required an accurate and thorough risk analysis. The Department of Health and Human Services Office for Civil Rights has spent the last two years making that requirement expensive to ignore. In April 2026 alone, OCR announced four ransomware settlements, marking 19 completed ransomware investigations and 13 resolutions under its Risk Analysis Initiative. The pattern across those cases is consistent: the enforcement action targets what was missing before the attack, not the attack. That makes a current compliance assessment a legal position as much as a security one for any Michigan healthcare organization handling ePHI.
Defense manufacturing has been through a different kind of whiplash. The Defense Department Chief Information Officer suspended the November 2026 transition to CMMC Phase 2 in July 2026, pausing the requirement for third-party Level 2 assessments while a reform task force reviews the program. Read the memo carefully before you exhale. Phase 1 self-assessment requirements remain in force, DFARS 252.204-7012 and FAR 52.204-21 are untouched, and the Department continues to enforce NIST SP 800-171 Revision 2 through self-assessment and government-led review. The deadline moved. The obligation did not. For manufacturers in the defense supply chain, the honest read is that the pause bought preparation time, not relief.
One clarification worth keeping straight: no IT provider certifies anyone. Accredited third parties perform CMMC certification. A technology partner assesses, prepares, remediates, and coordinates the evidence. Anyone who tells you otherwise is selling something they cannot deliver.
What Does an Unaddressed Gap Cost?
The cost is rarely the ransom. It is the days of stopped output, the overtime spent catching up, and the customer who quietly moves the next order elsewhere.
Consider a manufacturer with 220 employees and 50 million dollars in annual revenue across roughly 250 production days. That is about 200,000 dollars of output per day. A ransomware event that halts production for four days costs approximately 800,000 dollars in lost output before a single invoice arrives from incident response, outside counsel, or forensics, and before any contractual penalty for a missed delivery window. Run that math for your own operation. The number is usually larger than the entire annual security budget being debated.
Business continuity belongs inside the assessment for exactly this reason. Recovery time objectives that have never been tested are aspirations. If leadership believes the plant can be running again in eight hours and the last restore test took three days, the assessment has just found the most expensive gap in the organization.

How Do You Turn a Cybersecurity Risk Assessment Into a Remediation Plan?
You rank the findings by what an attacker would reach first, assign each one an owner and a date, and accept that some items will be deferred deliberately rather than forgotten accidentally.
Fix now. Internet-facing unpatched systems, missing MFA on remote access, active accounts for departed staff — directly reachable, low effort, high consequence.
Fix this quarter. Backup restore testing, privileged access review, endpoint detection coverage gaps, logging retention — requires coordination but no capital project.
Plan and budget. Network segmentation, identity governance, OT monitoring, framework certification readiness — multi-month work with real dependencies.
Accept and document. Residual risks the business chooses to carry — written acceptance beats silent exposure.
The fourth item is the one most organizations skip, and it is the one auditors and regulators look for. Documented acceptance of a known risk is a defensible governance decision. Undocumented acceptance is negligence with better paperwork.
Capacity is usually the real constraint. Internal teams typically know what needs to happen and are already consumed by the ticket queue, which is how a report becomes shelfware. Targeted cybersecurity consulting or co-managed IT support earns its keep by owning specific workstreams your team will otherwise never reach.
Frequently Asked Questions
A few questions come up in nearly every assessment conversation. The short answers are below.
How often should an assessment be repeated, and what triggers an early one?
Annually at minimum, and immediately after any significant change: an acquisition, a major system migration, a move to a new facility, or a security incident. Environments drift faster than most teams expect, and a two-year-old assessment describes a network that no longer exists.
Is a vulnerability scan the same as a risk assessment?
No. A scan identifies technical weaknesses in systems it can reach, and a security audit measures conformance against a defined standard at a point in time. A risk assessment adds business context, control validation, framework mapping, and prioritization across all of it. The scan and the audit are inputs, not substitutes.
Does an assessment make an organization compliant?
No. A compliance assessment identifies gaps against a framework and produces the remediation plan that closes them. Certification under CMMC, TISAX, or similar programs is performed by accredited third parties, and no technology provider can grant it.
What does an assessment require from the internal team?
Expect several hours of interviews with IT, operations, and compliance stakeholders, read-only access for technical discovery, and documentation review. Most engagements need far less internal time than teams fear, and the interviews frequently surface the most useful findings.

Find Out Where You Actually Stand
Every one of the gaps described above is fixable. The organizations that get breached are rarely the ones that lacked the budget. They are the ones that never produced an honest picture of their own environment, so every security dollar went somewhere plausible instead of somewhere necessary.
Centaris is an IT and cybersecurity partner working with manufacturers, healthcare organizations, and other regulated businesses across Michigan and the Great Lakes region. Our approach starts with assessment because recommending controls before understanding exposure is guesswork, however confident it sounds. We show you what we find, explain what it means for your operation and your regulatory position, and let you decide what to address and in what order.
Schedule a no-obligation assessment and find out what is actually running in your environment.