1. Work through your priorities
A 60-minute session with your IT or security lead. We discuss the tools in use, intended workflows, sensitive information, and the controls you have today.
Free AI Readiness Snapshot
Whether Claude or Copilot is already in use or coming next, start with a focused review of permissions, data access, and governance. Leave with written findings and a clearer next step.
60-minute working session · Written findings · 30-minute review · No obligation to purchase
AI often reaches the business before the controls catch up. We help your team identify where an approved rollout can enable useful work—and where permissions, connectors, or oversight need attention first.
A 60-minute session with your IT or security lead. We discuss the tools in use, intended workflows, sensitive information, and the controls you have today.
A short written summary of the issues identified, the evidence behind them, open questions, and recommended next steps.
A 30-minute findings review with your team. Decide what to handle internally and whether a deeper assessment or implementation would help.
We review the controls and evidence relevant to your AI plans, using your team’s inputs and a live Microsoft Secure Score review. This is a baseline for decisions, not an exhaustive audit of every tool or site.
Discuss data classification, sensitivity labels, DLP policies and enforcement, and the information connected AI tools may reach. Identify questions that need deeper testing.
Review the permission model, access-review practices, guest access, and sharing in Microsoft 365. Use the SharePoint exposure script’s M365 Group risk counts to identify areas for closer review.
Review endpoint and identity monitoring, visibility into AI interactions, available prompt and activity records, and SIEM retention. Identify what is covered and what remains unverified.
Discuss approved AI tools, usage policy, and firewall or proxy controls. If agreed in advance, review a client-provided 30-day DNS, firewall, or proxy export for signs of external AI services.
Network activity can identify services contacted; it does not establish what users typed or what data they shared.
Review Microsoft Secure Score and recommended actions live with your administrator. Focus on recommendations relevant to Copilot and connected agents, rather than treating the score as proof that AI use is secure.
The free Snapshot is a bounded diagnostic based on the session and agreed inputs. It is not a full DLP audit, a complete tenant permissions audit, penetration testing, regulatory certification, or an implementation plan.
Written findings with Critical, High, or Medium severity where supported by the evidence, plus the basis for each finding, missing evidence, and limitations.
M365 Group risk counts from the SharePoint script and a Secure Score exhibit with relevant recommended actions. A Shadow AI exhibit is included when suitable logs are supplied and that review is agreed.
Recommendations ranked by risk with the reasoning behind them, followed by a 30-minute walkthrough. Decide what your team can address and where deeper work is needed.
The script’s M365 Group view does not cover every classic, communication, or other SharePoint site and is not a complete permissions analysis.
Before we meet, we send a read-only SharePoint exposure script and a session brief. Your administrator reviews the script, confirms the required permissions, runs it in your environment, and shares the CSV output through an agreed secure method. Cocha reviews that output before the working session.
Bring your IT or security lead and an administrator who can show Microsoft Secure Score and its recommended actions. Plan for script preparation and evidence sharing in addition to the 60-minute session and 30-minute review. We agree on permissions and data handling before any tooling runs; do not send credentials or confidential files with your request.
See the preparation checklistWe aim to respond within 4–8 business hours, Monday–Friday, 8 AM–5 PM Central.
Written findings are provided within five business days after the working session and receipt of the required inputs. Your team’s availability can affect the overall schedule.
Steven R. Combs brings 30 years in IT and 15 years working with law firms. Cocha works alongside your internal IT team or MSP. Gabriella San Miguel coordinates scheduling, project management, and the next steps.
For a large Canadian law firm, Cocha’s work has included governance and pilot readiness, roles, connectors, monitoring, and architecture planning for a new Claude Enterprise rollout.
For a large US law firm, Cocha supports Copilot rollout and ongoing governance advisory as the ecosystem changes.
Engagement descriptions are anonymized. They describe the work, rather than a claim that a firmwide rollout is complete.
Five review areas, the M365 Group exposure script, live Secure Score review, written findings, and a 30-minute walkthrough. No purchase obligation.
A deeper scope can include DLP and classification analysis, tenant-wide SharePoint permissions, on-premises file access, connector or Graph API access scope, and Shadow AI evidence. The agreed engagement can map findings to relevant frameworks and develop a remediation plan with effort estimates and a prioritized 90-day sequence.
Scope and pricing are agreed separately. These deeper analyses and the remediation plan are not included in the free Snapshot.
Watch the recorded conversation on keeping law-firm client data safe as AI use expands.
Yes. The session, written findings, and findings review carry no fee and no obligation to purchase. Any paid work is scoped separately.
Yes. We can start with an existing deployment, proposed expansion, or the controls around current use.
Yes. The Snapshot can help your team establish priorities and decide which actions it will own.
We respond to confirm fit, agree on preparation, and arrange the working session. Submitting the form does not book a session automatically.