Cybersecurity & Managed IT Prepared for Valerie, Thomas, and Forrest · after our call on September 1
Last year we raised your score.This year, let's make it stick.
Eighteen months ago Diageo asked for a number, and together we took PROOF from a forecast under 400 to 649. Now
CyberVadis is asking again, and one rough Saturday just showed why the paperwork was never the point.
Here's the plan: get the reassessment done, close out the incident properly, and put real protection on
every machine so the next ScreenConnect never gets a foothold.
The lowest bar is Identify: knowing what's on your machines and who's on them. That's exactly the gap August exposed, and it's the one that moves the most.
FROM Five silent days, then Geek Squad
TO Someone on the door, 24/7
The principle
The door, the floor, and the wrap report, brought to the laptops you run on.
"Nobody at PROOF would run a Smirnoff night at SoFi without a guest list at the door, security on the floor,
a staff briefing, and a wrap report. Your forty laptops ran the last five years without any of those. That's the whole
gap, and it maps one to one. Everything on this page is us bringing your own standard to your own machines."
Joshua R. Easters, Managing Partner, Diversicom
What you produce
Experiential campaigns for Diageo, Smirnoff, Don Julio, and the brands that live on them
Activations in Louisville, Los Angeles, and wherever the client needs a crowd
A remote team on Google Workspace, with ambassadors and vendors coming and going
A reputation built on the PROOF is on our people and our results
same standard
What we produce
25 years of managed IT and security for Florida businesses, from the same Ybor City office
A real security practice: application control, managed detection, a 24/7 security operations team
The team that already wrote PROOF's 26 policies and knows your Workspace from the inside
The same do-it-right approach, applied to the machines behind the people
The guest listApplication control
Nobody gets past the door without a wristband. On a computer, only approved software runs. A remote-access installer with no wristband gets stopped at the rope, and we hear about it within minutes.
Security on the floorManaged detection, 24/7
Eyes on the room the whole night, not a walkthrough at close. A security operations team watches every machine around the clock and can pull one off the floor at 3 AM.
The staff briefingTraining and phishing drills
Your ambassadors know the pour, the script, and who to call. Your staff will know a fake Google login when they see one, because they've already refused one in a drill.
The wrap reportQuarterly risk report
Every event ends with numbers the client can read. Every quarter you get the same for security: what improved, what's open, and what it means for the next CyberVadis cycle.
We did our homework
We already know your week.
First, the part that deserves saying out loud: you handled a bad Saturday about as well as a
team without a security partner can. You caught it within the hour, warned 1,200 people before lunch, changed the
passwords that mattered, called the bank, and took the laptop to someone. You just shouldn't have had to
do any of it yourselves. Here's what we mapped from Tuesday's call and last year's work.
Aug 24
ScreenConnect lands
A legitimate remote-control tool, installed by the wrong people. Antivirus passed it the day before.
Aug 29, 8:02 AM
RiskWare fires
mymals.exe scrapes every address ever sent, received, or copied. About 1,200 of them.
Aug 29, 8:05 AM
"A night to remember"
Sent as you, to clients, vendors, family, and both 401k reps. Some typed a password into a fake Google page.
Aug 30 to Sep 1
36 things removed
Geek Squad found ScreenConnect still mirroring in the background. A work order, not a report.
Company computers
About 40
Plus personal devices in the mix. Count confirmed together on the walkthrough
Email and files
Google Workspace
No physical office. Workspace is the whole environment, and we hold a super-user seat from 2025
MFA today
On, not enforced
We said so in February 2025. This year it gets enforced, with a rollout your team hears about first
Policies on file
26, from 2025
Access, PAM, passwords, incident response, and 22 more. Ready to refresh, not rewrite
Who's asking
Diageo, via CyberVadis
Reassessment opened August 27. We manage the analysts directly, like last time
The UHC emails
Genuine. Not the source
Both are real Proofpoint messages from UHC's own mail system. We'll show you how we confirmed it
The work that starts now
Two projects, priced, ready this week.
You told us to send the assessment over and you'd sign it. Here it is, on the same terms
as last year, with one addition you also asked for: a proper investigation of what happened, in writing.
Both are fixed prices. Neither requires anything ongoing.
Same as 2025
The CyberVadis reassessment
$4,500fixed
The full questionnaire, answered and evidenced by us, the way we did it in February 2025. We refresh all 26 policies to reflect what's true today, add the incident-response record this year's assessors will expect, and re-verify every Workspace control with screenshots.
One thing we do differently this time: last year several controls were on but not enforced. This year we enforce them. Everything we saw last year says the next number is higher than 649. This time we want it to hold.
We manage the CyberVadis analysts; nobody at PROOF spends a night on their portal
Two or three business questions for Valerie or Thomas, same as last time
The incident disclosed the way assessors respect: what happened, what you did, what changed
New this year
The incident investigation
$2,500fixed
The questions you asked on Tuesday, answered with evidence rather than guesses. We pull the ScreenConnect and Windows logs still on the laptop, the Workspace audit trail for August 21 through 29, and the browser and download history.
You get three things in writing: how it got in, what was touched, and whether anyone has to be notified. If notification is owed, we say so and help you write it. If it isn't, you have the document that says why.
Workspace hardening and MFA enforcement in the first 48 hours
A review of every account that was signed in during the window
A one-page note your staff and your broker can actually use
This week
Sign, and we start the same day. The investigation runs first because its findings feed the reassessment. Workspace gets tightened before anything else.
Weeks one and two
Findings delivered in writing. Policies refreshed, evidence gathered. MFA enforcement announced to staff, then switched on. That's the extent of your homework.
Submission
Questionnaire submitted well ahead of the CyberVadis deadline. We handle the analysts' follow-ups until the scorecard publishes.
Then, your call
Choose a path below, or don't yet. Either way the reassessment is handled and the incident is closed properly, with a document you can hand to anyone who asks.
Run of show
The same week, with security on the floor.
You plan every event cue by cue. Here's the week you just lived, laid out the same way,
next to how each cue goes when every company computer has our security layer on it. Nothing on the right
is hypothetical. These are the tools we run for our clients today.
With Fortify Contained at cue 1
You're onCue 1: The lure
The week
Cue 01 · Aug 21 to 24
The lure
Between an executive's forward, a broker's reassurance, and an ordinary weekend of email, a remote-control tool ended up installed on the laptop.
As it ran
Something got in, and nobody saw it
No alert, no prompt anyone remembers. Legitimate software used by the wrong people is exactly what antivirus is built to ignore.
With security on the floor
The installer never runs
Application control means only approved software can run. An unapproved remote-access installer is blocked on the spot, and the block lands on our desk with the machine, the user, and the file named.
What you'd notice Nothing. That's the point. A short note from us that something was stopped, and who to remind.
Cue 02 · Aug 24 to 29
Five quiet days
For five days a remote session sat open on a laptop that signs into payroll and the bank. Nothing looked wrong from the chair.
As it ran
A stranger with a seat at the desk
Malwarebytes scanned the day before and passed it, because a signed remote-access tool is not malware. Nothing on the machine was asking whether it should be there.
With security on the floor
Someone is watching the door around the clock
Managed detection on every machine, monitored 24 hours a day by a security operations team, sees a remote-control session that has no business existing and isolates the computer while it wakes us up. Tuesday, not Saturday.
What you'd notice A call from us on Tuesday, and a laptop that's already been cleaned.
Cue 03 · Aug 29, 8:02 AM
The payload
A file called mymals.exe loads through the open session and starts harvesting while the laptop sits alone.
As it ran
RiskWare fires, 1,200 contacts scraped
Every address ever sent, received, or copied, personal and business, going back decades. Plus a payroll document pulled into Downloads.
With security on the floor
Killed at the first move
Endpoint detection watches behavior, not names. A process that starts reading the mailbox and writing a contact list is stopped at the first read, the session is cut, and the account's sign-ins are revoked. The list is never built.
What you'd notice An alert on your phone from us, before the boxing class ends.
Cue 04 · Aug 29, 8:05 AM
The blast
"A night to remember" goes to clients, vendors, friends, and family from the real valerie@ address.
As it ran
1,200 invitations, sent as you
A handful of people who should have known better typed a password into a fake Google page. Now their accounts are the next problem.
With security on the floor
Nothing to send, and nowhere for it to land
The blast never happens because the harvest never did. And on the receiving end, MFA enforced across Workspace and staff drilled on lookalike login pages means a password typed into a fake page opens nothing.
What you'd notice No "disregard that email" note. No calls from your 401k rep.
Cue 05 · Aug 30 to Sep 1
The week after
The laptop goes to Geek Squad. Passwords change, a card gets closed, the banker gets a call. And the questions nobody can answer yet.
As it ran
Best Buy, guesswork, and open questions
Thirty-six things removed, a work order for a receipt. What did they see, and who has to be told? Still open a week later.
With security on the floor
An incident report by Monday, in writing
Our team pulls the logs the same day and writes it up: timeline, exposure, whether notification is owed, and what changed. One call to make, to us, and a document you can hand to anyone who asks. That includes CyberVadis.
What you'd notice A calm Monday, and a PDF.
You asked, we answered
Every question from Tuesday's call.
You asked a lot in an hour, and every one deserved a real answer. Here they are, in writing. Filter by area.
The incident
Was the UHC email the source of the ScreenConnect?
No. We took both emails apart. They're genuine Proofpoint secure messages from UHC's own mail system, and the attachment is a plain form with no code in it. Something else got in that week, and the investigation finds out what.
Answered
The incident
What could they have seen or taken?
Best case, a phishing-only campaign, which is what the evidence so far looks like. ScreenConnect does give hard-drive access, so we work the logs to a written determination rather than guess. That's the investigation.
In the investigation
The incident
Do we have to notify anyone?
If the facts support phishing-only, no. If they don't, we tell you plainly and help you write the notice. Either way you get the document that says why, which is what your broker and CyberVadis will want.
In the investigation
The incident
Did Geek Squad's cleanup destroy the trail?
Probably not. The ScreenConnect folder still on the drive is likely logs, which is why we asked you to leave it. Windows and Workspace keep their own records that a cleanup doesn't touch.
Answered
The incident
Why didn't Gmail catch it when other people's mail did?
Workspace has settings we can raise, and we raise them in the first 48 hours. But no spam filter would have stopped this one, and we'd rather say that than sell you a filter. The real answer lives on the computer.
Answered
The reassessment
Do we have to disclose the incident to CyberVadis?
Yes, and it's to your advantage. Assessors score how you detected, responded, and changed, not whether something happened. An incident you can document well is worth more than one you hope they don't notice.
In the reassessment
The reassessment
Will the score go up again?
We don't promise numbers. We can say that last year several controls were on but not enforced, and this year they get enforced. Everything we saw in 2025 says the next number is higher than 649, and with Fortify in place it holds.
Honest answer
Going forward
Can your team field the "I clicked it, now what?" calls?
Yes. On either path, your staff get one number, the same number, every time something looks off. We handle it and you get a summary. Your colleague who's been doing this out of goodwill gets his evenings back.
Included on either path
Going forward
What else should we change right now?
Two things, today: change the password on every account signed into during the window (Human Interest is still open), and turn on two-factor everywhere it's offered. Everything past that is the plan below.
Do this today
The Diversicom difference
Where a partner earns the name.
Plenty of vendors sell security software. These are the things that, day to day, make PROOF's life
genuinely easier, and they're built into how we work, not billed as extras.
One number, every time
Today a security question at PROOF finds whoever happens to be reachable. With us in place, everyone on your team has our support line, staffed by our helpdesk and security engineers. "Is this email real?" gets answered by a person in minutes, not by a group text.
Everything in writing
Incident reports, quarterly risk scores, the reassessment evidence. When your broker, your insurer, or Diageo asks, you hand them a document instead of a story.
No-surprise billing
Incident response on things we should have caught is on us. Projects are quoted in writing and approved first. When we say a number, it's the number.
A team that already knows PROOF
We wrote your policies. We've been in your Workspace admin console. We know Thomas, Forrest, and Todd. Nobody re-learns your business on the first call.
Wherever the activation is
Three cities, one desk. None of this needs a site visit.
You have no office to secure, only people and their machines, in Louisville, Los Angeles, and wherever
the client needs a crowd this month. That's the environment we built last year's work in, remotely, from Tampa.
Every tool on this page installs, monitors, and responds the same way whether the laptop is at a kitchen table or a
festival lawn. And the 12 to 2 window you offered us works in every one of these time zones.
LouisvilleOperations, Thomas and the Kentucky teamET
Los AngelesActivations, the West Coast crewPT
TampaDiversicom, same Ybor City office for twenty yearsET
9
states we already cover
1,500+
users under management
~15s
median time to a live person
Proof, for PROOF
Built for companies that get hit, and get back to work.
We've spent two decades supporting remote, regulated, and field-heavy teams, many of them the same size as
PROOF. We're happy to put you in touch.
25+
years managing IT and security in Florida and beyond
15+
industries served
1,500+
users with technology managed by us
24/7
security operations watching every protected machine
Regulated lab
Donor Services Laboratory
Tampa, FL · life sciences
A regulated laboratory whose leadership wanted security they could show an auditor, not just install. We run their environment day to day and handle the questionnaires and corrective-action plans their partners require.
Small team, big exposure
The Fechtel Company
Builder · Tampa, FL
A construction firm where money moves by email every day. They came to us for responsive support and straight answers, and their staff know exactly who to call the moment a message looks wrong.
Long partnership
Lions World Vision Institute
350 users · 17 locations · 10 states
A 20-year partnership that grew with them from 4 employees and one branch to nearly 400 across ten states, with the security and compliance work included the whole way.
Investment
Two ways to keep us around. You pick.
You asked for a cybersecurity package you could pay for on its own. That's Path A, and
it's a real plan, not a consolation prize. Path B is what we'd choose if PROOF were our company. You haven't
asked for it, and we know that. We'd just be doing you a disservice not to put it next to the other one.
Path A · Fortify
The door, the floor, and the wrap report, on its own
$40/user/mo
Priced to stand alone. Your existing IT arrangement stays exactly as it is
Application control, managed detection, behavioral endpoint protection on every machine
$4,500 reassessment, same as your January 2025 agreement, plus $2,500 incident investigation
Both fixed price, both starting the week you sign
Security-layer deployment on every machine included if you choose a path within 60 days
No separate onboarding fee for Path A; Path B onboarding is $2,500 one-time
$1,500 of this fee credits toward your first months on either path, per section 9.1 of your 2025 agreement
Your environment, by the numbers
≈ $1,600/mo
Change the path and the headcount to match reality. We settle the real count together on the walkthrough. The $1,500 credit comes off your first monthly invoices on either path.
Protected usersa company computer, or company email that needs the security layer
Fortify, standaloneper user$40
Manageper user$150
Fortify, add-on rateper user$25
Light userscompany email on their own device, security only
Light seatper user$75
Your monthly number
Credit applied: $1,500 of this year's project fee comes off the first monthly invoices, per section 9.1 of your 2025 agreement.
Last year, and this year
The same questionnaire, a different kind of engagement. Every line on the right is on this page.
What you get
2025
2026, with Fortify
The CyberVadis questionnaire
Answered and evidenced by us
Same, plus the incident disclosed properly
The 26 policies
Written, several forward-looking
Refreshed and enforced
MFA
On, not enforced
Enforced, with a rollout plan
What's on the machines
Antivirus you already had
Application control, managed detection, 24/7 SOC
When something gets in
Geek Squad and a work order
A written incident report
The next client questionnaire
Back to you
Managed by us. Diageo asks, we answer
Next year's reassessment
$4,500 project again
Included from year two
"I clicked it. Now what?"
A colleague, out of goodwill
One number, every time
Either path is month to month after the first year, and either path starts with the two projects above. The headcount is the one number we still need to confirm together.
Straight talk
What this assumes.
Transparency up front. The pricing above is based on the assumptions below. We confirm each on the walkthrough and review any material change with you before proceeding.
About 40 company computers and users, confirmed at kickoff. Brand ambassadors on their own devices are usually not a seat
Google Workspace stays the platform; our 2025 super-user seat is reactivated for the work
The laptop from the incident is available to us, with the ScreenConnect folder left in place until we've read it
Timely answers to the two or three business questions the questionnaire always raises
The CyberVadis deadline as shown in your portal; we submit ahead of it
MFA enforcement announced to staff before it's switched on, with our help writing the note
Path A pricing assumes no Diversicom management agent on the machines; Path B assumes it, which is why Fortify drops to $25
Any hardware or licensing we purchase for you bills at cost plus a stated markup, approved first
Next steps
You already know how we work. That's the pitch.
Eighteen months ago Todd sent you our way with a deadline three weeks out and a score nobody liked. We got it done, and then we got out of the way. This time the ask is bigger than a questionnaire, and we'd like to be the people who make sure it never gets this big again. Here's all it takes:
1A 30-minute walkthrough with Thomas and Forrest: the investigation, the two paths, the real headcount
2Say the word and the two project agreements go out the same day
3Choose a path on your own timeline, or don't yet. The reassessment gets handled either way