Cyber insurance renewal
The questionnaire got longer, and nobody could answer it
Situation
A 35-person marketing agency's cyber insurance renewal jumps from a 2-page form to an 18-page technical questionnaire. The office manager who normally handles this can't answer questions about Endpoint Detection and Response (EDR) coverage or backup immutability.
Assessment
Multi-Factor Authentication (MFA) is enabled but not enforced on admin accounts. Backups exist but have never been restore-tested. No documented incident response plan.
Workshop
A session with the office manager and the IT contractor — reading the actual questionnaire line by line and building the evidence binder (screenshots, config exports, dated reports) the underwriter will ask for.
Retainer
Ongoing evidence-binder maintenance, so next year's renewal is a copy-paste job instead of a scramble.
Outcome
Renewal passes without a premium increase — and the owner finally understands what they're actually covered for.
No dedicated security team
Everyone's job, so nobody's job
Situation
A 60-person accounting firm has no one whose title includes "security" — it falls to whoever's available, usually a partner who also carries a full client load.
Assessment
No formal access review since the firm was founded. Former employees still hold active credentials to shared drives.
Workshop
Training for partners and staff on the precursor framework, plus a one-page escalation path so a concern has somewhere to go.
Retainer
Quarterly access reviews and a real point of ownership — without hiring a full-time Chief Information Security Officer (CISO).
Outcome
A functioning process at a fraction of a full-time hire's cost.
Shadow Artificial Intelligence (AI)
Nobody approved it, but everyone's using it
Situation
A 40-person product design studio's leadership assumes nobody uses Artificial Intelligence (AI) tools on client work. A quick review of expense reports finds six different AI subscriptions nobody approved.
Assessment
No AI acceptable-use policy exists. Client design files have already been uploaded to at least two consumer AI tools for "quick feedback."
Workshop
Building the first AI usage inventory and acceptable-use policy — using Samsung's 2023 ChatGPT leak as the cautionary example: well-meaning engineers, no policy, real exposure.
Retainer
Ongoing AI tool discovery as new tools launch, with a quarterly policy refresh.
Outcome
Leadership finally knows what's actually running through their business — and can answer their next insurance renewal's AI questions honestly.
Growing past DIY
The stakes outgrew the "we'll figure it out" plan
Situation
A healthcare billing company has grown from 5 to 25 employees in two years. Client health data now runs through their systems, but security is still handled the way it was at 5 people — informally.
Assessment
No documented incident response plan. No employee security training. A patchwork of personal and shared logins.
Workshop
A session for leadership and staff — the precursor framework, an incident response plan draft, and a training program they can actually run themselves.
Retainer
Ongoing fractional Chief Information Security Officer (CISO) advisory as they keep growing, so security scales with headcount instead of trailing years behind it.
Outcome
A company that finally looks, to a client or an insurer, like it takes its own growth seriously.