A Reality Check for cyber, IT and AI

Make digital dependency governable

Hartwich Risk & Resilience helps executives, boards and owners see what critical processes depend on, what is vulnerable, who is accountable and where evidence is missing.

Erik Hartwich, founder of Hartwich Risk & Resilience
Compact diagnosis
From fragmented input to a single clear picture.

Scoped, independent and focused on evidence.

The fixed line of enquiry

Five questions reveal what really matters

One fixed line of enquiry. Five simple questions.

ContinuityWhat must not stop?

The critical process, service, customer promise or information that is directly hit by disruption.

DependencyWhat does it depend on?

The systems, suppliers, data, access rights, processes or AI applications beneath that critical process.

ExposureWhat can go wrong?

The disruption, error, attack, decision failure or dependency that starts to matter to the business.

OwnershipWho is accountable?

The person or role accountable for the decision, the follow-up, whether it works and the reporting on it.

EvidenceWhere is the evidence?

The evidence that agreements, measures and decisions exist, are carried out and work as intended.

Behind every measure is a decision, and a decision is only complete when you can show that it works. A plan that has never been tested is not a plan.

For organisations that recognise this

A lot is in place, but the overall picture is fragmented

Policies, suppliers, tools and reports only create value once it is clear which critical dependency they actually cover, who is accountable and what evidence counts.

A lot is in place

Measures, suppliers, systems and reports are present.

Not enough coherence

Individual assurances do not yet add up to a coherent picture.

Ownership and evidence

It is not always clear who is accountable and what demonstrates that it works.
The real starting point

You know what must not stop

The Reality Check examines whether those dependencies are clear enough to manage.

Governable means: clear what is critical, what it depends on, what can go wrong, who is accountable and where the evidence lies.

Customer processCare processSupplier or MSPCritical applicationSensitive dataAI use case

The Reality Check does not start with technology, compliance or standard checklists. It starts with what must not stop and tests what lies beneath it.

Every assignment starts here

One concrete question defines the scope

A Reality Check is only valuable when it is clear what the executive, board or owner needs answered.

One questionOne domainOne processOne supplierOne systemOne AI use case
Can we show that we are in control of this critical supplier?
Are the dependencies beneath our critical process manageable?
Is our confidence in this AI application soundly based?
Cyber, IT, AI or a combination

The scope follows your question

Sometimes it is cyber. Sometimes IT. Sometimes AI. Often the question touches several domains at once.

Cyber

Digital threats, data breaches, ransomware, access management, incident response, NIS2 pressure.

IT

Systems, applications, infrastructure, cloud, MSPs, continuity and technical debt.

AI

AI use, data, output, agents, human approval, logging and permissions.

Combination

AI on customer data, security at an MSP, cloud dependency or a digital supply chain.
What you receive

A compact overview

A sharp view of what is substantiated, what rests on assumptions, where ownership is missing and which decisions are needed.

A Reality Check asks little of you and your team: a few conversations and the documents you already have. The memo gives you substantiated input for your own decision and your own communication, internally or towards your supplier.

From analysis to decision.

Responsibility becomes manageable once it is clear what needs attention first, who is accountable and what evidence is missing.

  • Core question and scope
  • Core picture of the critical dependencies
  • Main exposure and uncertainties
  • Decisions that are explicitly required
  • Ownership and execution
  • Available and missing evidence
  • Where relevant: 30/60/90-day advice
After delivery

What you do with it

A memo is only useful if something changes because of it. These are the conversations where a Reality Check earns its keep.

The management meeting

The decisions that need to be made are set out, each with an owner. The conversation shifts from "we should do something about cyber" to who decides what, and by when.

The conversation with your supplier

You stop asking whether it is all under control and start asking for the evidence that is missing. The gaps become the agenda for that meeting.

The investment decision

A quote for a tool, a migration or a certification programme can be weighed against the exposure you actually have, rather than the exposure the vendor points to.

The question from outside

When a customer, insurer or accountant asks how you manage digital risk, you have a substantiated answer rather than an assumption.

Whatever needs to happen next can then be assigned where it belongs. A Reality Check makes sure you know what you are assigning.

Illustration

How findings bear on each other

A fictional example, included to show the form and the connections. This is not a client case.

Manufacturing company, 60 employees. The production line runs on a network and systems managed by a single external IT provider. Central question: can we show that we are in control of that provider?

One finding

The observation
IT management was outsourced years ago and has not been reviewed since. What the provider is expected to do about patching, access control and recovery after an outage is set out in a quote from 2019, not in a current contract.
Why it matters
Without a current contract there is no standard to hold the provider to. What actually happens may well be sound; you simply cannot establish that, and so you cannot steer on it.

This finding does not stand on its own. Other observations from the same case bear directly on it:

Each of these can be addressed on its own, and doing so achieves little. Together they point to one thing: there is no recorded standard the provider is held to. That is what the decision is about. Making that connection visible is the work; a checklist does not produce it.

Practical indication

A scoped Reality Check with a fixed starting price

The final price depends on your question, the chosen scope and the information available.

From €4,990 excl. VAT

A scoped Reality Check with limited document review, analysis, clear interpretation and a compact memo.

  • One clear core question
  • A bounded scope
  • No hourly rate as the starting point
Deliberate boundaries

A fit when you are looking for clarity you can act on

Not a fit when you want to outsource execution, certification or formal assurance.

Fits with

  • A concrete question
  • Uncertainty about cyber, IT or AI
  • A fragmented overall picture
  • Preparing a decision
  • Evidence is missing or unclear

Does not fit with

  • Audit or pentest
  • Formal assurance statement
  • Certification
  • Implementation project
  • Tool selection or interim CISO
How the Reality Check works

Focused enquiry, limited burden, clear outcome

The method is compact: sharpen the question, review the relevant information, formulate conclusions and explain them clearly.

1
Sharpen the central question
2
Work through the five questions
3
Review the relevant information
4
Analysis and clear interpretation
5
Compact memo and briefing
Erik Hartwich, founder of Hartwich Risk & Resilience
Why Hartwich Risk & Resilience

Fine words at director level are only valuable when the reality beneath holds up

I am Erik Hartwich. Since 1990 I have worked in the digital systems organisations run on: as a network and systems administrator, infrastructure architect and security advisor. From the data centre of a retail group to the security standards of one of the largest telecom operators in the Netherlands. Not from the boardroom, but from the operations beneath it.

That background is why a Reality Check holds up. I have seen up close where assumptions at the top and technical reality diverge, and I test whether that is the case for you.

Experience as a touchstone, not a story.

Most of what runs in a data centre I have built, managed or improved myself. I use that depth to test whether the picture at the top matches what actually lies beneath it.

  • Technical depth without unnecessary jargon
  • An eye for systems, suppliers and processes
  • Independent assessment
  • A sharp separation of dependency, ownership and evidence

No tools, no implementation, no stake in the outcome. My full career history is on LinkedIn.

Starting point

Discuss your question

In a short conversation we determine whether a Reality Check fits, what scope makes sense and which decision needs preparing.

  • What is the trigger?
  • What must not stop?
  • What must you be able to decide?
Erik Hartwich, founder of Hartwich Risk & Resilience