Skip to main content
NexITC
A4 · CYBERSECURITY · 2 WEEKS · ASSESS

The controls that matter most.
Baselined and prioritised.

A4 · Security Posture Scorecard™ is NexITC's 2-week zero-trust readiness baseline for UAE organisations that need a defensible security posture view and an executable 90-day control plan. Not a penetration test. Not a maturity model rating. A posture heatmap across the controls that matter most — identity, privileged access, logging coverage, vulnerability hygiene, incident response readiness — with a prioritised control backlog, logging and evidence checklist, and executive readout the board can actually work from.

DURATION
2 wks
DELIVERABLES
4 named
COMMERCIAL
Fixed fee
A4·PROJECTION / MFA COVERAGE
A4
BEFORE
60%
MFA COVERAGE · GAPS UNKNOWN
A4
AFTER
95%
MFA COVERAGE · PLAN IN EXECUTION
WK 00
WK 01
WK 02
PLAN
EXECUTION
HEATMAP
5-DIM
BACKLOG
90d
BOARD-READY
YES
SCENARIO · UAE BANK · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY SECURITY DASHBOARDS
MISS THE BOARD QUESTION.

Every UAE CISO we have engaged with has a security dashboard. Some have several. What is rarely present when the board asks 'are we at acceptable risk?' is the specific answer — the specific MFA coverage percentage, the specific privileged accounts without governance, the specific logging blind spots, the specific vulnerability aging trend. Dashboards report activity; boards ask about posture. The two rarely converge without deliberate work between them.

The instinct is to buy another dashboard or commission another pen test. The instinct treats different symptoms. What produces a defensible board answer is baselining the controls that matter most — identity, privileged access, logging coverage, vulnerability hygiene, incident response readiness — against measurable KPIs, and translating the baseline into a 90-day control plan that closes the highest-impact gaps in a defined execution window. A4 does that work on a fixed scope in 2 weeks. Not a penetration test. Not a maturity model. The controls that matter most, baselined and prioritised.

STATE · DASHBOARD-BUSY
Multiple security dashboards. Activity metrics reported weekly. MFA coverage 'high' without specific percentage. Privileged accounts sprawl unknown. Logging gaps assumed non-critical.
STATE · POSTURE-BASELINED
Five-dimension heatmap with specific KPIs per control class. Prioritised 90-day backlog with named remediation owners. Logging and evidence checklist current. Executive readout the board can defend.
§ 01 · WORK STREAMS

Six streams,
ending in the 90-day plan signed.

Security tooling review and control-scope confirmation front-load week 1. KPI baselining, backlog build, and executive readout overlap through week 2. Two phases; six streams tightly sequenced.

STREAM 01
WK 01

Security tooling review

Existing security stack inventoried — SIEM, EDR, IAM, PAM, vulnerability management, IR tooling. Coverage and configuration state assessed against the five control dimensions.

STREAM 02
WK 01

Control-scope confirmation

The five control dimensions (identity, privileged access, logging, vulnerability, IR readiness) scoped to your environment. Cloud posture included where applicable — same scoring frame, cloud-adjacent evidence.

OUTCOME
90-day
CONTROL PLAN SIGNED
+ HEATMAP DEFENSIBLE
STREAM 03
WK 01–02

KPI baselining

MFA coverage %, privileged access governance %, log coverage %, vulnerability aging, incident readiness score — measured against your actual environment, not vendor defaults. This is where most engagements do the load-bearing work.

STREAM 04
WK 02

Prioritised control backlog

Every gap with severity rating, remediation recommendation, and named owner. Sequenced by risk-reduction impact against the 90-day window — not by ease of fix.

STREAM 05
WK 02

Logging and evidence checklist

The specific log sources and evidence artefacts the security team must produce for ongoing SOC operations and audit cycles. Where SIEM gaps exist, they surface here — the checklist is executable, not aspirational.

STREAM 06
WK 02

Executive readout & board pack

Direct executive readout with CISO, CIO, and board sponsor. Posture heatmap and 90-day plan in board-defensible format — the document that answers the 'are we at acceptable risk?' question without further work.

EXPLICITLY NOT COVERED
Penetration testing or adversarial validation
A4 assesses control posture and evidence readiness — not attack-surface exploitation. Traditional network and application penetration testing is a different engagement class. For AI-specific adversarial validation, A9 AI Safety & Red-Teaming Sprint™ handles LLM and agent attack surfaces.
Control implementation itself
The 90-day backlog identifies what to close and in what order. Execution runs through B9 Zero-Trust Core Build™ for zero-trust identity/access controls, or B10 SOC Integration Build™ for SIEM/SOC gaps. A4 defines the plan; B9 and B10 execute against it.
Ongoing security operations
Continuous SOC operations, monitoring, and IR runs through C7 SecOpsCommand™. A4 baselines posture; C7 operates it continuously.
Cyber insurance evidence packaging
Where the assessment output needs insurer-ready formatting for premium optimisation or coverage qualification, A10 Cyber Insurance Readiness Pack™ provides the specific evidence-pack format underwriters expect. Sometimes sequenced A4 → A10 when both audit-cycle and insurance-cycle drivers apply.
§ 02 · TIMELINE

Two weeks.
Two phases.

Duration is fixed at 2 weeks. Phase count is fixed at 2 for engagements this compact. Milestones are signed gates — not aspirations. This is the tightest AssessSKU engagement pattern; scope discipline is what makes it fit.

WK 01WK 02Phase 1 · Tooling review & KPI baselinePhase 2 · Backlog & board packBaseline complete · KPIs measuredEND WK 01 · GATE 01Backlog signed · board pack readyEND WK 02 · GATE 02OPERATING RHYTHMDaily standup · CISO check-in twice-weekly · Practice Lead present at each gateNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalationavailable)
§ 03 · METHODOLOGY

The baseline,
run on measured KPIs not vendor defaults.

Every A4 engagement follows a fixed methodology tuned to your environment in the first two days. Not a pen test. Not a maturity model interview. The sequence that produces a defensible posture baseline and a 90-day control plan in 2 weeks.

METHODOLOGY · SIX STEPS
SEQUENCED · GATED · SIGNED
This is the methodology applied on every A4 engagement — adapted to your environment and control stack, not reinvented per engagement.
01
Security stack inventory
Existing SIEM, EDR, IAM, PAM, vulnerability management, IR tooling catalogued with coverage and configuration state. Scope for the five control dimensions confirmed upfront.
02
KPI baseline against actual environment
MFA coverage %, privileged access governance %, log coverage %, vulnerability aging, incident readiness score — measured against your actual environment, not vendor-defaulted benchmarks. This is where most engagements do the load-bearing work, because vendor-reported baselines routinely overstate coverage.
03
Cloud posture where applicable
Where cloud identity or centralised logging patterns are in scope, cloud posture assessed with the same scoring frame — cloud-adjacent evidence not treated as a separate discipline. Multi-cloud environments assessed per-cloud with unified backlog.
04
Backlog prioritisation by risk-reduction
Every gap sequenced by risk-reduction impact against the 90-day execution window — not by ease of fix. The order matters: a fix that reduces the largest identity-attack-surface gap ranks above three easier fixes that touch lower-risk surfaces.
05
Logging and evidence checklist
The specific log sources and evidence artefacts the security team must produce for ongoing SOC operations and audit cycles. Where SIEM coverage gaps exist, they surface here — the checklist is executable, not aspirational.
06
Board-defensible readout
Posture heatmap and 90-day plan in the format the board sponsor can actually work from — not a security-team internal artefact repackaged. The 'are we at acceptable risk?' question gets a specific answer with specific evidence, not a maturity rating.
!
DISCLOSURE · INDEPENDENCE
A4 is an assessment, not a security-platform selection. The deliverable is a posture baseline, control backlog, and 90-day plan — not a vendor recommendation NexITC benefits from. NexITC works across SIEM/XDR platforms, IAM/PAM providers, vulnerability management tools, and MDR delivery partners without vendor economics gating the baseline. In practice, we have identified logging gaps in SIEM platforms with which we have commercial arrangement, and we have recommended remediation patterns that use tools we do not partner with.
§ 04 · EVIDENCE PACK

From dashboard confidence
to board-defensible posture.

A typical pre-engagement state has multiple security dashboards, activity metrics reported weekly, and no specific answer to the 'are we at acceptable risk?' board question. The engagement produces the posture baseline and 90-day plan the CISO can defend at the next board review without further work.

WITHOUT · T=0
TYPICAL STATE
STATE_01
Multiple security dashboards
ACTIVITY · NOT POSTURE
STATE_02
MFA coverage 'high'
NO SPECIFIC %
STATE_03
Privileged account sprawl unknown
UNMEASURED
STATE_04
Logging gaps assumed non-critical
NOT PROBED
BOARD ANSWER
Dashboard activity + vendor claims + 'we're doing OK' — no specific posture position
OPERATIONAL REALITY
  • Board question 'are we at acceptable risk?' answered without measurable posture
  • MFA coverage overstated by vendor default reporting
  • Privileged accounts without governance identified only during incident response
  • SIEM coverage gaps surface during audit, not during monitoring
A4 · POSTURE
WITH · POST-HANDOVER
TARGET-STATE
PLATFORM_01
5-Dimension Posture Heatmap
Identity · Privileged Access · Logging · Vulnerability · IR Readiness — Measured KPIs per Dimension
PLATFORM_02
90-Day Control Plan
Prioritised Backlog · Named Owners · Risk-Reduction Sequencing · Logging & Evidence Checklist · Board-Defensible Readout
↓ INVENTORIED · MEASURED · PRIORITISED · SIGNED ↓
SECURITY STACK · RETAINED
A4 baselines what you have — no platform swap, no vendor pre-selection. The backlog goes to your team with specifications, not vendor picks
STEADY-STATE OUTCOME
  • Posture heatmap with specific KPIs per control dimension
  • 90-day plan owned by named counterparts, priority-ordered by risk reduction
  • Logging and evidence checklist executable by the security team
  • Board sponsor able to defend 'are we at acceptable risk?' with specific evidence

Reference pattern. Some engagements produce a posture heatmap where the honest output is 'you are in better shape than the dashboard suggested — the specific gaps are these three narrow classes.' That's a legitimate deliverable, not a failure. The alternative is manufacturing findings that would justify a larger backlog than the environment warrants — which produces remediation work the security team does not respect.

§ 05 · REPRESENTATIVE SCENARIO

A UAE bank,
privileged accounts baselined.

Representative pattern for a UAE financial institution facing audit and board-review pressure — MFA adoption uncertain, privileged account sprawl unmeasured, logging gaps assumed non-critical. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / A4 / UAE BANK · ZERO-TRUST BASELINE
DURATION · 02 WKS
PRIVILEGED ACCOUNTS SURFACED
40+
Without MFA governance — identified for remediation
LOGGING GAP PLAN
APPROVED
Board sponsor sign-off within readout session
BUILD KICKOFF
2 WKS
Transition to B9 Zero-Trust Core Build inside 14 days of readout
SITUATION

A UAE financial institution lacked visibility into MFA adoption, privileged account sprawl, and logging gaps — creating audit risk and incident response delays. CBUAE audit cycle six weeks out; board sponsor asking for a defensible posture answer that dashboard activity metrics could not provide. Prior maturity assessment produced a Level 3 rating with no actionable backlog.

ENGAGEMENT

2-week A4. Week 1 security tooling review across SIEM, IAM, PAM, EDR, and vulnerability management, plus KPI baselining across the five control dimensions with cloud posture assessment for the AWS identity plane. Week 2 prioritised control backlog with risk-reduction sequencing (40+ privileged accounts without MFA surfaced), logging and evidence checklist for ongoing SOC operations, and direct executive readout with CISO, CIO, and board sponsor.

OUTCOME

40+ privileged accounts without MFA identified with named owners for remediation. Logging gap coverage plan approved by board sponsor in the readout session. 90-day zero-trust backlog signed with risk-reduction sequencing. Bank transitioned to B9 Zero-Trust Core Build™ within 2 weeks of readout — direct execution against the A4 backlog with scope, KPIs, and named owners carrying over as scope input.

§ 06 · DELIVERABLES

Four artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

Posture Heatmap

Five-dimension heatmap — identity, privileged access, logging, vulnerability, IR readiness — with specific KPIs measured against your actual environment (not vendor defaults). The visualisation the CISO uses with the board.

D_02

Control Backlog

Every gap with severity rating, remediation recommendation, and named owner. Sequenced by risk-reduction impact against the 90-day window — not by ease of fix.

D_03

Logging & Evidence Checklist

The specific log sources and evidence artefacts the security team must produce for ongoing SOC operations and audit cycles. Executable, not aspirational.

D_04 · BOARD-READY

Executive Readout & 90-Day Zero-Trust Plan

Direct executive readout with CISO, CIO, and board sponsor — posture heatmap and 90-day control plan in board-defensible format. The document that answers the 'are we at acceptable risk?' question with specific evidence, and the delivery vehicle that turns the readout into signed execution rather than another shelf-ware plan. Sequenced by risk-reduction impact so the first 30 days close the highest-priority gaps, not the easiest.

HANDOVER
WK 02
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not "the assessment happened." It is measured against six specific outcomes captured at engagement start and re-measured at the executive readout and 30-day post-handover check-in.

THE MFA-COVERAGE JOURNEY · REPRESENTATIVE
Sixty percent to ninety-five, across the plan.
95%MFA COVERAGE
100%75%50%25%060%BaselinePRE-ENGAGEMENT70%Gaps identifiedREADOUT85%30-day sprintHANDOVER + 30D95%90-day plan completeHANDOVER + 90D
01 · MFA COVERAGE
MEASURED
Specific percentage against enterprise identity plane — not vendor default.
02 · PRIVILEGED ACCESS
GOVERNED
Every privileged account with named owner and governance policy.
03 · LOG COVERAGE
BASELINED
SIEM coverage gaps surfaced with named remediation owner.
04 · VULNERABILITY AGING
TRENDED
Aging trend measurable with backlog closing highest-severity classes first.
05 · IR READINESS
SCORED
Incident response readiness measured with backlog closing the specific gaps identified.
06 · BOARD ANSWER
SIGNED
'Are we at acceptable risk?' answered with specific evidence in board-defensible format.
§ 08 · FIT

Honest scoping.

A4 is a fit when specific conditions are met. It is not a fit when other conditions are — and "you need attack-surface validation, not posture baseline" is a legitimate not-a-fit answer we surface before scoping.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
CISO or Head of IT Security as counterpart

Signs off scope, KPI baseline, and 90-day control plan. Typically 30% time commitment through the 2-week engagement.

02
Security-tool access agreed

Read-only access to SIEM, IAM, PAM, vulnerability management, and EDR consoles. Access negotiation post-kickoff extends timeline; sort it up front.

03
Executive sponsor for board-defensible readout

The board sponsor accountable for security posture at board level. Readout without the accountable sponsor produces reports that get filed rather than acted on.

04
Existing baseline data available

Prior audit reports, tooling dashboards, and incident logs from the last 12 months. A4 baselines against your actual environment; historical context accelerates Phase 1.

05
90-day execution appetite

Backlog appetite agreed at commitment level (not exact figure). Without appetite, even signed backlogs become unfunded — filed, not delivered.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
You want attack-surface validation, not posture baseline

That's a penetration test — different engagement class. For AI-specific adversarial validation, A9 AI Safety & Red-Teaming Sprint™ covers LLM and agent attack surfaces. A4 baselines control posture; pen tests exploit attack surfaces.

You need cyber insurance evidence, not audit posture

That's A10 Cyber Insurance Readiness Pack™ — insurer-ready security evidence for premium optimisation. Different evidence set, different buyer (CFO/risk manager alongside CISO), different framework (Federal Decree-Law No. 34 + underwriting standards). Sometimes sequenced A4 → A10 when both drivers apply.

You want zero-trust build, not the plan for it

That's B9 Zero-Trust Core Build™ — fixed-scope Cybersecurity build for the highest-priority zero-trust controls. A4 defines the plan; B9 executes. Sequence: A4 → B9 when the plan needs to be defined first; B9 directly when the plan is already signed.

You need SOC integration or SIEM implementation

That's B10 SOC Integration Build™ for structured SIEM/SOC gap-closure execution. A4 surfaces logging gaps and produces the checklist; B10 implements against it.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based. No surprises.

Every A-tier engagement is scoped and priced upfront against defined deliverables. Milestones tied to signed gates. Change orders negotiated through the Practice Lead, not surfaced as invoice surprises.

COMMERCIAL MODEL
ENGAGEMENT MODEL
Fixed fee, milestone-based
PAYMENT SCHEDULE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 4 named deliverables with acceptance criteria
  • Weekly executive sponsor review
  • Practice Lead present at every phase gate
  • Executive readout at handover
  • Evidence pack and stakeholder map
  • 30/60/90-day post-handover check-ins
01

Scoped upfront

No hourly billing. No open-ended scope. Everything priced against deliverables signed at kickoff.

02

Milestone-gated

Payment tied to phase gates, not calendar. If a gate slips, invoicing slips with it.

03

Change orders authorised

Practice Lead has authority to negotiate scope amendments in the same conversation, not through a separate commercial cycle.

§ 10 · QUESTIONS

Five, most asked.

Q_01Is this a penetration test?

No. A4 is a control posture and evidence readiness assessment — not attack-surface exploitation.

Penetration testing is a different discipline that validates whether attackers can breach specific attack surfaces; A4 measures whether the underlying controls are in place, governed, and operational.

The two are complementary but scope separately. Organisations often run both across an annual cycle — A4 for posture baseline and 90-day plan, penetration testing for adversarial validation of specific attack surfaces.

Q_02What does the posture heatmap actually assess?
Five control dimensions that matter most for defensible security posture: identity (MFA coverage, IAM configuration, guest-account governance), privileged access (PAM configuration, privileged account inventory, session recording), logging coverage (SIEM ingest completeness, log retention, correlation rules), vulnerability hygiene (aging trend by severity, patch cadence, exception governance), and incident response readiness (playbook currency, tabletop exercise recency, escalation-path definition). Each dimension gets specific KPIs measured against your environment, not vendor-defaulted benchmarks.
Q_03Can this include cloud security posture?
Yes. Where cloud identity or centralised logging patterns are in scope, cloud posture is assessed with the same scoring frame — cloud-adjacent evidence not treated as a separate discipline. Multi-cloud environments assessed per-cloud (AWS, Azure, GCP) with unified backlog. Cloud posture is included in the same 2-week duration when scope stays focused; enterprise-wide multi-cloud with 5+ major services extends the engagement to 3 weeks and moves into cross-scope territory that A4's fixed-duration doesn't accommodate.
Q_04How does this differ from A10 Cyber Insurance Readiness Pack?
A4 baselines control posture for audit and board defence — the buyer is the CISO/CIO answering 'are we at acceptable risk?' at board level. A10 packages security posture as insurer-ready evidence — the buyer is the CFO/risk manager qualifying for competitive cyber insurance premiums, with a specific evidence format underwriters expect. Different frameworks (audit-cycle standards vs Federal Decree-Law No. 34 + underwriting), different output format, sometimes overlapping input data. Sequence A4 → A10 when both drivers apply within the same cycle.
Q_05What comes after A4?
Three paths depending on scope. B9 Zero-Trust Core Build™ executes the 90-day plan for identity/access controls. B10 SOC Integration Build™ closes SIEM/SOC gaps A4 surfaced. C7 SecOpsCommand™ operates continuous security operations — sensible once the 90-day sprint completes and ongoing SOC discipline becomes the priority. Some engagements sequence A4 → A10 in parallel when both audit and cyber-insurance cycles apply.
§ 11 · NAMED ACCOUNTABILITY

One name.
Six accountabilities.

Specialist consulting means the person who scopes the work is the person who delivers it — with escalation to CEO on any material issue within 24 hours.

THE ROLE

Practice Lead — Cybersecurity

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 4 deliverables.

03
Weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

30 minutes.
One posture question.

Bring the specific posture question blocking your board conversation — MFA coverage uncertainty, privileged account sprawl, SIEM gaps, IR readiness. A4 is scoped in the clinic — control-stack access, sponsor, timeline, prerequisites. If A4 is not the fit (pen test needed, insurance-cycle driver dominant, controls already known-and-missing), the clinic surfaces the honest alternative.

CLINIC · A4
  • Security tool access confirmation
  • Cloud posture scope check
  • Board sponsor availability
  • Fit assessment against A10, B9, B10
Practice Lead — Cybersecurity attends every clinic.