When Should You Start with a Discovery Session?
When Should You Start with a Discovery Session?
Hilde van Kessel

Hilde van Kessel

Service Delivery Manager

When Should You Start with a Discovery Session?

You start with a Discovery Session as soon as you doubt whether your organisation knows its biggest cyber risks, whether that is caused by growth, an upcoming compliance requirement, an incident at another company or simply a gut feeling that things could be better. There is no fixed moment when everyone should start. There are, however, clear signals that indicate that it is relevant now.


In this article, we discuss which situations call for more insight, how you recognise this within your own organisation and why waiting until something goes wrong is often the most expensive choice.

Signs that insight is missing

Most organisations do not start with a risk assessment because they are following a checklist, but because something makes them think. Recognisable signals are that nobody can explain exactly where the biggest vulnerabilities are, that security decisions are mainly based on gut feeling, or that IT and management have a different view of how secure the organisation actually is. As soon as that doubt exists, that is exactly where a Discovery Session helps. It identifies where an attacker actually has a chance, instead of relying on assumptions.

Growth as a reason

Growing organisations change faster than their security policies can keep up. New systems, new employees, new suppliers and sometimes new offices create an IT environment that nobody fully oversees anymore. What was well organised a few years ago may now contain blind spots. Growth is therefore one of the most common moments to take another look at where the organisation's crown jewels are and how well they are protected.

Laws and regulations such as NIS2

Many organisations have to deal with obligations arising from the Cybersecurity Act, ISO 27001 or requirements from an insurer. That pressure often feels like an obligation, but the first question underneath it is simple. do you actually know where your risks are. A Discovery Session is not a compliance checklist, but it does provide the insight needed to meet those requirements in a targeted way later on. It makes clear what deserves immediate attention and what can wait, so you do not have to blindly start working on every individual requirement.

An incident at another company

An attack or data breach at an industry peer, supplier or competitor often acts as a wake-up call. That is understandable, but there is a risk that organisations then start treating symptoms instead of the cause. Instead of taking individual measures in response to someone else's problem, it is more valuable to first investigate whether the same attack path would also be open within your organisation. This prevents you from investing in protection against the wrong risk.

Doubt at management level

Sometimes the reason does not come from IT, but from management or the board. Questions are asked about control over cyber risk, for example by an auditor, an insurer or shareholders, and nobody can answer that question with confidence. That is a strong signal to start, precisely because a Discovery Session produces a result that is useful for both IT and management. Not a technical report, but a clear picture of where the organisation stands and which choices follow from that.

Even without your own security team

You do not need a large internal security team to get started. In fact, organisations without extensive internal expertise often benefit most from an accessible starting point. Within two to four weeks, you get an overview of where the risks are, without first having to build a complete security team yourself before you can begin.

Why waiting usually does not pay off

Many organisations postpone this kind of insight until there is a concrete reason, while risks continue to grow unnoticed in the meantime. Systems change, people come and go, processes shift. Being secure is a snapshot in time, and that snapshot becomes less reliable as more time passes since you last took a proper look. Starting early means making choices based on facts instead of assumptions that may have become outdated.

When a Discovery Session is the logical next step

If you doubt whether now is the right time, the question is actually simple to answer. Can you confidently explain where your biggest risks are and which priorities follow from them. If you cannot, that in itself is already the answer. A Discovery Session gives you the overview needed within a few weeks to continue working towards better decisions in a focused way, whether that leads to a deeper technical review, a discussion about priorities with management or a follow-up process such as an assessment. The starting point is not complicated. It is simply the moment when you acknowledge that assumptions are no longer sufficient.