Practice 02 / Security
Find the gaps before someone else does.
A security assessment that returns a ranked list with evidence attached, not a vulnerability scan with four hundred rows and no priority. We look at the controls you have already paid for, the habits that form around them, and what would actually happen on the day something goes wrong.
What the assessment covers
Six questions, answered with evidence.
Every finding arrives with the artefact that produced it, whether a configuration export, a screenshot or a log excerpt, so nothing in the report has to be taken on faith.
Controls you already own
What your existing licences actually enable, how much of it is switched on, and how often a security feature you are paying for turns out to be sitting in its default state.
Identity and access
Privileged accounts, shared logins, second factors, conditional access, and the leavers whose access outlived their employment by a year or more.
Sensitive data exposure
Where personal data, payment details, health records and credentials are sitting outside the systems meant to hold them, in file shares, mailboxes, personal drives and the finance folder everyone has access to.
Email and payment fraud
The invoice, the vendor bank-change request, the message from the CEO at 4:50 on a Friday. Authentication records, mailbox rules, and whether your payment process would catch it.
Third-party exposure
Which vendors hold your data, what their contracts promise, which ones have standing access to your environment, and what happens to any of it when the relationship ends.
Incident readiness
Who decides, who calls the insurer, who talks to clients, where the plan is kept, and whether it has ever been read aloud by the people whose names are in it.
Evidence, not assertion
We test with the tools we ship.
The sensitive-data portion of an assessment is run with FileSentinel, the scanner we build and sell. Nothing leaves your machines to do it, you can watch it run, and you can keep using it after we leave.
FileSentinel
What is in the files nobody has opened since 2021?
Twenty-five-plus detectors for personal identifiers, payment cards, health records, credentials and API keys, with OCR for scanned documents and images. It runs entirely on the device, which is what makes it usable on a share you are not allowed to copy off-site.
See FileSentinel
What you get
A list you can work down, in the right order.
Ranked by what the gap would cost you rather than by a generic severity score, because the same misconfiguration is trivial in one environment and existential in another.
The ranked findings
Each one with the evidence behind it, the business consequence in plain language, and the effort to close it, separated into what you can fix this week and what belongs in a budget cycle.
The remediation plan
Sequenced so that the fixes which reduce the most exposure for the least disruption happen first, and so no step depends on a step scheduled after it.
The evidence pack
The artefacts behind every finding, assembled the way an insurer, an auditor or a client’s security reviewer will ask for them. Most clients reuse it within the year.
Who you are working with
Most incident plans have never met an actual incident.
Christopher Moskowitz founded and ran enterprise security and governance programmes at two regulated investment firms, delivered alongside PwC, ACA and outside counsel, and defended them in investor due-diligence sessions. He has also run technology for a firm that became the subject of an investigation that was front-page news internationally. The redundant architecture he had built meant the authorities could be given everything they required and the business still did not lose a day, and he spent the months that followed working alongside investigators and counsel. Your insurer’s questionnaire is a gentler version of an exercise already survived.
Common questions
Is this a penetration test?
No, and the two answer different questions. A penetration test asks whether a specific path can be exploited today. An assessment asks why that path exists, what else looks like it, and which of them to fix first. If a test is what you need, we will say so and help you scope one.
We already run a scanner. What does this add?
A scanner produces findings. It does not know that the flagged server is offline next month, that the finance workstation matters more than the lab, or that two of its criticals are mitigated by a control it cannot see. The value of the assessment is the ranking, and ranking requires context.
Our insurer sent a security questionnaire we cannot answer.
That is one of the most common reasons clients call. The assessment produces the evidence those questions ask for, and where the honest answer is currently "no" it tells you what it would cost to make it "yes", usually before the renewal date.
Do you handle compliance frameworks?
We map findings to the framework you are actually held to, whether that is HIPAA, GLBA, PCI DSS, SOC 2, FERPA or a client’s own security addendum. We are not an audit firm and will not sign an attestation; we prepare you for the people who do.
What happens if you find something serious mid-assessment?
You hear about it that day, by phone, not in a report six weeks later. Anything actively exploitable is escalated immediately with a containment suggestion attached.
Most breaches begin somewhere a team already suspected.
info@vandien.io · (551) 236-3191 · Ridgewood, NJ, serving the New York metro