Skip to main content

Pine IT · Fixed-scope assessment

Pine IT Risk & AI Controls Review.

A fixed-scope review of the seven controls your regulator, your insurer, and your clients’ auditors actually ask about. Built for 15-50 person professional-services firms in Metro Vancouver: law, accounting, engineering, and financial services.

  • Flat CAD $2,500
  • 100% credited if you proceed
  • One-page scorecard
  • Founder-led walkthrough
$2,500Flat fee, CAD, no hourly surprises
7Fixed assessment areas
1 pageScorecard with a prioritized fix list
100%Credited toward remediation or managed services

The fixed scope

Seven areas. The same seven, every time.

The scope does not flex to fit a sales agenda. These are the controls that decide cyber-insurance renewals, client security questionnaires, and regulator conversations.

  1. Microsoft 365 security and permissions

    Tenant configuration, sharing settings, and who can actually reach client files today.

  2. MFA and identity

    Multi-factor coverage, admin accounts, and the access lifecycle for joiners and leavers.

  3. Endpoint protection

    Laptop and desktop protection, monitoring coverage, and patch posture.

  4. Backup and recovery

    What is backed up, where it lives, and whether a restore has ever been tested.

  5. Incident-response readiness

    Who does what in the first hour, and whether the plan exists anywhere outside one person’s head.

  6. Cyber-insurance and client-audit gaps

    The controls your renewal application and your clients’ security questionnaires assume you already have.

  7. AI-use, Copilot, and data-leakage controls

    Where staff are putting client data into AI tools today, and the permissions Copilot inherits from your tenant.

What you walk away with

One page. A prioritized fix list. A founder across the table.

The deliverable is a one-page scorecard across the seven areas, with a prioritized fix list, walked through with a founder in plain language. No hundred-page PDF, no scare tactics: what is solid, what is exposed, and what to fix first.

The review is built to improve cyber-insurance readiness and renewal outcomes, and to give you defensible answers when a client or regulator asks how client data is protected.

How it works

Three steps, no pre-sales maze.

  1. Book a time

    The review is founder-led from the first conversation. You talk to the people who run the work, not a sales team.

  2. We assess the seven areas

    Configuration, evidence, and the paper trail behind each control, mapped to what your regulator and insurer expect.

  3. You get the scorecard, walked through

    A one-page scorecard with a prioritized fix list, explained in plain language by a founder. You keep it either way.

Who it is for

15-50 person firms whose clients expect answers.

Metro Vancouver professional-services firms where a partner, principal, or operations lead is accountable for client data, and needs to know what regulators and insurers expect.

Law firms

Law Society of BC expectations and client confidentiality

Accounting firms

CPABC practice-inspection and client-data obligations

Engineering firms

Project data, client IP, and prime-consultant requirements

Financial services

CIRO and OSFI E-23 expectations for technology and third-party risk

After the review

The review is the door. Managed IT is the product.

Most firms do not need another audit; they need the findings fixed and kept fixed. After the walkthrough, Pine IT can take the fix list into remediation and then into compliance-native managed IT, run on the same operating model as everything else we do: compliance is the exhaust, not the engine. Your $2,500 is credited in full against that work.

See the compliance model
  1. Observe

    Every endpoint, identity, network, and cloud system is monitored.

  2. Operate

    Senior engineers resolve, patch, recover, and improve the environment.

  3. Evidence

    The work produces the records insurers and regulators ask to see.

  4. Plan

    Your roadmap stays tied to business risk, client needs, and real system state.

Pine IT

Start with the review

Know what your regulator and insurer expect.

Booking is two fields and a calendar pick. Prefer email? Write to info@pineit.ca or use the contact form and we reply within one business day.

Book a Risk & AI Controls Review