Skip to content

Security & Compliance Readiness Review

Confirm what you already believe — or find out what needs to change.

You know your business. You may have personally chosen the technology, approved the spending, or watched the current setup take shape over years of growth and change. What you want isn't someone telling you what you got wrong. It's confirmation — that your controls are real, that your documentation would hold up, and that your security and compliance practices still fit the company you run today.

See all Guardian assessments

Which situation fits you?

Three reasons companies bring us in

Open the one that sounds like your situation.

Someone outside your company is asking+

A bank or lender is asking questions. A cyber-insurance renewal is approaching. A major customer has sent a questionnaire, an auditor needs evidence, or a new regulatory requirement applies. Each one means someone wants security and compliance information from you. You need accurate answers, supporting documentation, and help understanding what the questions really mean — including when an attorney, insurance advisor, or other specialist should weigh in.

You want independent confirmation+

Your provider or internal team believes the right safeguards are in place. An outside review confirms whether those safeguards actually hold up, using the same controls, documentation, and evidence leadership is already relying on.

You want to know where the single points of failure are+

A key employee, outside provider, administrative account, aging device or server, or undocumented system may be carrying more of the business than anyone realizes. We identify where access, knowledge, or operations depend on one person, one vendor, or one piece of technology — and where there is no practical backup plan.

What we look at

Depending on which of the above brought you here, this can include:

01Access & identity+
  • Microsoft 365 configuration and governance
  • Access, MFA, and administrative rights
  • Vendor and account ownership
  • Administrative accounts and who controls them
02Systems & continuity+
  • Backup and recovery readiness
  • Endpoint protection and patching
  • Email security
  • Aging devices, servers, and undocumented systems
03Documentation & key-person dependence+
  • Written policies and whether they match actual practice
  • Documentation and key-person dependence
  • Provider arrangements and what they actually cover
  • Evidence that supports the answers you give
04Outside requirements+
  • Questionnaire and evidence requirements from cyber-insurance, banks, and customers
  • Readiness for applicable requirements such as HIPAA, PCI DSS, or CMMC
  • Auditor and lender information requests

We validate the picture through leadership interviews, configuration and access review, policy and documentation review, evidence collection, and, where appropriate, testing of critical controls.

Certified Information Systems Auditor (CISA)Certified Information Security Manager (CISM)Project Management Professional (PMP)

Assessments are led by Jean Prejean, Principal, CISA and CISM certified, with project execution led by Wayne Speziale, Director of Operations, a certified Project Management Professional (PMP).

As part of the review, we also look at whether licensing, subscriptions, vendors, and infrastructure still fit the business. Technology spending often accumulates gradually as companies grow and change; the goal is simply to make sure today's spending supports today's needs.

Why an outside review matters

An outside review validates controls, gathers evidence, and identifies gaps that day-to-day support may not surface. We typically work directly with your current IT provider or internal team throughout the process — this adds a second set of eyes, it doesn't replace anyone.

Internal view, then independent validation, then prioritized findings

The goal is to independently confirm what's working and identify what deserves attention.

What happens after

You receive a plain-language findings report — including a visual risk heat map showing where concerns cluster by impact and likelihood, so it's clear at a glance what matters most — covering what is already solid, what needs attention, what evidence supports your current answers, and what should happen next.

Business impact ↑ · Likelihood →
Critical
2
1
High
Moderate
3
Low
RarePossibleLikelyFrequent
1Administrative access. Standing admin rights with no MFA on the accounts that control everything else.
2Recovery untested. Backups are running, but a restore has never been proven end to end.
3Policy vs. practice. Written policies exist but no longer describe how the business actually operates.

Illustrative example. Your report reflects what we actually find in your environment.

Know exactly what you can put in front of a bank, insurer, customer, or regulator

And where additional work or outside advice is needed.

What this isn't. This is compliance readiness and support — not a legal opinion, formal attestation, or certification of compliance. Where you need an attorney, insurance broker, or certifying body, we'll say so plainly, and we're glad to work alongside them rather than in their place.