Know what you own, who can reach it, and whether the backup actually works.
The technology foundation — what systems exist, what they hold, who can reach them, how you recover when something breaks, and how sensitive records are protected under the confidentiality rules that actually apply to human-services work.
Does this sound like your technology?
“Nobody has an inventory of your systems, what each costs, what data each holds, or who administers it.
“Access is granted informally and never reviewed. Departed staff retain accounts. At least one critical system has a shared password.
“Backups are assumed rather than tested. Nobody has attempted a restore.
“There is no incident-response plan, so a ransomware event or a lost laptop becomes an improvisation on the worst day of the year.
“Protected records are stored in systems chosen without reference to the confidentiality rules that govern them.
“Technology contracts auto-renew and nobody has read them since signing.
The foundation underneath your systems
- A systems and vendor inventory: every application, what it does, what data it holds, what it costs, who administers it, the contract term, and whether it is actually used.
- A target architecture: what to consolidate, keep, and retire, in what order, with the cost and disruption of each move stated.
- Identity and access management conventions: role-based access, multi-factor authentication, an administrator inventory, provisioning and deprovisioning tied to the HR onboarding and separation checklists, and periodic access recertification.
- Backup, recovery, and continuity conventions with a tested restore and a written recovery-time expectation for each critical system.
- An incident response plan scaled to your organization — who is called, in what order, what gets preserved, who notifies whom, on what clock — proven with a tabletop exercise.
- A data classification and handling standard mapped to the confidentiality regimes that apply to your work, including what may not be stored on personal devices or personal cloud accounts.
- A security-awareness training package for staff, and a device and acceptable-use policy.
- Vendor and contract management: renewal calendar, security-review checklist for new vendors, and a data-processing schedule for vendors touching protected information.
The deliverables
Systems and vendor inventory · target architecture with sequencing and cost · access management conventions and administrator inventory · provisioning and deprovisioning workflow · backup and recovery plan with a documented tested restore · incident response plan and tabletop record · data classification and handling standard · security-awareness training package · acceptable-use and device policy · vendor renewal calendar and security-review checklist.
What you can run afterward
You know what you own, who can reach it, and what it costs. Access changes follow a workflow. A restore has actually been tested. When an incident happens, someone opens a plan instead of a browser.
Where the line is
We design and implement the architecture and the conventions, and we can manage the transition. Where you need ongoing helpdesk and device management, we specify the requirement, run the selection, and hand you a managed relationship with a provider you contract directly — rather than becoming your permanent helpdesk. Security architecture is not a substitute for your own legal compliance obligations.
Through The Assessment and Implementation Coaching.