Every yes, with the evidence behind it.

A questionnaire is on your desk — an insurance renewal, a customer’s security review, a procurement schedule. The answers have to be true, and you have to be able to show why.

Illustrative example — not a client deliverable

17. Is multi-factor authentication enforced for all remote access?

Yes — verified, not assumed

Evidence: the conditional-access policy that enforces it, exported from your tenant, showing the account count it actually covers — including the service accounts that are usually exempted and usually forgotten.

How the two-week engagement works

From a questionnaire line to the artifact that proves it Three stages left to right. First, the question as it appears on a questionnaire: is multi-factor authentication enforced for remote access. Second, the control that answers it: the conditional access policy as actually deployed. Third, highlighted, the evidence: the configuration export showing which accounts it really covers. A note reads that most suppliers stop at the second stage, and the answer is only true if the third exists. THE QUESTION Is MFA enforced for remote access? THE CONTROL Conditional access policy, as deployed THE EVIDENCE The export, showing what it covers Most suppliers stop at the middle box. The answer is only true if the third one exists.
Illustration of the method. Not a client artifact.

Where I sit

Three kinds of supplier get asked to help with this, and each stops somewhere.

A law firm
Tells you what the rule says. Will not touch your systems.
A managed provider
Runs your tooling. Does not read your regulator.
A compliance platform
Collects evidence. Never scoped your environment, or argued a control with an assessor.
SecHB
Reads the document you were sent, checks what is actually running, fixes the cheap gaps, and hands you the record that backs every answer.

A control you cannot evidence is a control you do not have.

Every deliverable here ends in artifacts from your systems — exports, configurations, access reviews, dated. Not a policy asserting the safeguard exists.

Start here

The Evidence Pack

Two weeks. You bring the questionnaire or application you have been asked to complete. I go through it line by line against what is actually running, tell you which answers are already true, fix the cheap gaps inside the engagement, and give you a written record of what backs every answer — plus a plain list of what is still outstanding and what it would take to close.

What the engagement covers

When the question is what is actually true of your systems rather than what your paperwork says, the other half of the practice is testing: web application and API penetration testing, and external attack surface assessment. Alongside it, readiness work for PCI DSS, HIPAA, SOC 2, ISO/IEC 27001, privacy programmes, and the AI section that has appeared on questionnaires in the last two years. All services.

Who this is for

  • BC businesses of roughly 10–150 staff with an external deadline: an insurance renewal, a customer security review, or a procurement requirement.
  • Teams where the person answering the questionnaire is the founder, the CFO, or whoever was nearest — and nobody is sure the answers would survive scrutiny.
  • Organizations that have bought tooling and want to know whether it is actually configured to do the thing they are about to attest to.

Background

CISSP since 2010, earned in Vancouver. Around twenty years of security programme work: risk assessment, threat modelling, security policy and standards, audit readiness, business continuity and disaster recovery. I also still write and ship the code, which is why the deliverable points at artifacts rather than assertions.

I managed a HIPAA/HITRUST readiness programme for a NYSE-listed communications company. Its final audit was performed by PricewaterhouseCoopers. To be exact about that: PwC audited that client’s programme. PwC did not assess me, did not audit me, and has not endorsed me or this practice.