Prepared for Valerie, Thomas, and Forrest · following our call, September 1, 2026

Last year we raised your score.
This year, let's make it stick.

Eighteen months ago Diageo asked for a number and we went from a forecast under 400 to 649, with 26 new policies behind it. Now CyberVadis is asking again, and a rough week just showed why the paperwork was never the point. Here's the plan: get the reassessment done, close out the incident properly, and put real protection on every machine so the next ScreenConnect never gets a foothold.

649your 2025 CyberVadis score, from a forecast under 400
26policies written for PMM last year, ready to build on
1number your team calls when something looks wrong

Tampa to Louisville, Los Angeles, and everywhere PROOF activates: we already know your Workspace, and it's all remote anyway

From our call on Tuesday

We listened. Here's what we heard.

First, the part that deserves saying out loud: you handled a bad Saturday about as well as a team without a security partner can. You caught it within the hour, got the warning out to 1,200 people before lunch, changed the passwords that mattered, called the bank, and took the laptop to someone. That's more than most companies your size manage. You just shouldn't have had to do any of it yourselves. Here's what's actually in the way:

The reassessment clock is running

CyberVadis opened your reassessment on August 27, and Diageo is still the one asking. Last year's score was built on 26 new policies and a set of Workspace changes. This year the questionnaire will ask what changed, and an incident you can document well is worth more than one you hope they don't notice.

A remote-control tool nobody installed on purpose

ScreenConnect sat on the laptop for five days before anything happened, and the scanner passed it the day before because it's a legitimate program. That's the whole problem with antivirus alone. The question isn't "is this file bad," it's "should this be running here at all." Nothing on the machine was asking that question.

1,200 people got an email from you

Clients, vendors, family, and the two 401k reps. Some clicked. Some typed a password into a fake Google page. Forrest did the right thing quarantining the list, but the list existed because the mailbox was readable from a session nobody knew was open. That's fixable, and it's the part CyberVadis will ask about.

"Why didn't Gmail catch it?"

Fair question, and the honest answer has two parts. Google Workspace has settings we can tighten, and we'll tighten them in week one. But no spam filter would have stopped this one, and we'd rather tell you that now than sell you a filter. The real answer lives on the computer, not in the inbox.

"I clicked it. Now what?"

You've got someone fielding those calls today, out of goodwill. You asked whether our team could take that on. Yes. That's the difference between a cybersecurity vendor and a security partner: your people get a number, the same number, every time something looks off.

Last year's policies were honest about being forward-looking

We said so at the time: MFA was turned on but not enforced, and several policies described where PMM was headed rather than where it stood. Those were the right calls under a February deadline. This year, the gap between the paper and the practice is what we close.

The work that starts now

Two projects, priced, ready to start this week

You told us to send the assessment over and you'd sign it. So here it is, on the same terms as last year, with one addition you also asked for: a proper investigation of what happened, in writing. Both are fixed prices. Neither requires you to commit to anything ongoing.

The CyberVadis reassessment same as 2025

$4,500

The full questionnaire, answered and evidenced by us, the way we did it in February 2025. We refresh all 26 policies to reflect what's true today, add the incident-response record this year's assessors will expect, and re-verify every Workspace control with screenshots. We manage the CyberVadis analysts directly, so nobody at PROOF spends a night on their portal.

One thing we'll do differently: last year several controls were "on but not enforced." This time we enforce them, with a rollout your team is told about in advance. Everything we saw last year says the next number is higher than 649. This time we want it to hold.

The incident investigation new this year

$2,500

The questions you asked us on Tuesday, answered with evidence rather than guesses. We pull the ScreenConnect and Windows logs still on the laptop, the Workspace audit trail for Aug 21 through 29, and the browser and download history, and we tell you three things in writing: how it got in, what was touched, and whether anyone has to be notified.

You also get the cleanup you asked for: the Workspace hardening, MFA enforcement, a review of the accounts that were logged in during the window, and a one-page note your staff and your broker can actually use. If notification is owed, we'll say so and help you write it. If it isn't, you'll have the document that says why.

  1. This week

    Sign, and we start the same day. The investigation runs first, because its findings feed the reassessment. Workspace gets tightened in the first 48 hours, before anything else.

  2. Weeks one and two

    Incident findings delivered in writing. Policies refreshed and evidence gathered. MFA enforcement announced to staff, then switched on. Two or three business questions for Valerie or Thomas, same as last time. That's the extent of your homework.

  3. Submission

    Questionnaire submitted well ahead of the CyberVadis deadline, with the incident disclosed the way assessors respect: what happened, what you did, and what changed. We handle the analysts' follow-ups until the scorecard publishes.

The part that keeps it from happening again

The same week, with Fortify in place

A policy binder didn't stop August 29, and another one won't stop the next one. Here's the week you just lived, stage by stage, next to how it goes when every company computer has our security layer on it. Nothing on the right is hypothetical. These are the tools we run for our clients today.

What happened · Aug 21 to 24

Something got in, and nobody saw it

With Fortify

The installer never runs

Click any stage, or let it play.

On every machine

  • Application control: only approved software runs. Remote-access installers, unknown executables, and "helpful" browser add-ons are blocked by default
  • Managed detection and response, monitored 24 hours a day by a security operations team, with the authority to isolate a machine at 3 AM
  • Endpoint protection that watches behavior, not just file names, so a legitimate tool doing an illegitimate thing still gets stopped
  • Disk encryption on, patching on a schedule, and a written inventory of what's on each computer

On your people

  • Security awareness training with a completion record, four sessions a year, built around what actually hit PROOF
  • Quarterly phishing simulations, so a fake Google login page is something your team has already seen and refused
  • MFA enforced across Google Workspace and everything that supports it, with a rollout plan instead of a surprise
  • The "I clicked it" line: your staff call us, we handle it, you get a summary

On paper, when it counts

  • An annual external penetration test, with a report that reads like English and a fix list we own
  • Dark-web monitoring: if a PROOF credential shows up for sale, we know before the buyer uses it
  • A quarterly risk-score report to leadership: what improved, what's open, what it means for the next CyberVadis cycle
  • Every future assessment, questionnaire, and client security review managed by us. Diageo asks, we answer

Honest options

Two ways to keep us around. You pick.

You asked for a cybersecurity package you could pay for on its own. That's Path A, and it's a real plan, not a consolation prize. Then there's Path B, which is what we'd choose if PROOF were our company. You haven't asked for it, and we know that. We'd just be doing you a disservice not to put it next to the other one.

Path A Fortify, on its own

$40per user / month

Everything in the three columns above, on every company computer and every company account, run by our security team. The annual CyberVadis reassessment is included from year two on, so this year's $4,500 is the last time you pay for it as a project. Your existing IT arrangement stays exactly as it is. We handle security, you keep handling the rest.

  • Application control, managed detection, and behavioral endpoint protection on every machine
  • Enforced MFA, awareness training, phishing simulations, dark-web monitoring
  • Annual penetration test and quarterly risk-score report
  • Incident response: first call, containment, and the written report, at no extra charge when it's ours to catch
  • All future CyberVadis cycles and client security questionnaires managed by us

Right for PROOF if you're happy with how day-to-day IT gets handled today and the gap is purely protection. That's a legitimate answer, and plenty of our clients started here.

Path B Manage plus Fortify

$175per user / month

Path A, plus we become PROOF's IT department. One number for every computer, every login, every new hire and every departure, Google Workspace administered properly, laptops that show up configured, and a partner at the table when the next Diageo requirement lands. Security is cheaper and better when the same team already runs the machines it's protecting.

  • Unlimited helpdesk for every user, wherever they are: Louisville, Los Angeles, on the road, at an activation
  • First-day and last-day runbooks: accounts, laptop, and email ready before they start, everything closed the hour they leave
  • Google Workspace owned end to end: sharing, retention, device management, licensing cleanup
  • Procurement handled: we order it, build it to the standard, ship it to the person
  • Quarterly sit-downs with Valerie and Thomas: what happened, what's next, what it costs

Right for PROOF if "who handles that?" is a question anyone still asks. The honest math: the security layer in Path A is priced to stand alone. In Path B it drops to $25 because our agents are already on the machine.

Either path is month to month after the first year. Either path starts with the two projects above. And on either path, $1,500 of this year's project fee credits toward your first months, the same term that was in your 2025 agreement.

The numbers

The investment, no fine print

Two one-time projects, then a monthly number that's per person and moves with your headcount. Not per incident, not per hour. The first two lines are the ones you already said yes to. The rest is your decision, on your timeline.

Path A, monthly: Fortify on its own

Protected users a company computer, or company email that needs the security layer
40
Fortify, standalone per user$40
Your monthly number $1,600
Credit applied: $1,500 of this year's project fee comes off your first monthly invoices on either path, per section 9.1 of your 2025 agreement.

Starting now one-time

$7,000

$4,500 reassessment, the same scope and price as your January 2025 agreement, plus $2,500 incident investigation with the written findings and the Workspace hardening.

Sign these two and the security layer's deployment on every machine is included when you choose a path within 60 days. No separate onboarding fee for Path A.

If you choose Path B one-time

$2,500

Onboarding for the full IT relationship: agents and standards on every machine, the Workspace and licensing review, the first-day and last-day runbooks, and the written standard with your twelve-month roadmap. Making your current setup right is part of starting, not an extra.

Why us, and what happens next

You already know how we work. That's the pitch.

Eighteen months ago Todd sent you our way with a deadline three weeks out and a score nobody liked. We got it done, and then we got out of the way. That's still who we are: a Tampa managed-IT and security firm, twenty-five years in, big enough to run a real security practice and small enough that Valerie calls Josh's cell. This time the ask is bigger than a questionnaire, and we'd like to be the people who make sure it never gets this big again.

The next step is 30 minutes

Read this with Thomas and Forrest, then let's walk through it together: the investigation, the two paths, the real headcount, and the hard questions. Say the word and the two project agreements go out the same day. Then you choose a path on your own timeline, or you don't yet. Either way you'll have the reassessment handled and the incident closed properly.

Email Josh to set it up or just call or text: (813) 766-9995

Josh Easters and Dave Work, Diversicom