Security & Risk

Measured against your real threat model, not a vendor checklist.

Domain 2 of 8. Back to the assessment

Security assessments usually arrive as a list of products you do not own yet. This one starts from your actual exposure: what an attacker would reach first, what it would cost you, and which controls change that math. Companies of your size are rarely targeted by name. They are caught in campaigns that punish the ordinary gaps.

Why it matters

Ransomware is a business continuity event with a legal and insurance tail. What determines the cost is not the malware; it is whether identity, backups, and the first hour of response were sorted out beforehand.

The benchmark

What good looks like at your size

We score against this benchmark, meaning what a well-run company of 50 to 500 employees should reasonably have in place, rather than against theoretical perfection.

Multi-factor authentication with no exceptions

Every account that touches company data requires a second factor, including administrators, contractors, service accounts, and the legacy systems that sit outside your identity provider.

Administrative rights are rare and reviewed

Standing admin access is the exception rather than the convenience. Someone can produce the current list of privileged accounts and explain why each one exists.

Departures remove access the same day

Offboarding is a defined process covering every system, not just email, and there is evidence it ran for the last several people who left.

Alerts have an owner and a clock

Detection tooling is monitored by a named party, internal or contracted, with an agreed response time. A license that nobody watches is a purchase, not a control.

The first hour is rehearsed

People know who declares an incident, who calls the insurer and counsel, who can authorize a shutdown, and how the company communicates while systems are down.

Compliance answers come from evidence

Insurance applications and customer security questionnaires are answered from documented reality, so the answers stay true when they are tested at claim time.

The pattern

What we typically find

Patterns common enough to name. None of them indicate a bad team. They are what happens when a company grows faster than the decisions that shaped its technology.

MFA everywhere, except where it matters

Coverage is real for email and genuinely absent for the VPN, the ERP, or a shared administrative account, precisely the paths an attacker prefers.

Former employees with live access

Accounts still active months after departure, almost always in a system that sits outside the central identity provider and outside the offboarding checklist.

Detection with nobody watching

Endpoint detection is deployed and licensed, and the alerts land in a console or mailbox that no one has an obligation to read within any particular timeframe.

An insurance application answered optimistically

Questions about MFA, backups, or privileged access were answered as intended rather than as implemented. The gap becomes a coverage argument at exactly the wrong moment.

Backups reachable with production credentials

The backup system trusts the same directory as everything else, so a single compromised administrator account takes production and recovery together.

The method

How we assess it

Where a document does not exist, that is itself a finding, and we say so plainly rather than treating the gap as an obstacle.

What we examine
  • Identity and access: MFA coverage, admin rights, and departed-employee hygiene
  • Core controls: patching, email protection, endpoint detection, network segmentation
  • Incident readiness: who does what in the first hour of a ransomware event
  • Alignment with cyber-insurance requirements and customer security questionnaires
What we ask you for
  • Identity provider configuration, MFA coverage report, and the list of privileged accounts
  • The offboarding process and a sample of recent departures traced across systems
  • Patching and endpoint protection coverage reports
  • Current cyber-insurance application and policy, plus the most recent customer security questionnaire
  • Any prior penetration test, vulnerability scan, or audit findings and what was done about them
  • Working sessions with IT and with the business owners of your most sensitive systems
The output

Questions the readout answers

What would a ransomware event actually cost us, and how likely is it today?

Can we answer our largest customer’s security audit without a fire drill?

The deliverable

What this domain contributes to your report

  • A risk register ranked by business impact, with likelihood stated plainly
  • The gap list against your insurance requirements and your largest customers’ demands
  • A realistic ransomware scenario for your business, with the cost modeled end to end
  • A ninety-day risk-reduction plan, separated from the longer security program
The scale

How this domain is scored

Every domain is scored 0–10 on the same scale, so the scorecard shows you where to look first rather than a single undifferentiated grade.

0–3
Material risk today

Something here can hurt the business now. These findings lead the roadmap.

4–6
Workable, but behind

Functioning, but behind where a company of your size and stage should be.

7–8
Solid

In good shape. Worth maintaining rather than investing further right now.

9–10
Ahead of peers

A genuine strength, and often something to build on elsewhere.