Reasonably solid: how to stay that way
Score below 13, no incident reported
Your fundamentals are largely in place, which puts you ahead of most firms your size. The failure mode from here is not neglect — it is drift. Controls quietly stop being enforced, the vendor list ages, the person who owned it moves on, and the firm keeps believing a picture that was true two years ago. This page is the maintenance rhythm that keeps the picture honest.
A good result reflects the answers you gave. If any of them were 'I believe so' rather than 'I checked', treat those as untested assumptions rather than strengths.
Firms at this level are usually strong on controls and weakest on evidence — able to do the right things, unable to prove it quickly when a client, insurer, or regulator asks.
The highest-value outside work for you is not remediation. It is verification and a read on what changes as you grow, take on regulated data, or add AI to your workflow.
The rhythm that keeps you here
- 1
Test a restore every quarter and log the result
Same drill each time: real data, isolated location, timed, written down. The log itself becomes the evidence you hand to an insurer or client without a scramble.
Quarterly You can do this yourself - 2
Review who has access, especially the accounts nobody watches
Admin rights, service accounts, shared logins, API keys, and anyone who changed roles rather than leaving. Privilege accumulates silently and is invisible until it is used.
Quarterly You can do this yourself - 3
Refresh the vendor list and check what changed
New tools added by teams without asking, vendors that were acquired, integrations still connected long after the project ended. Ask your most critical vendors for their own current attestation once a year.
Twice a year You can do this yourself - 4
Run a real tabletop exercise, not a discussion
Give a scenario and a clock, include someone who will actually be on the phone with clients, and end with two or three changes to the plan. Rehearsed teams recover materially faster and cheaper than teams with a good document.
Annually Specialist help pays off here - 5
Re-read your insurance conditions against reality
Policies change wording at renewal. Confirm, in writing, that what you actually do still satisfies what the policy requires — MFA scope, backup frequency, training, notification windows.
Annually, at renewal You can do this yourself - 6
Keep the AI rule current
Tooling here changes faster than any other part of your stack. Revisit which tools are approved, whether anything is now retaining or training on your inputs, and whether staff have quietly adopted something new.
Twice a year You can do this yourself - 7
Get an independent second opinion before the picture changes
The moments worth a specialist: taking on regulated data for the first time, a merger or acquisition, a major system migration, a first enterprise client with real security requirements, or adding AI to a workflow that touches customer data. Outside eyes are cheapest before the change, not after.
At each inflection point Specialist help pays off here - 8
Consider a penetration test — now it is worth it
Unlike firms with basic gaps, you will get real value from adversarial testing because the findings will be things you could not have guessed. Scope it to what would actually hurt you, and insist on a retest of the fixes.
Annually or on major change Specialist help pays off here
Where firms like yours slip
- Assuming a control is enforced because it was enabled. Verify scope — 'MFA is on' often means on for most people.
- Letting security become one person's private knowledge. If it lives in one head, it leaves when they do.
- Treating a good year as proof. Absence of an incident is not evidence of a working program.
- Adding AI tools or a big new vendor without running them through the same review as everything else.
What this usually costs
- The quarterly and annual rhythm above is time, not money — a few hours per quarter for an internal owner.
- Independent consultants commonly bill $150-$400 per hour if you want facilitation for the tabletop or an outside review.
- Penetration testing is scoped work and varies widely with the size of the environment being tested.
- The second-opinion meeting through us is free to your firm — specialists cover the cost — so a verification conversation costs you nothing but the hour.
Questions worth putting to a specialist
- Where would you attack a firm that looks like ours on paper?
- What are we likely believing that is no longer true?
- What changes about our risk if we take on regulated data, or an enterprise client with security requirements?
- What evidence should we be keeping now so an audit or questionnaire is a one-day job?
- Is there anything we are spending on that we could stop?
Get a free second opinion
Not a rescue — a read on the assumptions you have not tested and what changes as you grow. One meeting with a vetted specialist, free to your firm. Free for your firm — specialists cover the cost.
Get a Free Second OpinionCommon questions
If we're in good shape, why talk to anyone?
Because the value here is verification, not remediation. An hour with someone who sees dozens of firms a year tells you which of your assumptions are still true, and it costs your firm nothing.
Do we need a full-time security hire?
Usually not at this stage. A named internal owner with a defined rhythm, plus periodic outside review, covers most firms until headcount, regulated data, or enterprise clients push the workload past one person's spare hour.
How often should we redo this self-check?
Every six months, and immediately after any significant change — a new system, a new class of data, an acquisition, or a change in who owns security.
What does the free meeting actually cover?
A candid outside read: where a firm like yours is typically weakest, what evidence you should be keeping, and what changes as you grow. Free to your firm — specialists cover the cost.
This page is general guidance, not legal advice. If regulated data such as health or payment records may be involved, confirm your notification obligations with qualified counsel.