Services

How an Assessment Works

A simple engagement that typically takes about a month. What we examine, what we ask of your team, what you receive, and what the document does once it is written.

Coverage

What We Examine

Govern

Oversight and Direction

Where accountability for cybersecurity actually sits, how decisions get made and recorded, which policies exist, and whether anyone works to them. Also which obligations your firm carries and how they are tracked.

Identify

Business Data — Your Precious Asset

The client and firm information in your possession, where it lives, who can reach it, and which vendors, platforms, and carrier connections can reach it too. Some of this data should be protected like the gold at Fort Knox, and we confirm that it is.

Protect

Controls and Protection

Access control and authentication, how staff and producers are trained, how data moves in and out of the firm, and the controls standing between a routine human mistake and a reportable event.

Detect

Monitoring and Detection

What is being monitored, what those tools would actually catch, who reads the output, and how long something could run inside your environment before a person became aware of it.

Respond

Responding to a Problem

Who gets called, who decides, what notification obligations trigger and on what clock, which carriers and counterparties have to be told — and whether anyone has ever walked through it before the day it matters.

Recover

Getting Back to Business

Whether your backups have been restored from rather than merely scheduled, how long the firm can transact without its systems, and what returning to normal operations would realistically cost in time and revenue.

What You Receive

Each Risk Assessment Has the Following

  • One-Page Executive Summary
    Where the firm stands, what matters most, and what it will take — on a single page, for the principal. Written to be read in one sitting by someone who does not work in technology, and to be handed to a partner, a board, or an owner without translation.
  • The Assessment Report
    Written in understandable, business-focused terms for your firm's security officer. Each finding carries its evidentiary basis, its rating, and the reasoning behind every observation and recommendation.
  • Plan of Action and Milestones (POA&M)
    Your action plan laid out for the year ahead: what to do, in what order, by when, and who owns it, sequenced by exposure and effort. This is the plan you will work from and measure the progress and results of your firm each year.
  • Technical Appendix
    The supporting record behind the report, prepared for your security lead and organized to be reviewed control by control: what was examined, the evidence relied on for each control, its source and date, and the basis for each determination.
  • Confirmation of Risk Assessment Performed
    A one-page signed statement of the assessment performed, the period it covered, the scope areas reviewed, and the categories of evidence relied on. This is the document you hand a carrier, an examiner, or a distribution partner who asks whether the assessment was done.

Process

A Simple, Straightforward Process

  1. Phase 01Scope
  2. Phase 02Evidence
  3. Phase 03Analysis
  4. Phase 04Delivery
Phase 01

Scope

We establish the boundary of the engagement — which entities, systems, locations, and vendor relationships fall inside it — and which framework the assessment measures against. We also agree what the deliverable will contain, so there is no discovery about the output after the fact. This is written down and agreed before any information changes hands.

What we need from you: one conversation with the principal and whoever holds responsibility for technology.  ·  Typical duration: a single onboarding call.

Phase 02

Evidence

A documentation request list goes out in advance, so your team can see everything being asked for and assemble it on their own schedule rather than in response to interruptions. Much of the rest is confirmed directly, on an Evidence Confirmation Call: your security lead walks us through the relevant systems and settings by screen share, so control state is observed and recorded rather than described. Anything that cannot be confirmed on the call is requested in writing.

Where something cannot be evidenced, we record that rather than assume the control works. An assessment that credits undocumented controls is worth very little to the person who has to rely on it later.

What we need from you: your security lead for approximately one hour, plus the documents on the request list.  ·  Typical duration: a ten-business-day evidence window.

Phase 03

Analysis

We work through the evidence control by control, recording where each one stands and the reasoning behind that conclusion. Risks are rated against criteria stated plainly in the report and weighted for how your firm actually operates — what matters for a twelve-person agency running two systems is not what matters for a firm with sixty producers. Nothing is scored on a scale only we can interpret.

What we need from you: nothing — this phase is ours, aside from the occasional clarifying question.  ·  Typical duration: the draft is delivered within thirty days of complete evidence.

Phase 04

Delivery

You receive the draft assessment and a defined period to review it and provide written comments. Once you approve the draft, or the review period closes, it becomes the final assessment, issued together with the signed Confirmation of Risk Assessment Performed.

What we need from you: written comments on the draft, or confirmation that you have none.  ·  Typical duration: a ten-business-day review period.

Your Side of the Engagement

Our Efficient Approach Will Respect Your Time

What the engagement asks of your team:

  • A documentation request list, sent in advance, so nothing arrives as a surprise
  • One call with the principal at the start, to settle scope before work begins
  • One screen-share session with your security lead, to confirm control state directly
  • Written comments on the draft assessment within the review period

Optional

Quarterly POA&M Follow-Up

An action plan is worth what gets done against it. The optional quarterly follow-up keeps the plan moving through the year, rather than having it surface again the week before the next assessment.

Progress Reviewed

We walk the open items with you and record what has moved since the last session, so the plan reflects where the firm actually is.

Completed Work Verified

For anything reported complete, we review the evidence behind it — so "done" means the same thing to your carrier and your regulator as it does to your team.

Blocked Items Surfaced

Items that are stuck, overdue, or deferred get named, along with what they need to move and who needs to move them.

New Risks Captured

Anything that has changed since the assessment — a new platform, a new partner, a change in the team — gets picked up and set against the priorities for the next quarter.

How It Runs

Sessions at approximately 90, 180, and 270 days after the final report, scheduled within a one-week window by advance notice. Each is followed by a brief written update addressed to the principal. At twelve months the cycle begins again with a fresh assessment, measured against the prior baseline so you can see movement rather than start over.

Get Started

The Principal's Introduction

One hour with the principal, at no cost. We walk through what the requirements actually ask of a firm your size, where firms like yours most often carry exposure, and what an assessment would and would not cover. You leave with a clearer view of your own position.

Request

Request the Introduction

One hour with the principal, at no cost.

Email

Please keep system detail and client information out of email.

Telephone

770-275-3585

Business hours, Eastern time.