CIS Controls Assessment
Implement CIS Controls, benchmark systems and prove compliance without the guesswork.
CIS-aligned security and compliance services for South African businesses. We use CIS-CAT Pro, CIS Benchmarks and CIS Controls v8 to harden servers, Microsoft 365, Active Directory, firewalls and workstations — with cyber insurance and POPIA-ready documentation.
Sound Familiar?
CIS work usually starts because somebody outside the business has started asking questions. These are the ones we hear most:
- Your cyber insurer or a large customer has asked for evidence of your security controls, and you have nothing to send them.
- You've bought security products over the years, but nobody can say what they cover and what they leave exposed.
- You know "CIS Controls" is the answer to a question you're being asked — you just don't know what it involves or where to start.
- Your last assessment produced a score and a long list, with no indication of what to fix first.
- You need to show a board or an auditor that security is being managed, not just purchased.
- A security assessment sounds like it ends in a report nobody reads and nothing actually changes.
What's included in our CIS Services service
Everything you need from a modern cis services partner — delivered by our engineering team.
- CIS Controls v8 implementation roadmap
- CIS-CAT Pro scanning against CIS Benchmarks
- CIS Benchmarks for Windows Server 2016, 2019 and 2022
- Microsoft 365 (Exchange Online, Teams, SharePoint, Entra ID) baseline
- Active Directory and Group Policy review
- Firewall and network hardening assessments, including FortiGate and Sophos benchmark scans
- Windows 10 / 11 workstation and laptop security baselines
- Detailed pass/fail report per CIS control
- Gap analysis and prioritised remediation roadmap
- Re-scan after remediation to verify improvements
- Executive summary for management and board
- Cyber insurance readiness reports
- Security baseline development aligned to ISO 27001
- Documentation to support your POPIA and audit obligations
- Ongoing compliance monitoring and reviews
What a CIS assessment should give you
The CIS Controls are a prioritised set of safeguards published by the Center for Internet Security. They are useful because they are ordered — they tell you what matters first. Most assessments lose that ordering somewhere between the scan and the report.
Findings you can act on in order
We report against the CIS Controls with findings ranked by business impact and likelihood of exploitation, not by raw severity score. You get a remediation sequence, not a wall of red.
Alignment, not certification
CIS is a framework, not a certification scheme — there is no such thing as being CIS certified. We assess your environment against the Controls, report where you stand, and give remediation guidance you can work through.
The team that finds it can fix it
Assessment and remediation aren't separate engagements handed between vendors. Where you want us to close the gaps we found, we can — and where you'd rather your own team did, the reporting is written so they can.
Evidence you can hand over
Reporting written for the people actually asking: cyber insurers, enterprise customers running vendor due diligence, and boards that need to see security is being governed rather than bought.
Frequently asked questions
What are the CIS Controls?
A set of 18 prioritised safeguards published by the Center for Internet Security, drawn from how attacks actually happen rather than from theory. They're grouped into Implementation Groups so a small business isn't measured against the same expectations as a bank. The value is in the ordering — the Controls tell you which basics close the most risk, which is exactly what most security shopping lists lack.
Can we become CIS certified?
No, and you should be wary of anyone offering it. CIS is a framework for assessing and improving security, not a certification scheme, and there is no certificate to issue. What you can have is a documented assessment of where your environment stands against the Controls, a remediation plan, and evidence of progress over time. That is what insurers and enterprise customers are actually asking for.
How is this different from a vulnerability scan?
A vulnerability scan tells you which systems have known technical weaknesses. A CIS assessment asks whether the controls and processes exist at all — whether you have an asset inventory, whether administrative access is controlled, whether backups are tested, whether logs would tell you anything after an incident. A scan finds holes in what you have. A CIS assessment finds what you don't have.
We already have antivirus and a firewall. Do we still need this?
Those are two controls out of eighteen, and they're the two almost everyone already has. The gaps we find are rarely in the products — they're in the areas nobody owns: unmanaged devices, administrative accounts that were never reviewed, backups nobody has restored from, and no record of who has access to what.
What does an assessment actually produce?
A documented view of your environment measured against the Controls, findings prioritised by business risk, and a remediation plan in the order we'd tackle it. Written to be read by someone who has to make a decision, not only by an engineer.
Will this disrupt our business?
Assessment work is largely read-only — we're examining configuration and process, not changing them. Anything we would change is agreed with you first and scheduled around your operations.
Other IT services
Cybersecurity Services
ROI Technologies delivers end-to-end cybersecurity services including EDR/XDR endpoint protection, vulnerability scanning, network security and compliance. We support SentinelOne and Sophos Intercept X for endpoint protection.
Learn moreCompliance & Governance
CIS Controls implementation, IT governance, risk assessments and POPIA compliance readiness.
Learn moreKnowBe4 Security Awareness Training
KnowBe4 Security Awareness Training and Human Risk Management — managed by ROI Technologies for South African businesses. Simulated phishing, training modules and POPIA-aligned content.
Learn moreNeed CIS Services?
Get a free assessment today and see how ROI Technologies can streamline your IT.
Book a Free Assessment