The first ten questions save more time than the first ten promises. If you are preparing a call with a security or assessment provider, the goal is not to sound clever. It is to avoid vague scope, bad assumptions, and the expensive kind of “we thought you meant something else.”
What exactly do you need? What will it cost in time and coordination? What information is safe to share now? And what should a serious provider be able to explain before anyone starts talking about next steps?

That is the point of this article. It gives you a practical checklist for the first conversation, based on the kind of structure a modern security partner should be able to describe clearly. For broader background, see the CISA insider-threat mitigation guidance and the NIST risk assessment guidance. If your provider cannot discuss scope with similar discipline, that is already information.
For readers comparing options on this site, the practical path usually starts with the about page, the services overview, and the contact page. If you are working through a Brillstein-specific matter, the Brillstein page and Problem gelöst! page provide useful context.
Why the first ten questions matter
Most security engagements go wrong in the same three places: the objective is fuzzy, the scope is too broad, or the communication rhythm is undefined. The fix is not dramatic. It is operational. Clarify the work before you commit to it.
That approach also aligns with formal risk guidance from NIST and the World Economic Forum’s Global Cybersecurity Outlook, both of which emphasize structured assessment over improvisation. Chaos is easy. Accountability takes a schedule.
1) What is the goal and what counts as success?
Start with the result you want. Not the service name. The result.
- Are you trying to reduce exposure?
- Are you trying to understand what happened?
- Are you trying to prepare for a transition, relocation, or internal decision?
- Are you trying to decide whether further action is justified?
A serious provider should translate the goal into a measurable deliverable: a risk summary, an evidence review, a communication plan, or a recommended course of action. If the answer sounds like brand poetry, continue asking.
2) What scope are you actually asking for?
Be specific about the category of work. Many clients mix several needs into one sentence and then expect the first call to sort the entire architecture. That is optimistic, which is a polite word for expensive.
| Scope area | What it covers | What to clarify |
|---|---|---|
| Security support | Protective planning, risk reduction, operational support | Physical, procedural, or advisory? |
| Investigation support | Fact-finding, observation, documentation, review | Internal issue, external matter, or both? |
| Fraud or loss-response support | Review of irregularities, patterns, and evidence | Containment, analysis, or escalation? |
| Combined engagement | Multiple workstreams under one plan | Which part is priority one? |
If one team is expected to do everything, it should at least be able to explain what it is not doing.
3) Which people, places, or events are involved?
Define the target area. Is this about a company, a private matter, one site, several locations, specific individuals, or an event with a time window?
- Company: office, facility, warehouse, field operation, or mixed environment
- Private: home, travel, family, or personal safety context
- Location: one site or multiple sites
- People: staff, contractors, visitors, management, or external parties
- Event: meeting, move, launch, transfer, or public-facing activity
The cleaner the scope, the cleaner the recommendation. Vague scope produces vague competence, which is a familiar but not useful trade.
4) What is the timeline?
Some matters need immediate stabilization. Others need a structured review before anyone takes action. Say which one you are in.
- Do you need an urgent response within hours or days?
- Do you need a phased assessment over several weeks?
- Is there a fixed date that changes the risk profile?
- Are there business cycles, staff schedules, or travel windows that matter?
Any provider worth hiring should explain how urgency changes staffing, reporting, and decision points. If it cannot, the timeline will be invented later. That is rarely the good kind of improvisation.
5) What information is helpful to prepare?
Do not over-share sensitive material in the first exchange. Prepare enough to make the problem legible.
- a short description of the issue
- the date range or sequence of events
- the main people or functions involved
- the places, systems, or records affected
- any existing notes, screenshots, logs, or correspondence that are appropriate to share
If you want more structure, the CISA physical security resources and SafeWise security guidance are useful references for thinking about prevention and preparation at a basic level.
6) What does the process look like from first call to recommendation?
This is one of the most important questions, because process is where seriousness shows up.
- Initial intake and scope confirmation
- Priority setting and basic risk triage
- Document review or fact collection
- Assessment of options and constraints
- Recommendation, execution plan, or referral if the issue sits elsewhere
Ask what happens at each stage, who is responsible, and how decisions are approved. If the answer is “we keep it flexible,” that is not a process. That is a lack of a process with nicer lighting.
7) How will results and updates be documented?
Documentation is not bureaucracy. It is memory with a spine.
Ask how updates are delivered, what is written down, and what level of detail you can expect. A professional approach usually includes:
- clear status updates
- named decision points
- recorded next steps
- a final summary or handoff note
If you are responsible for internal reporting, ask for a format that can be shared upward without rework. Nobody enjoys rewriting the same facts three times for different audiences.
8) What are the privacy and compliance basics?
You do not need legal advice in the first call. You do need basic discipline.
Ask how sensitive information is handled, how communication is limited to need-to-know, and how privacy expectations are managed across the engagement. For general reference, the CISA privacy and identity protection resources and the overview of data protection principles can help frame the discussion. They are not a substitute for counsel, but they do keep the conversation from drifting into slogans.
A simple first-call checklist
- State the main objective in one sentence.
- Name the scope category.
- List the people, places, or events involved.
- Describe the timeline and urgency.
- Prepare a short set of non-sensitive supporting materials.
- Ask how the process works.
- Ask how updates are documented.
- Ask how privacy is handled.
- Clarify who decides next steps.
- End with a concrete follow-up date.
What a good provider should be able to say
By the end of the call, you should know whether the provider understands the issue, whether the scope is realistic, and whether the communication style fits your business. If those three things are unclear, the relationship is not ready yet.
For more context on service framing and next-step coordination, see the services page and the contact page.
Conclusion
The best first call is not the longest one. It is the one that removes uncertainty early. If you prepare the ten questions above, you improve the odds of getting a clear scope, a sensible process, and communication that does not depend on guesswork.
Key takeaways:
- Define the goal before you define the service.
- Separate security, investigation, fraud-response, and combined workstreams.
- Be precise about people, places, and timing.
- Ask how the process, documentation, and privacy handling work.
- Walk away from vague answers. Clarity is cheaper than repair.
