Illustration only. The organization, findings, and data below are fictional and created for demonstration purposes. All ALC engagement deliverables are tailored to the client's specific environment, industry, and risk profile. No client information appears on this page.

SMB Security Sprint — Deliverable Package

Organization
Heartland Advisory Group (Illustration)
Industry
Accounting / Professional Services
Employee Count
52 employees
Compliance Drivers
FTC Safeguards Rule, Cyber Insurance
Engagement
Remote — 60 days
Framework
NIST Cybersecurity Framework

This deliverable package includes the organization's current-state assessment, prioritized gap findings, a 90-day action plan, and an executive leadership briefing summary. All documents are provided in PDF and editable formats.

NIST CSF Current-State Snapshot

The table below reflects current posture across the five NIST CSF functions based on the structured intake process and documentation review. Ratings reflect leadership engagement, policy existence, and operational evidence — not just tool presence.

CSF Function Current Rating Key Finding Primary Gap
Identify
Asset inventory, risk assessment, governance
Partial No formal asset inventory. Leadership cannot enumerate all systems with access to client financial data. Risk assessment has not been conducted. Missing asset register; no documented risk tolerance statement
Protect
Access controls, training, data security
Partial MFA deployed on Microsoft 365 but not on accounting platform or remote access. No formal security awareness training in 18+ months. Written access policy does not reflect current roles. Inconsistent MFA; stale access policy; no training program
Detect
Monitoring, anomaly detection, logging
Not Addressed No centralized logging. No alerts configured for failed logins, unusual access patterns, or after-hours activity. IT provider does not provide security monitoring as part of current contract. No monitoring capability; alert gap across all systems
Respond
Incident response, communications
Not Addressed No written incident response plan. No defined escalation path. Leadership has not discussed what constitutes a reportable incident under FTC Safeguards. No IRP; no defined escalation; FTC notification gap
Recover
Recovery planning, backups, communications
Basic Automated cloud backups in place via Microsoft 365. No test of restore capability in the past 12 months. No written recovery plan covering non-Microsoft systems. Untested backups; no recovery plan for on-premise systems

Top Priority Gaps

The following findings represent the highest-risk gaps identified during the assessment — ranked by likelihood, potential business impact, and feasibility of remediation. These are not an exhaustive list of all findings; they are what leadership should address first.

  • 01
    No Incident Response Plan — FTC Safeguards Exposure

    The organization is subject to the FTC Safeguards Rule, which requires a written incident response plan and defined notification procedures. No such plan exists. A covered data event would require notification to the FTC within 30 days; without a plan, response would be reactive and likely non-compliant.

    Compliance: FTC Safeguards Risk: High Effort: Medium Timeline: 30 days
  • 02
    MFA Not Deployed on Accounting Platform or Remote Access

    Multi-factor authentication is active on Microsoft 365 but not on the primary accounting software or the VPN. Remote workers access client financial data over the VPN without a second authentication factor. This is the most common initial access vector for ransomware and credential theft in professional services firms.

    Risk: Critical Effort: Low Timeline: 14 days
  • 03
    No Security Monitoring — Blind to Active Threats

    The organization has no visibility into login activity, access patterns, or anomalous behavior across any system. If credentials were compromised today, there is no mechanism to detect the intrusion until a system fails or data is visibly missing. Centralized logging is a prerequisite for any meaningful detection capability and is required for cyber insurance coverage in most policies renewed after 2024.

    Risk: High Effort: Medium Timeline: 60 days

90-Day Action Plan

The roadmap below sequences remediation actions by risk priority and implementation feasibility. Quick wins are front-loaded. Longer-lead items begin in parallel. All actions are scoped for internal execution or coordination with the existing IT provider.

Days 1–30

Immediate Risk Reduction

  • Enable MFA on accounting platform (all users)
  • Enable MFA on VPN / remote access
  • Conduct access review — remove former employees, adjust elevated access
  • Assign incident response owner (leadership)
  • Begin IRP drafting process
Days 31–60

Foundation Building

  • Complete written Incident Response Plan
  • Define FTC Safeguards notification procedures
  • Complete asset inventory (all systems with client data access)
  • Conduct security awareness training (all staff)
  • Test Microsoft 365 backup restore
Days 61–90

Program Maturity

  • Implement centralized logging (SIEM or managed logging)
  • Configure baseline alerts (failed logins, after-hours access)
  • Update written access policy to reflect current roles
  • Conduct tabletop exercise with leadership (incident scenario)
  • Schedule annual IRP review and training cadence

What's Included in the Full Deliverable Package

Every SMB Security Sprint produces the following. Documents are tailored to the client's environment, not templated fill-in-the-blank outputs.

NIST CSF Current-State Assessment (full version)
Prioritized Gap Analysis with Risk Ratings
90-Day Action Plan with Owner and Timeline Fields
Compliance Exposure Summary (applicable regulations)
Vendor and Third-Party Risk Summary
Executive Leadership Briefing (written)
Leadership Debrief Session (live, 90 minutes)
30-Day Follow-Up Check-In

Ready to see what your roadmap would look like?

The SMB Security Sprint delivers this for your actual organization — tailored to your systems, your compliance obligations, and your risk profile. Fixed fee. 60 days. You own everything.

Learn About the Sprint → Talk to Adam First
About This Page

What this page is about: A sample/illustration of what the SMB Security Sprint produces — using a fictional 52-employee Midwest accounting firm. Shows the CSF current-state snapshot, top 3 priority gaps with risk ratings, a 90-day action plan, and the full deliverable list. Clearly labeled as an anonymized illustration.

Purpose: Allows skeptical buyers to see the depth, format, and quality of the deliverable before committing to an engagement. Supports the "know exactly what you're getting" positioning.

Provider: Advantage Leadership Consulting provides fractional CISO, cybersecurity roadmap, and security leadership advisory services for small and mid-sized businesses in the Midwest.