Cybersecurity & GRC

What a Cybersecurity Gap Assessment Actually Finds (And Why None of It Is Your Fault)

What a Cybersecurity Gap Assessment Actually Finds (And Why None of It Is Your Fault)

When business owners imagine a cybersecurity assessment, they picture something out of a heist movie: a hooded figure in a dark room, green text scrolling across a screen, someone typing very fast while saying "I'm in." They brace for us to find something equally dramatic. What we actually find, almost every single time, is far less cinematic and far more human: a handful of ordinary, forgivable things that got deprioritized because everyone was busy running an actual business.

We want to say this clearly, up front, before we get into the details: nothing in this article is a judgment of you, your team, or your decisions. Every gap we're about to describe is one we've seen at well-run, successful, smart companies. Security gaps are not a report card on your competence. They're a report card on the fact that securing a business properly is a full-time specialty, and you were busy doing your actual full-time job.

The most common finding: nobody currently "owns" security

Not "nobody cares." Nobody owns it, in the specific sense of having it clearly assigned as their job with time carved out to do it. Security tasks get handled reactively, by whoever happens to be free, with no single person tracking what's been done and what hasn't. This single gap explains a huge share of everything else on this list, because ownership is what turns a good intention into a habit, and a habit is what actually protects you. Good intentions, on their own, protect nobody, which is a very depressing sentence to read but also very fixable.

The "Dave left in March" problem

This deserves its own section because it's so common it should have its own holiday. A huge number of the gaps we find trace back to one very specific, very sympathetic cause: the person who used to manage this left the company, and nobody fully replaced their knowledge, only their job title. Dave set up the firewall rules in 2021. Dave configured the backup schedule. Dave had a system, in his head, that made sense to Dave. Then Dave took a job in Calgary, and the company hired someone lovely named Priya to do "IT stuff," and Priya inherited Dave's kingdom with none of Dave's memory. This is not Priya's fault. It was never fully documented, which means it was never really transferable in the first place, which means the gap existed the moment Dave was hired, not the moment Dave left. Businesses don't create this problem. Time and turnover create this problem, for absolutely everybody, eventually.

Shared logins, and the ghosts of employees past

Almost every assessment turns up at least one shared password used by multiple staff members ("the WiFi password is also the router password is also, somehow, the accounting software password"), and at least one account still fully active for someone who left the company months or, memorably, one time, six years ago. Neither of these is a sign of incompetence. It's simply what happens when there's no formal, automatic process for onboarding and offboarding access, and a human has to remember to do it manually, and humans are, as a species, famously bad at remembering things that don't have a calendar reminder attached.

Multi-factor authentication, applied like sunscreen: unevenly and usually missing the back

Most businesses have multi-factor authentication turned on somewhere. Fewer have it turned on everywhere it actually matters: email, remote access, financial systems, and admin accounts especially. Assessments routinely find MFA enabled on the systems that were easy to configure and quietly skipped on the systems that would actually stop an attacker, the digital equivalent of locking your front door while leaving a spare key taped to the doormat labelled "spare key."

Backups that exist, technically, in the same way a gym membership "exists"

We covered this in more detail in our piece on aging infrastructure, but it bears repeating because it comes up in nearly every assessment: there's a very big difference between "we have backups" and "we know our backups actually work," and almost every business we meet has confidently claimed the first one without ever having tested the second. It's the IT equivalent of buying a fire extinguisher and never checking whether it's expired. Comforting to look at. Untested. Hopefully fine.

No formal incident response plan (also extremely normal)

If something goes wrong today, who gets called first? What gets shut down? Who talks to customers, and who talks to the insurance company? Most small businesses have never written this down, which means the first time anyone will figure it out is during an actual incident, at 11pm, in a group text chat with increasingly alarmed punctuation. This isn't a planning failure so much as a "nobody has ever had two free hours to sit down and think about the worst day of the business's life" problem, which, understandably, ranks low on most people's to-do lists until it's the only thing on the list.

  • Vendor and third-party access that was granted once, for one project, and simply never revisited
  • Personal devices connecting to business systems with no policy governing them, because "just use your phone for email" felt like a small, harmless decision in 2019
  • Security awareness training that happened exactly once, years ago, for a team that has since almost entirely turned over
  • Old software licences still active, still billing, still occasionally still accessible to people who left long ago

Why all of this is genuinely good news

Here's the part that tends to surprise people: every single item on this list is fixable, usually without a large budget, once someone identifies it clearly and gives it an owner. A gap assessment isn't a scary report designed to make you feel behind. It's a short, ranked list of exactly what to do first, second, and third, written by someone who has seen this exact pattern hundreds of times and can tell you, with total confidence, that you are not the outlier here. You are, statistically, the norm.

What we don't do during an assessment

We don't ask "whose fault was this." We don't hand you a hundred-page report designed to be intimidating. We don't act surprised, because nothing on this list is surprising to us anymore, in the way a dentist is not shocked that you haven't flossed as much as you should have. We look, we document, we rank, and we hand you something you can actually act on, in an order that makes sense for a business your size, not a checklist copied from a Fortune 500 template that assumes you have a security team of forty people.

A cybersecurity GRC program takes findings like these and turns them into an ongoing practice instead of a one-time fire drill, with clear ownership, documented policies, and evidence you can hand an auditor, an insurer, or a customer who asks. It also means the next time someone like Dave leaves, the knowledge leaves with a full handoff, not a mystery.

If you read this whole list and recognized your business in three or four of these points, congratulations, you are a completely normal small business, and also, good timing: this is exactly the moment to fix it, calmly, before anything forces the issue.

Keep Reading

More on this topic