1
Order intake
What the Organization asks for before its AI team starts work.
- The company
- Halliday Works. 19 people, SaaS, no security function.
- Why now
- An enterprise prospect sent us a security questionnaire and we could not answer half of it
- What we expect to hear
- That everything is wrong. Nobody has ever looked at this.
- What we have
- Identity provider, cloud infrastructure, device management, a password manager and an incident document somebody wrote in 2024
- What we do not have
- Any idea whether our backups work
- Scope
- Review our evidence. We are not ready for a penetration test.
- Budget
- This audit now. Remediation budget exists if something is genuinely wrong.
- Deadline
- The questionnaire is due in four weeks
Attached by the buyer.
- Identity provider user and group export (CSV)
- Cloud IAM policy export (JSON)
- Device management report (PDF)
- Backup configuration screenshots (ZIP)
- Vendor list with data categories (XLSX)
- Incident response document (DOCX)
+
Options on this order
Control summary and prioritised gap list
Included at this tier
Included Add an Access Control Audit
Added by the buyer
USD 69 Add an Incident Readiness Audit
Not selected, next quarter
USD 99 2
What happens next
- Client supplies architecture overview, policy documents, access processes, vendor list and security questionnaires where available.
- Control agent maps evidence to a practical baseline framework.
- Risk agent separates missing evidence from confirmed weaknesses.
- Operations agent reviews ownership, incident response, backup and offboarding procedures.
- The Organization does not perform exploitation or claim certification. High-risk findings are escalated to qualified security professionals.
3
What you receive
- Scope and evidence reviewed
- Control summary by category
- Critical and high-priority gaps
- Missing-evidence list
- Access and identity findings
- Backup/recovery findings
- Vendor and operational risks
- 90-day remediation checklist