Recent Projects

Cybersecurity Risk Assessment for Government Compliance Validation

NIST CSF 2.0 Security Assessment and Phishing Awareness Training

Q1 2026

Evaluating Security Controls and Uncovering Residual Risk

Following a previous security incident and subsequent remediation efforts, this Maryland healthcare regulatory agency sought independent validation of its cybersecurity posture to ensure no residual vulnerabilities or operational “blind spots” remained within the environment.

The agency needed to confirm that prior remediation activities had successfully addressed known risks while also evaluating the effectiveness of its current technical, administrative, and human-centric security controls. In addition, the agency needed to maintain alignment with both Maryland Department of Information Technology (DoIT) Security Guidelines and the requirements of the NIST Cybersecurity Framework (NIST CSF) 2.0.

The environment included approximately 70 workstations and six servers requiring comprehensive internal and external security analysis, endpoint hardening validation, governance review, and phishing awareness testing. Leadership also required a formal maturity scorecard and prioritized remediation roadmap to support long-term cybersecurity planning and compliance initiatives.

Applying a Layered Cybersecurity Risk Assessment Framework

Data Networks delivered a layered cybersecurity risk assessment designed to validate the effectiveness of prior remediation efforts while identifying any remaining technical or procedural security gaps.

cybersecurity risk assessment framework

The engagement began with a formal project kickoff and governance review to evaluate existing security documentation, including incident response plans, acceptable use policies, and administrative security controls. These controls were assessed against NIST CSF 2.0 and Maryland DoIT standards to establish a baseline maturity framework.

To support the technical assessment, Data Networks coordinated deployment of internal vulnerability scanning appliances and configured secure scanning workflows to minimize operational disruption. The assessment included a hybrid methodology combining automated vulnerability scanning with manual engineering validation to identify high-risk configuration issues, unpatched vulnerabilities, and endpoint security weaknesses across the workstation and server environment.

Data Networks also performed an external perimeter assessment and “Shadow IT” validation exercise to identify unauthorized cloud services and evaluate the effectiveness of existing access restrictions and security controls. Endpoint hardening reviews focused on Microsoft 365 and Windows security configurations, including Windows Hello for Business fallback methods and Microsoft Office application security settings designed to reduce the risk of lateral movement and exploitation.

As part of the human-centric security validation process, Data Networks deployed a controlled phishing awareness campaign using the KnowBe4 platform. The phishing simulations were tailored to scenarios relevant to the agency’s operational environment, enabling leadership to baseline employee security awareness, reporting behavior, and susceptibility to social engineering attacks.

KnowBe4 phishing training

Following data collection, Data Networks performed extensive manual analysis and false-positive filtering to prioritize findings based on real operational risk. Technical and governance findings were then mapped directly to NIST CSF 2.0 categories and Maryland DoIT security requirements to produce a formal compliance maturity scorecard and remediation roadmap.

Building a Roadmap for Security Maturity and Compliance

Through this cybersecurity risk assessment, the regulatory agency gained an independent validation of its remediation efforts and a clearer understanding of its current cybersecurity maturity.

The final deliverables included a comprehensive technical assessment report, prioritized remediation recommendations, governance analysis, phishing simulation results, and a formal NIST CSF 2.0 and Maryland DoIT maturity scorecard. These deliverables provide leadership and IT staff with actionable guidance to strengthen operational resilience, reduce cybersecurity risk, and support ongoing compliance initiatives.

The inclusion of a one-year KnowBe4 subscription also establishes a foundation for continued phishing awareness training and ongoing employee security education, helping the agency reinforce security best practices over time.

By combining vulnerability analysis, governance validation, phishing awareness testing, and compliance mapping into a unified engagement, Data Networks helped the agency improve visibility into its security posture while supporting long-term cybersecurity readiness and operational resilience.

Tags: SLG, local, government