No. An audit is an attestation: a licensed firm issues a formal opinion against a defined standard, with workpapers and professional liability behind the signature. We perform practitioner-grade assessments, recognizable to auditors in methodology and evidence discipline, but we do not issue an opinion and we are not a CPA firm.
Common questions from managing partners, answered directly.
The short version of how Tidebreak works, where scope begins and ends, and what shows up in a delivered scorecard.
Theme 1
Methodology and rigor
Every engagement maps findings to CIS Controls v8.1.2 (Implementation Group 2) and NIST CSF 2.0, plus the professional standard that governs your practice (ABA Model Rules, AICPA Code and SQMS 1, the HIPAA Security Rule, or the FTC Safeguards Rule). CIS and NIST are the frameworks your carrier, your auditor, and your regulator already recognize. The dual mapping is how a finding lands in a register your outside counsel or CPA can defend.
Tools find configured controls. We find process gaps.
A GRC platform is a control-monitoring tool. It collects evidence against a predefined catalog and reports whether a box is checked; it does not sample, it does not observe, and it cannot tell you whether a control is designed well for your practice. We do the part of the work that is judgment, not automation. If you are pursuing SOC 2 you may still need a GRC platform; we will tell you so, and we do not sell the subscription.
Risk-based sampling. We scope the environment, identify the controls most likely to fail under professional-standard pressure, and size the sample so observations support defensible conclusions. Sample selection is documented in the scorecard the same way an audit workpaper would document it.
Theme 2
Independence and scope
Our compensation isn't tied to the finding. MSPs' is.
No. We do not resell software, we do not operate an MSP, and we do not take referral fees from tools or providers named in findings. Revenue comes only from the assessment work. When a finding names a tool category, the scorecard explains why and leaves the selection to you and your IT provider.
See: Positioning · Independence.
A vCISO is on your team. Tidebreak is on your side.
No. The assessment is designed to run alongside your existing IT provider, with their participation in fieldwork. The final report is as useful to them as it is to you: a neutral third read on where controls are strong, where they are not, and what a disciplined remediation plan looks like. Most MSPs welcome it; a few do not, and that itself is a finding.
No. Those are different professions with different standards of care, and performing them alongside assessment work would compromise independence. The methodology page enumerates the hand-off items and the kind of specialist each one belongs to.
See: Methodology → Hand-off.
Theme 3
Engagement mechanics
A typical engagement runs six to eight weeks from kickoff to delivered scorecard: roughly two weeks of scoping and discovery, three weeks of fieldwork, one to two weeks of observation development and report writing, and a delivery debrief. Firms with more complex environments or multiple entities may run longer; the engagement letter sets the timeline before work begins.
We need a single engagement point of contact (typically the managing partner or the COO), scheduled access to your IT provider for interviews and evidence requests, and read-only access to a small set of systems. Expect roughly six to eight hours of internal time over the engagement, plus the IT provider's participation in fieldwork sessions. The engagement is designed to avoid client-work disruption.
Jeff White leads every engagement and performs the sampling, observation development, and reporting work directly. When specialized depth is required (for example, cloud posture review in complex Azure or AWS environments), named subject-matter experts participate under confidentiality and their involvement is disclosed in the engagement letter. You always know who is touching your evidence. Tidebreak carries professional liability and cyber liability insurance and provides evidence of coverage on request. Your evidence stays in an encrypted, role-limited workspace under the engagement letter's custody terms for the life of the engagement. If the principal becomes unavailable mid-engagement, the engagement letter's continuity terms govern: the work pauses, your evidence remains under those custody terms, and it is returned or destroyed at your election.
Theme 4
Pricing and procurement
Fixed fee for one-time engagements (Snapshot Scorecard and Comprehensive Assessment), stated up front in the engagement letter and tied to the scope of your environment. The Ongoing Oversight retainer is priced as a standing quarterly engagement, with the annual full reassessment and the interim quarterly deltas defined in the scope rider. We do not bill hourly for assessment work, and we do not sell a subscription to a tool. Typical investment, scope-dependent: Snapshot Scorecard $12,000 to $20,000; Comprehensive Assessment $35,000 to $45,000; Ongoing Oversight $50,000 to $75,000 per year. The exact fixed fee is set in the scoping conversation, which takes about thirty minutes.
Either works. Tidebreak has a standard engagement letter that handles scope, confidentiality, data handling, and limits of reliance; client-paper engagement letters are also acceptable with reasonable adjustments. We will not sign language that misrepresents the deliverable (for example, describing it as an audit opinion) or that transfers liability appropriate to a regulated profession.
Theme 5
Post-engagement
It contains scoped findings with evidence citations, dual-framework mapping (CIS plus your professional standard), severity ratings tied to a defined rubric, a prioritized remediation plan, and a disclaimer stack that states plainly what the document is and is not. It does not contain an audit opinion, a certification, a legal conclusion, or a warranty of security outcomes.
See: Sample scorecard.
Yes, within the distribution clause of the engagement letter. The scorecard is written so it can be forwarded to your carrier, your outside counsel, or a financial-statement auditor without edit; the disclaimer stack makes scope plain to any reader. Regulatory distribution (for example, an OCR response or a state AG inquiry) is usually coordinated through counsel, and we will work with your attorney on the production.
A one-time engagement ends at report delivery. A six-month follow-up reading is included, and most firms book a Tier 2 re-engagement in year two, which runs faster because scoping and baseline observations carry forward. Firms that want standing independent review book Ongoing Oversight: a quarterly-cadence relationship with an annual full reassessment and targeted quarterly deltas between. The relationship is governance discipline, not a subscription to advice.
During engagement, evidence is collected to an encrypted workspace with role-limited access, retained for the period stated in the engagement letter, and returned or destroyed at close-out per your preference. Under the Ongoing Oversight retainer, standing access is narrower and time-bounded; access is re-attested each quarter, and the Tier 3 engagement-letter rider covers the incremental data-handling terms. We do not train AI models, sell data, or share evidence outside the engagement team.
See: Privacy Policy · Services.
Disclaimer stack
Not legal advice. This document does not constitute legal advice. Firm leadership and the firm's counsel make all legal determinations.
Not an attestation (or "not a risk analysis" for Healthcare). Tidebreak performs assessments, not attest audits. Where a covered entity requires the §164.308(a)(1) deliverable, this document serves as foundation; the covered entity or its counsel formally adopts the analysis.
Framework currency. Framework references are to the editions identified in this document: CIS Controls v8.1.2 (2024), NIST CSF 2.0 (2024), and the professional standards cited by name and edition. Frameworks are reviewed annually and on material changes.
Regulatory or jurisdictional scope. This assessment does not address state bar opinions or jurisdiction-specific variations beyond those enumerated in the Regulatory Variation section (for crosswalks) or in the engagement letter (for assessments).
Distribution. This document is provided for the use of the client and its designated advisors. Further distribution, in whole or part, requires written permission.