Skip to content

The report

One written document, dated and versioned, walked through with leadership. This page shows what is in it, how the scorecard reads, and one finding as written.

How to read it in five minutes

The report answers four questions leadership asks. The findings and the appendix are written for the people who will do the work, including your provider.

Are we actually protected, or just busy?
Section 1, the executive findings summary
Are our providers delivering what we pay for?
Section 2, provider commitments compared with delivered service
Where are the gaps, and who owns them?
Section 3, the scorecard, and section 4, the findings
What should leadership fix first?
Section 5, the 30/60/90-day roadmap

What is in it

  1. 1. Executive findings summary

    The bottom line for leadership, and the findings that need a leadership decision before anything else starts.

  2. 2. Provider commitments compared with delivered service

    What the firm understood it was buying, set beside what the agreement and the records show, and what the difference means.

  3. 3. Security confidence scorecard

    One line per domain: status, maturity, who owns the control, and the immediate action.

  4. 4. Findings

    Each finding records the evidence reviewed, what it does not establish, the business consequence, the recommended action, ownership, and the evidence that closes it.

  5. 5. 30/60/90-day roadmap

    Actions in order, each with an owner and a way to confirm it is done.

An appendix records every piece of evidence requested, whether it arrived, and which findings rest on it. A record that was not supplied is reported as a limitation, not as evidence that a control has failed.

How the scorecard reads

One line per domain. Here is the line for the finding shown below.

One illustrative scorecard line
Backup & RecoveryStatus ○ Critical GapMaturity 1 of 5Control owner Internal / provider sharedImmediate action Protect backup copies from production credentials and run a recovery exercise
Status
Defensible, At Risk, or Critical Gap. Defensible means the reviewed evidence supports the control within the agreed scope, at the time of review. It is not a guarantee. If the evidence is insufficient to rate a domain, the report says so instead of guessing.
Maturity
How the control is managed, on the 0 to 5 scale published on the how we work page. A different view of the same evidence, not a second score.
Control owner
Who holds the control today: the firm, the provider, shared, or unassigned. Unassigned is itself a finding.
Immediate action
The one thing to do first for this domain.

The twelve domains

  • Governance
  • Asset Management
  • Identity & Access
  • Endpoint Security
  • Network Security
  • Email Security
  • Vulnerability Management
  • Monitoring & Detection
  • Incident Response
  • Vendor Risk
  • Security Awareness
  • Backup & Recovery

The decision and roadmap in this example

Leadership authorizes the provider to protect the backup copies and run a controlled recovery exercise. The application owner defines acceptable downtime and data loss; the managing partner approves closure after reviewing the evidence.

  1. Today

    The provider confirms whether production credentials can delete copies and applies agreed safeguards. An exposed recovery path is triaged the same day, not held for the 30-day milestone.

  2. Within 30 days

    The provider runs an authorized recovery exercise. The application owner records the workflow checks, elapsed time, and data recovered. The managing partner reviews the protection and recovery evidence promptly and records closure or remaining actions.

  3. Within 60 days

    The application owner and provider document recovery responsibilities, escalation, and acceptance in the service record.

  4. Within 90 days

    The managing partner checks that safeguards remain in place, reviews any open actions, and confirms the next exercise date. This follow-up does not defer approval of the initial recovery result.

One finding, as written

Every finding follows this structure. The framework reference is for the provider.

F-01. Backup copies can be deleted with production credentials, and recovery has not been demonstrated

Domain: Backup & RecoveryStatus: Critical GapSeverity: Critical, act within 30 days

Framework reference for the provider: NIST CSF 2.0 PR.DS-11

Evidence reviewed
Thirty days of job reports record successful nightly backups of the main business application. The permissions export shows that the production administrator account can also delete backup copies. The service agreement includes backup operation but assigns nobody responsibility for confirming that a recovery works.
What the evidence does not establish
The records cover one application and one review period. They do not show that the application, its database, and user access can be restored together. No recovery exercise record was supplied, and no restore was performed as part of this review.
Business consequence
Client work and billing depend on this application. Leadership's stated tolerance is one working day of disruption, and the evidence does not establish that recovery could meet it. If the administrator account is compromised, the attacker can delete the working system and its recovery copies in the same session.
Recommended action
The provider configures backup copies that cannot be deleted through the production administrator account, then runs an authorized recovery exercise in an isolated environment. The application owner agrees in advance on acceptable downtime and data loss, checks the restored workflow, and approves the outcome in writing.
Ownership
Accountable: the partner who owns the application. Responsible: the IT provider. Approves closure: the managing partner.
Evidence that closes the finding
A configuration review confirming that production credentials cannot delete the protected copies, and a recovery record naming the backup used, the elapsed time, the data point recovered, the checks performed, any exceptions, and the owner's approval. One successful exercise supports that tested scenario; it does not guarantee every future recovery.

The check behind this finding is one of six described on how we test.

Discuss what you need to understand.

Tell us which decision or concern prompted your inquiry, and we will discuss scope before agreeing on an engagement.

Contact us about a review