Know which security gaps your business needs to fix first
The FrostPalm Security Baseline reviews access, email, recovery, and security responsibilities for Fargo-Moorhead professional firms. You leave with a prioritized risk register and a practical 30/60/90-day action plan, not a 60-page report nobody reads.
The conversation is free. The assessment is a paid, fixed-scope engagement.
Prioritized Risk Register
Verified gaps, reported controls, and unverified areas, separated clearly so you know what is real.
30/60/90-Day Plan
Each item has an owner (you, your IT provider, or FrostPalm) so the work actually moves.
Answers You Can Defend
The evidence an insurer, customer, or partner is asking you to produce, organized and documented.
Built for professional firms without a security team
Usually 10–40 employees in Fargo or a surrounding city, with sensitive client data, one main Microsoft 365 or Google Workspace tenant, and outsourced or generalist IT.
Accounting & Advisory Firms
Firms holding financial and client records that clients and insurers increasingly ask about.
Engineering & Technical Consulting
Teams with confidential project data and customer security requirements to answer.
Firms With a Real Trigger
A customer questionnaire, insurance renewal, new contract, ownership change, or access cleanup is driving a decision.
It may not be a fit if you need break-fix IT support, a blanket compliance certificate, 24/7 monitoring, or active incident response. In those cases we will tell you directly and point you toward the right kind of help.
Eight focused areas, reviewed against real evidence
The Baseline samples the controls that cause the most risk for small firms. We review what we can observe and clearly record anything we cannot verify.
Identity & MFA
Tenant settings, an agreed account sample, admin roles, stale access, and account recovery methods.
Microsoft 365 or Workspace
Agreed security settings on one tenant, through read-only access or supervised evidence collection.
Endpoint & Email Posture
Policy and configuration evidence, a sample of up to five endpoints, plus email authentication and protection settings.
Privileged & Vendor Access
Who holds admin rights, which third parties have access, and how access is approved and removed.
Backup & Recovery
Backup scope, ownership, and evidence of the most recent restore. A production restore exercise is separate work.
Onboarding & Offboarding
A walkthrough of one recent hire and one departure, using sanitized evidence where possible.
External & Website Exposure
A non-intrusive review of one domain and agreed public assets. Active scans require written scope and permission.
Insurance & Governance
Your evidence compared with insurer or customer questions, with ownership clarified and gaps documented.
Deliverables you can act on and hand to your IT provider
Two-Page Executive Summary
The main decisions and the evidence limitations, written for owners, not engineers.
Prioritized Risk Register
Findings separated into verified gaps, reported controls, and unverified areas, each with consequence and owner.
Immediate Actions
Anything urgent is escalated promptly through your agreed contact, not held for the final readout.
30/60/90-Day Roadmap
A sequenced plan with each action assigned to you, your MSP, or FrostPalm.
45-Minute Readout
A live walkthrough with your decision maker, plus a separately priced remediation recommendation where it is justified.
A clear path from conversation to action plan
Delivered in ten business days after kickoff and receipt of the agreed evidence.
1. Fit Conversation
A short, no-cost call to confirm the problem, your environment, and whether a paid Baseline makes sense. If it does not, we say so.
2. Scope & Kickoff
We agree a fixed scope and fee in a signed statement of work, then reserve your delivery slot.
3. Evidence Review
A focused six-to-eight-hour review across about two weeks, using read-only access or supervised evidence.
4. Readout & Plan
You receive the risk register and 30/60/90-day plan and walk through it live with your IT provider in the room.
Fee and terms. The Baseline is a fixed-scope, paid engagement. We confirm the exact scope, fee, and payment terms on the discovery call so the work matches your environment. Nothing starts until a signed statement of work is in place.
What you provide. An executive sponsor, an IT contact, a basic system inventory, any relevant insurance or customer questions, authorized evidence access, and one decision maker for the readout.
What the Baseline is, and what it is not
Clear limits are part of the value. You should know exactly what you are buying.
What it is
- A sampled, evidence-based review of selected controls
- A prioritized, owner-assigned action plan
- Independent evidence you can share with insurers or customers
- Delivered alongside your existing IT provider
What it is not
- A penetration test or exhaustive audit
- A compliance certification or legal assurance
- A guarantee that incidents cannot happen
- Break-fix IT, help desk, or 24/7 monitoring
We give you evidence, not a turf war
Most of our clients already have an IT provider or MSP. The Baseline gives you an independent view and a plan your provider can implement. We do not presume they are failing.
Independent Second View
A clear, outside read on what is covered and what still needs an owner.
Your IT Provider in the Readout
They are welcome in the walkthrough so everyone leaves with the same priorities.
Implement It Your Way
Use your MSP, your internal team, or a scoped FrostPalm remediation. The plan is yours.
Common questions before a Baseline
Is this a penetration test or full audit?
No. It is a sampled, evidence-based review of selected controls, not a penetration test, exhaustive audit, or compliance certification. Anything we cannot observe is recorded as not verified rather than assumed effective.
Do you replace our IT provider?
No. FrostPalm works alongside your existing IT provider. You get independent evidence and a prioritized plan, and your provider can implement any or all of it.
What does it cost?
The Baseline is a paid, fixed-scope engagement. We confirm the exact scope and fee in a short, no-cost discovery call so you only pay for the work your environment needs.
How long does it take?
Ten business days after kickoff and receipt of the agreed evidence. The review itself is a focused six-to-eight-hour effort across about two weeks.
Start with a conversation, not a commitment
Tell us what is driving the decision: an insurance renewal, a customer questionnaire, an access cleanup, or just uncertainty. If a Security Baseline fits, we will scope it. If it does not, we will point you the right way.