Security-questionnaire response
A customer, partner, or insurer sends a security questionnaire. Each question is mapped to evidence that actually exists in your environment, producing a response workbook your team can attest to.
Included
- One questionnaire of an agreed length, explained in plain language
- Each question mapped to verified evidence from identity, email, endpoint, backup, recovery, and training systems
- Missing, contradictory, and unevidenced controls identified
- One review round with the responsible person
Not included
- Answering from assumptions, plans, or intentions
- Acting as the respondent, broker, or signatory
- Remediating the gaps found — separate scoped work
- Coverage, limits, exclusions, legal interpretation, or certification of any kind
- You receive
- An evidence matrix showing implemented, not applicable, and unresolved items, and a response workbook with supporting evidence recorded beside each answer. Unresolved items stay visibly unresolved.
- You provide
- The questionnaire, a named responsible person, and read access to the systems the questions concern.
Bounded security posture review
A point-in-time review of a defined set of systems against a stated baseline, producing findings ranked by consequence with the evidence behind each one.
Included
- One agreed scope — a named set of systems, accounts, or one tenant
- Identity and administrative access, multi-factor coverage, email authentication, endpoint configuration, backup configuration, logging, and recovery ownership
- Findings recorded with observed evidence, not inferred
- A remediation list ordered by consequence, each item with an owner and an effort estimate
Not included
- Penetration testing, exploitation, social engineering, or attack simulation
- Continuous or repeat scanning, or a vulnerability-management program
- Remediation itself
- Any statement that the environment is secure, compliant, or insurable
- You receive
- A findings report with evidence, a ranked remediation list, and a residual-risk register recording what was accepted rather than fixed.
- You provide
- Scope agreement in writing, read access to the systems in scope, and one named technical contact.
Backup and tested restore verification
Most organizations have backups configured and have never proven one restores. Three agreed restore paths are performed end to end, each with a receipt.
Included
- Inventory of what is backed up, what is not, retention as configured, and who receives alerts
- Three agreed restore paths performed end to end
- A receipt per restore: what was restored, from which point in time, how long it took, who verified it
- A written account-loss and outage procedure usable by your administrator
Not included
- Designing or replacing your backup platform
- Full-tenant or full-site disaster-recovery testing
- Any recovery-time or recovery-point guarantee
- Restoring into production without your written approval
- You receive
- The backup inventory, one receipt per tested restore, and the account-loss and outage procedure. A tested restore proves that path on that date. It does not prove full disaster recovery.
- You provide
- Backup platform access, a target environment the restore may write to, and approval of each restore before it runs.