A free security assessment is a scheduled look at the controls you already claim, written down as gaps with owners. It is how SAINT starts. It is not a penetration test, not a compliance certificate, and not a contract for monitoring.
Lincoln businesses that want that conversation from the local team book it through cybersecurity services in Lincoln or book a free assessment. Omaha is a secondary market on the technology site. This page does not add a city landing page.
The control-by-control walkthrough — identity, email, endpoints, backup — stays on the technology site so the two articles are not the same piece: what a cybersecurity assessment walks through.
What you should expect
You should leave with three things:
- A gap list sorted into fix now, fix next, and later.
- An owner for each gap. A finding without a name is a poster.
- A statement of what was not reviewed. Unreviewed is not “fine.”
The list is mapped to the questionnaire in front of you when there is one — a cyber insurance form, a HIPAA readiness question, a CMMC conversation. Mapping is language. It is not a finding that you comply, and it is not an authorization to tell a carrier or an auditor that SAINT certified you.
What the free assessment is not
- Not a penetration test. Nobody is hired, in the free pass, to break in and write an exploit report.
- Not a certificate. Not HIPAA, not CMMC, not SOC 2, not “Zero Trust certified.” SAINT does not sell those stamps.
- Not a vCISO retainer. A fractional security lead, a board report cadence, and a year of follow-up are a scoped engagement after the writing. They are not included because the first conversation was free.
- Not managed detection. Monitoring, after-hours investigation, and containment are an operating contract. The assessment can say you do not have that. It does not turn it on.
- Not a guarantee. No assessment makes ransomware, business email compromise, or a failed audit impossible. Anyone who offers that result is selling a feeling.
There is no public price and no invented “value of the free review” on this page. Paid work starts when both sides agree the scope in writing.
How this differs from the self-check
The insurability self-check is a form you can run alone. It asks whether you can point at evidence. The free assessment is a person reading that evidence with you and writing the gaps down. Use the tool first if you want a private pass. Use the assessment when you want the list argued with someone who will later have to operate the fixes.
If something is already wrong
An assessment is the wrong tool for an active mailbox takeover or encrypting files. Use the incident page and call (531) 625-2111. Read business email compromise or ransomware for a Nebraska business for the decision framing, then the checklists on the technology site for the first hours.
