IT + AI SECURITY ASSESSMENT   /   DIAGNOSTIC 03
Available now · 2 weeks

The five insurer
questions.
Plus where
your data goes.

Is MFA on everywhere. Is there a password manager. Are devices protected. Does your email prove it's you. Has the team been trained. Then the sixth question nobody's insurer asks yet: which AI tools can see your data, and under what terms. Two weeks, evidence-backed, and a report you can hand to the insurer and the board.

CAD 3,500, fixed.
Credited against Protected Workplace or the retainer if you go ahead within 60 days.

Two weeks. Read-only. Nothing is changed
until you say so.

WHAT WE LOOK AT
WHAT WE LOOK AT

Six lenses.
One report.

Each lens is scored with the evidence beside it. Nothing in the report is an opinion without a screenshot, an export or an interview behind it.

Identity & access

MFA coverage by account, shared passwords, who still has access that shouldn't, admin sprawl.

Devices

Every laptop and phone that touches organization data: known or unknown, encrypted or not, wipeable or not.

Email trust

SPF, DKIM and DMARC as they actually are, who can send as you, and what a spoof would look like.

AI data flows

Which AI tools your people use, personal and approved, what gets pasted where, and what the vendor terms say about training and residency.

Backups & recovery

Whether a separate copy exists, how long it's kept, and whether anyone has ever restored from it.

People

Phishing exposure tested with your real scenarios, and who reports versus who clicks.

WHAT YOU GET

Three things
you can act on.

Delivered in a 60-minute walkthrough with the owner, then yours to keep.

One-page posture report

The five basics plus AI data flows, each rated with the evidence beside it. Written to answer the insurer's questionnaire line by line.

The AI exposure map

Every AI tool in use, approved or not, what data it can see, and what the terms allow. Usually the page that changes the meeting.

A ranked fix list

What to switch on this week with licences you already own, what needs a decision, and what can wait. Most of it maps to Protected Workplace and Backups.

HOW IT WORKS

Two weeks.
Then a decision.

You can stop after the report and keep everything. Most organizations don't, because the fix list is already written.

Week 1

Evidence

Read-only access to your tenant, a device inventory, a phishing simulation with your scenarios, and the AI-tool survey. Nothing is changed.

Week 2

Report

Posture report, AI exposure map and the ranked fix list. A 60-minute walkthrough with the owner, and the insurer version if you want it.

After

Fix

Protected Workplace and Backups for the basics; AI, Switched On Properly for the AI side. Or your own IT team, with the list.

INVESTMENT

CAD 3,500, fixed.

Credited against Protected Workplace or the retainer if you go ahead within 60 days.

Book the assessment
FAIR QUESTIONS

Before you
say yes.

The things owners ask us on the first call.

We already have cyber insurance. Why would we need this?

Because you signed a questionnaire. If a claim is investigated and a 'yes' wasn't true, it can be denied. This produces the evidence behind each yes, dated.

What's different about the AI part?

Most security reviews stop at devices and passwords. This one maps which AI tools your people actually use, what data they paste in, and what the vendor terms permit. In most organizations it's the biggest exposure nobody has written down.

Will it disrupt the team?

No. Access is read-only, the device inventory is passive, and the phishing test is a few emails. Two weeks, mostly invisible.

Do we have to use GoodOps to fix what you find?

No. The fix list is written so any competent IT provider can run it. If you do go ahead with us within 60 days, the fee is credited.

KNOW WHAT YOU SIGNED.

Answer
the insurer
honestly.

Book the assessment. Two weeks, read-only, a report you can hand to the insurer and the board.

Book a 30-minute call

A conversation about your organization.
Not a demo of software.

GOODOPS MODULES
The 30-minute mini-diagnostic

Let's find out
in 30 minutes.

Tell us a little about your organization. No documents, system access or long explanation needed.

Preview mode: this form does not send or store your information. Try it with fictional details to see the flow.