Skip to content
Tidebreak Advisory

The methodology an auditor would recognize.

A practitioner's description of how a Tidebreak assessment is scoped, evidenced, scored, and reported. Written for the CPAs, outside counsel, and insurance professionals who refer the firms we serve.

The 60-second version

We independently check whether the security your IT provider says you have is actually in place. We review your systems and configuration, interview your team and your provider, test a sample of controls against a recognized framework, and hand you two reports: a short one your leadership can act on, and a detailed, evidence-cited one your provider can remediate against. Every finding cites the evidence behind it. The detail below is for readers who want to see exactly how.

An assessment, not an attestation

A CPA performs an attestation audit and issues an opinion: a regulated statement that the client's representations are fairly stated in the respects the engagement covers. The work supports the opinion; the opinion is the product.

A Tidebreak assessment is the work without the opinion. We apply audit-grade discipline (scoping, sampling, evidence collection, finding rationalization, and framework mapping) to one question: whether a firm's IT environment supports the professional obligations its leadership already carries. We describe what we found, how we found it, and what the frameworks say about it. We do not issue an opinion, a pass, a grade, or a seal.

A practitioner-grade assessment is work a professional auditor would recognize as competent. Findings cite their evidence, sampling logic, and framework editions in the register professional standards already require, not in the vocabulary of a vendor demo. When the question becomes "can you defend this," the CPA, outside counsel, or carrier who asks it can trace any claim to its source.

We identify exposure, describe it in language a firm's advisors can act on, and recommend remediation. The firm, with its counsel and auditors, makes the compliance determinations. We inform those decisions; we do not make them.

Takeaway

We do the audit-grade work and stop short of the opinion. You get findings you can defend, not a pass or a seal.

The framework stack

A Tidebreak assessment maps against three frameworks at once: a security controls framework, a governance framework, and the professional standard that governs the firm itself. That combination is the distinguishing claim of the work. It is why a finding can be defended to a CPA and a CISO in the same meeting, and why one report can serve a carrier questionnaire and a partnership-level risk discussion.

Controls

CIS Controls v8.1.2

Edition: 2024

Publisher: Center for Internet Security

Governance

NIST CSF 2.0

Edition: 2024

Publisher: National Institute of Standards and Technology

Professional standard

Per vertical

Edition: current per governing body

Publisher: profession-specific authority

Takeaway

Three frameworks at once: controls, governance, and your profession's standard. One report speaks to your CISO, your CPA, and your carrier.

The procedural walk

Every engagement runs the same ten-step sequence. Each step's scope adjusts to the firm's size, regulatory surface, and prior assessment history, but the discipline is constant. Each step produces a specific, citable work product, and any finding traces back to the step that surfaced it.

  1. Step 01 · Scope confirmation

    Engagement letter issued with defined firm scope, assessment period, frameworks referenced, and out-of-scope boundaries.

    Artifact produced

    Executed engagement letter

  2. Step 02 · Environment discovery

    Inventory of systems, data stores, identity providers, and third parties that touch the scoped environment. Asset inventory reconciled against what the IT provider reports.

    Artifact produced

    Environment inventory memorandum

  3. Step 03 · Control walkthrough

    Structured interviews with the firm's IT provider, named control owners inside the firm, and selected workforce members. Control population established.

    Artifact produced

    Walkthrough notes, control population register

  4. Step 04 · Risk-based sample selection

    Samples drawn from the control population using documented risk factors: privilege level, system criticality, control coverage gap, prior finding history.

    Artifact produced

    Sample selection memorandum

  5. Step 05 · Evidence collection

    Configuration captures, log extracts, policy documents with version identifiers, access control list exports, and backup restoration test records collected per sample.

    Artifact produced

    Evidence register, per sample

  6. Step 06 · Observation development

    Evidence reviewed against CIS Controls v8.1.2 safeguards, NIST CSF 2.0 categories, and the applicable professional standard. Observations drafted with evidence references.

    Artifact produced

    Draft observations

  7. Step 07 · Finding rationalization

    Observations aggregated into findings where aggregation clarifies the reading. Severity tier assigned per the published severity framework.

    Artifact produced

    Draft findings

  8. Step 08 · Fieldwork close-out

    Findings reviewed with the firm's IT provider for factual accuracy. Disputes documented. Firm leadership briefed.

    Artifact produced

    Close-out memorandum

  9. Step 09 · Reporting

    Executive Report and Full Assessment Report drafted. Evidence register and framework mapping appendices assembled. Disclaimers reviewed.

    Artifact produced

    Executive Report, Full Assessment Report

  10. Step 10 · Delivery and debrief

    Reports delivered. Working session with firm leadership, and separately with the IT provider, to walk each finding.

    Artifact produced

    Delivered reports, debrief notes

Steps five and six are where the practitioner-grade claim is earned or lost. If the evidence does not support the observation, the observation does not ship. If the observation does not map cleanly to a safeguard and a professional standard, the finding rewrites until it does.

Five evidence types

Every item in the evidence register is collected by one of five techniques. The label tells a reader how the fact was obtained, which is what makes a finding defensible.

1. Observation
Watching a control operate, such as a backup restoration test run during fieldwork.
2. Inspection
Examining records and settings directly: configuration captures, log extracts, access control list exports, and versioned policy documents.
3. Confirmation
Corroborating a fact with an independent party, such as the IT provider or a third party that touches the scoped environment.
4. Recalculation
Independently re-deriving a figure, such as the implementation score against the CIS Controls v8.1.2 safeguards in scope.
5. Inquiry
Structured interviews with the IT provider, named control owners, and selected workforce members.

Takeaway

Ten steps, each with a citable artifact. Every piece of evidence is labeled by how it was obtained, so any finding can be traced to its source.

Dual framework mapping

A finding that reads only in security-control language tells a CISO what to fix but leaves the managing partner unsure what obligation is at stake. A finding that reads only in professional-standard language cannot be translated into remediation by the IT provider. Tidebreak's reports carry both readings at once, because each is necessary and neither is sufficient.

  • The security mapping. Every finding cites the CIS Controls v8.1.2 safeguards and, where relevant, NIST CSF 2.0 categories that the finding implicates.
  • The professional-standard mapping.Where meaningful dual mapping exists, the finding also cites the ABA Model Rule, AICPA Code provision, HIPAA requirement, or financial-services rule that the finding implicates.
  • When mapping is absent. Findings without meaningful dual mapping are labeled as such. The absence is information.
  • Where it appears in the report. Both mappings appear on the finding card itself, on the Framework Mapping appendix, and in the vertical crosswalk.

Worked example

Critical

Shared attorney drive with standing privileged access

Security mapping

CIS Safeguards 3.3 · 3.12 · 6.8

Professional-standard mapping

ABA Model Rules 1.6, 1.7, 1.10, and 1.1 Cmt 8

Evidence 4, 7, 12

Firm-wide shared drive granted read and write access to matter documents for all users, including terminated staff retaining credentials. Access was not segregated by matter, and standing privileged access remained active for MSP engineers.

Recommended action. Segregate matter access by practice need, remove standing privileged access, and enforce quarterly entitlement reviews with documented sign-off by firm leadership.

The dual reading is what makes the report useful to a referral network. The CPA can defend it, the IT provider can act on it, and outside counsel can read the same document and orient. The finding does not translate; it already speaks both languages.

Takeaway

Each finding carries a security reference and a professional-standard reference. Where no honest professional-standard tie exists, the finding says so, because the absence is information.

How we score

  • Critical. Conditions that create material professional, regulatory, or business-continuity exposure. Remediation priority measured in days or weeks, not quarters.
  • Moderate.Conditions that weaken the firm's defensible posture without creating immediate material exposure. Remediation within the current operating cycle.
  • Observational. Conditions worth noting that do not, on their own, carry meaningful exposure. Included to support the completeness of the reading.

The implementation score is a 0-100 number derived from the firm's position against the CIS Controls v8.1.2Implementation Group 2 safeguards in scope. IG2 is the default target, adjusted up or down with the firm's data sensitivity, regulatory surface, and size. Every Full Assessment Report discloses the calculation and its inputs. The score summarizes current posture. It is not a certification, a grade, or a carrier-facing attestation.

Every assessment also reports the firm's position against NIST CSF 2.0's four tiers (Partial, Risk Informed, Repeatable, Adaptive) across the six functions, adding a governance-level view alongside the safeguard-level one.

Takeaway

Three severity tiers rank what to fix first. The 0-100 score summarizes posture against IG2. It is a read on where you stand, not a certification.

Where we hand off

A Tidebreak assessment is one input into a firm's risk and compliance decisions, not the whole of it. The work below is work our clients often need and that we do not perform. We name it here so the boundary is visible and a firm's advisors know where our scope ends.

  1. 1. Attestation audits (SOC 2, HIPAA certifications, ISO 27001 audits). We do not issue opinions. Firms needing an attest report engage a licensed CPA firm with a registered attest practice.

  2. 2. Penetration testing. We do not conduct offensive security testing. Firms needing pen tests engage a dedicated offensive-security provider; we can advise on scoping.

  3. 3. Incident response during an active incident. We do not operate as a retained IR firm. Firms experiencing an active incident engage their IR retainer or cyber insurance panel; we can assist post-incident in root-cause and remediation tracking.

  4. 4. Managed security services (SOC, MDR, SIEM). We do not operate any managed security service. Firms needing continuous monitoring engage an MSSP or extend their MSP's service.

  5. 5. Regulatory filings and notifications. We do not prepare or submit breach notifications, regulator filings, or examination responses. Firms needing these engage outside counsel or a specialized notification service.

  6. 6. Legal opinions on rule interpretation. We do not interpret ABA, AICPA, HIPAA, SEC, NYDFS, state bar opinions, or any other legal or regulatory authority in specific-facts contexts. Firms with rule-interpretation questions engage outside counsel.

  7. 7. Day-to-day IT operations and remediation execution. We do not configure, patch, deploy, or operate technology on a firm's behalf. Firms execute remediation through their IT provider; we provide the specification and review implementation evidence.

  8. 8. Insurance placement or underwriting support. We do not place cyber insurance coverage or underwrite risk. Firms work with licensed brokers and carriers; our reports support those conversations rather than replace them.

  9. 9. Software procurement or reseller services. We do not resell, source-prefer, or receive commissions on any security product. Our recommendations are vendor-agnostic.

  10. 10. §164.308(a)(1) HIPAA risk analysis as a formal deliverable. Where a covered entity requires the specific deliverable that satisfies §164.308(a)(1), we can produce a Tidebreak-format assessment that serves as the foundation, but the covered entity or its counsel formally adopts and approves the analysis.

Takeaway

We assess and recommend. Attestation, pen testing, incident response, managed security, and regulatory filings sit with specialists we name, not with us.

Disclosure

Tidebreak performs assessments, not attest audits.

This page describes the Tidebreak Advisory assessment methodology as currently in practice. It is not legal advice, an attestation, or a certification. Tidebreak is not a law firm, a CPA firm, or a registered attest practice. Framework references are to the editions identified on this page and are reviewed annually and on material changes to any referenced framework.