InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Deutschland GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Deutschland GmbH
Am Gierath 20A
40885 Ratingen
Germany
InfoGuard GmbH
Kohlmarkt 8-10
1010 Vienna
Austria
Safety measures may be in place, processes may be defined, and regulatory requirements may be known. What matters is whether they actually achieve the desired state of safety in practice. The gap between assumptions and the verifiable actual state becomes particularly relevant when new requirements, technical changes, or business decisions call for a robust assessment of the current situation. Gap assessments and audits are therefore particularly relevant for companies that:
must comply with requirements from standards and regulations such as ISO 27001, NIS2, DORA, or the ICT Minimum Standard;
need clarity on their current security posture following a cloud migration or corporate acquisition;
need to provide well-founded statements on the risk situation to management and auditors;
systematically assess their maturity level prior to ISO 27001 certification.
The perceived level of security may differ from the actual state of affairs. Security managers work with a mental map of their organization. They know the systems, the measures, and the biggest risks. This map rarely fully reflects reality.
Typical blind spots uncovered by a structured assessment:
Policies exist on paper but are not consistently followed in day-to-day operations.
Access rights were initially assigned correctly but were not updated following reorganizations.
Cloud environments have grown over time without permissions and configurations being systematically updated.
Vendors are deeply integrated into critical processes but have never been vetted for security requirements.
AI systems were implemented without systematically evaluating the new attack surfaces.
An outside perspective helps to objectively identify such blind spots. It complements the technical expertise of internal teams and highlights where the actual security posture differs from the organization’s own assessment.
A gap assessment can compare the current state with requirements from NIS2, DORA, ISO/IEC 27001, the Cyber Resilience Act, or industry-specific Swiss guidelines, among others. Which of these are relevant depends on the industry, the company’s location, and its objectives. As threats increase, so do the regulatory requirements that organizations must address.
NIS2 (EU): Applies to essential and important facilities in 18 sectors; relevant to Swiss companies through EU subsidiaries and supply chain requirements.
DORA: Effective as of January 17, 2025, for financial firms and their third-party ICT service providers, with specific requirements for digital operational resilience.
The requirements are complex and constantly evolving. A gap assessment reveals which relevant requirements are already met and where gaps still exist. For regulated sectors, we work within the respective mandatory framework; for general assessments, we typically use NIST CSF 2.0.
Would you like to know which security gaps in your organization may still be undetected? Our cybersecurity assessments provide a robust assessment of your current status and highlight areas where action is needed.
Depending on the regulatory, technical, or organizational context, different types of assessments are used. They evaluate the security posture based on the requirements relevant to the specific company.
ISO/IEC 27001:2022 Assessment: Preparation for initial certification or review of an existing ISMS.
NIS2 & DORA Compliance Assessment: Gap analysis with a concrete action plan to meet regulatory requirements.
ICT Minimum Standard Assessment: Evaluation of the maturity level for critical infrastructure in accordance with Swiss federal guidelines.
Cloud Security Assessment: Analysis of the security posture in cloud environments, including a shared responsibility assessment, in accordance with the Cloud Controls Matrix of the Cloud Security Alliance.
CIS Benchmark Assessment: Technical evaluation of system configurations against the CIS Benchmarks as recognized hardening standards for operating systems, applications, and cloud platforms.
Zero Trust Readiness Assessment: Evaluation of the current maturity level relative to a zero-trust architecture model and derivation of a prioritized implementation path.
AI Security Assessment: Assessment of security risks associated with the use or development of AI systems.
Security Due Diligence (M&A): Systematic assessment of a target company’s security posture in the context of corporate transactions.
NIST CSF 2.0 Assessment: A structured evaluation across the six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
Our approach is consistent across all assessments: We conduct structured data collection, prioritize based on risk, and deliver reports that provide management with a robust basis for decision-making and can be directly translated into actionable steps by technical teams.
A thorough gap assessment proceeds in three steps: defining the scope and assessment framework, assessing the current state, and translating the identified gaps into risk-based actions. It provides a structured assessment of the security level, classifies risks, and identifies which steps will have the greatest impact first. The key is to translate these findings into a roadmap that management and technical teams can jointly steer.
Define the reference framework: Establish the applicable standard or framework for the assessment (e.g., NIST CSF 2.0, ISO 27001, NIS2, CRA, DORA, internal guidelines).
Clarify the scope: Which systems, processes, and organizational units are included?
Compile documentation: Guidelines, process documentation, technical configurations.
Robust technical controls are not enough if governance, supplier management, or documentation fall short of essential requirements.
Two real-world examples show how a structured comparison reveals such discrepancies.
A medium-sized industrial company was preparing for the requirements of NIS2. The internal team was well-positioned, had invested over the years, and was confident that it met the essential requirements. The assessment revealed that the technical controls were robust. The biggest gaps were in governance, supplier management, and documentation—areas that were considered “administrative” internally and had never been prioritized. The gaps were closed before the deadline because they were identified in time.
At a financial institution preparing for DORA, the gap lay elsewhere: Several critical third-party ICT providers had not been provided with contractual security requirements. This aspect had simply never been systematically reviewed as part of the organization’s existing security management. A structured assessment brought this gap to light, making it possible to address it.
Both cases illustrate a pattern that structured assessments frequently uncover: Even established security organizations deviate from relevant requirements in certain areas.
Without a structured assessment, it remains unclear just how robust the assumed security posture actually is. Companies then manage what they already know—and risk overlooking relevant gaps.
A gap assessment provides security managers and executive leadership with the foundation to make informed decisions:
Where do we need to invest now?
What should we prioritize?
How do we provide auditors and partners with verifiable proof that we meet relevant requirements?
Companies that can answer these questions provide verifiable proof of compliance and prepare more effectively for emergencies.
Would you like to know how your cybersecurity actually measures up against relevant standards and regulatory requirements? We’ll assess your current situation, identify relevant gaps, and highlight which measures should be prioritized. Contact us for a no-obligation discussion about a gap assessment.
Don’t want to miss any more relevant developments in cybersecurity? Our blog updates regularly deliver in-depth analyses of new cyber threats, current security risks, and key trends directly to your inbox.
Caption: AI-generated image