The Security Reality Check
An independent, fixed-fee review of whether the IT and security services you pay for are actually being delivered, and who is responsible for what they leave uncovered.
What it is
A one to two week review of the agreements, configuration records, and operational evidence behind your IT and security, across twelve domains. We read what exists and talk to the people involved. We do not test systems or change anything.
The environment, participating providers, available records, and people who need to attend are confirmed during scoping. They determine the final scope, fee, and schedule.
What you get
One written report, walked through with leadership. It is yours to keep and use, with or without further work from us. See what is in it.
What it is not
Not a penetration test, a certification, or an audit opinion. Not a route to selling tools; we sell none. Not a verdict on anyone's competence. It is a record of where the service, the agreement, and your expectations differ, and who should close each gap.
Who it is for
Owners and managing partners who pay for IT and security, through an outside provider, their own staff, or both, and cannot tell from the invoices and reports whether it is working or what risks it leaves open. You hold client data or client funds, and you want someone with no stake in the answer to check what the records show before the next renewal, audit, or insurance review. Law firms, medical practices, insurance agencies, accountants, and other practices with the same duties.
- Typical duration
- 1-2 weeks
- Scope
- 12 domains
- Pricing
- Fixed fee, agreed first
You name a point of contact and arrange participation from the people responsible for the systems in scope. We start with agreements, configuration exports, and operational records. Before work begins, we confirm when the review window starts and how unavailable records or delayed provider access affect the schedule and conclusions. Do not send confidential records with your initial inquiry.
What you receive
The report is one document. These are its three main parts. Each finding carries a NIST CSF 2.0 reference to make its basis easier to discuss. That reference is not a certification or a promise that an insurer, client, or contract will accept the report.
Executive findings summary
What the evidence supports, what it does not, and which findings need a leadership decision.
Security confidence scorecard
Each domain rated Defensible, At Risk, or Critical Gap, with a control owner and an immediate action.
30/60/90-day roadmap
Actions in order, each with an owner and a way to confirm it is done.
The twelve domains
The same twelve, every time.
Governance
Whether security decisions, owners, and exceptions are documented and reviewed.
Asset Management
Whether you can identify the devices and systems that need protecting.
Identity & Access
Whether access is limited to the right people and removed when it should be.
Endpoint Security
Whether computers are managed, protected, and supported across their working life.
Network Security
Whether network access and equipment are configured to limit inappropriate connections.
Email Security
Whether email protections reduce spoofing, malicious delivery, and unsafe forwarding.
Vulnerability Management
Whether operating systems and everyday applications are patched within an agreed timeframe.
Monitoring & Detection
Whether important alerts are seen by someone responsible for acting on them.
Incident Response
Whether people know who does what when something goes wrong and how response is recorded.
Vendor Risk
Whether provider responsibilities, access, and assurances are understood before they affect your business.
Security Awareness
Whether people receive practical guidance and the business learns from reported concerns.
Backup & Recovery
Whether copies can be recovered when needed and are protected from deletion.
How the engagement runs
- 1.
Scoping
Before work begins we confirm the environment, the providers taking part, the records we will ask for, who attends, and the fee. You can do this by email without sending anything confidential.
- 2.
Review
We compare the agreement, the configuration, and the operational records against the twelve domains and record where they do not support the same conclusion.See how we test.
- 3.
Walkthrough
Findings are delivered to leadership in plain language, with the roadmap in order, so the first conversation is about what to do next.
We resell nothing and take no commissions. We do not perform technical testing or implementation as part of this review. If either is needed, we identify it during scoping and it belongs in an agreed scope with the appropriate provider or specialist. Ongoing oversight is separate work. Read more on how we work.
Decisions it can inform
- Whether to renew a provider on the same terms.
- What to show an auditor, an insurer, or a client who asks how their information is protected.
- Which fixes to fund first, and who owns each one.
- Whether the controls around wire, escrow, and trust account instructions would stop a compromised mailbox or a forwarding rule nobody is watching.
Find out what is actually protecting your business
Tell us about the concern or decision that prompted your interest. We will discuss scope and confirm the fee before any work begins.
Contact us about a review