Call Book the fit call
See before you buy

The paper you walk away with - before you pay for it.

Every engagement leaves artifacts, not just advice. Here are illustrative samples of the three you’ll actually use: a scored checkup, a “what we changed” page, and the answers your insurer asks for.

Baseline Security Checkup - Scorecard

Sample · Northgate Dental
58/100
Developing20 controls scored across email, identity, backups, devices, people and payments.
Email authentication (SPF/DKIM/DMARC)Exposed
Multi-factor on email & admin accountsDeveloping
Backups tested by a real restoreExposed
Guest Wi-Fi separated from business networkReady
Device encryption & screen locksDeveloping
Payment-change verification habitExposed
Onboarding / offboarding checklistDeveloping
Staff reporting culture (no-shame)Ready

Top risks, in plain English

  1. Anyone who guesses one reused password reaches the inbox - MFA is off for three admin accounts.
  2. Backups run nightly but have never been restore-tested; a bad Monday is an unknown.
  3. No callback step before a banking-detail change - the exact gap wire fraud walks through.

Security Tune-Up - What We Changed

Sample · Northgate Dental
ControlBeforeAfter
Multi-factor authenticationOff for 3 admins, patchy for staffEnforced on every account that touches email, money or records
Email authenticationNo DMARC; spoofableSPF + DKIM + DMARC set to quarantine, monitored
BackupsNightly, never testedRestore tested end-to-end; 22 min to recover the schedule
Payment changesAd-hoc, email-onlyWritten callback rule; two-person sign-off over $5,000
Guest Wi-FiShared with the serverSeparated onto its own network, can’t see business machines

Every change is logged with the date, who signed off, and how to undo it - the one-pager your insurer and your IT provider both get a copy of.

Cyber-Insurance Answer Pack

Sample · Northgate Dental
Do you enforce multi-factor authentication on email and remote access?

YesYes - enforced on all email, admin and remote-access accounts as of the engagement date. Evidence: tenant policy export in the handoff folder.

Are backups performed and tested?

YesYes - nightly backups with a documented restore test completed during the engagement (schedule restored in 22 minutes).

Do you provide security awareness training?

YesYes - live team training delivered, with a dated completion record and per-person certificates.

Do you have a written incident response plan?

YesYes - a one-page first-hour plan with an insurer-first call tree, kept with the office manager.

Mapped to the questions on a typical renewal - with the evidence to back each answer, so “yes” is one you can actually stand behind.

Your report, on your office, in three business days.

The checkup is $750 fixed. The fee credits toward any training or Tune-Up booked within 30 days - so the paper you just saw costs nothing extra if you act on it.

Book the baseline checkup - $750