Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Cyber Security Firm Collect Policies, Screenshots and Device Lists From Clients Without Endless Email Attachments?
Problems We Solve

How Does a Cyber Security Firm Collect Policies, Screenshots and Device Lists From Clients Without Endless Email Attachments?

Cyber firms chase clients for assessment evidence by email and lose track of versions. We build an evidence portal that requests, collects and tracks each item.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Assessments and audits depend on evidence from the client, such as policies, device lists, configuration screenshots and training records, and collecting it by email leaves your consultants chasing, renaming attachments and working out which version is current. We build an evidence portal that sends each client a tailored request list, lets them upload against each item, tracks what is missing and keeps every version with its date.

Forty attachments and a missing policy

Your consultant is preparing an assessment for a client: a certification assessment, a gap review against a standard, or a supplier assurance review the client's customer demanded. The first step is always evidence. You send a list: the information security policy, an asset register, a list of admin accounts, screenshots of certain settings, training records, and so on.

What comes back over the next three weeks is forty emails from four people at the client. Some attachments are named 'Document1.docx'. Some are the wrong policy. The asset register arrives twice, a week apart, with different numbers of laptops. One screenshot is taken on the wrong system. Your consultant saves them into a folder, renames them, and keeps a spreadsheet of what has arrived.

By the time the assessment starts, nobody is sure whether the evidence on file is the latest, and the consultant spends a morning confirming.

Your firm is also holding a pile of sensitive client documents in email and shared folders, which is not where a security firm wants them.

Why evidence collection drags

  • Request lists are sent as a document, and the client replies by email in pieces.
  • Several people at the client contribute, each sending their own attachments.
  • There is no link between an attachment and the request item it answers.
  • Versions arrive over time, and it is unclear which is current.
  • Chasing is manual and depends on the consultant remembering.

What the email approach costs

ProblemCost
Evidence scattered in emailConsultant time spent filing and renaming
Versions unclearAssessment based on the wrong document
Missing items found lateAssessment delayed
Manual chasingUneven, and depends on who is running it
Sensitive files in inboxesHarder to control who can see them

The cost also lands on the client relationship. A client who has sent the same asset register twice and then gets asked for it a third time starts to wonder how organised the firm assessing them really is, which is an awkward impression for a security firm to give.

The evidence portal we build

  1. Your consultants build request lists from templates per assessment type, adjusted for each client.
  2. The client gets a portal link with each item explained, and can assign items to colleagues, so the person who holds the asset register uploads it directly.
  3. Every upload is attached to a specific request item, with the uploader's name and the date. New uploads create a new version; old versions are kept.
  4. The consultant reviews each item and marks it accepted or needing more, with a comment the client sees.
  5. Missing and returned items are chased automatically on a schedule, with a summary to the client's lead contact.
  6. When the assessment starts, the consultant has a complete, versioned evidence set in one place. Retention and deletion follow the policy you set.

The portal runs in your environment, with access limited to named people, and we design storage and retention with you, given how sensitive client evidence is.

What your consultants get back

Evidence arrives against the right request, from the right person, with a date. The consultant reviews rather than files. Missing items are visible and chased without effort. And when a client comes back next year, their previous evidence and request list are the starting point, so they only update what has changed.

Clients prefer it too. One link, a clear list, the ability to hand items to colleagues, and a view of what is still needed.

Here is a typical run. The consultant picks the template for the assessment type, removes two items that do not apply to this client, and sends the link. The client's operations manager assigns the asset register to their IT lead and the training records to HR. Over the next fortnight uploads arrive against each item. The consultant returns one screenshot with a comment asking for the production system rather than the test one. The chaser goes out automatically for the two items still missing, and on the day the assessment starts, everything is in place with a date against it.

Signs you need an evidence portal

  • Evidence requests are sent as a document and answered by email.
  • Consultants spend time renaming and filing attachments.
  • You have assessed against an out-of-date document.
  • Chasing missing evidence is manual.
  • Client evidence sits in inboxes and shared drives.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Can we use our own request templates?

Yes. Templates are set per assessment type and can be adjusted per client.

Where is client evidence stored?

In your environment, with access and retention you set. We design this with you.

Can clients delegate items to colleagues?

Yes. The lead contact can assign items to anyone at the client, who uploads directly.

Does it assess the evidence?

No. Your consultants review and assess it. The portal collects, organises and tracks.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →