What Does a Cyber Security Gap Analysis Actually Check? 

Executive Summary 

A Cyber Security Gap Analysis gives your business a clear view of where its cyber security stands today, where the main weaknesses are, and what should be improved first. 

At Get Support, we use the NIST Cybersecurity Framework as the main structure for our assessment. Its six key areas — Govern, Identify, Protect, Detect, Respond and Recover — provide a clear and widely recognised way to understand cyber risk across the whole business. 

We then build on that structure using relevant CIS Controls, guidance from the UK’s National Cyber Security Centre (NCSC) and other recognised good practice. This creates a tailored security gap analysis for business owners: a clear view of your current position, the risks you face and the best opportunities to improve, without an overly technical report. 

Introduction 

If you are considering a Cyber Security Gap Analysis, one of the first questions you are likely to ask is: what do you actually check? 

It is an important question because cyber security covers much more than antivirus software, passwords and firewalls. 

A proper assessment should look at how your business manages security, the systems and information you depend on, the safeguards already in place, how quickly you could spot a problem and what would happen if a cyber incident occurred. 

That is why Get Support uses the six areas of the NIST Cybersecurity Framework to structure our Cyber Security Gap Analyses. 

Within that structure, we draw on CIS Controls, NCSC guidance and other recognised good practice where relevant. This gives us a consistent but flexible way to assess your current position and turn technical findings into clear, practical guidance for your business. 

What is a Cyber Security Gap Analysis? 

A Cyber Security Gap Analysis gives you a structured view of your current cyber security position and highlights where improvements may be needed. 

An important part of the process is first understanding what needs protecting. 

That means identifying the systems, information, devices, accounts and services your business relies on, and understanding which of them are most important to your day-to-day operations. 

From there, we can look at: 

  • what security measures you already have in place 
  • where there are weaknesses or missing controls 
  • what risks those gaps create for the business 
  • which improvements should be prioritised 
  • what practical steps should be taken next 

This is important because not everything carries the same value or risk. 

A system containing sensitive customer information, for example, may need stronger protection than something with very little business impact. Equally, a service that would stop your team working if it became unavailable deserves particular attention. 

The Gap Analysis therefore helps answer a wider set of questions: 

What do we have? What matters most? How well is it protected? Where are the gaps? And what should we do next? 

The objective is not to find fault for the sake of it. 

Most businesses will have a mixture of strong areas, opportunities for improvement and a few issues that deserve more urgent attention. 

The Gap Analysis helps turn all of that into a clear picture and gives you a useful baseline for making better cyber security decisions. 

How we structure our assessment 

The NIST Cybersecurity Framework provides the backbone of our assessment through six main areas: 

Govern, Identify, Protect, Detect, Respond and Recover. 

These six areas keep the assessment easy to follow and help us look beyond individual security products to consider how cyber security works across the whole business. We use them as the structure, then apply relevant detail from CIS Controls, NCSC guidance and other recognised good practice to create a rounded assessment that suits the organisation rather than a generic technical checklist. 

Govern 

This is about how cyber security is managed. 

We look at areas such as responsibility for cyber security, internal policies, how risks are considered and whether security responsibilities are clear. 

For example, does somebody have responsibility for making security decisions? Are important policies documented? Is cyber risk considered when new systems or suppliers are introduced? 

For smaller businesses, this does not mean creating unnecessary paperwork. It simply means making sure important decisions are being made deliberately rather than being left to chance. 

Identify 

You cannot protect systems and information properly if you do not have a clear understanding of what you rely on. 

We look at the devices, systems, cloud services, applications and information that are important to your business. 

That might include laptops, Microsoft 365, servers, business applications, network equipment and important customer or company data. 

We also consider which systems matter most. 

If losing access to a particular application would stop your team working or affect your customers, that should influence how the risk is managed. 

Protect 

Protect covers many of the security measures people are most familiar with. 

Depending on your environment, we may review areas such as: 

  • multi-factor authentication 
  • user accounts and access 
  • administrator permissions 
  • device security 
  • software and security updates 
  • antivirus and endpoint protection 
  • Microsoft 365 security 
  • encryption 
  • staff cyber security awareness 
  • backup arrangements 

The key question is not simply whether these protections exist. 

We look at whether they are configured appropriately and whether they are being used consistently. 

For example, a business may technically have multi-factor authentication available, but that is very different from confirming that it is properly enforced across the accounts that need it. 

Detect 

Even a well-protected business needs to be able to recognise when something suspicious is happening. 

We therefore consider how potential security incidents are detected. 

That can include monitoring for suspicious logins, malware, unusual account activity or security alerts. 

An important part of this is understanding what happens when an alert is generated. 

If a security system identifies a problem but nobody is reviewing the alerts, the business may not know that action is required. 

Respond 

We also look at what would happen if a cyber incident occurred. 

For example: 

  • Who would staff contact? 
  • Who would make decisions? 
  • How would affected accounts or devices be secured? 
  • Are responsibilities clear? 
  • Is there an incident response process? 
  • Are important contact details readily available? 

Cyber incidents are stressful enough without having to work out the response from scratch. 

Even a straightforward response plan can help a business act more quickly and confidently. 

Recover 

The final area looks at how the business would restore normal operations following an incident. 

Backups are an important part of this, but simply having backups is not enough. 

We look at questions such as what is backed up, how often backups run, whether they are protected and whether recovery has been tested. 

The practical question is: if an important system or piece of information became unavailable, could you get it back when you needed it? 

How do we prioritise the risks we find? 

Not every gap carries the same level of risk. 

That is why one of the most important parts of the process is deciding what should be addressed first. 

We consider factors such as: 

  • how likely a weakness is to cause a problem 
  • what systems or information could be affected 
  • how widely the issue affects the business 
  • the possible operational impact 
  • whether sensitive information is involved 
  • what protection is already in place 

This helps separate urgent risks from useful but less critical improvements. 

For example, weak protection around an administrator account that can access large parts of the business is likely to deserve more attention than a minor configuration improvement on a low-risk system. 

We also look for opportunities to reduce risk quickly and cost-effectively. If a relatively simple or low-cost change can make a meaningful improvement to your security, it often makes sense to tackle that early. 

This prioritisation is important because most businesses cannot, and do not need to, change everything at once. 

Our aim is to help you get the maximum practical value from the time and budget available. We focus on changes that can make the biggest difference, then work through the remaining risks in a sensible order. 

Finding a gap does not always mean buying something 

A Cyber Security Gap Analysis is not an exercise in producing a shopping list of security products. 

Some of the most valuable improvements can be surprisingly straightforward. 

A recommendation might involve: 

  • enabling a security feature you already have 
  • changing a configuration 
  • removing unnecessary administrator access 
  • improving how staff accounts are removed when someone leaves 
  • updating a policy or process 
  • testing an existing backup 
  • improving staff awareness 

Where these kinds of changes can reduce risk significantly without major cost or disruption, we will normally prioritise them. 

From there, we can work onwards through the remaining recommendations, balancing the security benefit against the cost, effort and potential disruption involved. 

Some findings may require a larger project or additional technology, particularly where there is a more significant risk to address. The important thing is that the recommendation should be proportionate to the risk and make sense for your business. 

The goal is not to spend more on cyber security for the sake of it. It is to make sensible improvements in the right order and get as much security value as possible from your investment. 

What do you receive at the end? 

A useful Cyber Security Gap Analysis should leave you with greater clarity, not a large technical report that nobody wants to read. 

At the end of the process, you should understand four things. 

Your current position 

You receive a clear overview of how your business currently performs across Govern, Identify, Protect, Detect, Respond and Recover, supported by relevant checks drawn from CIS Controls, NCSC guidance and other recognised good practice. 

This helps decision-makers understand the overall picture without needing to become cyber security experts. 

The gaps that have been identified 

We explain where controls, processes or protections could be improved and what those weaknesses mean in practical terms. 

Where technical language is unavoidable, we explain it in plain English. 

Your prioritised risks 

We identify which findings deserve the most attention. 

This gives you a sensible order in which to address them rather than treating every recommendation as equally urgent. 

Finally, we explain what can be done to reduce the risks we have identified. 

That may include quick, low-cost improvements, short-term projects and longer-term changes. 

Together, these recommendations give you a practical cyber security roadmap, starting with the actions that are likely to deliver the greatest value and working onwards from there. 

Is a Gap Analysis the same as a penetration test? 

No. 

A penetration test is primarily focused on finding technical vulnerabilities by actively testing whether systems can be compromised. 

A Cyber Security Gap Analysis takes a broader view. 

It considers technology, but also looks at areas such as people, processes, access, policies, monitoring, incident response and recovery. 

Penetration testing can be a valuable part of a wider cyber security programme, but it does not replace a broader assessment of how cyber security is managed across the business. 

Final Thoughts 

A Cyber Security Gap Analysis should answer a simple but important question: 

Where should we focus our cyber security efforts next? 

By using the six areas of the NIST Cybersecurity Framework as our foundation, then blending in CIS Controls, NCSC guidance and other recognised good practice, Get Support can assess the wider security picture rather than concentrating on individual products or isolated technical issues. 

We look at what your business relies on, what matters most, what is already working, where the gaps are and which improvements should take priority. 

We also look for the improvements that can deliver the greatest impact for the time and budget available. That might mean starting with a simple configuration change or making better use of technology you already have before moving on to larger projects. 

The result is a clearer, more practical approach to cyber security. 

Instead of trying to answer the impossible question of whether your business is completely secure, you can focus on something much more useful: understanding your biggest risks and taking sensible steps to reduce them. 

Get a clearer picture of your cyber security risks 

If you are unsure where the weaknesses are in your current cyber security setup, Get Support can help. 

Our Cyber Security Gap Analysis is structured around Govern, Identify, Protect, Detect, Respond and Recover. We combine this NIST-led approach with relevant CIS Controls, NCSC guidance and other recognised good practice to assess your current position, identify important gaps and prioritise the improvements that will make the biggest difference. 

We explain everything in plain English and help you build a practical improvement plan, starting with high-impact, cost-effective changes where possible and working onwards from there. 

Contact Get Support to discuss a Cyber Security Gap Analysis for your business. 

FAQs 

It depends on the size and complexity of your business. A smaller organisation with a straightforward IT environment will usually require a different level of assessment from a business with multiple offices, systems or suppliers. The scope should be proportionate to your environment and risks. 

No. We may need input from people who understand particular systems or business processes, but the findings are designed to be understandable to non-technical decision-makers. 

No assessment can guarantee that a business will never experience a cyber incident. The purpose of the analysis is to help you understand your current risks and identify practical ways to reduce them. 

Yes. The framework is designed to be flexible and can be applied proportionately to businesses of different sizes and levels of complexity. It gives SMEs a useful structure for understanding security without requiring every organisation to take exactly the same approach. 

Yes. We can help you understand the recommendations, decide what should be tackled first and implement the improvements. Where possible, we will prioritise high-impact, cost-effective changes before working through larger or longer-term improvements. 

Sources 

This article reflects Get Support’s NIST-led approach to Cyber Security Gap Analysis, supplemented by relevant CIS Controls, guidance from the UK’s National Cyber Security Centre (NCSC) and other recognised cyber security good practice.