Skip to main content

Display options

These change how this site looks in your browser and are remembered on this device. They do not replace your own browser or device settings, which apply everywhere and will usually do more.

Text size
Reading
Colour and clarity
Movement and controls
Accessibility statement
SectorsAboutBlogNewsContactCall 01444 222889Book a Consultation

Information Security Health Check

Get a clear picture of your security posture and expert guidance to close the gaps.

Diagram of the Vinula information security health check journey: discover, assess, detect, protect and recover

Most organisations know they should take information security seriously, but few have a clear, honest picture of where they actually stand. An Information Security Health Check gives you that picture. It is a structured review of your security controls, policies, and the way your people work, ending in plain English guidance on what to fix first. It is ideal for organisations that are not pursuing full ISO 27001 but still need genuine assurance that their information is well protected.

What the health check looks at

We review your existing controls, policies, and processes, and we look at how security works in practice day to day, not just what your documents say. The result is a clear view of where the real gaps and risks are.

What you walk away with

A report that prioritises what matters, written so you can act on it, not a list of jargon. Depending on the level you choose, this extends to tailored policies, staff training, and ongoing support to work through the improvements.

Why start here

You cannot protect what you have not assessed. A health check is the natural starting point because it tells you where to focus your effort and budget for the biggest reduction in risk.

What we measure your security against

A review is only useful if it is measured against something solid. We assess your information security approach against recognised industry standards and good practice, so the findings are grounded rather than a matter of opinion. That covers the areas any well run organisation needs in place: governance and policies, risk management, access to systems and data, device and network security, supplier arrangements, incident handling, business continuity and the way staff handle information day to day. Because this ground overlaps heavily with ISO 27001 and Cyber Essentials, the findings stay useful if you later decide to pursue either. Every gap we record comes with a plain explanation of why it matters and a recommended action, so your information security health check turns into a plan you can actually work through.

Who the health check suits

The health check was designed for small to medium sized businesses and public bodies that want to know how well their information is protected, without taking on a full certification project. It suits organisations that are not sure where to start, those that have been asked searching security questions by a client or in a tender, and those that simply want peace of mind and an independent view of where they stand. It is also a sensible first step before a major change, such as pursuing certification, merging with another business or taking on a contract with demanding security terms. We work with organisations in Sussex, London and across the UK, and much of our work is delivered remotely, so where you are based is rarely a barrier.

How a health check runs

Our approach is straightforward and collaborative. We start by meeting you to understand your organisation, your systems and how you currently handle information. We then review your security approach against relevant standards, looking both at your documents and at how things are really done, and identify the key gaps and risks. Next comes a clear, prioritised report with recommendations tailored to your business, so the most important fixes are obvious and the smaller ones are kept in proportion. Finally, if you want it, we support you to put the changes in place or to prepare for further audits or certification. We scope the review with you at the outset, and the level you choose decides how deep the assessment goes and how much support follows the report.

From health check to ISO 27001 or Cyber Essentials

Many organisations use the health check as a stepping stone. If your customers or tenders start asking for ISO 27001, the gap analysis, policies and risk work from the health check give you a head start, and our ISO 27001 preparation service can build on them rather than starting again. If Cyber Essentials is the more realistic target, the review will highlight where your technical controls fall short of what that scheme expects, such as secure configuration, access control and keeping software up to date. Vinula is Cyber Essentials certified and our team includes a qualified Cyber Essentials assessor, so we can advise on which route fits your situation. Where the findings point to technical weaknesses that need testing, we can also arrange penetration testing through our partners.

Where we work

We work with organisations across the UK. Much of our work is delivered remotely, so we support clients wherever they are based, with particular strength in London and the Southeast. We are based in Haywards Heath, West Sussex, and the areas we cover include London, Brighton and Hove, Crawley, Horsham, Haywards Heath, Burgess Hill, Worthing, Guildford, Tunbridge Wells, Reading, Slough, Newbury, Swindon and Bristol.

Want to know if this is the right fit for your organisation? We will talk it through with you, with no obligation.

Get in touch

A structured review of your security controls, policies and behaviours for organisations that are not implementing ISO 27001 but need assurance their information is well protected.

Pricing and tiers

Bronze
£1,900
  • Basic information security gap analysis and report identifying key compliance gaps
  • Recommended mitigating actions to address areas of risk
  • One-hour online training session on information security basics for key staff
  • Checklist for ongoing information security improvement
Silver
Enquire for pricing
  • Comprehensive gap analysis with detailed report and actionable recommendations
  • Customised essential information security policies
  • Two 90-minute training sessions for staff and leadership
  • Assistance with information security processes and templates
  • Support for a risk assessment of one high-risk process
Gold
Enquire for pricing
  • In-depth audit with ongoing monitoring and quarterly compliance reviews
  • Fully customised information security documentation suite
  • Support for risk assessment of high-risk processes during engagement
  • Comprehensive process setup and security training
  • Ongoing consultancy support up to one day per month for six months

Ready to get started?

Book a consultation and we will tailor this service to your organisation and the risks it faces.

Book a consultation
Questions

Frequently asked questions

It depends on the size and complexity of your organisation, but the Bronze level is designed to give you a clear picture quickly and affordably. We scope it with you first so you know what to expect.

No. A health check is a lighter, faster way to understand and improve your security. If you later decide to pursue ISO 27001, the health check is a useful first step, but it is valuable on its own for organisations that do not need certification.

That is up to you. You can act on the recommendations yourself, or we can support you through them, from policies and training to ongoing consultancy, depending on the level you choose.

No. A penetration test, like the IT Health Check (ITHC) used in parts of the public sector, is a technical exercise in which specialists try to find exploitable weaknesses in your systems. Our information security health check is broader: it reviews your controls, policies, processes and people. The two work well together, and we can arrange penetration testing through our partners where the findings suggest it.

Free tools, such as the National Cyber Security Centre's online checks, are a useful quick scan of your public facing systems. They cannot see your policies, your access controls, your suppliers or how staff handle information. Our health check looks at all of that with you and ends in prioritised recommendations written for your organisation.

The Bronze level is £1,900. It gives you a gap analysis and report, recommended actions for each area of risk, a one hour online training session for key staff and a checklist for ongoing improvement. Silver and Gold add tailored policies, more training and ongoing support, and are priced on enquiry because they depend on your size and needs.

Yes. Much of our work is delivered remotely, so we can support organisations wherever they are based in the UK, and the Bronze level training session is delivered online. If you would find time on site more useful for your organisation, let us know when we scope the work together and we will discuss what suits you.

Gold goes beyond a one off review. It includes an in depth audit with ongoing monitoring and quarterly compliance reviews, a fully customised documentation suite, risk assessment support for high risk processes, process setup and security training, and consultancy support of up to one day per month for six months while you put the improvements in place.

Interested in Information Security Health Check?

Book a consultation and we will tailor the right level of support to your organisation.

Book a Consultation