Signs an assessment is generic, not tailored to you
A generic vulnerability assessment misses your real risks. Learn the red flags: checklists without context, no prioritisation, and recommendations that ignore.
A vulnerability assessment costs time and money. A generic one costs both and delivers nothing useful. The core tension: a thorough assessment must be customised to your operation, but some assessors treat it like a box-ticking exercise, applying the same checklist to every client regardless of industry, size, location or threat profile. The result is a report that looks credible but misses what actually matters to your business.
This article walks you through the red flags that signal a generic approach—and what to demand instead.
The clipboard walk that ignores your workflow
A tailored assessment begins with listening. A consultant should ask what you do, how you do it, who your people are, what data moves through your systems, and which assets matter most. A generic assessment skips this entirely.
Watch for an assessor who arrives with a pre-printed form and works through it mechanically. They'll inspect door locks, check CCTV coverage, and test access logs—all legitimate checks—but they'll apply the same scoring to a financial services firm and a retail shop. They won't ask why your warehouse stays open after hours, or whether your staff turnover is unusually high, or whether you hold client information that makes you a target.
A real red flag: the report reads like it could have been written before they visited. Vague language, generic observations, no mention of your specific layout, no acknowledgment of your business type or risk appetite. If the assessment doesn't reference your operations by name, it wasn't tailored to you.
The checklist that ticks boxes instead of finding problems
Generic assessments often rely on industry checklists—standard security frameworks applied wholesale. Frameworks have value, but they're a starting point, not the finish line. A generic assessor treats the checklist as the destination.
This shows up in the findings. You'll see broad statements like "access control procedures should be documented" without any comment on whether *your* access control is the actual problem. You'll get recommendations that sound professional but don't address your operation: install a second fence, upgrade to facial recognition, implement visitor logs—none of which may be relevant to your specific risk.
Ask the assessor how they'll customize the assessment to your business before they start. If the answer is vague or defensive, that's a signal. A tailored approach will be bespoke from the moment they walk through the door.
The prioritisation that treats all risks equally
A good assessment ranks findings by likelihood and impact. A generic one often doesn't. You'll see a report that lists thirty "vulnerabilities" without clear guidance on which ones matter.
For example, a generic assessment might flag both "broken window latch on warehouse" and "no background checks on staff with access to sensitive documents" as equal concerns. A tailored assessment understands your context: the window faces an internal courtyard in a low-crime industrial park (low priority), while staff vetting is critical because you process payment card data (high priority).
If the report doesn't rank findings by risk to *your* business—not just by checkbox—it was written generically. Equally, if the assessor can't explain in conversation why one finding matters more than another to your specific operation, they haven't done the thinking.
The assessment that prescribes without understanding cost or feasibility
Generic assessors often recommend expensive or impractical solutions because they haven't learned your constraints. They'll suggest changes that sound secure in theory but are operationally impossible for your workflow, budget or premises.
A tailored consultant asks: What's your appetite for investment? What can your team actually manage? What's already in place that works? A generic one doesn't, so the report gathers dust because nothing in it is realistic for you.
Before hiring, ask how the assessor will factor in your operational and financial reality. Will they suggest a phased approach? Will they distinguish between must-do and nice-to-have? If they say "apply all recommendations immediately" or give no sense of practicality, they're treating you like a template, not a client.
When you're ready to move forward, look for an assessor on Strove who shows genuine curiosity about your operation during the initial conversation—that's the sign of someone who'll deliver findings that actually fit your business.
Common questions
- What's the difference between a generic and tailored vulnerability assessment?
- A tailored assessment starts by learning your specific business, assets, workflow and threats. It applies findings to your context. A generic assessment uses the same checklist for every client, producing observations that could fit any business and often don't address your actual priorities.
- How can I tell if an assessor is generic before they start?
- Ask how they'll customise the scope to your operation. If they describe a fixed process or mention a standard template, that's a warning. A tailored assessor will ask detailed questions about your business, data, staff and constraints before quoting.
- What should a good assessment report tell me that a generic one won't?
- A good report ranks findings by your real risk (likelihood and impact to your business), explains why each matters in your context, and offers practical recommendations fitted to your constraints. A generic report lists vulnerabilities without ranking them or considering your feasibility.
- Can a framework-based assessment still be tailored?
- Yes. Many good assessors use industry frameworks as scaffolding, but they overlay it with questions about your specific operation, threat profile and priorities. The framework is a tool; the tailoring is how they apply it.
Find a verified provider on Strove
Compare vetted vulnerability assessments providers, check their credentials, and book or request a quote — all in one place.
Find a Business