When a Client Asks How You Protect Their Data - You Should Have a Confident Answer
A 20-minute assessment gives your business a documented, industry framework-aligned information security baseline - plus a full year of ongoing guidance. Built for financial advisors, accountants, professional practices, and businesses that handle sensitive data. No IT department required.
Is multi-factor authentication required everywhere — for everyone, not just some people?
The firm answered Mostly.
The two accounts without it are the two an attacker would want most. IAM-02 is a critical control, so this caps the firm's overall maturity until it's closed.
Send to your IT provider
Which accounts are currently exempt from MFA, and why? A good answer names them. Not “everyone’s covered.”
See a no-cost sample report first…
The question is coming. Be ready before it's asked twice.
41% of small businesses are targeted by cyberattacks, and in 2026, AI has made those attacks faster, cheaper, and far more convincing. Phishing emails with perfect grammar. Phone calls that clone a client's voice. Software flaws exploited in hours instead of months.
Your clients, your insurer, and your regulator are all starting to ask the same question: how do you protect the data we trust you with?
Most small firms are challended to answer it because a consultant-led assessment costs $2,500 to $10,000, and generic checklists don't hold up when an insurer or examiner looks closely.
That gap is exactly what Echo Hill Security helps you address.
A trusted security advisor your firm can actually afford
How it works:
1. Answer. A 15–20 minute guided conversation covering all thirty controls. Morgan asks, you answer in plain language, and it follows up where something's unclear. No jargon, no wrong answers.
2. Receive. A personalized, framework-aligned assessment report: your security score, your priority risks, and a 30/60/90-day action plan sized for a firm like yours - delivered through a secure private link, never as an email attachment.
3. Keep going. Your assessment includes 12 months of advisory support. A one-page security note for your staff each month, a quarterly check on the findings you're still working through, and a full reassessment at twelve months showing exactly what moved. Questions by email — the ones that need a human answer, not a monitoring service.
What you get
Your security posture score — thirty controls mapped to NIST CSF 2.0 and CIS Implementation Group 1, scored by fixed arithmetic. The appendix shows every control and every point.
A full findings report — domain-by-domain results, findings prioritised by severity, and a 30/60/90-day plan sized for a firm like yours.
Provider question sheets — every control you couldn't confirm, turned into a specific question for your IT provider, platform, bank, or insurer, with what a good answer looks like.
Twelve months of advisory support — a monthly one-page security note for your staff, a quarterly check on open findings, and a full reassessment at twelve months showing exactly what moved.
We handle your assessment the way we'd tell you to handle client data
Your report documents your firm's security posture, so we treat it like the sensitive document it is. The conversation is encrypted in transit and nothing is stored on our servers - no conversation history, no saved reports. Your report is delivered through a private, expiring link. Your answers are never used to train models and never shared; anonymised statistics may inform published research, but nothing that identifies your firm. What we retain, and why, is in the privacy policy in plain English.
An advisory this careful with its own product is the kind of advisor you want.
Founding client pricing
Baseline Security Assessment + 12 months advisory — $1,495. First ten firms.
Your full assessment with Morgan, the complete findings report, and provider question sheets for every control you couldn't confirm. Then twelve months of advisory: a monthly one-page security note for your staff, a quarterly check on the findings you're still working through, and a full reassessment at twelve months showing exactly what moved.
Founding clients keep founding pricing for 24 months.
If the report doesn't give you a clearer picture of where your firm stands, we'll refund it within 30 days.
This is an advisory baseline assessment aligned to recognized frameworks - a practical starting point for stronger security and a documented answer for clients, insurers, and reviewers. It is not a formal audit, a penetration test, or a compliance certification, and no assessment can guarantee against incidents. We're honest about that, because honest is the only kind of security advice worth paying for.