Information security gap analysis

Before you commit to a certification budget, find out where you actually stand and what the distance really costs.

← Back to home

The question a gap analysis exists to answer

Before committing a budget to certification or a compliance route, you want three answers: where you stand today, what it takes to close the distance, and how long that will take. A gap analysis exists to produce those three. Everything else it produces is decoration.

Most organisations misjudge the distance in a predictable way. They overestimate what is missing in technology and underestimate what is missing in governance. The controls that turn out to be absent are rarely the technical ones. What is absent is that nobody owns the process, nobody reviews it, and nothing it does leaves a trace.

That distinction matters commercially, because the two kinds of gap have very different price tags.

Measured against what

Against ISO/IEC 27001:2022, covering both the management system requirements and the Annex A controls. Against the CyberFundamentals framework at the assurance level that applies to you. Or against both, which is the sensible option when NIS2 is the driver and you have not yet settled on a conformity route.

The frame should match the decision you are about to make. Measuring against a standard you have no intention of adopting produces an interesting document and no decision.

How I run it

  1. Frame the decision We establish what this analysis feeds: a certification go or no-go, a budget request, a customer commitment, a regulatory route. The framing determines the depth needed, and stops the exercise turning into an audit you did not ask for.
  2. Review what exists Policies, procedures, registers, previous assessments, contracts and whatever governance already runs. A surprising amount of the requirement is usually already met somewhere, in a form nobody has ever called a control.
  3. Talk to the people who do the work Interviews with process owners across the business, not only with IT. Information security requirements land on HR, procurement, facilities and operations at least as much as on the technical team, and that is exactly where undocumented practice tends to be found.
  4. Score against evidence Each requirement scored with the evidence recorded beside it, and a clear separation between what is genuinely missing and what exists but cannot be demonstrated. The second category is usually the larger one and always the cheaper one to fix.
  5. Turn it into a roadmap Findings sequenced into a plan with owners, effort bands and dependencies, ordered so that early work makes later work easier. A list of gaps is a problem statement. A roadmap is something you can fund.

What you get

Who this is for

Organisations deciding whether to commit to ISO 27001 or a CyFun route, organisations that need a defensible number to put in a budget, and organisations that inherited a security programme and want to know what they actually own. It suits management teams who would rather have an uncomfortable baseline than a comfortable assumption.

A gap analysis is not always worth buying. If you already know you are a long way from the standard and you are committed to getting there anyway, the analysis mostly confirms what you know and delays the work. When that is your situation, I will say so and we can start on the implementation instead.

Questions I get

How long does it take?

For a typical SME, one to two weeks, of which your team spends perhaps an hour each in interviews. You get the report within a week of the last conversation, because a gap analysis delivered late is a gap analysis delivered after the decision.

Do you need access to our systems?

Very little. This is an assessment of governance and evidence, built on documents and conversations. It is not a penetration test or a technical audit, and where a technical examination is the right next step I will say so rather than improvise one.

Is this the same as a risk assessment?

No, and the difference matters. A gap analysis measures you against a standard. A risk assessment measures you against your own risks. A gap analysis will not tell you what matters most to your business, and a risk assessment will not tell you whether you would pass an audit. Certification requires the risk assessment; the gap analysis is what makes the road towards it predictable.

What if the result is bad?

Then it is the cheapest bad news in the project. Every gap found now is a gap you plan for, rather than one a certification body finds under time pressure at your expense.

Could we not do this ourselves?

You can, and it is worth doing as a first pass. Be aware that internal self-assessments run optimistic in a consistent direction: people score the intention rather than the evidence, and nobody enjoys scoring their own area poorly. The value I add is mostly that I have no reason to be kind about it.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call