Security Advisory

Security work in most organizations is already underway, just unevenly.

This is the work of finding out what is actually covered, what is half covered, and what nobody owns.

Timeline2 to 4 weeks
Best start60 to 90 days pre-deadline
About this engagement

How it works

The call usually comes from a form. A cyber insurance renewal, a customer security review, or a CMMC or SOC 2 requirement arrives with questions that assume someone can describe the environment in specific terms. The answers live in three or four heads and two vendor portals. That gap, not the underlying posture, is what stalls the date.

The scope is what you have, what it covers, who operates it, and what is written down. That spans endpoint and identity, email, network edge, backup and recovery, and the monitoring layer sitting above all of it. It does not replace a penetration test or an audit. It produces a picture accurate enough to answer the form and to decide what to fix first.

There is no product to sell. Compensation comes from the vendors through the TSD model, so the engagement carries no cost to you and the recommendation follows the requirements rather than a quota.

TSD compensation model
01

Risk and Gap Assessment

The questionnaire is not the problem. The problem is that no single document describes the environment, so every answer is a guess that someone signs. This starts by writing that document.

Establishing a documented baseline

  • Current asset and endpoint inventory, including personal and unmanaged devices
  • Cyber insurance questionnaire language matched to what is actually deployed
  • Identity boundary: who has admin, where MFA is enforced, where it is not
  • Which framework applies: CMMC, HIPAA, PCI, or SOC 2, and at what level

Most gaps found here are not missing products. They are products already purchased, partially deployed, then left at vendor defaults because the person who owned the rollout changed jobs.

02

Tooling and Coverage Review

Security tools accumulate one purchase at a time, usually at a renewal or after an incident somewhere else. Overlap by itself is not the issue. The question is whether the overlap covers the same ground twice while something else sits uncovered.

Mapping tools to coverage

  • EDR agent coverage compared against the actual endpoint count
  • Email filtering, DNS filtering, and firewall rules checked for duplicate function
  • Backup immutability and retention verified, not assumed from the vendor datasheet
  • Which licenses you already pay for and have never turned on

The most common finding is not a hole in the stack. It is a tool that would close the hole if someone had the hours to tune it, and a control nobody has time to operate is not a control.

03

Monitoring and Response Review

Detection and response are different things. Most environments generate alerts. Far fewer can name the person who reads them outside business hours, or show what happened to the last one.

Confirming who is watching

  • Alert destinations traced: who receives them, on what schedule
  • MDR contract scope compared against what an internal SOC would cover
  • Whether the provider can isolate a host or only notify you
  • Log retention length measured against your insurance and contract requirements

The line worth checking is authority, not coverage. A provider that must call three people before isolating a machine is a notification service, and its contracted response time starts after that call chain finishes.

04

Vendor Vetting and Sourcing

A deadline sets the date. It does not set the requirement. This writes the requirement first, then puts it in front of vendors who can meet it.

Scoping before you buy

  • Requirements written from the control, not from a vendor feature list
  • Vendor claims about CMMC or SOC 2 support checked against evidence
  • Onboarding hours and ongoing operator time quoted in writing
  • Contract term, exit terms, and data return on termination

Compliance dates reward buying whatever maps cleanly to the control language, which is not always what fits the environment. The purchase that holds up is the one where a named person on your side agreed, before signing, to own it on a Tuesday afternoon in month seven.

Process

How the engagement runs

01

Understand your environment

Current inventory, contract dates, sites, and what the business actually needs the technology to do.

02

Define where you want to go

Target state, growth requirements, and success criteria, all agreed before a single vendor is contacted.

03

Evaluate solutions

The requirement goes to every provider that can meet it, and the responses come back on terms that can be read side by side.

04

Define a solution and negotiate terms

Pricing, term length, service levels, and exit language are settled before signature rather than discovered on the first invoice.

05

Oversee activation

We stay in the project through installation, porting, and acceptance, and we escalate on the client's behalf when dates slip.

Deliverables

What you walk away with

A written current state document covering assets, identity, tooling, and monitoring ownership

A completed answer set for your insurance questionnaire or customer security review, in their wording

A gap register listing each finding, the control it maps to, and who would operate the fix

A shortlist of two to three vendors with scoped quotes and side by side comparison notes

Common questions

Questions we get

Is this a penetration test or a security audit?
No. A penetration test tells you whether a specific defense can be beaten, and an audit tells you whether your evidence matches a standard. This work sits earlier than both: it establishes what you have, what it covers, and who operates it. Most organizations get more out of a test or an audit once that picture exists.
We already have an MSP or an internal IT team. Does this duplicate their work?
It usually does not. They operate the environment day to day, and this documents it from the outside and compares it against what your insurer, your customers, or your framework actually ask for. Your team is a participant in the review, not the subject of it. In most cases the output gives them a clearer scope than they had before.
What if the review concludes we do not need to buy anything?
That is a normal result and a useful one. A frequent finding is that the tools already in place would cover the gap if they were finished, tuned, or assigned to a named owner. When that is the case, the recommendation is configuration and ownership rather than procurement.
How are you paid if the engagement costs us nothing?
Compensation comes from the provider through the TSD model, which stands for technology services distributor. When a contract is signed, the provider pays a distribution fee that would otherwise go to its own direct sales team. Your pricing comes off the same rate card either way.
What if the right answer is staying where we are?
That gets recommended when it is correct. A renegotiated contract with the incumbent, or leaving a working system alone, counts as a finished engagement and gets the same work as a migration.
When should we start relative to our contract end date?
Roughly six months out. Auto-renewal notice windows commonly close 60 to 90 days before term end, and starting inside that window removes most of the leverage. Check your specific renewal clause, since the window is the constraint rather than the end date.
Vendors we compare

The market we compare for you.

The first conversation is a scoping call, not a pitch.

Bring your current cyber insurance application or renewal questionnaire, a list of the security tools you pay for, and the name of whoever receives alerts today. That is enough to say whether there is anything worth pursuing.

Next step

The first conversation is a scoping call, not a pitch.

We ask what you have, what is expiring, and what is not working, then tell you whether there is work here worth doing. If Elk Run is not the right fit for the decision in front of you, we will say so.