Is multi-factor authentication enforced on email and remote access?
Enforced across the tenant and reported, not merely available to the people who turned it on.
Professional services
No regulator, but the same questions arrive anyway: from your cyber insurer at renewal, and from a larger client before they share anything worth protecting. We run the IT that lets you answer yes.
What they ask
A cyber insurance application asks closed questions about specific controls, and an answer on it is a legal statement. A client security questionnaire asks the same things. These are the four that recur, and what we do about each.
Enforced across the tenant and reported, not merely available to the people who turned it on.
Antivirus is not EDR, and EDR nobody watches is not monitored. On Protect and Protect+, every managed device has both.
Held offsite where ransomware on a device cannot reach them, and every job checked daily.
On a schedule you can name, applied and reported, so the answer is an interval and a record.
What you hold
What makes a professional services firm worth attacking is rarely its own data. It is the credentials to a client platform, the shared drive holding three years of a client's documents, and the mailbox where all of it was discussed. Your clients are now measuring that exposure from the other end, and the only lever they have is the questions they ask before they sign.
Which plan
Protect covers what insurers ask about for a firm with company devices: monitored endpoint detection, patching, device management, and offsite backup as an add-on. Protect+ adds awareness training, a documented incident response plan, and the controls a written program describes, which is worth it where questionnaires are frequent or a significant contract depends on the answers. Every plan rate and the add-ons most businesses need are on the pricing page.
Frequently asked
Not as regulation, but the questions arrive anyway from two directions. Cyber insurance applications ask closed questions about specific controls, and larger clients run vendor due diligence before sharing anything sensitive. One decides whether you are insurable and at what price; the other decides whether you win the work.
Yes, and it is a normal part of the engagement. We supply the technical answers and the evidence behind them for the parts we run. The commercial and organizational answers stay with the firm, because they are about how you operate rather than how your systems are configured.
That changes nothing about what you would receive. The three listed have pages because a named obligation makes the conversation specific. The plans, the monitoring and the published pricing are the same for a construction firm, a manufacturer or a non-profit.
A thirty-minute call where we go through what you run and what is not working. We reply within one business day, and there is no obligation.
Schedule an IT assessment