s90
A woman alone at a long conference table reading a bound report.

Technology and Compliance Posture Reports

Proof isn't something you request from us. It's just something you receive.

A printed control table with checkmarks lying on a pale wood desk beside a black pen.

Does this sound familiar?

Why does asking for proof feel so awkward?

Asking your provider to show their work can sound like an accusation, so most people never ask. The question goes unanswered, and you keep trusting your IT on faith. You shouldn't have to ask. The proof should arrive on its own.

Two reports

Two reports, two different jobs.

Technology Posture Report

Who gets it
Every client
How many
One
What it answers
Is our IT in good shape, and getting better?
What's in it
A Posture Score out of 100, five categories, what we finished and what's next, mapped to NIST CSF 2.0 and CIS Controls
Who it's for
You and your leadership
How you get it
Sent every quarter, then reviewed with your Technology Adviser

Compliance Posture Report

Who gets it
Clients who answer to a regulated framework
How many
One for each framework, never combined
What it answers
Can we show the evidence this rule asks for?
What's in it
Each requirement, the control behind it, its status and the evidence
Who it's for
The person in charge of compliance, and the examiner, auditor or insurer they hand it to
How you get it
Sent every quarter, then reviewed with your Technology Adviser

Every client, every quarter

What's in a Technology Posture Report?

Every client gets one. Every check in it is mapped to NIST CSF 2.0 and CIS Controls, so the same report answers client, insurer and funder questionnaires.

Sample report · Technology Posture Report

78/ 100
points since last quarter
5
points since Baseline
31
Protected86
Recoverable82
Reliable71
Well spent69
AI-ready66

Posture Score

A score out of 100 for where your IT stands, measured against your Baseline Posture Score (the score taken before we take over), so you can see it move from quarter to quarter.

Protected

Are your protections actually working?

Recoverable

Would you get back to work if something went wrong?

Reliable

Do your systems stay up and run the way they should?

Well spent

Are you paying for things you don't need while missing things you do?

AI-ready

What AI tools are people using, and what are they putting into them?

One for each regulated framework

What's in a Compliance Posture Report?

If you answer to a regulated framework, such as SEC Regulation S-P, HIPAA or CMMC, you get a Compliance Posture Report for it every quarter. Each framework gets its own report. Two frameworks are never combined.

Sample · Compliance Posture Report

ACME Corp · Quarter 3 · Reg S-P

Incident response program
Tested
Service provider reviews
Current
Access reviews
Current

Sample report for a fictional business. Example figures.

Every requirement

What the rule asks for, the control that meets it, and the evidence.

A status for each control

Tested, current or enforced, with the date it was last checked.

Open gaps

What isn't in place yet, and which to close first.

You decide

We provide the evidence. The person in charge of compliance on your team decides whether you're compliant.

See every framework

When it arrives

When do Posture Reports arrive?

Your Baseline Posture Score comes before handoff, so you know exactly where you started. After that, your Posture Reports arrive every quarter, without you asking, and your Technology Adviser reviews them with you: what we finished, what's planned next, how your score moved and what we recommend. Proof in hand is never more than three months old.

A fair question for any provider

Two questions to ask about any IT report.

Even if you've had an IT report before, ask two questions about it. Did it arrive without you asking? And would it answer the next person who asks you for proof?

See one first

Want to see what you'd receive?

Get a sample of each report by email: a Technology Posture Report and a Compliance Posture Report.

Get the sample Posture Report by email

By submitting, you agree to the Terms of Use and acknowledge the Privacy Policy.

s90

One question to ask yourself

Does your IT provider show you proof without you having to ask?

Up to$500,000Cyber WarrantyBacked by Cork Inc.

In 30 minutes, we talk through your setup and you leave knowing which plan fits.

Book a call