Your auditor just asked
for a network security
assessment. Now what?

We map your network, analyze your firewall posture, identify exposure, and deliver a written report with findings ranked by severity. Whether you're responding to an audit or getting ahead of one — the assessment is the same.

Request an assessment
PCI DSS HIPAA Cyber insurance SOC 2 Post-breach Due diligence
What triggers this

Something happened.
That's why you're here.

Nobody wakes up wanting a network security assessment. Something triggered it — and we know how to respond to each of these.

📋
PCI compliance requirement

Your bank, payment processor, or QSA is asking for evidence of network segmentation and firewall documentation. The SAQ has questions you can't answer.

"Our processor said we need to prove cardholder data is segmented."
🏥
HIPAA audit or risk assessment

You received a HIPAA audit notification or your compliance officer needs a Technical Safeguards assessment of the network layer. PHI exposure is the concern.

"OCR sent a letter. We need to document our network security controls."
🛡️
Cyber insurance renewal

Your insurer is asking for proof of network segmentation, MFA, firewall management, and security controls before renewing or issuing your cyber liability policy.

"The insurance application asks about our firewall and segmentation. We don't know what to put."
🔴
Breach or incident response

Something already happened — ransomware, unauthorized access, data exposure. You need an independent assessment of what failed and what to fix before it happens again.

"We got hit. We need someone to tell us how they got in."
🏢
Acquisition due diligence

Your company is being acquired or acquiring another and the deal team wants an independent assessment of the network security posture as part of technical due diligence.

"The acquirer wants a network security report before close."
🤷
Nobody has ever looked

You've been operating for years and no one has ever independently assessed your network security. You don't know what you don't know — and that keeps you up at night.

"Honestly, we have no idea if our network is secure. We need someone to tell us."
Proactive security

Find it before
it finds you.

You don't have to wait for an audit letter, a breach, or an insurance questionnaire. The strongest security posture starts with knowing exactly where you stand — before anything goes wrong.

Proactive discovery

  • Map what's actually on your network — devices, connections, and paths you didn't know existed
  • Identify shadow IT, rogue endpoints, and undocumented infrastructure
  • Baseline your current security posture with a written score you can track over time
  • Surface misconfigurations before they become exploitable vulnerabilities

Preventive remediation

  • Close exposure gaps — open ports, permissive firewall rules, flat network segments
  • Harden configurations against known attack vectors specific to your vendor stack
  • Implement segmentation and access controls before compliance requires it
  • Document everything — so when the audit does come, you're already ready
The cost of waiting

A proactive assessment costs a fraction of what a single incident costs — in downtime, breach notification, legal exposure, and reputation. The businesses that come to us after an incident always say the same thing: "We should have done this sooner."

What we assess

Full-scope network
security analysis.

Every assessment is tailored to your environment, but here's the standard scope of work. We don't run an automated scan and hand you a PDF — this is hands-on analysis by a network engineer.

Discovery & mapping

  • Active device discovery — what's actually on the network
  • Network topology mapping — how it's all connected
  • VLAN and subnet structure analysis
  • Undocumented devices, shadow IT, rogue endpoints
  • Cloud infrastructure inventory — AWS, Azure, GCP resources

Firewall & perimeter

  • On-premises firewall rule review — FortiGate, Palo Alto, Meraki, pfSense, any vendor
  • Cloud firewall analysis — Security Groups, NSGs, VPC rules
  • Host-based firewall audit — Windows Firewall, iptables, nftables
  • NAT and port forwarding exposure
  • External attack surface — open ports, exposed services

Segmentation & internal controls

  • Network segmentation effectiveness — are zones actually isolated?
  • Inter-VLAN access control review
  • PCI cardholder data environment boundaries
  • HIPAA PHI zone isolation
  • Lateral movement exposure — east/west traffic analysis

Wireless, remote access & documentation

  • Wireless security — encryption, guest isolation, rogue AP detection
  • VPN configuration review — split tunnel policy, MFA
  • Remote management interface exposure — RDP, SSH, web admin
  • Existing documentation gap analysis
  • Compliance control mapping — PCI, HIPAA, SOC 2, cyber insurance
What you get — the deliverable

A written assessment report documenting every finding, organized by severity, with specific remediation recommendations for each. Not a 200-page automated scan output — a focused, readable document written by an engineer who understands your environment.

Findings are categorized by severity so you can prioritize what to fix first and communicate risk to leadership, auditors, or insurers in language they understand.

CRITICAL HIGH MEDIUM LOW
Pricing

Flat-rate assessments.
Not open-ended hourly billing.

You know the cost before we start. No scope creep, no surprise invoices, no vague "it depends." Scoped to your environment size.

Small business
Flat rate

Under 25 network devices · single location · standard perimeter

  • Full scope assessment
  • Written findings report
  • Remediation priorities
  • One compliance framework mapping
  • 30-minute walkthrough of findings
Enterprise / complex
Custom

100+ devices · multiple sites · hybrid cloud · M&A due diligence

  • Scoped per engagement
  • Full assessment + custom deliverables
  • Board-ready executive summary
  • Remediation project planning
  • Ongoing retainer available
💬
Assessment → Remediation → Managed services. Most assessment clients also need remediation work. We quote remediation separately — either as a fixed-scope project or on an hourly basis. Many clients transition to a managed services agreement after remediation — we handle the fix and then keep it fixed.
How it works

From assessment to
ongoing protection.

Most engagements follow this path. You don't have to buy the next step — but most clients do once they see the findings.

01
Assessment

We map your network, analyze your security posture, and deliver a written report with findings ranked by severity. Flat-rate, fixed scope.

02
Remediation

We fix what the assessment found — firewall rules, segmentation, access controls, documentation. Quoted per project or billed hourly.

03
Ongoing management

Once it's fixed, we keep it that way. Managed firewall, monitoring, and change management on a flat monthly rate. Your network stays compliant.

04
Annual reassessment

Networks change. Annual reassessments verify your controls are still effective and catch drift before auditors do. Discounted for managed clients.

Questions

Common questions about
security assessments.

Straight answers.

No. A penetration test simulates an attacker trying to break in. Our assessment is an analysis of your network architecture, firewall configuration, segmentation, and documentation — the foundational controls that a pentest would evaluate you against. Many organizations need the assessment first to fix the basics before a pentest is even useful. If you need a pentest, we can recommend trusted partners who specialize in that.
Most small business assessments are completed in 5–7 business days from kickoff to report delivery. Mid-market engagements typically take 2–3 weeks depending on complexity and access scheduling. We'll give you a specific timeline during scoping.
Most of the analysis can be done remotely via secure access to your firewall management interfaces and network infrastructure. On-site work is sometimes needed for wireless assessments and physical network documentation. We'll identify this during scoping and schedule accordingly.
The report is designed to address the specific requirements of PCI DSS, HIPAA Technical Safeguards, SOC 2 CC6/CC7, and cyber insurance security questionnaires. We map findings directly to the compliance framework you're dealing with. Most auditors and insurers accept an independent third-party network assessment as evidence of due diligence.
If we discover an active critical vulnerability or exposure during the assessment, we notify you immediately — we don't wait for the final report. You'll have the option to engage us for emergency remediation or address it with your own team.
Yes. Most clients engage us for remediation after the assessment. We quote remediation work separately — either as a fixed-scope project or at our standard hourly consulting rate. There's no obligation to use us for remediation, but the context we've gained during the assessment means we can execute faster than bringing in a new vendor.
Get started

Let's assess your
network security.

Tell us what triggered the need and we'll scope the engagement. No obligation, no vague proposals — you'll get a specific scope, timeline, and flat-rate quote.

Request an assessment Ask a question

info@nimblenetconsulting.com · We respond within one business day.

Flat-rate pricing — no open-ended billing
Written report with severity-ranked findings
Compliance framework mapping included
Vendor agnostic — we assess any stack