Security Readiness Review · USD 79
You can evidence 31 of 40 controls. One of the nine is blocking.
What your security posture looks like on paper, before a customer asks you to prove it.
Your engineering team believes the company is in reasonable shape. On the evidence, they are right: 31 of 40 controls are in place and can be demonstrated. The problem is not the security. It is that three of the nine gaps are things a procurement team will ask about in the first week, and one of them will stop the deal.
Access control, encryption, backups and logging are all in place and evidenced. The blocker is that eleven former staff and contractors still have active accounts in at least one system, including two in production. That is the single question most enterprise questionnaires ask directly, and it is answerable in a week.
Position
Where you stand by area
Evidenced
What is in place, with the proof
| Control | Evidence held | Owner |
|---|---|---|
| Encryption at rest | Cloud config export, all 6 stores | Platform |
| Encryption in transit | TLS config, certificate inventory | Platform |
| Multi factor on admin accounts | Identity provider report, 100 percent | IT |
| Automated daily backup | Job history, 90 days, no failures | Platform |
| Restore tested | Test record, 14 July 2026 | Platform |
| Centralised logging | Config, 400 day retention | Platform |
| Endpoint encryption | Device report, 23 of 24 devices | IT |
| Password policy enforced | Identity provider policy export | IT |
| Vulnerability patching | Patch report, 30 day SLA met | Platform |
| Supplier list maintained | Register, 31 suppliers | Operations |
| Data retention schedule | Documented, approved March 2026 | Operations |
Eleven of the 31 are shown. The full register with every evidence reference is in the pack.
Gaps
The nine, ranked by what a buyer asks first
| # | Gap | Why it ranks here | Effort |
|---|---|---|---|
| 1 | 11 stale accounts, 2 in production | Asked directly on almost every questionnaire, and it is a real exposure | 1 week |
| 2 | No offboarding checklist | It is why gap 1 exists. Fixing 1 without this repeats it | 2 days |
| 3 | No incident response plan | Second most asked. Currently nobody knows who to call | 1 week |
| 4 | No access review cadence | Asked as how often do you review access | 2 days |
| 5 | One laptop unencrypted | A single device, but it makes the answer to a yes or no question no | 1 day |
| 6 | No security training record | Training happens. Nothing records it | 3 days |
| 7 | Alerting on logs is partial | You collect logs and nothing watches three of them | 1 week |
| 8 | No documented change approval | Process exists in practice, nowhere in writing | 3 days |
| 9 | No penetration test | Increasingly asked at this deal size. Needs a qualified firm | External |
Questionnaire
How you would answer their questionnaire today
| Answer today | After the 8 internal fixes | |
|---|---|---|
| Is data encrypted at rest and in transit? | Yes, evidenced | Yes |
| Is MFA enforced on privileged accounts? | Yes, evidenced | Yes |
| Are backups tested? | Yes, July 2026 | Yes |
| Do you remove access when staff leave? | No, and 11 accounts prove it | Yes, with a checklist |
| Do you review access periodically? | No | Yes, quarterly |
| Do you have an incident response plan? | No | Yes, with contacts |
| Is all staff security training recorded? | No record | Yes |
| Are all endpoints encrypted? | 23 of 24 | Yes |
| Has a penetration test been performed? | No | Still no, needs a firm |
Eight of the nine gaps are fixable internally in about three weeks. The ninth requires a qualified testing firm and is the one item on this page we cannot help with.
Order
What to do, in this order
-
Revoke the 11 accounts, production first
An afternoon. Record the date of each revocation, because that record is itself evidence.
-
Write the offboarding checklist
One page. Named owner. Otherwise this list rebuilds.
-
Incident response plan
Who decides, who calls, who tells customers, and in what order. One page beats none.
-
Encrypt the last laptop, set a quarterly access review
Two small items that each turn a no into a yes.
-
Training record, change approval, log alerting
All three document something you already do.
-
Engage a qualified firm for a penetration test
The only item here that needs testing rather than documenting. We can prepare the scope and the questions to ask three firms.