A security function that is doing its job.
Most of this is covered, which is genuinely uncommon at this size. The few gaps below are worth a conversation rather than a project, and the more useful question at this point is whether what you have would hold up under an incident rather than on paper.
Where the gaps are
These are the ones you answered no to, in the order they were asked. They are not equally urgent, and the order to take them in depends on your business rather than on this list.
- The Human Firewall. Does every employee receive security awareness training at least twice a year, including simulated phishing tests?
- Identity Gatekeeping. Is Multi-Factor Authentication (MFA) mandated for every external-facing login (email, VPN, cloud portals)?
- Access Lifecycle. Can you confidently say an employee's access to all systems is revoked within 24 hours of their departure?
- The Crown Jewels. Do you have a formal data classification policy that defines who can access your most sensitive client or financial data?
- Shadow IT. Do you have a vetted list of all SaaS applications your teams use, or are departments buying their own apps without IT oversight?
- Device Control. If an executive lost their laptop at an airport today, is the hard drive encrypted, and can the data be wiped remotely?
- Perimeter Integrity. Has your organization performed a professional penetration test or external vulnerability scan in the last 12 months?
- Patch Management. Does your team have a documented process to update critical software vulnerabilities within 48 hours of a critical exploit being announced?
- The Boom Scenario. Do you have a written incident response plan that has been tabletop tested by leadership within the last year?
- The Ransomware Safety Net. Both parts must be true to answer yes: (a) are your backups stored off-site and offline (immutable), and (b) have you successfully tested a full system restoration in the last 6 months?
- Supply Chain Risk. Do you require your key vendors (payroll, cloud hosting) to provide an annual SOC 2 Type II report or equivalent security audit?
- Procurement and Development. Is security a formal requirement during the buy vs build phase of new software projects, or is it addressed only after the software is live?
What happens now
Nothing automatic. No sequence, no newsletter. We will look at your answers and come back to you with what we would do first and roughly what it costs, at no charge and with no obligation. If you would rather talk it through sooner, book 15 minutes.