Boldly Reimagined
Assessments

Three weeks to a decision
you can defend.

A structured read on where you stand, what your AI use is opening up, and which moves are worth making in what order, with a cost against each one. You finish with a ranked list you can take to your board, your insurer or your largest customer. Not a scan, and not a maturity score with no consequences attached.

The Exposure & Opportunity Review is a three-week assessment, starting at $9,500 and scoped to your size and complexity, that maps what AI has opened up in your business and where it can genuinely pay off. No systems access, no software installed.

THE EXPOSURE & OPPORTUNITY REVIEW Three weeks, quoted up front, no systems access WEEK 1 WEEK 2 WEEK 3 Intake Documents, contracts, policies. We read before we ask. Interviews Four to six short sessions with the people closest to the work. Readout Ranked decisions with costs, walked through with your team.
The shape of every review: intake, interviews, readout. Price agreed in writing before week one.
Two versions

One review, two tracks. Start with the louder question.

Track one: AI

What AI is doing in your company, whether you approved it or not

Where AI is already in use and by whom. What data it touches. What your customer and vendor contracts already commit you to. Which use cases are worth doing, which are not, and what has to be true before you start.

Track two: Security

Whether what you spend covers what you actually face

Exposure in plain terms. Controls coverage measured against real threat patterns rather than a generic checklist. Incident readiness. Third-party and vendor risk. What your insurer and your largest customers will ask next.

Start with whichever question is louder. You still get both sides either way: every AI review reports what it opened up on the security side, and every cyber review reports where AI is already changing the picture. The order is your choice. Getting half the story is not on the menu.

How it runs

Three weeks, quoted up front, no access

Week 1

Intake

Documents, contracts, policies, and a structured questionnaire. We read what you already have before asking you for anything new.

Week 2

Interviews

Short sessions with the people who actually know: IT, finance, operations, whoever is closest to the work. Four to six conversations, and they are the part clients tell us they enjoy.

Week 3

Readout

A written assessment, a ranked set of decisions with likely costs, and a working session to walk your leadership team through it.

No credentials, no agents, no scanners. Nothing we do can interrupt anything you run. That is a deliberate constraint, and it is also why we can start next week rather than after a security review.

See it before you buy it

What page two of your readout looks like

RANKED DECISIONS — SAMPLE READOUT (client details redacted) Page 2 of 14 # DECISION WHY NOW EST. COST 1 Turn on enforced MFA for the finance group and the two admin accounts Closes the entry path used in most ransomware incidents. One afternoon of work. Insurance renewal, 60 days $0 2 Publish the one-page AI use policy and name an owner Staff already use three AI tools; customer data has no stated boundary today. Customer questionnaire cites it $0–$1,200 3 Pilot AI drafting on the ██████ renewal workflow Measured 9–11 staff hours a week in drafting; clean data boundary; fastest payback found. Pays for itself in a quarter $4,000–$7,000 4 Consolidate the two overlapping security tools; keep █████ Both cover the same control; neither is fully deployed. Cancel one, finish the other. Saves ██,███ a year −$██,███ 5 Defer the ███████ platform purchase until Q2 The problem it solves ranks seventh. Decisions one and two remove most of its urgency. Spend nothing this quarter $0 Every decision carries a cost, an order, and a reason. The full readout runs the ranked list, the written AI position, and the evidence pack an insurer or customer asks for.
A redacted excerpt in the exact format every client receives. Rank, decision, reason, cost - including the ones that cost nothing and the one that tells you not to spend.

Notice decisions one and five. The first costs nothing and closes the most-used attack path. The last one tells you not to buy something. A readout that never says "spend nothing" is a sales document wearing a report's clothes.

What you get

Assessments start at $9,500. Where yours lands depends on what we are reading: business units, systems, contractual obligations, whether a live customer security program has to be evidenced. Every engagement is a little different, so yours is scoped to your business — and the quote is agreed in writing before any work starts. Once agreed and scoped, we hold that number for the engagement. The readout does not stop being useful when the work ends: clients forward it to insurers, hand it to a large customer’s security reviewer, and put it in the board pack, where it answers the governance question for the rest of the year.

The fast version

Renewal coming? There is a two-week version.

Insurance Renewal Readiness

Your carrier stopped taking your word for it. This engagement finds the gap between what your renewal asks and what you can prove, closes the two or three items that actually move your premium, and hands you the evidence pack: logs, screenshots, and the answers written out.

Starting at $4,500. Two weeks. Best started 60 to 90 days before the renewal date.

Why this one is separate

Because it has a deadline the full review does not. When a renewal packet is already on your desk, you do not need a map of everything — you need to pass, at the best price, without buying anything you do not need. The full review can come after, if it should come at all.

Why renewals got harder →

Shown, not described

What this looks like in practice

The two engagements below are real work, drawn from more than 600 AI and cybersecurity projects the people behind this firm have delivered. Names, figures and identifying details are withheld, because confidentiality does not expire when an engagement ends. Yours will get the same protection.

The Exposure & Opportunity Review

A specialty manufacturer with three plants

The setup. Three plants, one ERP nobody loves, a plant manager who started using an AI scheduling assistant on his own, and a new contract with an aerospace customer whose security addendum nobody has read closely. The CFO wants to know what all of it means before the board asks.

Week one, intake. We read what already exists: the aerospace addendum, the insurance policy, the IT asset list, the org chart, and the vendor terms of the four AI tools that turn out to be in use (they thought it was one). No logins, nothing installed. Two findings surface before a single interview: the addendum requires incident notification within 72 hours — no plan exists — and the AI scheduler's free tier retains uploaded production data.

Week two, interviews. Six conversations: CFO, plant managers, the IT lead of three people, the quality director. The opportunity side turns out bigger than the risk side: quoting is the bottleneck, and quoting is drafting-heavy work with a clean data boundary — the exact shape of AI use that pays.

Week three, the readout. Eleven ranked decisions. Top five: enforce MFA on finance and ERP admin accounts ($0, closes the insurer's top question); move the AI scheduler to a business plan with data protections ($40 a month, ends the retention exposure); write the 72-hour incident plan the aerospace contract already requires; pilot AI-assisted quoting in one plant with hours measured before and after; defer the $180K "AI-powered MES module" the ERP vendor pitched — it solves a problem that ranked ninth.

What this cost: with three plants and a live customer security addendum in play, this landed at the top of the range — quoted in writing before week one. The deferred module alone is ten times that.

Insurance Renewal Readiness

A regional logistics and trucking company

The setup. The cyber renewal packet arrived 70 days before the deadline and it is nothing like last year's: ninety days of sign-in logs requested, proof of enforced MFA, backup restoration evidence, and a new page of questions about AI tools in dispatch and back office. Last year they signed a checklist. The controller has a company to help run.

Week one. We map every question in the packet to one of three buckets: can evidence today, can close before the deadline, cannot honestly claim. The gap list comes back short but real: MFA is on for email but not for the TMS admin accounts, backups run nightly but restoration has never been tested and documented, and dispatch quietly uses an AI assistant nobody listed.

Week two. Their IT provider closes the two control gaps — we do not touch systems, we specify exactly what evidence the carrier needs and review what comes back. We draft the AI-use answers honestly, write the one-page policy the packet asks about, and assemble the evidence pack: log exports, screenshots, the restoration test record, the written answers.

The outcome shape. The renewal goes back complete and evidenced with three weeks to spare. Whatever the premium does, the two failure modes that actually hurt — a contested claim later, or a decline forcing a scramble to a worse carrier — are off the table.

What this cost: in the $4,500 range, two weeks. Best started 60 to 90 days before the renewal date, exactly as here.

Common questions

More about the review

Why are no client names on these engagements?

Confidentiality. The work behind these walkthroughs spans more than 600 AI and cybersecurity projects, and prior obligations do not expire when an engagement ends. Names, figures and identifying details are withheld; the shape of the work is exactly as described. Yours would get the same protection.

What do the assessments cover?

Two versions. The AI Readiness Assessment covers where AI is already being used, what data it touches, governance, and which use cases are worth pursuing. The Cybersecurity Readiness Assessment covers exposure, controls coverage against what you actually face, incident readiness, and third-party risk.

How long does an assessment take?

Three weeks from kickoff to the readout, at a price scoped to your business and agreed in writing in advance.

Do you need access to our systems?

No. Assessments run on documents, structured questionnaires, and interviews with your team. We take no credentials and install nothing.

What do we get at the end?

A written assessment, a ranked set of decisions with what each one is likely to cost, and a working session with your leadership team to walk through it.

Short answers to the questions that come up before an assessment: what an AI readiness assessment covers, how AI and security risk get read together, what independent means when nobody is selling you software, and what to fix first once you have the ranked list.

Questions

Is this a penetration test or an audit?

Neither. A pen test finds technical holes and an audit checks you against a standard. This asks a different question: given what you face and what you can afford, what should you do next. If you need a pen test we will tell you and help you scope it.

We are small. Is this overkill?

It is the opposite, and we say that from experience. Smaller companies carry the same customer and contractual obligations with far less specialist attention. The assessment is scaled to the company; the questions do not change.

Will you then sell us the fix?

No. Advice is the only thing we sell. If work is needed we help you scope it and judge whoever does it, and we earn nothing from the choice.