StudioSicuro® · Firm security review

Your client asked how you protect their data.
I give you the answer. Signed.

Independent advisory for professional firms. Nothing to buy, no system to replace, no conflict of interest.

The moment

This is usually how firms arrive.

  • The client questionnaire

    A corporate client or a bank sends you a vendor security assessment. It asks for evidence, not reassurance, and no one in the firm can answer with authority.

  • The policy at renewal

    The cyber policy comes up for renewal at a higher price, or is declined. The proposal form asks about controls no one has ever verified in writing.

  • The firm next door, stopped

    A nearby firm is down for days after ransomware, in the middle of tax or court deadlines. The question turns concrete: if it happened to us, could we show what we had done?

What you receive

Three documents. One carries a signature.

The Studio Security Review ends with three documents. Two are for you and your IT provider; the third answers whoever asks you to account for your security, and does so under the responsibility of the person who signs it.

The central item

Questionnaire response sheet

Ready, defensible answers to client and insurer questionnaires, signed by the consultant as an assumption of professional responsibility. It records the verified state of affairs, even when that is uncomfortable: that is what makes it defensible.

  • Vendor assessment
  • Cyber policy proposal
  • Signed by the consultant

Security status report

For the firm owner, in plain language and no jargon. What is protected, what is not, and what actually matters.

Remediation plan

Operational instructions for the firm's IT provider, in order of risk, with the criteria to verify each item is closed.

What I don't do

Where my perimeter stops.

I don't touch your systems. I verify whoever does.

Your IT provider is not replaced: they receive clear instructions and their work is verified. It is oversight, not competition.

  • No installs on your systems.
  • No software licences resold.
  • No helpdesk or technical support.
  • No on-call cover or day-to-day operations.

How it works

Four steps, fixed timing.

The stages of the review

  1. 01

    Initial conversation

    A first call to understand the firm, the clients asking questions and the deadline in front of you.

  2. 02

    Up to two half-days on site

    We gather the evidence where it lives: systems, providers, procedures. On site, without stopping the firm's work.

  3. 03

    Delivery of the three documents

    Report, remediation plan and response sheet, delivered within 15 working days of the on-site work.

  4. 04

    Debrief with the owner

    A meeting with the owner to read the findings, the priorities and the answers to give clients and insurers together.

Prices

Public, fixed, no surprises.

Review prices by number of workstations
Firm profileWorkstationsPrice
Small firmUp to 8€2,400 + VAT
Mid-size firm9-15€3,600 + VAT
Larger firm16-30€4,800 + VAT
Additional officeExtra office€600 + VAT

All inclusive. Invoiced 50% at the start and 50% on delivery. No extra costs within the covered provinces.

Workstation: any desktop, laptop or server that accesses the firm's data, regardless of headcount.

Covered provinces: Como, Lecco, Varese, Monza-Brianza and Milan.

After the review

If it helps, I stay. You pay when the record arrives.

Some firms are done after the review; others prefer oversight that doesn't stop at the first pass. Ongoing oversight keeps the firm's security current, answers the questionnaires that arrive through the year and verifies the IT provider's work. You pay when you receive the record, not up front.

Discuss ongoing oversight

Ongoing oversight

  • Quarterly review with a signed record
  • Answers to questionnaires through the year, up to 4
  • Oversight of the IT provider's work
  • A point of contact in the event of an incident
Oversight prices per quarter
Firm profileWorkstationsPer quarter
Small firmUp to 8€1,170 + VAT
Mid-size firm9-15€1,470 + VAT
Larger firm16-30€1,770 + VAT

Annual contract · invoiced quarterly on delivery of the record · 60 days' notice

Simone Nogara, independent consultant at Intarmour

Who signs

One person signs the work.

Simone Nogara

More than 14 years of enterprise security. Every task is carried out personally: no juniors, no subcontracting. The signature on the documents is the same person who did the review.

Signing the documents is an assumption of professional responsibility, backed by professional indemnity insurance with a €5,000,000 limit. Your IT provider cannot sign for what they sell; an independent consultant can.

Certifications
CCSPCEHAZ-500PMP
Behind the signature
Professional indemnity insurance, €5,000,000 limit

Frequently asked

The questions I hear most.

Before booking, firm owners almost always ask the same things: whether the service is really needed when there is already an IT technician, what changes for the IT provider, how much it weighs on the firm's day-to-day. Here are the most common answers, put plainly and without jargon. If your question is not among them, bring it to the first conversation: half an hour, no commitment.

Book the review
We already have an IT technician: do we still need this?

Yes, because they do two different things. Your technician runs the systems; I verify, independently, that they are protected and put it in writing under my own responsibility. The review gives your technician clear instructions and gives you a signed document to show clients and insurers.

Will our IT provider be replaced?

No. I don't touch your systems and I don't resell services. The provider stays yours: they receive a remediation plan in order of risk and their work is verified. It is oversight, not competition.

What exactly counts as a "workstation"?

A workstation is any desktop, laptop or server that accesses the firm's data, regardless of headcount. The price depends on workstations, not people: two professionals with five devices count as five workstations.

How long does it take and how much does it disrupt the firm?

The on-site work is at most two half-days. The documents arrive within 15 working days. I work around your commitments: there is no need to stop the firm or switch systems off.

What if the review finds serious problems?

They go into the remediation plan, in order of priority, with the criteria to verify each is closed. The response sheet states the real position and refers to the plan: never window-dressing. That honesty is exactly what makes it useful in front of clients and insurers.

Who is accountable for what you sign?

The consultant who signs. Signing is an assumption of professional responsibility, backed by professional indemnity insurance with a €5,000,000 limit. That is why your IT provider cannot sign for what they sell, while an independent consultant can.

Problems I solved

Recurring situations, made anonymous.

Representative cases from the firms I work with. Names and identifying details are omitted.

Client questionnaire

The bank wants evidence, not reassurance

An accounting firm receives a security questionnaire from its banking client, with a request for evidence. The practice software cannot answer for the firm and the technician is unwilling to sign. The review established the real state of the controls in writing, and the signed response sheet closed the request without further back-and-forth.

Cyber policy

Policy renewal refused

The proposal form asked for controls never verified in writing and the renewal had been refused: no one could say what was actually in place. The review separated what was already present from what was missing, with a remediation plan in order of risk for the IT provider. The insurer's answers were signed against the facts, not against good intentions.

Oversight

"It's all fine", but with no proof

The IT provider reassured the firm verbally, never with verifiable evidence, and the owner had no way to know if it was true. I did not replace them: I gave clear instructions in order of risk and verified the work. Some points were already fine, others were not, and it was put in writing who had to close them and how to prove it.

Multiple sites

A backup no one had tested

A firm with a secondary office assumed a backup no one had ever tried to restore: two offices, one copy, no check. The review covered both sites and the report explained to the owner, in plain language, where the risk actually was and in what order to address it. The remediation plan went to the provider, the response sheet stayed with the firm.

Access

A former colleague, access still live

A colleague had left the firm months earlier, but their accounts and access to the practice software were still active and no one had noticed. The review listed access and responsibilities, the remediation plan gave the IT provider a verifiable revocation procedure, and closure was recorded in the response sheet.

Responsibility

The client who asked who is accountable

At a notarial firm, an institutional client asked not only what had been done, but who was personally accountable for it. The consultant's signature gave the answer a weight an internal self-declaration could not: the firm could show a document signed by the person who had actually done the review.

The first step

Let's talk.

A 30-minute conversation, no commitment, to see whether the service fits your firm.

Book the review