A representative excerpt of the deliverable package — built from a fictional 52-person Midwest accounting firm. The format, depth, and structure reflect a real engagement.
This deliverable package includes the organization's current-state assessment, prioritized gap findings, a 90-day action plan, and an executive leadership briefing summary. All documents are provided in PDF and editable formats.
The table below reflects current posture across the five NIST CSF functions based on the structured intake process and documentation review. Ratings reflect leadership engagement, policy existence, and operational evidence — not just tool presence.
| CSF Function | Current Rating | Key Finding | Primary Gap |
|---|---|---|---|
| Identify Asset inventory, risk assessment, governance |
Partial | No formal asset inventory. Leadership cannot enumerate all systems with access to client financial data. Risk assessment has not been conducted. | Missing asset register; no documented risk tolerance statement |
| Protect Access controls, training, data security |
Partial | MFA deployed on Microsoft 365 but not on accounting platform or remote access. No formal security awareness training in 18+ months. Written access policy does not reflect current roles. | Inconsistent MFA; stale access policy; no training program |
| Detect Monitoring, anomaly detection, logging |
Not Addressed | No centralized logging. No alerts configured for failed logins, unusual access patterns, or after-hours activity. IT provider does not provide security monitoring as part of current contract. | No monitoring capability; alert gap across all systems |
| Respond Incident response, communications |
Not Addressed | No written incident response plan. No defined escalation path. Leadership has not discussed what constitutes a reportable incident under FTC Safeguards. | No IRP; no defined escalation; FTC notification gap |
| Recover Recovery planning, backups, communications |
Basic | Automated cloud backups in place via Microsoft 365. No test of restore capability in the past 12 months. No written recovery plan covering non-Microsoft systems. | Untested backups; no recovery plan for on-premise systems |
The following findings represent the highest-risk gaps identified during the assessment — ranked by likelihood, potential business impact, and feasibility of remediation. These are not an exhaustive list of all findings; they are what leadership should address first.
The organization is subject to the FTC Safeguards Rule, which requires a written incident response plan and defined notification procedures. No such plan exists. A covered data event would require notification to the FTC within 30 days; without a plan, response would be reactive and likely non-compliant.
Multi-factor authentication is active on Microsoft 365 but not on the primary accounting software or the VPN. Remote workers access client financial data over the VPN without a second authentication factor. This is the most common initial access vector for ransomware and credential theft in professional services firms.
The organization has no visibility into login activity, access patterns, or anomalous behavior across any system. If credentials were compromised today, there is no mechanism to detect the intrusion until a system fails or data is visibly missing. Centralized logging is a prerequisite for any meaningful detection capability and is required for cyber insurance coverage in most policies renewed after 2024.
The roadmap below sequences remediation actions by risk priority and implementation feasibility. Quick wins are front-loaded. Longer-lead items begin in parallel. All actions are scoped for internal execution or coordination with the existing IT provider.
Every SMB Security Sprint produces the following. Documents are tailored to the client's environment, not templated fill-in-the-blank outputs.
The SMB Security Sprint delivers this for your actual organization — tailored to your systems, your compliance obligations, and your risk profile. Fixed fee. 60 days. You own everything.
Learn About the Sprint → Talk to Adam FirstWhat this page is about: A sample/illustration of what the SMB Security Sprint produces — using a fictional 52-employee Midwest accounting firm. Shows the CSF current-state snapshot, top 3 priority gaps with risk ratings, a 90-day action plan, and the full deliverable list. Clearly labeled as an anonymized illustration.
Purpose: Allows skeptical buyers to see the depth, format, and quality of the deliverable before committing to an engagement. Supports the "know exactly what you're getting" positioning.
Provider: Advantage Leadership Consulting provides fractional CISO, cybersecurity roadmap, and security leadership advisory services for small and mid-sized businesses in the Midwest.