Approach

I start with your question and bring the evidence back to it.

A fixed line of enquiry, a limited burden and a judgement on paper you decide on.

1. Your question2. The line of enquiry3. The judgement
1

Your question

The question defines the scope

I start with what is business-critical, not with a standard or a checklist. A Reality Check is only valuable when it is clear what the executive, board or owner needs answered.

Can we show that we are in control of this critical supplier?
Are the dependencies beneath our critical process manageable?
Is our confidence in this AI application soundly based?
Does our service hold up if this application is down for a week?
Is what we have in place for cyber security shown to work?
Can we tell our customers, with substantiation, how we protect their data?

Sometimes it is cyber, sometimes IT, sometimes AI, and often the combination: AI on customer data, security at an MSP, a cloud dependency or a digital supply chain. The scope follows your question, not the other way round.

2

The line of enquiry

Six questions, the same on every assignment.

The six questions know no standard and no checklist. They follow the chain from what you cannot afford to lose to the evidence that it is protected.

Continuity

What must not stop?

The critical process, service, customer promise or information that is directly hit by disruption.

Dependency

What does it depend on?

The systems, suppliers, data, access rights, processes or AI applications beneath that critical process.

Ownership

Who is accountable?

The person or role accountable for the decision, the follow-up, whether it works and the reporting on it.

Exposure

What can go wrong?

The disruption, error, attack, decision failure or dependency that starts to matter to the business.

Measure

What is in place?

The arrangements, provisions and measures meant to contain that exposure, and what exactly they are meant to do.

Evidence

Where is the evidence?

The evidence that agreements, measures and decisions exist, are carried out and work as intended.

Behind every measure is a decision, and a decision is only complete when it can be shown to work. A plan that has never been tested is a plan nobody knows will work.

Answer the six questions about your own company →
3

The judgement

The evidence back to your question.

Anyone can collect evidence. What a Reality Check adds is the way back: every finding is set beside the others and judged together against your question. What has not been examined is stated too. So you know what is established, what rests on assumptions and what is open.

How deep I search for evidence, you decide with the tier.

Reality Check Outline

What you assume

I walk through the six questions with you and set out on one page what you assume, what you claim and where the evidence should be. I verify nothing in it.

Reality Check Core

What your documentation proves

In addition I read the documents that already exist: contracts, reports, test records. What they prove is marked substantiated; what they do not cover is marked as a gap.

Reality Check Complete

What actually holds

I examine the evidence itself and how it fits together: does the combination of measures carry the conclusion, where does one dependency break the chain, who is accountable.

What it asks of you

A few conversations, and nothing you do not already have.

Every tier starts with a one-hour conversation in which we walk through the six questions. A second conversation of half an hour follows, in which I report back what I have found. From Core onwards I also read the documents that already exist. At Complete, where the question requires it, I also speak with the owner of the dependency or your provider.

You do not have to produce anything or gather anything that is not already there. Lead time is one week for Outline, two to three weeks for Core and two to four weeks for Complete, depending on the availability of people and data.

  • Two conversations with me, 60 and 30 minutes.
  • Your existing documents, from Core onwards.
  • No preparation and no questionnaire beforehand.
What you receive

A compact overview

A sharp view of what is substantiated, what rests on assumptions, where ownership is missing and which decisions are needed.

  • Core question and scope
  • Core picture of the critical dependencies
  • Main exposure and uncertainties
  • Decisions that are explicitly required
  • Ownership and execution
  • Available and missing evidence
  • Where relevant: 30/60/90-day advice

The form follows the tier.

At Outline an evidence map of one page. At Core a compact memo with the statuses, the gaps, the contradictions and the decisions it puts before you. At Complete the full board memo, with advice for 30, 60 and 90 days and a briefing to the executive team or supervisory board.

The memo gives you substantiated input for your own decision and your own communication, internally or towards your supplier.

After delivery

What you do with it

A memo is only useful if something changes because of it. These are the conversations where a Reality Check earns its keep.

The management meeting

The decisions that need to be made are set out, each with an owner. The conversation shifts from "we should do something about cyber" to who decides what, and by when.

The conversation with your supplier

You stop asking whether it is all under control and start asking what exactly is in place and what shows that it works. The gaps become the agenda for that meeting.

The investment decision

A quote for a tool, a migration or a certification programme can be weighed against the exposure you actually have, rather than the exposure the vendor points to.

The question from outside

When a customer, insurer or accountant asks how you manage digital risk, you have a substantiated answer, with its limits stated, rather than an assumption.

Whatever needs to happen next can then be assigned where it belongs. A Reality Check makes sure you know what you are assigning.

Illustration

How findings bear on each other

A fictional example, included to show the form and the connections. This is not a client case.

The situation

Manufacturing company, 60 employees. The production line runs on a network and systems managed by a single external IT provider. Central question: can we show that we are in control of that provider?

The finding

The observation

IT management was outsourced years ago and has not been reviewed since. What the provider is expected to do about patching, access control and recovery after an outage is set out in a quote from 2019, not in a current contract.

Why it matters

Without a current contract there is no standard to hold the provider to. What actually happens may well be sound; you simply cannot establish that, and so you cannot steer on it.

This finding does not stand on its own. Other observations from the same case bear directly on it:

Each of these can be addressed on its own, and doing so achieves little. Together they point to one thing: there is no recorded standard the provider is held to. That is what the decision is about. Making that connection visible is the work; a checklist does not produce it.

Starting point

Discuss your question

In a short conversation we determine whether a Reality Check fits, what scope makes sense and which decision needs preparing.

  • What is the trigger?
  • What must not stop?
  • What must you be able to decide?
Erik Hartwich, founder of Hartwich Risk & Resilience