Business Resilience
AEGITz 40-Point IT Provider Audit
A printable, scored review of after-hours response, recovery, documentation, security, proactive work, business alignment, contract terms, and the human layer.

Working resources
The AEGITz library includes audits, models, checklists, scorecards, and implementation plans. Spreadsheets retain their working formulas, and printable documents are formatted for the provider or leadership review.
Business Resilience
A printable, scored review of after-hours response, recovery, documentation, security, proactive work, business alignment, contract terms, and the human layer.
Business Resilience
Percentage-of-revenue benchmarks are close to useless. A category-by-category model for building an IT budget you can defend, plus the costs that are always missing.
Business Resilience
A scored audit of your current IT provider across eight categories. Run it in an hour and find out whether you have a partner or a vendor.
Business Resilience
Most QBRs are a ticket count and a slide of green checkmarks. Here is the agenda that makes the meeting useful, and the numbers your provider should bring.
Risk and Resilience
Cyber insurance applications turn technical answers into representations that may determine whether a future claim is paid. Here is how to answer with evidence instead of optimism.
Growth and Governance
Enterprise security questionnaires are now revenue gates. Build one accurate response set and an evidence shelf instead of improvising a new answer under every deadline.
Technology Strategy
Compare in-house, managed, and co-managed IT on the same basis: labor, tooling, coverage, specialist depth, turnover, projects, and internal ownership.
Governance
Use NIST CSF 2.0 as a common decision language. Score current and target profiles, weight gaps by business criticality, and work a short, owned priority list.
AI Consulting
A week-by-week plan for putting AI into a small business without creating a data leak, a shelf-ware license bill, or a staff revolt.
AI Consulting
A buying framework for small businesses choosing between the major AI assistants, based on where your data lives and what your team actually does.
AI Consulting
A practical due diligence questionnaire for small businesses buying AI software, covering data handling, subprocessors, retention, and the answers that should end a conversation.
AI Consulting
AI assistants inherit your file mess and your permission mistakes. A six-part readiness audit you can run before you spend a dollar on licenses.
AI Consulting
Time saved is not money saved. A hard-nosed method for calculating whether your AI spend produces anything, with a free calculator.
Cybersecurity
AI agents connect to email, files, and CRM with real credentials that outlive the employee who created them. How to inventory and govern non-human identity.
Cybersecurity
Attackers routinely bypass text and app-based MFA with session theft and push fatigue. What phishing-resistant authentication looks like for a small business.
Business Resilience
A green backup dashboard tells you data was copied. It says nothing about how long you would be down. Build real RTO and RPO numbers with a free worksheet.
Cybersecurity
A concrete hardening baseline for Microsoft 365 in a small business, with the specific settings, why each matters, and what breaks if you rush it.
Cybersecurity
SPF, DKIM, and DMARC explained without jargon, plus a staged rollout plan that gets you to enforcement without breaking your invoices and newsletters.
Cybersecurity
Small business breaches increasingly arrive through a vendor with legitimate access. A right-sized third-party risk program, including the register and contract language.
Cybersecurity
Departing employees keep access far longer than owners realize. A sequenced checklist covering identity, devices, SaaS, physical access, and the accounts nobody remembers.
Compliance
A working HIPAA Security Rule gap assessment for practices under 50 people, built around the failures that show up repeatedly in enforcement actions.
Industry
Construction firms lose money to wire fraud and downtime more than data theft. What actually protects a general contractor, from trailer networks to change order verification.
Compliance
The Safeguards Rule covers tax preparers, accountants, and many financial advisers. What the written information security program requires and how to build one.
Compliance
The 17 practices behind CMMC Level 1, who they apply to, how the self-assessment and SPRS affirmation work, and what changes when Phase 2 begins.
Business Resilience
A 30-day transition plan for changing managed service providers, including the credentials to secure first and the bargaining power you lose after you give notice.
Business Resilience
Sublimits, coverage triggers, and vendor panel requirements decide whether a claim gets paid. A worksheet for reviewing your own policy line by line.