A security risk assessment takes about two days of hands-on practitioner work for a typical single-framework SMB client. Survey research across vCISO providers puts the assessment itself at 13.9 hours, with the client-ready report adding roughly 14 more and each policy roughly the same again. The engagement wrapped around those hours usually runs 2 to […] The post How Long Should a Client Security Assessment Take?