Book a scoping call

Most businesses end up with security that was designed for someone else.

The tools came from a vendor. The policy came from an auditor. Nobody independent has looked at the whole thing and told you whether it holds.

It's not that you're not spending enough. It's that what you have doesn't fit.

Book a scoping call
  1. Backups have not been restored and checked in over a year Fix first
  2. Three people who left still hold working accounts Fix first
  3. The response plan names no one who can decide Next
  4. Card handling matches what you told your processor Verified
Ranked by what matters, not by what there is to sell.

The premise

This isn't another audit

An audit checks you against someone else's list and produces a document for a third party. This is different. It's time with the people who actually run your company, asking questions until the picture is real.

We sell no products, resell no licenses, and take no commissions. Nobody pays to appear in your report. The findings are the entire product, and they don't point anywhere in particular.

Most companies come out of it knowing things about themselves they didn't know they should know.

What you can't verify from the inside

Thinking your people know isn't the same as knowing they do

The training was completed. The policy was circulated. Everyone signed. That's a record, not evidence.

What actually happens is decided in the ten seconds after someone notices something odd, when they decide whether it's worth bothering anyone about. That decision comes from what happened the last time somebody spoke up.

Ask several people the same question and the answers won't match. The gaps between them are the finding. Then you check what they told you against what is actually in place.

The engagement

What you get

A structured review of your security against recognized standards, run as a working session with you and whoever handles your technology. Fixed scope and a fixed fee agreed before it starts.

  1. Where you stand

    A scored account of your position, with findings ranked by what matters and what each one takes to fix.

  2. What you carry

    Obligations mapped against those findings: payment data, patient data, insurance requirements, federal contracts. Where federal contracts are in play, the applicable NIST requirements get mapped alongside the rest.

  3. A plan of action

    A meeting where we walk you through it in plain terms, and an order to work in. What's solid, what's exposed, what to fix first.

  4. In writing

    The written version is yours to hand to your IT provider, your insurer, or your board.

The measure

The measure is what your industry, your insurer, and your customers expect you to have in place. It's also what you have already told them you have.

Insurance applications. Customer security questionnaires. Contract terms with security language in them. Someone answered those, often from memory, sometimes before they were in the role. It doesn't matter who filled it in. The company signed it and you own the answer.

If one of those answers turns out to be wrong on the day it matters, the coverage and the contract are both in question. This is where you find out, while it's still a correction instead of a claim.

Led by David Tortora

Why this catches things

I've served as incident commander on more than 200 major incidents for organizations in the US, the UK, Europe, and Hong Kong.

Plenty of them should have been far worse than they were. They stayed contained because one ordinary control was already in place, put there before anyone knew it would be the one that mattered. The ones that went badly were missing a single ordinary piece, or never had it at all, because everyone assumed someone else had it covered.

I've seen the far end of it. Weeks of downtime. Infrastructure rebuilt from nothing. Legal exposure that outlasted the outage by years. One recovery I directed was fully back in operation inside a day. That's the range, and which end you land on is settled before anything happens.

Before that, ten years as a senior detective working financial crime and digital forensics, where the job was reconstructing what people did and what they had assumed was covered. It is the same question either way.

Current analysis is published weekly at State of the Threat, State of the Attack, and State of the Defense.

Incident readiness

The part nobody has rehearsed

Most companies have an incident response plan on paper. Few have a leadership team that has ever run a tabletop exercise together.

Put your executives in a room with a realistic scenario and the decisions that look obvious in writing turn out to have no owner. That hour is usually the one people talk about afterward.

Who this is for

Size decides how long this takes

It doesn't decide whether you need it. Fifteen people or fifteen hundred, the question is the same. Has anyone independent actually looked?

Most companies run security like a home office long after they stopped being one. If you hold customer records, move money, or sign contracts with security terms in them, you are carrying corporate risk on a small business setup. The obligations don't scale down with your headcount.

  • The business paying someone else to handle security, with no way of its own to check what's being done.
  • The regulated business carrying obligations it has no way to verify on its own.
  • The company where the person who set all of this up has moved on, and what they knew left with them.
  • The executive holding questions from a board, an insurer, or a customer that they can't answer with confidence today.

None of these companies would call this urgent. That is exactly why it's worth doing now.

Before you call

Questions we get asked first

What does an independent security assessment involve?
Conversations with the people who run the business, a structured review of what is actually in place measured against recognized standards, and a written report with findings ranked in the order they should be handled. Nothing is sold to you at the end of it.
Do you work with small businesses?
Yes. Fifteen people or fifteen hundred, the obligations don't scale down with headcount. Scope and fee follow the size of the business, and you know both before anything begins.
Where do you work?
New Jersey, with most work in Monmouth County, Ocean County and the surrounding region. Sessions run on site where that matters and remotely where it doesn't.
Can this help with a cyber insurance application or a customer security questionnaire?
Yes. Those forms contain statements the company is accountable for, whoever filled them in. The review checks whether the answers hold up before anyone has to rely on them.
Do you handle CMMC?
We can read your position against the requirements and tell you where you sit. Full CMMC implementation is specialist work and we will point you to someone who does it daily.

How this starts

A 30 minute call, then an engagement scoped to the company.

The call is to understand the business, what you're responsible for, and what you're already carrying. It costs nothing and it's enough to tell whether there's work here.

Some engagements are straightforward. Some involve several locations, a compliance obligation, and a technology setup nobody has fully mapped. You'll know the scope and the fee before anything begins.

ADS Risk Solutions works with businesses across New Jersey, most of them in Monmouth County, Ocean County and the surrounding region. On site where that matters, remote where it doesn't.