Skip to content

Independent security review

Find the gaps between what is meant to protect your business and what the evidence proves.

The Security Reality Check is an independent, fixed-fee review of whether the IT and security services you pay for are actually being delivered. We examine the records behind them and show what is covered, what is missing, and who needs to act.

For owners and managing partners who pay for IT and security, inside or out, and want an independent check on what they are getting. It is especially valuable for organizations where an internal IT team is managing security but is stretched thin, and needs to know where their limited resources will get the most "bang for their buck", whether that means hardening what they have without expanding, or building a roadmap for a growing program.

When an independent review helps

When the business changes, check what still protects it.

AI is helping attackers work faster and giving staff new ways to access data and automate work. Before connecting another tool or renewing another provider, know who can act, who must approve, and what evidence shows the controls work.

Read the NCSC assessment of AI-enabled threats and its guidance on delegated access and actions.

  • Before you renew a provider

    Compare the service you were sold with the evidence that it is being delivered.

  • Before connecting AI to company data

    Identify what it can access, what it can change, and which actions require approval.

  • Before an insurance or client review

    Know which security statements you can support with records and which still need checking.

A useful first step

What could you show evidence for today?

The free Security Reality Snapshot is a 15-question checklist covering responsibilities, access, and recovery. Use it to identify what you know, what you need to ask, and where to start.

No email required. Read it online or print it to work through with your provider.

What you receive

Evidence, ownership, and next steps.

One written report, walked through with leadership. Its three parts:

See the gaps clearly

Executive findings summary

What the evidence supports, what it does not, and which decisions are yours.

Know who owns the next step

Security confidence scorecard

Each domain rated, with a named owner and an immediate action.

Leave with a workable plan

30/60/90-day roadmap

Actions in order, each with an owner and a way to confirm it is done.