SVC-RA · Comprehensive risk assessment
The starting point for most engagements: a comprehensive cybersecurity risk assessment covering your technology, your people, and your obligations, with findings you own whether or not you engage us further.
What we examine
We map what you actually run: Google Workspace or Microsoft 365 tenant configuration, devices, practice management systems, file storage, backups, and the vendors touching client data. Many firms discover systems they didn't know were still connected.
Who can access what, and should they? Departed-employee accounts, over-broad permissions, shared logins, and administrative rights that accumulated over years are the findings that show up in almost every assessment, and in almost every breach.
Technical gaps are weighed against what they mean for your business: client confidentiality, wire-fraud exposure, uptime commitments, and the obligations in your engagement letters, customer contracts, and insurance policy, not a generic severity score.
The report ranks what to fix in the order it reduces risk, in language a managing partner can act on. No jargon walls, no hundred-page appendix designed to justify a retainer.
Common questions
Four things: documentation of your infrastructure and platforms as they exist today; a review of roles, responsibilities, and who can access what; analysis of vulnerabilities and the risks they create for your specific practice; and a prioritized set of recommendations in plain language, ranked by what reduces the most risk soonest.
For most small and mid-sized organizations, two to four weeks from kickoff to the written report. Most of it is low-touch document review and interviews, scheduled around your operations.
No. The assessment stands on its own: you keep the documentation and recommendations whether or not you engage us for anything else. You can hand the findings to your IT provider, implement them internally, or ask us to.
It's usually exactly what they're asking for: an independent review led by a certified auditor, with a deliverable that carries weight with whoever asked. If they require attestation against a specific framework such as SOC 2 or ISO 27001, the assessment feeds directly into our compliance and audit services.
Getting started
Tell us about your firm and we'll put the timeline, price, and deliverable in writing before you commit to anything.