All services

Cyber Resilience Baseline

Know where your cybersecurity risks are and what to fix first.

You may already have an IT provider, endpoint protection, backups, and MFA. The MEI Cyber Resilience Baseline helps management understand which safeguards can be demonstrated, where important gaps remain, and what deserves attention next.

Request a Fit Call

A defined assessment

What you receive

  • A plain-language executive summary and current-state profile
  • Prioritized findings and the Top 10 recommended actions
  • A 30-day plan, a 90-day plan, and a 12-month improvement roadmap
  • Supporting evidence and assumptions
  • A 60-minute leadership briefing

An evidence-based review

We review cybersecurity and operational resilience practices using NIST Cybersecurity Framework 2.0 and selected CISA Cross-Sector Cybersecurity Performance Goals. The review covers responsibilities, assets, account security, protection, detection, response, recovery, vendors, and critical dependencies.

Standard scope

The standard engagement is designed for approximately 25–150 employees, up to three primary locations, and one principal identity/cloud environment with a reasonably centralized IT setup. It normally includes up to four stakeholder interviews and review of existing documentation and technical evidence. Larger, highly regulated, OT/ICS, or unusually complex environments are scoped separately.

Clear boundaries

This is an advisory assessment to help management prioritize improvement. Penetration testing, compliance attestation, forensic investigation, remediation implementation, and 24-hour monitoring are outside the standard scope. The assessment does not guarantee that an incident will not occur.

Common questions

A clearer picture before you start.

We already have an MSP. Is this useful?

An MSP can be an important participant. The Baseline gives management a view across technology, process, recovery, and priorities. You can use the resulting plan with your MSP or internal team.

Will we have to buy more services?

No. You receive a usable roadmap. If you want MEI to help with selected improvements, that work is scoped separately.

What do we need to provide?

An engagement coordinator, available stakeholders, and agreed documentation and evidence. We do not ask you to submit passwords or live credentials through a public form.

Start with a conversation

What’s the system you’re most concerned about?

A 20-minute Fit Call can help identify the right starting point and whether MEI is a good match.

Request a Fit Call