I will assess your vendors for security risk

Vetted Pro

United States

I speak English

6 orders completed

The Cyber Friend, where you can Trust Us, with your Security

Most of my clients have a regulator, an insurer, or a customer asking questions they cannot answer, and no budget for a full-time security hire. That is the gap I fill. Six years in security. I have ...
Vetted by Fiverr Pro

Sam was selected by the Fiverr Pro team for their expertise.

Vetted for

  • Cybersecurity

About this Gig

Vetted Pro

Your regulator already requires this. 16 CFR 314.4(f) requires periodic assessment of your service providers based on the risk they present. 45 CFR 164.308(b)(1) requires satisfactory assurances from every business associate. PCI DSS 12.8 says the same for cardholder data.


Almost nobody does it. The contract is signed, the vendor gains access, and nothing is checked again until an auditor requests the file and finds none.


I run the process so there is one.


What you receive:

  • A security questionnaire sent to each vendor, chased until it comes back
  • Public record review: breaches, litigation, and exposed infrastructure
  • A written risk summary for every vendor in plain language
  • Risk ratings so you know which relationships need attention
  • A prioritized remediation list you can take to the vendor
  • Vendor scorecards and an executive report
  • Documentation dated and filed, so the next auditor gets an answer


I contact your vendors directly. You send the list, and I chase them, including the ones who ignore it twice.


CISM. CMMC Registered Practitioner Advanced. Master's in Cybersecurity.


Message me with how many vendors touch your regulated data, and I will tell you which tier fits.

Expertise:

Configuration management

Data Protection

Technology:

Cloud - IaaS

Mail Services

Saas

Databases

Regulation:

Other