What does a Cyber Security Gap Analysis actually check?
Related Company: Get Support IT Services

What does a Cyber Security Gap Analysis actually check?

6th Oct 2026

A Cyber Security Gap Analysis can give businesses a clearer picture of where their cyber security stands today, where weaknesses exist and which improvements should be prioritised. Get Support explains how its approach can help businesses understand and reduce their cyber risk.

Cyber security covers far more than antivirus software, passwords and firewalls.

For businesses trying to understand whether their current security measures are sufficient, one of the most important questions is often simply: what are we actually checking?

A Cyber Security Gap Analysis provides a structured way to answer that question, looking at how a business manages security, the systems and information it relies on, the safeguards already in place, how potential incidents are detected and what would happen if a cyber incident occurred.

At Get Support, the NIST Cybersecurity Framework provides the foundation for the assessment, using six key areas: Govern, Identify, Protect, Detect, Respond and Recover. The approach is then supported by relevant CIS Controls, guidance from the UK’s National Cyber Security Centre (NCSC) and other recognised good practice.

Understanding your current cyber security position

A Cyber Security Gap Analysis begins with understanding what a business actually needs to protect.

That includes the systems, information, devices, accounts and services that are essential to day-to-day operations. From there, the assessment considers what security measures are already in place, where weaknesses or missing controls exist, what risks those gaps create and which improvements should be addressed first.

Not every system or piece of information carries the same level of risk.

A system containing sensitive customer information may require stronger protection than one with limited business impact. Similarly, a service that would prevent a team from working if it became unavailable deserves particular attention.

The aim is therefore not simply to identify problems, but to create a clear picture of what the business has, what matters most, how well it is protected, where the gaps are and what should happen next.

Six areas of cyber security

Get Support structures its assessment around the six areas of the NIST Cybersecurity Framework: Govern, Identify, Protect, Detect, Respond and Recover.

Govern

This looks at how cyber security is managed within the business.

Areas considered include responsibility for cyber security, internal policies, risk management and whether security responsibilities are clearly defined.

For smaller businesses, this does not necessarily mean creating large amounts of paperwork. It means ensuring important security decisions are made deliberately rather than being left to chance.

Identify

Businesses cannot protect their systems and information effectively without understanding what they rely on.

This part of the assessment considers devices, systems, cloud services, applications and important business information, including laptops, Microsoft 365, servers, business applications, network equipment and customer or company data.

It also considers which systems are most important to the organisation and what the impact would be if they became unavailable.

Protect

Protect covers many of the security measures businesses will already be familiar with.

Depending on the organisation, this can include multi-factor authentication, user accounts and access, administrator permissions, device security, software updates, antivirus and endpoint protection, Microsoft 365 security, encryption, staff awareness and backup arrangements.

The assessment doesn’t simply ask whether a security feature exists. It considers whether it has been configured appropriately and is being used consistently.

For example, having multi-factor authentication available is different from ensuring it is properly enforced across the accounts that need it.

Detect

Even businesses with strong preventative measures need to be able to recognise when something suspicious is happening.

Get Support therefore considers how potential security incidents are detected, including suspicious logins, malware, unusual account activity and security alerts.

It also looks at what happens when an alert is generated. A security system can identify a problem, but if nobody is reviewing the alerts, the business may not realise that action is required.

Respond

A key part of cyber security is understanding what happens when something goes wrong.

A Gap Analysis considers questions such as who staff should contact, who is responsible for making decisions, how affected accounts or devices would be secured and whether an incident response process and important contact details are readily available.

Having even a straightforward response plan can help businesses act more quickly and confidently during what can otherwise be a stressful situation.

Recover

The final area considers how a business would restore normal operations following an incident.

Backups are an important part of this, but simply having backups is not enough. Businesses need to understand what is backed up, how frequently backups run, whether they are protected and whether recovery has actually been tested.

Ultimately, the question is: if an important system or piece of information became unavailable, could you get it back when you needed it?

Not every cyber security gap needs an expensive solution

One of the important principles behind the assessment is that finding a gap does not automatically mean buying new technology.

Some of the most valuable improvements can be relatively straightforward.

Recommendations could include enabling a security feature that a business already has, changing a configuration, removing unnecessary administrator access, improving how staff accounts are managed when employees leave, updating a policy or process, testing an existing backup or improving staff awareness.

Where a simple or low-cost change can significantly reduce risk, it can make sense to prioritise that before embarking on a larger project.

The objective is not to spend more on cyber security for the sake of it, but to make sensible improvements in the right order and achieve as much security value as possible from the time and budget available.

Prioritising the risks

Not every gap presents the same level of risk.

Get Support considers factors including how likely a weakness is to cause a problem, which systems or information could be affected, the scale of the potential impact, whether sensitive information is involved and what protection is already in place.

This helps distinguish urgent risks from improvements that are useful but less critical.

For example, weak protection around an administrator account with access to large parts of a business is likely to deserve greater attention than a minor configuration issue on a low-risk system.

The result is a prioritised approach, helping businesses focus first on the changes that can make the biggest difference.

What does a business receive from a Gap Analysis?

A useful Cyber Security Gap Analysis should provide clarity rather than simply producing a lengthy technical report.

Get Support aims to give businesses four key things: an understanding of their current position, a clear explanation of the gaps identified, prioritised risks and recommended actions.

The recommendations can include quick, low-cost improvements, short-term projects and longer-term changes, creating a practical cyber security roadmap for the business.

The approach is designed to explain technical findings in plain English so that decision-makers can understand the overall picture without needing to become cyber security experts.

Gap Analysis vs penetration testing

A Cyber Security Gap Analysis is not the same as a penetration test.

A penetration test primarily focuses on identifying technical vulnerabilities by actively testing whether systems can be compromised.

A Gap Analysis takes a broader view, considering technology alongside people, processes, access, policies, monitoring, incident response and recovery. Penetration testing can form part of a wider cyber security programme, but it does not replace an assessment of how cyber security is managed across the business.

Building a practical cyber security roadmap

Ultimately, a Cyber Security Gap Analysis should help answer a straightforward question:

Where should we focus our cyber security efforts next?

By combining the NIST Cybersecurity Framework with relevant CIS Controls, NCSC guidance and other recognised good practice, Get Support can assess the wider security picture rather than concentrating on individual products or isolated technical issues.

The result is a clearer and more practical approach to cyber security — one that focuses on understanding the biggest risks and taking sensible steps to reduce them.

Find out more

If you are unsure where the weaknesses are in your current cyber security setup, Get Support can help.

Its Cyber Security Gap Analysis combines a NIST-led approach with relevant CIS Controls, NCSC guidance and other recognised good practice to assess your current position, identify important gaps and prioritise improvements.

The aim is to help businesses build a practical improvement plan, starting with high-impact, cost-effective changes where possible.

Contact Get Support to discuss a Cyber Security Gap Analysis for your business.

Become a B4 member 

Back to news

What does a Cyber Security Gap Analysis actually check?

6th Oct 2026
What does a Cyber Security Gap Analysis actually check?
Related Company: Get Support IT Services

A Cyber Security Gap Analysis can give businesses a clearer picture of where their cyber security stands today, where weaknesses exist and which improvements should be prioritised. Get Support explains how its approach can help businesses understand and reduce their cyber risk.

Cyber security covers far more than antivirus software, passwords and firewalls.

For businesses trying to understand whether their current security measures are sufficient, one of the most important questions is often simply: what are we actually checking?

A Cyber Security Gap Analysis provides a structured way to answer that question, looking at how a business manages security, the systems and information it relies on, the safeguards already in place, how potential incidents are detected and what would happen if a cyber incident occurred.

At Get Support, the NIST Cybersecurity Framework provides the foundation for the assessment, using six key areas: Govern, Identify, Protect, Detect, Respond and Recover. The approach is then supported by relevant CIS Controls, guidance from the UK’s National Cyber Security Centre (NCSC) and other recognised good practice.

Understanding your current cyber security position

A Cyber Security Gap Analysis begins with understanding what a business actually needs to protect.

That includes the systems, information, devices, accounts and services that are essential to day-to-day operations. From there, the assessment considers what security measures are already in place, where weaknesses or missing controls exist, what risks those gaps create and which improvements should be addressed first.

Not every system or piece of information carries the same level of risk.

A system containing sensitive customer information may require stronger protection than one with limited business impact. Similarly, a service that would prevent a team from working if it became unavailable deserves particular attention.

The aim is therefore not simply to identify problems, but to create a clear picture of what the business has, what matters most, how well it is protected, where the gaps are and what should happen next.

Six areas of cyber security

Get Support structures its assessment around the six areas of the NIST Cybersecurity Framework: Govern, Identify, Protect, Detect, Respond and Recover.

Govern

This looks at how cyber security is managed within the business.

Areas considered include responsibility for cyber security, internal policies, risk management and whether security responsibilities are clearly defined.

For smaller businesses, this does not necessarily mean creating large amounts of paperwork. It means ensuring important security decisions are made deliberately rather than being left to chance.

Identify

Businesses cannot protect their systems and information effectively without understanding what they rely on.

This part of the assessment considers devices, systems, cloud services, applications and important business information, including laptops, Microsoft 365, servers, business applications, network equipment and customer or company data.

It also considers which systems are most important to the organisation and what the impact would be if they became unavailable.

Protect

Protect covers many of the security measures businesses will already be familiar with.

Depending on the organisation, this can include multi-factor authentication, user accounts and access, administrator permissions, device security, software updates, antivirus and endpoint protection, Microsoft 365 security, encryption, staff awareness and backup arrangements.

The assessment doesn’t simply ask whether a security feature exists. It considers whether it has been configured appropriately and is being used consistently.

For example, having multi-factor authentication available is different from ensuring it is properly enforced across the accounts that need it.

Detect

Even businesses with strong preventative measures need to be able to recognise when something suspicious is happening.

Get Support therefore considers how potential security incidents are detected, including suspicious logins, malware, unusual account activity and security alerts.

It also looks at what happens when an alert is generated. A security system can identify a problem, but if nobody is reviewing the alerts, the business may not realise that action is required.

Respond

A key part of cyber security is understanding what happens when something goes wrong.

A Gap Analysis considers questions such as who staff should contact, who is responsible for making decisions, how affected accounts or devices would be secured and whether an incident response process and important contact details are readily available.

Having even a straightforward response plan can help businesses act more quickly and confidently during what can otherwise be a stressful situation.

Recover

The final area considers how a business would restore normal operations following an incident.

Backups are an important part of this, but simply having backups is not enough. Businesses need to understand what is backed up, how frequently backups run, whether they are protected and whether recovery has actually been tested.

Ultimately, the question is: if an important system or piece of information became unavailable, could you get it back when you needed it?

Not every cyber security gap needs an expensive solution

One of the important principles behind the assessment is that finding a gap does not automatically mean buying new technology.

Some of the most valuable improvements can be relatively straightforward.

Recommendations could include enabling a security feature that a business already has, changing a configuration, removing unnecessary administrator access, improving how staff accounts are managed when employees leave, updating a policy or process, testing an existing backup or improving staff awareness.

Where a simple or low-cost change can significantly reduce risk, it can make sense to prioritise that before embarking on a larger project.

The objective is not to spend more on cyber security for the sake of it, but to make sensible improvements in the right order and achieve as much security value as possible from the time and budget available.

Prioritising the risks

Not every gap presents the same level of risk.

Get Support considers factors including how likely a weakness is to cause a problem, which systems or information could be affected, the scale of the potential impact, whether sensitive information is involved and what protection is already in place.

This helps distinguish urgent risks from improvements that are useful but less critical.

For example, weak protection around an administrator account with access to large parts of a business is likely to deserve greater attention than a minor configuration issue on a low-risk system.

The result is a prioritised approach, helping businesses focus first on the changes that can make the biggest difference.

What does a business receive from a Gap Analysis?

A useful Cyber Security Gap Analysis should provide clarity rather than simply producing a lengthy technical report.

Get Support aims to give businesses four key things: an understanding of their current position, a clear explanation of the gaps identified, prioritised risks and recommended actions.

The recommendations can include quick, low-cost improvements, short-term projects and longer-term changes, creating a practical cyber security roadmap for the business.

The approach is designed to explain technical findings in plain English so that decision-makers can understand the overall picture without needing to become cyber security experts.

Gap Analysis vs penetration testing

A Cyber Security Gap Analysis is not the same as a penetration test.

A penetration test primarily focuses on identifying technical vulnerabilities by actively testing whether systems can be compromised.

A Gap Analysis takes a broader view, considering technology alongside people, processes, access, policies, monitoring, incident response and recovery. Penetration testing can form part of a wider cyber security programme, but it does not replace an assessment of how cyber security is managed across the business.

Building a practical cyber security roadmap

Ultimately, a Cyber Security Gap Analysis should help answer a straightforward question:

Where should we focus our cyber security efforts next?

By combining the NIST Cybersecurity Framework with relevant CIS Controls, NCSC guidance and other recognised good practice, Get Support can assess the wider security picture rather than concentrating on individual products or isolated technical issues.

The result is a clearer and more practical approach to cyber security — one that focuses on understanding the biggest risks and taking sensible steps to reduce them.

Find out more

If you are unsure where the weaknesses are in your current cyber security setup, Get Support can help.

Its Cyber Security Gap Analysis combines a NIST-led approach with relevant CIS Controls, NCSC guidance and other recognised good practice to assess your current position, identify important gaps and prioritise improvements.

The aim is to help businesses build a practical improvement plan, starting with high-impact, cost-effective changes where possible.

Contact Get Support to discuss a Cyber Security Gap Analysis for your business.

Become a B4 member 

Back to news