Skip to content

Independent IT Assessment

Your IT deserves a
second opinion.

We know what your IT provider should be doing. We check if they are. An independent answer for firms that can't afford to guess.

25 years in IT · Assessments mapped to CIS Controls v8.1.2 · Former MSP executive turned independent advisor

  • CIS Controls v8.1.2
  • NIST CSF 2.0
  • HIPAA Security Rule
  • FTC Safeguards Rule
  • ABA Model Rules
  • AICPA SQMS No. 1

How It Works

A CPA audits your books.
We audit your IT provider.

Tidebreak conducts structured, independent assessments of your IT environment, evaluating your provider's performance against the frameworks used by the firms that insure you. Good providers welcome an independent read. We give them defensible evidence too, and the few that resist are themselves a finding.

  1. 01

    Examine.

    Documentation review and technical assessment of your environment, controls, and contracts.

  2. 02

    Interview.

    Structured conversations with your team and with your IT provider. Inquiry is evidence. What's configured is one story. What actually happens is often another.

  3. 03

    Map.

    Findings mapped to CIS Controls v8.1.2 and NIST CSF 2.0, with severity, evidence basis, and recommended action.

  4. 04

    Report.

    You receive a scorecard, a remediation roadmap, and a briefing session. Deliverables sized to the engagement tier.

Services

Three ways to engage.

Fixed fee, set in the scoping conversation. Typical-investment bands shown per tier.

TIER 1

Snapshot Scorecard

$12,000 to $20,000

1 to 2 weeks

A fast visibility read on where your controls stand. Scorecard plus a short remediation roadmap.

★ The core engagement

TIER 2

Comprehensive Assessment

$35,000 to $45,000

3 to 5 weeks

The core engagement. Documentation review, technical assessment, structured interviews with your team and with your IT provider, and a review of your MSP contract and service-level commitments against what's actually being delivered. You receive a full deliverable set built around five core documents: an Executive Report for your leadership, a Full Assessment Report, a Risk Register, a Remediation Roadmap, and a CIS Controls v8.1.2 Scorecard. Where the scope reaches them, the set also carries an MSP Assessment Summary, a Cloud Migration Assessment, a Vulnerability Assessment, a Hardware and Device Inventory Summary, a Secure Score Reconciliation, and a Platform Decision Memo. The engagement closes with a briefing session for your leadership.

TIER 3

Ongoing Oversight

$50,000 to $75,000 per year

Quarterly retainer

An independent read as a standing part of governance. Quarterly reassessment plus advisory.

Sample finding

What a finding actually looks like.

Drawn from a real 2026 engagement, anonymized. Every finding is severity-rated, mapped to a control and to the professional standard that governs the practice, and cited to the evidence behind it.

From a 2026 assessmentCritical

Backup recovery has not been tested in the last 12 months

Your provider's documentation shows backups running nightly. In interview, no one on the IT team could point to a documented recovery test. The last one on record is outside the 12-month window most frameworks treat as the acceptable maximum. A backup you have never restored is not a recovery plan; it is an assumption.

Remediation direction

Quarterly recovery tests against a documented runbook, with results retained as evidence for your insurance renewal and any future audit.

  • CIS v8.1.2 Control 11.5
  • NIST CSF 2.0 RC.RP

See a full sample report →

This finding is drawn from a 2026 Comprehensive Assessment of a law firm. The same engagement surfaced a critical-severity software vulnerability running across dozens of endpoints and end-of-life software still in daily use, each mapped to a CIS safeguard and to the firm's professional-conduct obligations, with the evidence cited behind it.

Implementation score · illustrative

0/ 100

Scored 0 to 100 against CIS Controls v8.1.2 Implementation Group 2. Representative, not drawn from any engagement; every Full Assessment Report discloses the calculation and its inputs.

You wouldn't let your bookkeeper audit your own books. Why are you letting your IT provider grade their own security?

Portrait of Jeff White, founder of Tidebreak Advisory.

The person behind the firm

We assess MSPs. I used to run one.

Jeff White has spent twenty-five years in the IT business. Enterprise infrastructure architecture. Eight years at Microsoft Consulting Services. Most recently, VP of Engineering Services at a mid-market MSP, where he built out the service delivery organization and a 24/7 security operations center from the ground up.

Now he works for you, not your provider. Tidebreak exists to give firms like yours a read most don't have a way to get: an independent look at whether the IT you pay for is actually the IT you're getting.

  • VP Engineering Services, MSP
  • 8 years Microsoft Consulting Services
  • Azure Solutions Architect Expert
  • Assessments mapped to CIS Controls v8.1.2 and NIST CSF 2.0

“We expected a second opinion to put us at odds with our IT provider. The opposite happened: the assessment gave both of us the same evidence to work from, our provider took the roadmap and ran with it, and for the first time we have a way to see that it's getting done.”

Managing Partner · Law firm
Time in IT
25 yearsin IT, from enterprise to MSP
Referral fees taken
0referral fees or vendor kickbacks, ever

Who we work with

Firms where the stakes go beyond downtime.

Organizations where client confidentiality isn't optional, and where the cost of an IT failure goes far beyond a day of lost productivity.

Law Firms

ABA ethics rules require technology vendor oversight. Your clients trust you with privileged information. We help you verify that your IT provider is protecting it.

ABA Model Rules

Healthcare Practices

HIPAA Security Rule compliance starts with knowing whether your IT environment meets the standard. Most firms assume their MSP has it covered. We verify it.

HIPAA Security Rule

Financial Services

FTC Safeguards Rule, SEC disclosure requirements, FINRA examinations. Your regulators expect evidence-based security controls. We help you prove you have them.

FTC Safeguards Rule

Fair questions

The things firms ask before engaging.

No. The assessment is designed to run alongside your existing IT provider, with their participation in fieldwork. The final report is as useful to them as it is to you: a neutral third read on where controls are strong, where they are not, and what a disciplined remediation plan looks like. Most MSPs welcome it; a few do not, and that itself is a finding.

Read the full FAQ →

Not sure if your IT provider is doing enough?

That question is the right place to start, and it's one I know from the other side. We assess IT providers now; I used to run one. Tell us a little about your firm.

By submitting this form you agree to our Privacy Policy. Tidebreak does not sell personal information, does not train AI models on it, and does not share it with any organization Tidebreak assesses.