Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

Security risk assessments that say what to fix first.

F Creative Studio 360 reviews assets, controls and the rules that apply to organisations in any country, then hands back a prioritised roadmap.

A findings list is not a plan.

The assessment follows NIST SP 800-30 for how risk is identified and ranked, and ISO/IEC 27005 where the organisation already manages information security risk that way. The NIST Cybersecurity Framework is used when that is the language management already speaks.

Alignment with a standard is not a certification. F Creative Studio 360 does not claim the organisation is certified to ISO/IEC 27001.

Not everything can be protected equally
A long list of findings does not tell a leadership team what to fund first. The assessment ranks issues by the effect on the business, so spend follows the risk that matters.
The framework follows the organisation
A bank, a factory, a hospital and a public body do not sit under the same rules. F Creative Studio 360 uses the references that apply where you operate, not a single country’s statute.
A finding is not a decision
The report says what was observed, what it could affect, and what to do first. It does not certify the organisation, and it does not replace your counsel.
This is not a penetration test
The work is a review of assets, controls and the rules that apply. Systems are not attacked. A test of live systems is a separate engagement, and only when it is written into scope.

What the assessment covers

The scope is set for the organisation in front of you. The same method works in any country. The rules inside it change with the entities and the sector.

Assets and what they support
The systems, data and suppliers the organisation depends on, grouped by the service they keep running. Classification follows how the business uses them.
The rules that actually apply
A gap view against the frameworks in scope. A rule from one country is used only when that organisation is subject to it.
How well the controls work
Whether the controls that are supposed to be in place are operating, including for suppliers where third-party risk is in scope.
Industrial and operational technology
When a plant or connected device environment is in scope, a non-intrusive look at zones, conduits and security level, using IEC 62443. Live disruption is not part of the work.
What to fix first
A ranked list tied to business effect, so a leadership team can see what to do now and what can wait.
A roadmap you can hand on
Priorities, owners and what evidence to keep. F Creative Studio 360 does not file the programme with a regulator.

How an assessment runs

The same shape works in any country. It can be done on site or remotely, including when the systems sit in more than one place.

  1. 1

    Confirm the context

    Which entities, which countries, which assets, and which rules those entities are actually subject to.

  2. 2

    Review against those rules

    A structured look at assets, controls and suppliers. No attack on systems, and no availability test.

  3. 3

    Rank the risk

    Findings are ordered by the effect on the service, the data and the obligations that apply.

  4. 4

    Hand back the roadmap

    A business-facing note and a prioritised plan. Your team and your counsel own the actions and any filing.

What you receive

  • A picture of the assets and suppliers the organisation depends on.
  • A gap view against the frameworks that were in scope.
  • Findings ranked by business effect, not by a raw technical count.
  • A roadmap with what to do first, and what can wait.
  • A record of what was reviewed, without a claim that you are compliant.

Rules the assessment can use

F Creative Studio 360 uses the references that apply where you are governed. Examples include IEC 62443 for industrial environments, NIS2, the HIPAA Security Rule and PCI DSS.

For an organisation that is actually subject to them, the assessment can use CPS 234, the Security of Critical Infrastructure Act, the Information Security Manual, the Protective Security Policy Framework and the Essential Eight. Naming a rule is not a statement that you comply with it.

Common questions

What is included in a security risk assessment?+

Asset identification, a gap view against the frameworks in scope, and a prioritised roadmap. You receive a report a leadership team can use. F Creative Studio 360 does not certify that you comply with a standard.

How is this different from a cybersecurity audit?+

An audit checks whether controls, policies and configuration match a stated baseline. A risk assessment goes on to rank what was found by the effect on the business, and says what to do first. They can be scoped together, and they are not the same engagement.

Where do you deliver this?+

For organisations in any country. The assessment uses the rules that apply where you are governed. Examples include the NIST Cybersecurity Framework, ISO/IEC 27005 and IEC 62443. A local rule, such as CPS 234, the SOCI Act, the Information Security Manual or the Protective Security Policy Framework, is used only when that organisation is actually subject to it.

Will you test our systems?+

No. This engagement does not attack systems, send phishing mail, or run a denial-of-service test. If authorised testing is needed, it is written as a separate scope. In an industrial environment the review stays non-intrusive.

Do you file the risk programme for us?+

No. The assessment names the obligations that apply and turns them into a roadmap. Interpretation of the statute, and any registration or filing, stays with your counsel. F Creative Studio 360 does not file reports for you.

How much does it cost, and how long does it take?+

It depends on the size of the environment and how many frameworks are in scope. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Start with the risk the business actually carries.

F Creative Studio 360 will look at the entities, the assets and the rules that apply, then say what a sensible assessment includes.