Skip to content

The Security Reality Check

An independent, fixed-fee review of whether the IT and security services you pay for are actually being delivered, and who is responsible for what they leave uncovered.

What it is

A one to two week review of the agreements, configuration records, and operational evidence behind your IT and security, across twelve domains. We read what exists and talk to the people involved. We do not test systems or change anything.

The environment, participating providers, available records, and people who need to attend are confirmed during scoping. They determine the final scope, fee, and schedule.

What you get

One written report, walked through with leadership. It is yours to keep and use, with or without further work from us. See what is in it.

What it is not

Not a penetration test, a certification, or an audit opinion. Not a route to selling tools; we sell none. Not a verdict on anyone's competence. It is a record of where the service, the agreement, and your expectations differ, and who should close each gap.

Who it is for

Owners and managing partners who pay for IT and security, through an outside provider, their own staff, or both, and cannot tell from the invoices and reports whether it is working or what risks it leaves open. You hold client data or client funds, and you want someone with no stake in the answer to check what the records show before the next renewal, audit, or insurance review. Law firms, medical practices, insurance agencies, accountants, and other practices with the same duties.

Typical duration
1-2 weeks
Scope
12 domains
Pricing
Fixed fee, agreed first

You name a point of contact and arrange participation from the people responsible for the systems in scope. We start with agreements, configuration exports, and operational records. Before work begins, we confirm when the review window starts and how unavailable records or delayed provider access affect the schedule and conclusions. Do not send confidential records with your initial inquiry.

What you receive

The report is one document. These are its three main parts. Each finding carries a NIST CSF 2.0 reference to make its basis easier to discuss. That reference is not a certification or a promise that an insurer, client, or contract will accept the report.

Executive findings summary

What the evidence supports, what it does not, and which findings need a leadership decision.

Security confidence scorecard

Each domain rated Defensible, At Risk, or Critical Gap, with a control owner and an immediate action.

30/60/90-day roadmap

Actions in order, each with an owner and a way to confirm it is done.

See the report structure and one finding as written

The twelve domains

The same twelve, every time.

  • Governance

    Whether security decisions, owners, and exceptions are documented and reviewed.

  • Asset Management

    Whether you can identify the devices and systems that need protecting.

  • Identity & Access

    Whether access is limited to the right people and removed when it should be.

  • Endpoint Security

    Whether computers are managed, protected, and supported across their working life.

  • Network Security

    Whether network access and equipment are configured to limit inappropriate connections.

  • Email Security

    Whether email protections reduce spoofing, malicious delivery, and unsafe forwarding.

  • Vulnerability Management

    Whether operating systems and everyday applications are patched within an agreed timeframe.

  • Monitoring & Detection

    Whether important alerts are seen by someone responsible for acting on them.

  • Incident Response

    Whether people know who does what when something goes wrong and how response is recorded.

  • Vendor Risk

    Whether provider responsibilities, access, and assurances are understood before they affect your business.

  • Security Awareness

    Whether people receive practical guidance and the business learns from reported concerns.

  • Backup & Recovery

    Whether copies can be recovered when needed and are protected from deletion.

How the engagement runs

  1. 1.

    Scoping

    Before work begins we confirm the environment, the providers taking part, the records we will ask for, who attends, and the fee. You can do this by email without sending anything confidential.

  2. 2.

    Review

    We compare the agreement, the configuration, and the operational records against the twelve domains and record where they do not support the same conclusion.See how we test.

  3. 3.

    Walkthrough

    Findings are delivered to leadership in plain language, with the roadmap in order, so the first conversation is about what to do next.

We resell nothing and take no commissions. We do not perform technical testing or implementation as part of this review. If either is needed, we identify it during scoping and it belongs in an agreed scope with the appropriate provider or specialist. Ongoing oversight is separate work. Read more on how we work.

Decisions it can inform

  • Whether to renew a provider on the same terms.
  • What to show an auditor, an insurer, or a client who asks how their information is protected.
  • Which fixes to fund first, and who owns each one.
  • Whether the controls around wire, escrow, and trust account instructions would stop a compromised mailbox or a forwarding rule nobody is watching.

Find out what is actually protecting your business

Tell us about the concern or decision that prompted your interest. We will discuss scope and confirm the fee before any work begins.

Contact us about a review