Insight: IT and cyber risk assessment
A confidential review of where your technology and data are exposed, and what to deal with first
For family offices, trustees, law firms and private clients, Insight establishes where your technology and data are exposed. One confidential engagement combines an audit against recognized frameworks, authorized penetration testing, a workflow and vendor review, and a private debrief for the people who decide what happens next.
Why it matters
- Most exposure sits where nobody has clear ownership: software bought outside IT, accounts with more access than they need, vendor connections nobody reviews, and backups nobody has tested.
- Authorized penetration testing replaces opinion with evidence: it shows how an attacker would get in and what they would reach.
- Findings are written in business terms, so principals and trustees can see what is at stake and what to decide.
- The work is done under a non-disclosure agreement, through secure channels, and leaves no public trace.
What the engagement covers
Seven steps, balancing technical depth with executive oversight:
-
Confidential Discovery
A scoped intake of policies, systems and boundaries, handled through secure channels. -
Security Audit
Identity, email, cloud, devices, backups and access, reviewed against ISO/IEC 27001 and the NIST Cybersecurity Framework. -
Targeted Penetration Testing
Authorized testing of the systems you agree in writing, to establish what an attacker could actually reach. -
Risk Register & Gap Analysis
Every finding tied to the asset and process it affects, with a remediation plan in priority order. -
Workflow & Vendor Review
Third-party access, approval routes and change procedures, with support for vendor selection where you need it — including AI vendors, where the questions that matter are what the service does with your data and who can see it. -
AI Exposure Review
Which AI tools your people already use, what they have been given access to, and where confidential material is leaving your boundary without anyone deciding that it should. Usually the shortest path to a surprise. -
Executive-Level Reporting
A structured briefing for the board, principals or trustees, matched to your risk appetite.
What you receive
-
Confidential Exposure Map
One view of where you are exposed, ranked by severity. -
Executive Briefing Report
20–30 pages: findings, risk matrix and prioritized actions, written for governance review. -
Remediation roadmap
Work sequenced across the first 90 days, the first year, and beyond. -
Private Debrief
A closed session with the executives, principals or trustees you choose. -
Optional reviews
Quarterly or annual re-checks, so the picture stays current as your environment changes.
How we work
-
Defined scope
Written boundaries: we examine only what you authorise. -
Minimal disruption
Testing is scheduled around your operations, so daily work continues. -
Findings reviewed with you
You see and challenge the findings before the report is final. -
A basis for what follows
The findings feed directly into Revive or Fortify if you choose to continue.
Who it suits
-
Family Offices
Visibility across entities, jurisdictions and the households attached to them. -
Trustees & Law Firms
Documented evidence of oversight for duty-of-care and compliance obligations. -
Private Clients and High-Net-Worth Individuals
A discreet review of household IT, devices and personal data.
What changes
-
A clear picture of exposure
Blind spots identified and tied to the assets that matter. -
An order of work
Urgent containment separated from longer-term change. -
Governance-ready reporting
Documentation you can put in front of a board or trustee meeting. -
A foundation to build on
A baseline you can measure later work against.
In short
Insight gives leaders a defensible picture of IT and cyber risk without putting sensitive information at risk. It combines an audit against recognized frameworks, authorized penetration testing, a risk register, a workflow and vendor review, and a private debrief. You finish knowing what to fix, in what order, and why.