Pine IT · Fixed-scope assessment
Pine IT Risk & AI Controls Review.
A fixed-scope review of the seven controls your regulator, your insurer, and your clients’ auditors actually ask about. Built for 15-50 person professional-services firms in Metro Vancouver: law, accounting, engineering, and financial services.
- Flat CAD $2,500
- 100% credited if you proceed
- One-page scorecard
- Founder-led walkthrough
The fixed scope
Seven areas. The same seven, every time.
The scope does not flex to fit a sales agenda. These are the controls that decide cyber-insurance renewals, client security questionnaires, and regulator conversations.
-
Microsoft 365 security and permissions
Tenant configuration, sharing settings, and who can actually reach client files today.
-
MFA and identity
Multi-factor coverage, admin accounts, and the access lifecycle for joiners and leavers.
-
Endpoint protection
Laptop and desktop protection, monitoring coverage, and patch posture.
-
Backup and recovery
What is backed up, where it lives, and whether a restore has ever been tested.
-
Incident-response readiness
Who does what in the first hour, and whether the plan exists anywhere outside one person’s head.
-
Cyber-insurance and client-audit gaps
The controls your renewal application and your clients’ security questionnaires assume you already have.
-
AI-use, Copilot, and data-leakage controls
Where staff are putting client data into AI tools today, and the permissions Copilot inherits from your tenant.
What you walk away with
One page. A prioritized fix list. A founder across the table.
The deliverable is a one-page scorecard across the seven areas, with a prioritized fix list, walked through with a founder in plain language. No hundred-page PDF, no scare tactics: what is solid, what is exposed, and what to fix first.
The review is built to improve cyber-insurance readiness and renewal outcomes, and to give you defensible answers when a client or regulator asks how client data is protected.
How it works
Three steps, no pre-sales maze.
-
Book a time
The review is founder-led from the first conversation. You talk to the people who run the work, not a sales team.
-
We assess the seven areas
Configuration, evidence, and the paper trail behind each control, mapped to what your regulator and insurer expect.
-
You get the scorecard, walked through
A one-page scorecard with a prioritized fix list, explained in plain language by a founder. You keep it either way.
Who it is for
15-50 person firms whose clients expect answers.
Metro Vancouver professional-services firms where a partner, principal, or operations lead is accountable for client data, and needs to know what regulators and insurers expect.
Law firms
Law Society of BC expectations and client confidentiality
Accounting firms
CPABC practice-inspection and client-data obligations
Engineering firms
Project data, client IP, and prime-consultant requirements
Financial services
CIRO and OSFI E-23 expectations for technology and third-party risk
After the review
The review is the door. Managed IT is the product.
Most firms do not need another audit; they need the findings fixed and kept fixed. After the walkthrough, Pine IT can take the fix list into remediation and then into compliance-native managed IT, run on the same operating model as everything else we do: compliance is the exhaust, not the engine. Your $2,500 is credited in full against that work.
See the compliance model- Observe
Every endpoint, identity, network, and cloud system is monitored.
- Operate
Senior engineers resolve, patch, recover, and improve the environment.
- Evidence
The work produces the records insurers and regulators ask to see.
- Plan
Your roadmap stays tied to business risk, client needs, and real system state.
Start with the review
Know what your regulator and insurer expect.
Booking is two fields and a calendar pick. Prefer email? Write to info@pineit.ca or use the contact form and we reply within one business day.