Cybersecurity Put to the Test: How Compliant Is Your Company, Really?

Author
Andreas Winet
Published
14. September 2026

Share article

Firewalls, cybersecurity policies and tools provide protection. However, without an objective benchmark, it remains unclear just how resilient your organisation actually is. A gap assessment compares your current security status with relevant standards and regulations. It identifies security gaps, assesses the need for action and recommends measures. This article outlines current compliance requirements and uses a checklist to guide you through the three steps of a thorough gap assessment.

Safety measures may be in place, processes may be defined, and regulatory requirements may be known. What matters is whether they actually achieve the desired state of safety in practice. The gap between assumptions and the verifiable actual state becomes particularly relevant when new requirements, technical changes, or business decisions call for a robust assessment of the current situation. Gap assessments and audits are therefore particularly relevant for companies that:

  • must comply with requirements from standards and regulations such as ISO 27001, NIS2, DORA, or the ICT Minimum Standard;

  • need clarity on their current security posture following a cloud migration or corporate acquisition;

  • need to provide well-founded statements on the risk situation to management and auditors;

  • systematically assess their maturity level prior to ISO 27001 certification.

Why the Current State of Cybersecurity Is Often Deceptive

The perceived level of security may differ from the actual state of affairs. Security managers work with a mental map of their organization. They know the systems, the measures, and the biggest risks. This map rarely fully reflects reality.

Typical blind spots uncovered by a structured assessment:

  • Policies exist on paper but are not consistently followed in day-to-day operations.

  • Access rights were initially assigned correctly but were not updated following reorganizations.

  • Cloud environments have grown over time without permissions and configurations being systematically updated.

  • Vendors are deeply integrated into critical processes but have never been vetted for security requirements.

  • AI systems were implemented without systematically evaluating the new attack surfaces.

An outside perspective helps to objectively identify such blind spots. It complements the technical expertise of internal teams and highlights where the actual security posture differs from the organization’s own assessment.

What Standards and Regulations does a Gap Assessment cover?

A gap assessment can compare the current state with requirements from NIS2, DORA, ISO/IEC 27001, the Cyber Resilience Act, or industry-specific Swiss guidelines, among others. Which of these are relevant depends on the industry, the company’s location, and its objectives. As threats increase, so do the regulatory requirements that organizations must address.

  • NIS2 (EU): Applies to essential and important facilities in 18 sectors; relevant to Swiss companies through EU subsidiaries and supply chain requirements.

  • DORA: Effective as of January 17, 2025, for financial firms and their third-party ICT service providers, with specific requirements for digital operational resilience.

  • ISO/IEC 27001:2022: International standard for information security management systems, serving as the basis for external certifications.
  • Cyber Resilience Act (CRA): EU regulation setting requirements for the cybersecurity of products with digital elements.
  • FINMA RS 23/1 (Switzerland): Requirements for the management of operational risks and operational resilience of banks and securities firms, including ICT and cyber risks.
  • ICT Minimum Standard (Switzerland): Recommendation by the Federal Office of Energy (BWL) for critical infrastructure; made mandatory for grid operators in the electricity sector via the Electricity Ordinance (StromVV).

The requirements are complex and constantly evolving. A gap assessment reveals which relevant requirements are already met and where gaps still exist. For regulated sectors, we work within the respective mandatory framework; for general assessments, we typically use NIST CSF 2.0.

Would you like to know which security gaps in your organization may still be undetected? Our cybersecurity assessments provide a robust assessment of your current status and highlight areas where action is needed.

Cyber Security Assessment

Which Type of Assessment is right for your Situation?

Depending on the regulatory, technical, or organizational context, different types of assessments are used. They evaluate the security posture based on the requirements relevant to the specific company.

Compliance and Certification

Technical Security Status
  • Cloud Security Assessment: Analysis of the security posture in cloud environments, including a shared responsibility assessment, in accordance with the Cloud Controls Matrix of the Cloud Security Alliance.

  • CIS Benchmark Assessment: Technical evaluation of system configurations against the CIS Benchmarks as recognized hardening standards for operating systems, applications, and cloud platforms.

  • Zero Trust Readiness Assessment: Evaluation of the current maturity level relative to a zero-trust architecture model and derivation of a prioritized implementation path.

New Technologies
Corporate Transactions

Comprehensive Status Assessment
  • NIST CSF 2.0 Assessment: A structured evaluation across the six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Our approach is consistent across all assessments: We conduct structured data collection, prioritize based on risk, and deliver reports that provide management with a robust basis for decision-making and can be directly translated into actionable steps by technical teams.

Three-Step Checklist: How Is a Thorough Gap Assessment Conducted?

A thorough gap assessment proceeds in three steps: defining the scope and assessment framework, assessing the current state, and translating the identified gaps into risk-based actions. It provides a structured assessment of the security level, classifies risks, and identifies which steps will have the greatest impact first. The key is to translate these findings into a roadmap that management and technical teams can jointly steer.

1. Preparation: Define clear Objectives and a precise Scope

  • Define the reference framework: Establish the applicable standard or framework for the assessment (e.g., NIST CSF 2.0, ISO 27001, NIS2, CRA, DORA, internal guidelines).

  • Clarify the scope: Which systems, processes, and organizational units are included?

  • Compile documentation: Guidelines, process documentation, technical configurations.

2. Execution: Systematically Assess the Current State

  • Assess the security status: Conduct interviews with subject matter experts to determine the operational status of security measures.
  • Document the current state: Review documents and perform technical analyses to objectively verify the current status.
  • Conduct in-depth configuration reviews: Optionally, perform technical reviews of selected configurations, such as Active Directory, firewall rules, or Microsoft 365.
  • Assess the degree of compliance: Compare the assessed current state with the requirements of the reference framework and identify gaps as well as requirements that have been met.

3. Evaluation: Prioritize cyber risks, derive measures

  • Prioritize gaps: Evaluate and prioritize identified gaps based on potential damage and probability of occurrence.
  • Action Plan: What has high priority, and what can be implemented in the medium or long term?
  • Results Report: Understandable for senior management, actionable for technical teams.

What Gap Assessments Reveal in Practice

Robust technical controls are not enough if governance, supplier management, or documentation fall short of essential requirements.

Two real-world examples show how a structured comparison reveals such discrepancies.

Case Study 1: Governance Gaps Despite Robust Technology

A medium-sized industrial company was preparing for the requirements of NIS2. The internal team was well-positioned, had invested over the years, and was confident that it met the essential requirements. The assessment revealed that the technical controls were robust. The biggest gaps were in governance, supplier management, and documentation—areas that were considered “administrative” internally and had never been prioritized. The gaps were closed before the deadline because they were identified in time.

Case Study 2: Security Gaps with Critical Third-Party ICT Providers

At a financial institution preparing for DORA, the gap lay elsewhere: Several critical third-party ICT providers had not been provided with contractual security requirements. This aspect had simply never been systematically reviewed as part of the organization’s existing security management. A structured assessment brought this gap to light, making it possible to address it.

Both cases illustrate a pattern that structured assessments frequently uncover: Even established security organizations deviate from relevant requirements in certain areas.

Conclusion: Cybersecurity Requires Clarity, Not Assumptions

Without a structured assessment, it remains unclear just how robust the assumed security posture actually is. Companies then manage what they already know—and risk overlooking relevant gaps.

A gap assessment provides security managers and executive leadership with the foundation to make informed decisions:

  • Where do we need to invest now?

  • What should we prioritize?

  • How do we provide auditors and partners with verifiable proof that we meet relevant requirements?

Companies that can answer these questions provide verifiable proof of compliance and prepare more effectively for emergencies.

Would you like to know how your cybersecurity actually measures up against relevant standards and regulatory requirements? We’ll assess your current situation, identify relevant gaps, and highlight which measures should be prioritized. Contact us for a no-obligation discussion about a gap assessment.

Cyber Security Assessment

Don’t want to miss any more relevant developments in cybersecurity? Our blog updates regularly deliver in-depth analyses of new cyber threats, current security risks, and key trends directly to your inbox.

Subscribe to Blog Updates

 

Caption: AI-generated image

Table of Contents
    Share article