Every yes, with the evidence behind it.
A questionnaire is on your desk — an insurance renewal, a customer’s security review, a procurement schedule. The answers have to be true, and you have to be able to show why.
Illustrative example — not a client deliverable
17. Is multi-factor authentication enforced for all remote access?
Yes — verified, not assumed
Evidence: the conditional-access policy that enforces it, exported from your tenant, showing the account count it actually covers — including the service accounts that are usually exempted and usually forgotten.
How the two-week engagement works
Where I sit
Three kinds of supplier get asked to help with this, and each stops somewhere.
- A law firm
- Tells you what the rule says. Will not touch your systems.
- A managed provider
- Runs your tooling. Does not read your regulator.
- A compliance platform
- Collects evidence. Never scoped your environment, or argued a control with an assessor.
- SecHB
- Reads the document you were sent, checks what is actually running, fixes the cheap gaps, and hands you the record that backs every answer.
A control you cannot evidence is a control you do not have.
Every deliverable here ends in artifacts from your systems — exports, configurations, access reviews, dated. Not a policy asserting the safeguard exists.
Start here
The Evidence Pack
Two weeks. You bring the questionnaire or application you have been asked to complete. I go through it line by line against what is actually running, tell you which answers are already true, fix the cheap gaps inside the engagement, and give you a written record of what backs every answer — plus a plain list of what is still outstanding and what it would take to close.
When the question is what is actually true of your systems rather than what your paperwork says, the other half of the practice is testing: web application and API penetration testing, and external attack surface assessment. Alongside it, readiness work for PCI DSS, HIPAA, SOC 2, ISO/IEC 27001, privacy programmes, and the AI section that has appeared on questionnaires in the last two years. All services.
Who this is for
- BC businesses of roughly 10–150 staff with an external deadline: an insurance renewal, a customer security review, or a procurement requirement.
- Teams where the person answering the questionnaire is the founder, the CFO, or whoever was nearest — and nobody is sure the answers would survive scrutiny.
- Organizations that have bought tooling and want to know whether it is actually configured to do the thing they are about to attest to.
Background
CISSP since 2010, earned in Vancouver. Around twenty years of security programme work: risk assessment, threat modelling, security policy and standards, audit readiness, business continuity and disaster recovery. I also still write and ship the code, which is why the deliverable points at artifacts rather than assertions.
I managed a HIPAA/HITRUST readiness programme for a NYSE-listed communications company. Its final audit was performed by PricewaterhouseCoopers. To be exact about that: PwC audited that client’s programme. PwC did not assess me, did not audit me, and has not endorsed me or this practice.