I start with your question and bring the evidence back to it.
A fixed line of enquiry, a limited burden and a judgement on paper you decide on.
Your question
The question defines the scope
I start with what is business-critical, not with a standard or a checklist. A Reality Check is only valuable when it is clear what the executive, board or owner needs answered.
Sometimes it is cyber, sometimes IT, sometimes AI, and often the combination: AI on customer data, security at an MSP, a cloud dependency or a digital supply chain. The scope follows your question, not the other way round.
The line of enquiry
Six questions, the same on every assignment.
The six questions know no standard and no checklist. They follow the chain from what you cannot afford to lose to the evidence that it is protected.
What must not stop?
The critical process, service, customer promise or information that is directly hit by disruption.
What does it depend on?
The systems, suppliers, data, access rights, processes or AI applications beneath that critical process.
Who is accountable?
The person or role accountable for the decision, the follow-up, whether it works and the reporting on it.
What can go wrong?
The disruption, error, attack, decision failure or dependency that starts to matter to the business.
What is in place?
The arrangements, provisions and measures meant to contain that exposure, and what exactly they are meant to do.
Where is the evidence?
The evidence that agreements, measures and decisions exist, are carried out and work as intended.
Behind every measure is a decision, and a decision is only complete when it can be shown to work. A plan that has never been tested is a plan nobody knows will work.
Answer the six questions about your own company →The judgement
The evidence back to your question.
Anyone can collect evidence. What a Reality Check adds is the way back: every finding is set beside the others and judged together against your question. What has not been examined is stated too. So you know what is established, what rests on assumptions and what is open.
How deep I search for evidence, you decide with the tier.
What you assume
I walk through the six questions with you and set out on one page what you assume, what you claim and where the evidence should be. I verify nothing in it.
What your documentation proves
In addition I read the documents that already exist: contracts, reports, test records. What they prove is marked substantiated; what they do not cover is marked as a gap.
What actually holds
I examine the evidence itself and how it fits together: does the combination of measures carry the conclusion, where does one dependency break the chain, who is accountable.
A few conversations, and nothing you do not already have.
Every tier starts with a one-hour conversation in which we walk through the six questions. A second conversation of half an hour follows, in which I report back what I have found. From Core onwards I also read the documents that already exist. At Complete, where the question requires it, I also speak with the owner of the dependency or your provider.
You do not have to produce anything or gather anything that is not already there. Lead time is one week for Outline, two to three weeks for Core and two to four weeks for Complete, depending on the availability of people and data.
- Two conversations with me, 60 and 30 minutes.
- Your existing documents, from Core onwards.
- No preparation and no questionnaire beforehand.
A compact overview
A sharp view of what is substantiated, what rests on assumptions, where ownership is missing and which decisions are needed.
- Core question and scope
- Core picture of the critical dependencies
- Main exposure and uncertainties
- Decisions that are explicitly required
- Ownership and execution
- Available and missing evidence
- Where relevant: 30/60/90-day advice
The form follows the tier.
At Outline an evidence map of one page. At Core a compact memo with the statuses, the gaps, the contradictions and the decisions it puts before you. At Complete the full board memo, with advice for 30, 60 and 90 days and a briefing to the executive team or supervisory board.
The memo gives you substantiated input for your own decision and your own communication, internally or towards your supplier.
What you do with it
A memo is only useful if something changes because of it. These are the conversations where a Reality Check earns its keep.
The management meeting
The decisions that need to be made are set out, each with an owner. The conversation shifts from "we should do something about cyber" to who decides what, and by when.
The conversation with your supplier
You stop asking whether it is all under control and start asking what exactly is in place and what shows that it works. The gaps become the agenda for that meeting.
The investment decision
A quote for a tool, a migration or a certification programme can be weighed against the exposure you actually have, rather than the exposure the vendor points to.
The question from outside
When a customer, insurer or accountant asks how you manage digital risk, you have a substantiated answer, with its limits stated, rather than an assumption.
Whatever needs to happen next can then be assigned where it belongs. A Reality Check makes sure you know what you are assigning.
How findings bear on each other
A fictional example, included to show the form and the connections. This is not a client case.
Manufacturing company, 60 employees. The production line runs on a network and systems managed by a single external IT provider. Central question: can we show that we are in control of that provider?
The observation
IT management was outsourced years ago and has not been reviewed since. What the provider is expected to do about patching, access control and recovery after an outage is set out in a quote from 2019, not in a current contract.
Why it matters
Without a current contract there is no standard to hold the provider to. What actually happens may well be sound; you simply cannot establish that, and so you cannot steer on it.
This finding does not stand on its own. Other observations from the same case bear directly on it:
Ownership
No one is formally accountable for this provider's performance. In practice the operations manager picks it up. As long as the standard is missing, there is nothing to hold anyone to, the two keep each other in place.
Reporting
There is monthly reporting, but it has never been set against the contract. Reporting without a standard mainly confirms that something is being measured, not that it is right.
Recovery after an outage
How much downtime production can absorb has not been recorded anywhere, so the provider has never had to deliver against it. The same gap, one layer down.
Each of these can be addressed on its own, and doing so achieves little. Together they point to one thing: there is no recorded standard the provider is held to. That is what the decision is about. Making that connection visible is the work; a checklist does not produce it.
Discuss your question
In a short conversation we determine whether a Reality Check fits, what scope makes sense and which decision needs preparing.
- What is the trigger?
- What must not stop?
- What must you be able to decide?

