Source Point Security 360 · PLAN 03

Program

Foundation, plus vendor risk, board reporting, and a yearly test.

Program is for a company that has started selling to larger customers and answering to a board. On top of the Foundation rhythm, we review the vendors you bring in, report to your leadership each quarter in their language, put guardrails around how your team uses AI, and schedule a penetration test once a year to validate the agreed scope and prioritize fixes.

WHAT'S INCLUDED

Everything in this plan.

  • Everything in Foundation
  • Reviews of new vendors and third parties as you take them on, with a yearly refresh
  • A quarterly board or leadership update with the metrics and decisions that matter
  • Governance for how your team adopts and uses AI, with an approved-tools inventory
  • One scheduled, scoped penetration-test milestone each year, with one retest of remediated findings; additional tests are separate scope
  • Cyber-insurance evidence kept ready for renewal
WHAT YOU GET OUT OF IT

The outcomes that matter.

  • A quarterly leadership and board narrative backed by evidence
  • A handle on the risk your vendors and third parties introduce
  • Clear rules for AI use before it becomes a liability
  • Annual testing evidence, documented limitations, and prioritized remediation
IS THIS THE RIGHT PLAN?

Who it’s for.

  • Companies closing larger deals that come with security scrutiny
  • Teams onboarding vendors or reporting to a board or investors
  • Organizations adopting AI tools and needing to govern their use

When you are pursuing a formal compliance framework and want testing and exercises on a schedule, step up to Leadership.

START AT THE SOURCE

Ready to run Program?

Tell us what you run and what the year holds. We’ll confirm the plan and shape the cadence around it.

Let’s talk security