Controls
CIS Controls v8.1.2
Edition: 2024
Publisher: Center for Internet Security
A practitioner's description of how a Tidebreak assessment is scoped, evidenced, scored, and reported. Written for the CPAs, outside counsel, and insurance professionals who refer the firms we serve.
We independently check whether the security your IT provider says you have is actually in place. We review your systems and configuration, interview your team and your provider, test a sample of controls against a recognized framework, and hand you two reports: a short one your leadership can act on, and a detailed, evidence-cited one your provider can remediate against. Every finding cites the evidence behind it. The detail below is for readers who want to see exactly how.
A CPA performs an attestation audit and issues an opinion: a regulated statement that the client's representations are fairly stated in the respects the engagement covers. The work supports the opinion; the opinion is the product.
A Tidebreak assessment is the work without the opinion. We apply audit-grade discipline (scoping, sampling, evidence collection, finding rationalization, and framework mapping) to one question: whether a firm's IT environment supports the professional obligations its leadership already carries. We describe what we found, how we found it, and what the frameworks say about it. We do not issue an opinion, a pass, a grade, or a seal.
A practitioner-grade assessment is work a professional auditor would recognize as competent. Findings cite their evidence, sampling logic, and framework editions in the register professional standards already require, not in the vocabulary of a vendor demo. When the question becomes "can you defend this," the CPA, outside counsel, or carrier who asks it can trace any claim to its source.
We identify exposure, describe it in language a firm's advisors can act on, and recommend remediation. The firm, with its counsel and auditors, makes the compliance determinations. We inform those decisions; we do not make them.
Takeaway
We do the audit-grade work and stop short of the opinion. You get findings you can defend, not a pass or a seal.
A Tidebreak assessment maps against three frameworks at once: a security controls framework, a governance framework, and the professional standard that governs the firm itself. That combination is the distinguishing claim of the work. It is why a finding can be defended to a CPA and a CISO in the same meeting, and why one report can serve a carrier questionnaire and a partnership-level risk discussion.
Controls
CIS Controls v8.1.2
Edition: 2024
Publisher: Center for Internet Security
Governance
NIST CSF 2.0
Edition: 2024
Publisher: National Institute of Standards and Technology
Professional standard
Per vertical
Edition: current per governing body
Publisher: profession-specific authority
Takeaway
Three frameworks at once: controls, governance, and your profession's standard. One report speaks to your CISO, your CPA, and your carrier.
Every engagement runs the same ten-step sequence. Each step's scope adjusts to the firm's size, regulatory surface, and prior assessment history, but the discipline is constant. Each step produces a specific, citable work product, and any finding traces back to the step that surfaced it.
Engagement letter issued with defined firm scope, assessment period, frameworks referenced, and out-of-scope boundaries.
Artifact produced
Executed engagement letter
Inventory of systems, data stores, identity providers, and third parties that touch the scoped environment. Asset inventory reconciled against what the IT provider reports.
Artifact produced
Environment inventory memorandum
Structured interviews with the firm's IT provider, named control owners inside the firm, and selected workforce members. Control population established.
Artifact produced
Walkthrough notes, control population register
Samples drawn from the control population using documented risk factors: privilege level, system criticality, control coverage gap, prior finding history.
Artifact produced
Sample selection memorandum
Configuration captures, log extracts, policy documents with version identifiers, access control list exports, and backup restoration test records collected per sample.
Artifact produced
Evidence register, per sample
Evidence reviewed against CIS Controls v8.1.2 safeguards, NIST CSF 2.0 categories, and the applicable professional standard. Observations drafted with evidence references.
Artifact produced
Draft observations
Observations aggregated into findings where aggregation clarifies the reading. Severity tier assigned per the published severity framework.
Artifact produced
Draft findings
Findings reviewed with the firm's IT provider for factual accuracy. Disputes documented. Firm leadership briefed.
Artifact produced
Close-out memorandum
Executive Report and Full Assessment Report drafted. Evidence register and framework mapping appendices assembled. Disclaimers reviewed.
Artifact produced
Executive Report, Full Assessment Report
Reports delivered. Working session with firm leadership, and separately with the IT provider, to walk each finding.
Artifact produced
Delivered reports, debrief notes
Steps five and six are where the practitioner-grade claim is earned or lost. If the evidence does not support the observation, the observation does not ship. If the observation does not map cleanly to a safeguard and a professional standard, the finding rewrites until it does.
Every item in the evidence register is collected by one of five techniques. The label tells a reader how the fact was obtained, which is what makes a finding defensible.
Takeaway
Ten steps, each with a citable artifact. Every piece of evidence is labeled by how it was obtained, so any finding can be traced to its source.
A finding that reads only in security-control language tells a CISO what to fix but leaves the managing partner unsure what obligation is at stake. A finding that reads only in professional-standard language cannot be translated into remediation by the IT provider. Tidebreak's reports carry both readings at once, because each is necessary and neither is sufficient.
Worked example
CriticalSecurity mapping
CIS Safeguards 3.3 · 3.12 · 6.8
Professional-standard mapping
ABA Model Rules 1.6, 1.7, 1.10, and 1.1 Cmt 8
Evidence 4, 7, 12
Firm-wide shared drive granted read and write access to matter documents for all users, including terminated staff retaining credentials. Access was not segregated by matter, and standing privileged access remained active for MSP engineers.
Recommended action. Segregate matter access by practice need, remove standing privileged access, and enforce quarterly entitlement reviews with documented sign-off by firm leadership.
The dual reading is what makes the report useful to a referral network. The CPA can defend it, the IT provider can act on it, and outside counsel can read the same document and orient. The finding does not translate; it already speaks both languages.
Takeaway
Each finding carries a security reference and a professional-standard reference. Where no honest professional-standard tie exists, the finding says so, because the absence is information.
72/100
The implementation score is a 0-100 number derived from the firm's position against the CIS Controls v8.1.2Implementation Group 2 safeguards in scope. IG2 is the default target, adjusted up or down with the firm's data sensitivity, regulatory surface, and size. Every Full Assessment Report discloses the calculation and its inputs. The score summarizes current posture. It is not a certification, a grade, or a carrier-facing attestation.
Every assessment also reports the firm's position against NIST CSF 2.0's four tiers (Partial, Risk Informed, Repeatable, Adaptive) across the six functions, adding a governance-level view alongside the safeguard-level one.
Takeaway
Three severity tiers rank what to fix first. The 0-100 score summarizes posture against IG2. It is a read on where you stand, not a certification.
A Tidebreak assessment is one input into a firm's risk and compliance decisions, not the whole of it. The work below is work our clients often need and that we do not perform. We name it here so the boundary is visible and a firm's advisors know where our scope ends.
1. Attestation audits (SOC 2, HIPAA certifications, ISO 27001 audits). We do not issue opinions. Firms needing an attest report engage a licensed CPA firm with a registered attest practice.
2. Penetration testing. We do not conduct offensive security testing. Firms needing pen tests engage a dedicated offensive-security provider; we can advise on scoping.
3. Incident response during an active incident. We do not operate as a retained IR firm. Firms experiencing an active incident engage their IR retainer or cyber insurance panel; we can assist post-incident in root-cause and remediation tracking.
4. Managed security services (SOC, MDR, SIEM). We do not operate any managed security service. Firms needing continuous monitoring engage an MSSP or extend their MSP's service.
5. Regulatory filings and notifications. We do not prepare or submit breach notifications, regulator filings, or examination responses. Firms needing these engage outside counsel or a specialized notification service.
6. Legal opinions on rule interpretation. We do not interpret ABA, AICPA, HIPAA, SEC, NYDFS, state bar opinions, or any other legal or regulatory authority in specific-facts contexts. Firms with rule-interpretation questions engage outside counsel.
7. Day-to-day IT operations and remediation execution. We do not configure, patch, deploy, or operate technology on a firm's behalf. Firms execute remediation through their IT provider; we provide the specification and review implementation evidence.
8. Insurance placement or underwriting support. We do not place cyber insurance coverage or underwrite risk. Firms work with licensed brokers and carriers; our reports support those conversations rather than replace them.
9. Software procurement or reseller services. We do not resell, source-prefer, or receive commissions on any security product. Our recommendations are vendor-agnostic.
10. §164.308(a)(1) HIPAA risk analysis as a formal deliverable. Where a covered entity requires the specific deliverable that satisfies §164.308(a)(1), we can produce a Tidebreak-format assessment that serves as the foundation, but the covered entity or its counsel formally adopts and approves the analysis.
Takeaway
We assess and recommend. Attestation, pen testing, incident response, managed security, and regulatory filings sit with specialists we name, not with us.
Tidebreak performs assessments, not attest audits.
This page describes the Tidebreak Advisory assessment methodology as currently in practice. It is not legal advice, an attestation, or a certification. Tidebreak is not a law firm, a CPA firm, or a registered attest practice. Framework references are to the editions identified on this page and are reviewed annually and on material changes to any referenced framework.