Working method
A simple way to review risk: clear scope, sufficient evidence, explicit limits and next steps.
Review first. Implementation separately.
Each engagement starts with a concrete question and ends with findings, limits and prioritized actions.
Initial review
We understand the situation, deadline, responsible teams and constraints before proposing scope.
Scope
We define assets, systems, users, dates, exclusions, permissions and minimum evidence.
Evidence intake
We collect documents, limited access, contacts, context and constraints.
Review and interviews
We review controls, data flows, vendors, architecture and operational reality.
Synthesis
We prioritize by impact, exposure, available evidence and urgency.
Closeout and plan
We close with findings, limits, recommendations and 30/60/90 actions.
Evidence language
- Verified: confirmed with direct evidence.
- Unknown: not enough evidence exists.
- Not verified: out of scope or without sufficient access.
- Assumption: hypothesis used for analysis.
- Relevant risk: finding that may change priorities or conditions.
Confidence levels
- High: direct, consistent and sufficient evidence.
- Medium: partial or indirect evidence.
- Low: early signals requiring validation.
| Severity | Criteria | Suggested action |
|---|---|---|
| Critical | Material loss, sensitive exposure, major interruption or transaction blocker. | Mitigate, pause or add conditions before proceeding. |
| High | Relevant risk with real exposure or high probability. | Mitigate within 30 days or sooner if there is an external deadline. |
| Medium | Controllable risk that should enter the work plan. | 60-90 day plan with an assigned lead. |
| Low | Hygiene, documentation or control improvement with limited impact. | Normal backlog. |
Findings
Relevant findings include evidence or an explicit limitation.
Limits
Every closeout states what was reviewed, what was not and what remains open.
Follow-up
Any ongoing work is separated from the original scope and defined in writing.