BLOG

We Don’t Know How Secure We Actually Are. How Do You Find Out?

Cybersecurity posture assessment layers: posture assessment, vulnerability assessment, and penetration test.

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 28, 2026

Key Takeaways

  • Security tools and security posture are not the same thing. An organization can have endpoint protection, a firewall, and email filtering and still have exploitable gaps between those controls that an attacker can navigate.
  • A cybersecurity posture assessment evaluates the full breadth of an organization’s security programme against a recognized framework, producing a maturity score and a prioritized improvement roadmap.
  • A vulnerability assessment identifies specific technical vulnerabilities in systems, applications, and network infrastructure through automated scanning and expert analysis.
  • A penetration test goes further, using the techniques of real attackers to determine whether identified vulnerabilities can actually be exploited to gain unauthorized access or escalate privileges.
  • The combination of a posture assessment, vulnerability assessment, and penetration test gives leadership an accurate, defensible picture of security posture that supports board reporting, cyber insurance applications, and compliance certification.

Why “We Have Antivirus and a Firewall” Is Not an Answer

The most common security posture self-assessment is an inventory of tools. Most organizations can list the security products they have purchased: an endpoint protection platform, a next-generation firewall, email security filtering, perhaps a SIEM or a cloud access security broker. The list sounds reasonable. The problem is that tools are not the same as protection. A tool that is deployed but misconfigured provides the cost and complexity of the tool with none of its protective value. Controls that do not cover the full environment leave gaps that an attacker can enter through. Security products that are not monitored generate alerts that no one acts on.

Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the gap between perceived and actual security posture is the rule rather than the exception. Most teams can list their tools but cannot say which controls are misconfigured, unmonitored, or leaving gaps between them. The organizations that discover they are less secure than they believed almost always discover it one of two ways: through a professional security assessment that reveals the gaps, or through an incident that exploits them. The cost of discovery through assessment is the cost of the assessment. The cost of discovery through an incident is everything that follows: breach response, forensic investigation, regulatory notification, legal exposure, reputational damage, and customer loss. The assessment is, by any measure, the preferable path to the same information.

Leadership teams that ask “how secure are we?” and receive answers built on tool lists rather than professional assessment are operating on incomplete information. Boards and executives who have been told the organization is secure because it has deployed a set of security products have not been given a reliable answer. Armour Cybersecurity’s assessment services provide the reliable answer.

What a Cybersecurity Posture Assessment Covers

A cybersecurity posture assessment evaluates the organization’s security programme in its entirety against a recognized framework, typically NIST CSF, CIS Controls, or a framework aligned to the organization’s compliance requirements. The assessment covers governance and risk management, identity and access management, data protection, infrastructure and endpoint security, network security, application security, third-party risk management, incident response capability, and business continuity and disaster recovery.

For each domain, the assessment assigns a maturity rating based on the evidence gathered through stakeholder interviews, documentation review, and technical observation. The result is a compliance readiness score that shows where the organization is strong, where it has gaps, and where its controls exist on paper but are not operating effectively in practice. The prioritized improvement roadmap that follows tells leadership exactly what to fix, in what order, and at what estimated cost.

The posture assessment is the foundation on which everything else is built. An organization that does not know its current posture cannot build a meaningful security roadmap, make informed investment decisions, respond credibly to board questions about cyber risk, or engage a compliance certification programme with a clear understanding of how far it needs to travel. The assessment creates the map.

What a Vulnerability Assessment Adds

A vulnerability assessment drills into the technical layer of the security programme. Where the posture assessment evaluates the breadth of the programme, the vulnerability assessment evaluates the depth of specific technical controls by identifying vulnerabilities in the systems and applications in scope.

Armour Cybersecurity’s vulnerability assessment uses both automated scanning tools and expert analyst review to identify vulnerabilities in network infrastructure, servers, endpoints, web applications, and cloud environments. Every identified vulnerability is rated by severity using the Common Vulnerability Scoring System, contextualized for the organization’s specific environment, and included in a remediation roadmap that distinguishes critical vulnerabilities requiring immediate action from lower-severity items that can be addressed in scheduled maintenance cycles.

The vulnerability assessment answers the technical question that the posture assessment leaves open: not just whether vulnerability management is a defined programme, but whether specific, exploitable vulnerabilities exist in the environment right now. The answer is almost always yes. What matters is knowing which ones they are, how severe they are, and what it takes to remediate them.

What a Penetration Test Proves

A penetration test is the definitive answer to the question of whether an attacker can actually exploit the vulnerabilities that exist in the environment. Armour Cybersecurity’s penetration testing engagements use the same techniques that real threat actors use: reconnaissance, exploitation of identified vulnerabilities, lateral movement, privilege escalation, and data access. The test is conducted in a controlled manner with defined rules of engagement, and every step is documented.

The penetration test report answers the question that no other assessment answers: not whether vulnerabilities exist, but whether they can be chained together by a skilled attacker to produce a meaningful compromise. A vulnerability assessment might identify an unpatched application server and a weak credential on a service account. A penetration test determines whether those two findings can be combined to gain administrative access to the production environment. The combination is what an attacker would find. The penetration test finds it first.

Penetration test reports are also the most credible response to enterprise security questionnaires and compliance auditors who ask for evidence of offensive security testing. A report from an independent third-party penetration test with documented methodology, findings, severity ratings, and remediation status is the evidence that closes this section of virtually every major compliance audit.

How Armour 360 and vCISO Connect the Picture

Assessment services answer the question of where the organization stands. Acting on that answer requires ongoing security management that addresses the identified gaps and maintains the programme as the threat landscape evolves. Armour 360 is the managed cybersecurity service that operationalizes the improvements identified in the assessment: endpoint protection, email security, network monitoring, and continuous vulnerability management, delivered as a managed service with transparent monthly cost.

The fractional vCISO provides the senior security governance layer that connects the assessment findings to the board, the business, and the compliance programme. The vCISO owns the security roadmap, tracks remediation progress, reports to leadership in business terms, and serves as the accountable senior security leader that enterprise customers and compliance auditors expect to see. For organizations that do not have a CISO, the vCISO fills that gap immediately. For organizations that have a security programme but lack senior strategic direction, the vCISO provides it without the cost of a full-time executive hire.

Frequently Asked Questions

How often should we conduct a security posture assessment?

A full posture assessment should be conducted annually at minimum. For organizations in active growth, those that have made significant infrastructure or personnel changes, or those facing a compliance audit or enterprise procurement review, a more frequent assessment cadence is appropriate. Vulnerability assessments should run quarterly. Penetration testing is typically annual for most organizations, or following significant changes to the environment.

What if the assessment finds serious vulnerabilities? Who remediates them?

Armour Cybersecurity provides both the assessment and the remediation support. The assessment produces a prioritized remediation roadmap with effort and cost estimates for each item. For technical remediation, Armour’s professional services team can implement the required changes. For programmatic improvements, the vCISO engagement provides the governance and oversight to drive remediation to completion. Assessment without remediation support is where most organizations stall; Armour is structured to take the finding through to resolution.

Can assessment findings be used in our cyber insurance application?

Yes. A cybersecurity posture assessment, recent penetration test report, and documented vulnerability management programme are among the evidence that cyber insurers use to assess risk and set premiums. Organizations that can demonstrate a maturing security programme with professional third-party validation receive better coverage terms and lower premiums than those that cannot. Armour’s Cyber Insurance Advisory service includes support for using assessment findings in insurance applications and renewals.

The Bottom Line

You cannot manage what you have not measured, and a list of security tools is not a measurement. The organizations that know their real security posture are the ones that had it assessed: a posture assessment for the breadth of the programme, a vulnerability assessment for the specific technical gaps, and a penetration test to prove whether those gaps can actually be exploited. Together they replace the comfortable assumption that the tools are working with a defensible, prioritized picture of where you stand and what to fix first. Armour Cybersecurity produces that picture, starting with a cybersecurity posture assessment.

Leave the first comment