Cyber Security Assessment Tool

Your cybersecurity action plan, based on facts.

CSAT scans the estate you choose — endpoints, servers, identity, Microsoft 365 and your cloud — and turns the data into a prioritized action plan. No guesswork: you decide where to invest your security resources with real evidence. Our focus is CIS and NIST CSF 2.0.

Powered by QS Solutions

The problem

Organizations often decide blind — and it costs.

Most organizations don't underinvest in security: they invest without knowing where. Research shows a repeating pattern: companies overestimate their defenses, underestimate the impact, and react late.

Perceptions

  • The ability to withstand an attack is overestimated.
  • The real consequences are underestimated.

Decisions

56%take a reactive approach — the most expensive one.

  • Boards lack visibility of the organization's real security posture.

Outcomes

60%of small businesses close within six months of a breach.

  • 25% chance of a major breach; 10% face multi-million losses.

Sources: Smidt & Botsen (2017) · Zeijlemaker (2022) · Aguilar (2015) · Iris (2020)

Chile · Compliance

Get ready for the new data law.

Chile changed the rules. The Cybersecurity Framework Law (21.663) created ANCI, with powers to audit and sanction, while Law 21.719 on Personal Data Protection will create an agency able to issue fines. In both cases the question is the same: can you prove, with facts, where you stand? Our solution helps you find that evidence.

Get ahead of ANCI sanctions

Law 21.663 requires security measures and incident reporting, focused on essential services and vital-importance operators. CSAT surfaces your technical and governance gaps before they become findings: what's missing, how serious it is, and in what order to fix it.

  • Objective evidence for the board
  • Gaps prioritized by risk
  • Basis for your remediation plan

Know where your critical data lives

Law 21.719 forces you to answer something many companies can't today: where personal data sits, who can access it, and how it's protected. CSAT scans your information sources to show you, with real data, where your sensitive information is exposed.

  • Visibility of sensitive data & access
  • Spot exposure before an audit
  • Direct input for your data program

Note: CSAT delivers the technical evidence compliance is built on; it does not replace legal advice. At Fendari we help you translate those findings into decisions.

What it scans

Real data from your estate, not surveys.

CSAT collects information directly from your infrastructure through automated scans, and complements it with a questionnaire based on the CIS framework to cover the organizational layer.

Endpoints

Workstations and servers: configuration, patching and exposure.

Identity

Local Active Directory and/or Entra ID (Azure AD): accounts, privileges and access risks.

Microsoft 365

The tenant and its services: security configuration, data and collaboration.

Cloud & resources

Tenant, subscriptions and deployed resources, with their security configurations.

CIS questionnaire

Organizational controls, policies and key indicators, based on the CIS framework.

Three maturity layers

Technical, socio-technical (how people actually work) and governance. Security is more than firewalls.

Multicloud

Not just Microsoft: we assess the major clouds.

Your critical information rarely lives in one place. Part of the analysis covers the three clouds that dominate the market today, so the risk picture is complete and leaves no blind spots.

Microsoft Azure Microsoft Azure
AWS Amazon Web Services
Google Cloud Google Cloud
NIST

Our extension: NIST CSF 2.0 risk analysis

Fendari goes beyond the tool. We take CSAT's findings and run them through a structured risk analysis on the NIST Cybersecurity Framework 2.0, covering its six functions, including Govern — the one that matters most in front of a regulator. Our results stop being a technical list and become a business and strategy conversation.

What the extension adds

  • Risk by NIST CSF 2.0 function, not just isolated findings.
  • Prioritization by business impact.
  • Language for the board and for the technical team.
  • Traceability with CIS and with your local obligations.

The outcome

An action plan, not just a report.

The deliverable is a risk- and fact-based action plan: the right way to decide where to spend your security resources, which are always valuable and limited.

01

3-layer maturity

Where you stand today across technical, human and governance layers.

02

CIS & NIST gaps

Which controls are missing and how far you are from the standard.

03

Risk matrix

Every finding with its likelihood, impact and priority.

04

Actionable roadmap

What to do, in what order, and with what effort. Ready to execute.

Sample report · CIS v8

Scores backed by data.

1.8 Average maturity
  • 01Inventory & control of enterprise assets2.0
  • 02Inventory & control of software assets2.0
  • 03Data protection2.7
  • 05Account management1.7
  • 06Access control management1.5
  • 09Email & web browser protections3.0
  • 14Security awareness & skills training1.5
  • 17Incident response management4.0

Illustrative example. The real report covers all 20 CIS v8 controls and adds per-endpoint, application and identity detail.

What we hear

Do any of these sound familiar?

We're not sure about our security posture, and we wouldn't know if we were under attack.

There's little or no visibility of compliance with our current or mandated controls.

We have no solution for detection or automated response to attacks or threats.

We need to determine who is accountable for our security response.

Managing so many vendor consoles with a small team is a challenge.

If you nodded at any of these, CSAT is exactly the starting point you need.

Plans

Plans for every size and need.

We don't believe in one-size-fits-all. We tailor the scope to your size, your cloud and the regulatory pressure you face — from a one-off assessment to a continuous improvement program. Tell us your case and we'll propose the right plan.

Small business Mid-market Enterprise & vital operators

Let's talk about your case

I want to know more

Let's talk

Leave us your details and a Fendari Group advisor will contact you to explain the scope, answer your questions and send you a tailored proposal. No commitment.

Or email us at contact@Fendarigroup.com

Request about: CSAT