Services
How an Assessment Works
A simple engagement that typically takes about a month. What we examine, what we ask of your team, what you receive, and what the document does once it is written.
Coverage
What We Examine
Govern
Oversight and Direction
Where accountability for cybersecurity actually sits, how decisions get made and recorded, which policies exist, and whether anyone works to them. Also which obligations your firm carries and how they are tracked.
Identify
Business Data — Your Precious Asset
The client and firm information in your possession, where it lives, who can reach it, and which vendors, platforms, and carrier connections can reach it too. Some of this data should be protected like the gold at Fort Knox, and we confirm that it is.
Protect
Controls and Protection
Access control and authentication, how staff and producers are trained, how data moves in and out of the firm, and the controls standing between a routine human mistake and a reportable event.
Detect
Monitoring and Detection
What is being monitored, what those tools would actually catch, who reads the output, and how long something could run inside your environment before a person became aware of it.
Respond
Responding to a Problem
Who gets called, who decides, what notification obligations trigger and on what clock, which carriers and counterparties have to be told — and whether anyone has ever walked through it before the day it matters.
Recover
Getting Back to Business
Whether your backups have been restored from rather than merely scheduled, how long the firm can transact without its systems, and what returning to normal operations would realistically cost in time and revenue.
What You Receive
Each Risk Assessment Has the Following
-
One-Page Executive SummaryWhere the firm stands, what matters most, and what it will take — on a single page, for the principal. Written to be read in one sitting by someone who does not work in technology, and to be handed to a partner, a board, or an owner without translation.
-
The Assessment ReportWritten in understandable, business-focused terms for your firm's security officer. Each finding carries its evidentiary basis, its rating, and the reasoning behind every observation and recommendation.
-
Plan of Action and Milestones (POA&M)Your action plan laid out for the year ahead: what to do, in what order, by when, and who owns it, sequenced by exposure and effort. This is the plan you will work from and measure the progress and results of your firm each year.
-
Technical AppendixThe supporting record behind the report, prepared for your security lead and organized to be reviewed control by control: what was examined, the evidence relied on for each control, its source and date, and the basis for each determination.
-
Confirmation of Risk Assessment PerformedA one-page signed statement of the assessment performed, the period it covered, the scope areas reviewed, and the categories of evidence relied on. This is the document you hand a carrier, an examiner, or a distribution partner who asks whether the assessment was done.
Process
A Simple, Straightforward Process
- Phase 01Scope
- Phase 02Evidence
- Phase 03Analysis
- Phase 04Delivery
Scope
We establish the boundary of the engagement — which entities, systems, locations, and vendor relationships fall inside it — and which framework the assessment measures against. We also agree what the deliverable will contain, so there is no discovery about the output after the fact. This is written down and agreed before any information changes hands.
Evidence
A documentation request list goes out in advance, so your team can see everything being asked for and assemble it on their own schedule rather than in response to interruptions. Much of the rest is confirmed directly, on an Evidence Confirmation Call: your security lead walks us through the relevant systems and settings by screen share, so control state is observed and recorded rather than described. Anything that cannot be confirmed on the call is requested in writing.
Where something cannot be evidenced, we record that rather than assume the control works. An assessment that credits undocumented controls is worth very little to the person who has to rely on it later.
Analysis
We work through the evidence control by control, recording where each one stands and the reasoning behind that conclusion. Risks are rated against criteria stated plainly in the report and weighted for how your firm actually operates — what matters for a twelve-person agency running two systems is not what matters for a firm with sixty producers. Nothing is scored on a scale only we can interpret.
Delivery
You receive the draft assessment and a defined period to review it and provide written comments. Once you approve the draft, or the review period closes, it becomes the final assessment, issued together with the signed Confirmation of Risk Assessment Performed.
Your Side of the Engagement
Our Efficient Approach Will Respect Your Time
What the engagement asks of your team:
- A documentation request list, sent in advance, so nothing arrives as a surprise
- One call with the principal at the start, to settle scope before work begins
- One screen-share session with your security lead, to confirm control state directly
- Written comments on the draft assessment within the review period
Optional
Quarterly POA&M Follow-Up
An action plan is worth what gets done against it. The optional quarterly follow-up keeps the plan moving through the year, rather than having it surface again the week before the next assessment.
Progress Reviewed
We walk the open items with you and record what has moved since the last session, so the plan reflects where the firm actually is.
Completed Work Verified
For anything reported complete, we review the evidence behind it — so "done" means the same thing to your carrier and your regulator as it does to your team.
Blocked Items Surfaced
Items that are stuck, overdue, or deferred get named, along with what they need to move and who needs to move them.
New Risks Captured
Anything that has changed since the assessment — a new platform, a new partner, a change in the team — gets picked up and set against the priorities for the next quarter.
How It Runs
Sessions at approximately 90, 180, and 270 days after the final report, scheduled within a one-week window by advance notice. Each is followed by a brief written update addressed to the principal. At twelve months the cycle begins again with a fresh assessment, measured against the prior baseline so you can see movement rather than start over.
Get Started
The Principal's Introduction
One hour with the principal, at no cost. We walk through what the requirements actually ask of a firm your size, where firms like yours most often carry exposure, and what an assessment would and would not cover. You leave with a clearer view of your own position.