Skip to content

How we test

Six of the checks in a review, written for the person who will be asked to produce the records.

The approach

We review records that already exist: the agreement, configuration exports, operational reports, and the handling record for one real event. We compare them with what the agreement promises and what leadership expects, and talk to the people involved. We do not log into systems, test controls, or change settings. Before work starts, we agree the environment, records, evidence cutoff, and criteria for the question being answered. The examples below show evidence that can support a conclusion; they are not universal pass criteria. A missing record is recorded as missing, not as a failure. Most providers already hold much of what we ask for.

Backup & Recovery

Can your backup copies be deleted with the same account that runs production?

What we ask for
The backup platform configuration, the list of accounts with rights on it, and the retention settings.
What we look at
Whether copies are locked for the retention period, whether the production administrator identity can delete or shorten them, and whether the backup console has its own credential with a second factor.
What supports it
For the systems in scope, production accounts cannot remove or shorten a protected copy during retention. The records show the setting and a refusal when deletion was attempted.
What a gap looks like
Nightly jobs succeed, and one administrator account can delete every copy in an afternoon.

Backup & Recovery

Has anyone restored something recently and checked that it works?

What we ask for
The record of the last recovery exercise: what was restored, where, how long it took, and who confirmed the result was usable.
What we look at
Whether the exercise restored a working application with its data, not a single file; the elapsed time against how long the firm can be without the system; and the date.
What supports it
A recent, scoped exercise shows the application and its data restored, checked by someone who uses it, with the elapsed time compared with leadership's agreed tolerance.
What a gap looks like
The provider states that restores can be done at any time. The last one on record recovered one document.

Identity & Access

Is every privileged account protected by an enforced second factor, with emergency access separately controlled?

What we ask for
The sign-in policy export from your identity platform, the list of accounts holding administrator roles, and the registration report for authentication methods.
What we look at
Whether routine privileged accounts are covered by an enforced policy, whether any policy is in report-only mode, and whether emergency access is a small, documented, separately protected exception rather than a general exemption.
What supports it
The policy export and recent sign-in records show enforcement for routine privileged roles. Emergency-access accounts have documented strong authentication and monitoring, separate from policies that could prevent emergency use. They are not used for normal administration.
What a gap looks like
Multi-factor authentication is described as on. Three privileged accounts are excluded, including one used for ordinary provider work.

Monitoring & Detection

When an alert fires on a Saturday night, who is contracted to act, and by when?

What we ask for
The clause in the agreement that names monitoring hours and response times, the handling record for one recent alert raised outside business hours, and the escalation contact list with the date it was last checked.
What we look at
The time between the alert being generated and a person acknowledging it, whether the contracted hours match what leadership believes it is paying for, and whether the people on the contact list still work there.
What supports it
The agreement states hours and an acknowledgment time, the sampled alert was acknowledged inside that time, and the contact list was current for that event.
What a gap looks like
The platform raises alerts around the clock. The agreement covers business hours. The Saturday alert was read on Monday.

Vulnerability Management

Is everything patched, or only the operating system?

What we ask for
The patch report for the past month, the list of what the agreement covers, and the device inventory.
What we look at
Whether every device in the inventory appears in the report, whether browsers, document readers, meeting software, and the practice management application are in scope, whether anything is running an unsupported version, and how long critical updates take to reach every machine.
What supports it
The report covers the agreed device inventory, names the applications in scope, and shows critical updates applied within the agreed window. Anything excluded has a named owner.
What a gap looks like
Up to date means monthly operating system updates. Two reception machines and every third-party application belong to no one.

Identity & Access

When someone leaves, how quickly does their access end, and who checks?

What we ask for
The list of departures for the past six months from the office manager, the account disable dates from the identity platform, and the offboarding checklist.
What we look at
The leaving date against the disable date for each person, mailbox forwarding and shared access left behind, access to the document system and any provider portals, and who told the provider and how.
What supports it
The sampled departures have disable records within the agreed window, the checklist names each system, and any exception is written down.
What a gap looks like
The provider disables accounts when told. No one is assigned to tell them, and one account stayed active for weeks.

The other checks

The full review covers twelve domains with the same structure for each check, rated on the scale onhow we work.

Ask us to run these against your provider.

Tell us who runs your IT and which of these questions you cannot answer today.

Contact us about a review