// NETWORK SECURITY ASSESSMENT · HANS STUDY · ONTARIO, CANADA

Network security assessment and gap analysis

A cyber insurance questionnaire, a customer security review, a CPCSC or CMMC contract clause, an incident that moved sideways across the network, or a new site on a network nobody ever drew. This compares the network with the standard you owe and puts the gaps in the order to fix them.

What it covers

  • Segmentation and VLANs. Whether the sensitive systems are separated from everything else by more than a different SSID. The usual starting point is one flat subnet behind a consumer router, as in the flat network problem.
  • The firewall rule base. Deny by default, allow by exception, and no any-to-any. If the rule set can't be explained to an assessor in one sitting, it can't be defended in one either. See firewall review.
  • Switch configurations. Management plane, port security, and consistency across the stack. See switch config audit.
  • Remote access paths. Every way in that you can draw, ending at the edge of the protected network, with an MFA-protected jump host for support access.
  • MFA on admin paths. Privileged accounts and the cloud tenant's admin plane, not only the VPN.
  • Logging. Whether events are forwarded off the host, so a log on a compromised machine isn't the only copy.
  • DNS filtering. In Canada, CIRA DNS Firewall is the business service, with web access on the protected network limited to what the work needs.

What it is compared against

The required standard, whichever applies: CPCSC and ITSP.10.171, ISO 27001, the CIS benchmarks, or a client's own policy. For CPCSC the two families doing most of the work are system and communications protection and configuration management. A baseline, a change record, and evidence are what an assessor reads, and network configurations can be diffed automatically so drift shows up on its own.

What you receive

  • A ranked gap list, each gap tied to the requirement or standard it fails
  • A target architecture sketch: the segments, the boundaries between them, and the paths in
  • A remediation sequence, ordered so each step is safe to make before the next
  • A working session to go through the findings

How it runs

Four phases, delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.

PH-01

Scope and standard

A call to agree the sites and network segments in scope and the standard they are compared against: CPCSC and ITSP.10.171, ISO 27001, CIS, or a client policy.

PH-02

Collect

The logical topology diagram, the list of controls between a user and the data that matters, the firewall rule set, switch configurations, and the remote access and MFA settings. Collected remotely, through the DHD where needed.

PH-03

Review

The same method as the firewall review and the switch config audit, applied across the whole network and set against the standard.

PH-04

Report and plan

A ranked gap list, a target architecture sketch, and a remediation sequence, walked through with you.

Free tools you can start with

The assessment uses the same approach as these, and you can run them yourself before a call.

NSA-01

PortProof →

A free PowerShell script that proves a declared list of firewall paths is open and returns a pass/fail matrix.

Who it's for

  • Defence suppliers and small manufacturers working toward CPCSC or CMMC on a network that grew without a plan
  • Organizations answering an insurer or customer review that asks how the network is segmented and who can reach what
  • Organizations that were told by a provider that a branded firewall protects them, and want that checked
  • Teams planning a move to a segmented design who want the sequence worked out first

I don't resell hardware or software, so the target architecture is drawn for your needs, not for a price list. See the independence policy.

Related work

Questions

What does a network security assessment check?

Segmentation and VLANs, the firewall rule base, switch configurations, remote access paths, MFA on admin paths, logging, and DNS filtering. Each gap is tied to the requirement or standard it fails.

How is it different from a vulnerability assessment?

A vulnerability assessment scans systems for known weaknesses. This one reviews how the network is built and configured, and compares it with a standard such as CPCSC and ITSP.10.171, ISO 27001, the CIS benchmarks, or a client's own policy.

What do I need to collect before the assessment?

The logical topology diagram, the list of controls between a user and the data that matters, the firewall rule set, switch configurations, and the remote access and MFA settings. If no diagram exists, say so on the scoping call.

Can it be done remotely?

Yes. The 4 phases are delivered remotely, or through the DHD, a remote access device, where the network cannot otherwise be reached.

What do I get at the end?

A ranked gap list, a target architecture sketch of the segments, the boundaries between them, and the paths in, and a remediation sequence ordered so each step is safe to make before the next. We go through the findings together in a working session.

How much does a network security assessment cost?

The sites and network segments in scope are agreed on a scoping call, and a written quote comes before any work starts.

Book a scoping call

Bring the questionnaire or the clause that triggered this, and the topology diagram if one exists, and a short call confirms the scope.