One written document, dated and versioned, walked through with leadership. This page shows what is in it, how the scorecard reads, and one finding as written.
How to read it in five minutes
The report answers four questions leadership asks. The findings and the appendix are written for the people who will do the work, including your provider.
Are we actually protected, or just busy?
Section 1, the executive findings summary
Are our providers delivering what we pay for?
Section 2, provider commitments compared with delivered service
Where are the gaps, and who owns them?
Section 3, the scorecard, and section 4, the findings
What should leadership fix first?
Section 5, the 30/60/90-day roadmap
What is in it
1. Executive findings summary
The bottom line for leadership, and the findings that need a leadership decision before anything else starts.
2. Provider commitments compared with delivered service
What the firm understood it was buying, set beside what the agreement and the records show, and what the difference means.
3. Security confidence scorecard
One line per domain: status, maturity, who owns the control, and the immediate action.
4. Findings
Each finding records the evidence reviewed, what it does not establish, the business consequence, the recommended action, ownership, and the evidence that closes it.
5. 30/60/90-day roadmap
Actions in order, each with an owner and a way to confirm it is done.
An appendix records every piece of evidence requested, whether it arrived, and which findings rest on it. A record that was not supplied is reported as a limitation, not as evidence that a control has failed.
How the scorecard reads
One line per domain. Here is the line for the finding shown below.
One illustrative scorecard line
Domain
Status
Maturity
Control owner
Immediate action
Backup & Recovery
Status ○ Critical Gap
Maturity 1 of 5
Control owner Internal / provider shared
Immediate action Protect backup copies from production credentials and run a recovery exercise
Status
Defensible, At Risk, or Critical Gap. Defensible means the reviewed evidence supports the control within the agreed scope, at the time of review. It is not a guarantee. If the evidence is insufficient to rate a domain, the report says so instead of guessing.
Maturity
How the control is managed, on the 0 to 5 scale published on the how we work page. A different view of the same evidence, not a second score.
Control owner
Who holds the control today: the firm, the provider, shared, or unassigned. Unassigned is itself a finding.
Immediate action
The one thing to do first for this domain.
The twelve domains
Governance
Asset Management
Identity & Access
Endpoint Security
Network Security
Email Security
Vulnerability Management
Monitoring & Detection
Incident Response
Vendor Risk
Security Awareness
Backup & Recovery
The decision and roadmap in this example
Leadership authorizes the provider to protect the backup copies and run a controlled recovery exercise. The application owner defines acceptable downtime and data loss; the managing partner approves closure after reviewing the evidence.
Today
The provider confirms whether production credentials can delete copies and applies agreed safeguards. An exposed recovery path is triaged the same day, not held for the 30-day milestone.
Within 30 days
The provider runs an authorized recovery exercise. The application owner records the workflow checks, elapsed time, and data recovered. The managing partner reviews the protection and recovery evidence promptly and records closure or remaining actions.
Within 60 days
The application owner and provider document recovery responsibilities, escalation, and acceptance in the service record.
Within 90 days
The managing partner checks that safeguards remain in place, reviews any open actions, and confirms the next exercise date. This follow-up does not defer approval of the initial recovery result.
One finding, as written
Every finding follows this structure. The framework reference is for the provider.
F-01. Backup copies can be deleted with production credentials, and recovery has not been demonstrated
Domain: Backup & RecoveryStatus: Critical GapSeverity: Critical, act within 30 days
Framework reference for the provider: NIST CSF 2.0 PR.DS-11
Evidence reviewed
Thirty days of job reports record successful nightly backups of the main business application. The permissions export shows that the production administrator account can also delete backup copies. The service agreement includes backup operation but assigns nobody responsibility for confirming that a recovery works.
What the evidence does not establish
The records cover one application and one review period. They do not show that the application, its database, and user access can be restored together. No recovery exercise record was supplied, and no restore was performed as part of this review.
Business consequence
Client work and billing depend on this application. Leadership's stated tolerance is one working day of disruption, and the evidence does not establish that recovery could meet it. If the administrator account is compromised, the attacker can delete the working system and its recovery copies in the same session.
Recommended action
The provider configures backup copies that cannot be deleted through the production administrator account, then runs an authorized recovery exercise in an isolated environment. The application owner agrees in advance on acceptable downtime and data loss, checks the restored workflow, and approves the outcome in writing.
Ownership
Accountable: the partner who owns the application. Responsible: the IT provider. Approves closure: the managing partner.
Evidence that closes the finding
A configuration review confirming that production credentials cannot delete the protected copies, and a recovery record naming the backup used, the elapsed time, the data point recovered, the checks performed, any exceptions, and the owner's approval. One successful exercise supports that tested scenario; it does not guarantee every future recovery.
The check behind this finding is one of six described on how we test.
Discuss what you need to understand.
Tell us which decision or concern prompted your inquiry, and we will discuss scope before agreeing on an engagement.