Skip to content
Two decades of federal security engineering · Active Top Secret clearance

§ The Audit

A fixed-scope review of what actually touches your clients' data.

$2,500. One engagement, no retainer required. You get a written record of where your firm stands — and what to fix first — built on the same discipline used to secure federal systems.

Not just a finding.
A decision you can act on.

A useful report connects an observation to business exposure, a proposed action, and someone responsible for taking it forward.

Access after a vendor engagement ends

Observation
An external account appears in the workspace access list. Its current business purpose needs confirmation.
Business question
Should this account still be able to reach client files?
Proposed next step
Have the workspace owner confirm the need with the vendor; remove unnecessary access through the agreed change process.
Evidence & ownership
Record the decision, responsible owner, and date of the access check.

Not a client result. Actual findings and priorities depend on the evidence reviewed.

  1. Intake

    Agree the systems, vendors, and information in scope.

  2. Review

    Examine the evidence and record open questions.

  3. Prioritize

    Connect findings to practical business decisions.

  4. Walkthrough

    Discuss the written record and next steps directly.

Illustrative approach · Scope and responsibilities agreed before work begins

§ Scope

What's reviewed

Vendor and access mapping
Practice management, document storage, email, and any system a vendor can reach — matched against who has access and why.
Contract and control check
What your vendor agreements actually commit them to when something goes wrong, measured against what your confidentiality obligation requires.
Authentication and backup posture
Where multi-factor authentication and backups exist, where they don't, and where a cyber insurance application would ask you to prove it.
Written findings, ranked
A report in plain language, prioritized by what creates real exposure — not a checklist of everything that could theoretically be improved.

§ Process

How it runs

  1. 01

    Intake

    A short written questionnaire and one conversation to understand your systems, vendors, and how the firm actually works day to day.

  2. 02

    Review

    The systems and vendor agreements from intake are reviewed against your confidentiality obligation and against what a cyber insurer would ask for.

  3. 03

    Report & walkthrough

    A written report, delivered and walked through with you directly — in language built for a managing partner, not an IT department.

§ Fit

Built for

  • Firms of 5–25 attorneys in DC, Maryland, or Northern Virginia.
  • Firms preparing for a cyber insurance application or renewal.
  • Firms whose vendor stack has never been reviewed against an actual standard.

§ Not This

Not included

  • Not a managed IT contract or ongoing retainer.
  • Not round-the-clock monitoring or incident response.
  • Not a penetration test — this is a review of controls and vendors, not an attack simulation.

§ Before the Audit

Not ready for the full engagement?

The Executive Cyber Briefing is a shorter, no-obligation conversation — a working session that walks through roughly where your firm stands against the obligations above, without a formal review. Ask about the Executive Cyber Briefing.

$2,500. One engagement. A written record.

Book the Audit