Explain the pressure
Start with the buyer, insurer, authority, board, tender, or NIS2 question creating urgency.
Evidence handling protocol
Cyber evidence can expose systems, suppliers, contracts, customers, incidents, and internal decisions. NIS2 Advisory starts with context and boundaries before any sensitive material moves.
Operating sequence
Evidence work should move in order. The sequence prevents accidental over-sharing, vague claims, and uncontrolled document chasing.
Start with the buyer, insurer, authority, board, tender, or NIS2 question creating urgency.
Decide what output is needed before any sensitive material is requested or reviewed.
Separate public, internal, operationally sensitive, and customer-facing material.
Ask for relevant proof from approved owners, MSPs, providers, or internal teams.
Label evidence as ready, partial, missing, owner-dependent, MSP-dependent, or review-needed.
Keep internal evidence distinct from customer-safe answers, summaries, and external claims.
Evidence classification
A public process summary is not the same as an access export or incident record. We classify material before using it, summarising it, or turning it into customer-facing wording.
Website statements, standard process summaries, public policy extracts.
Useful for context, but still checked before reuse.
Risk notes, internal policies, owner decisions, supplier lists, action plans.
Reviewed for scope, owner approval, date, and whether it should remain internal.
Screenshots, access lists, tool exports, vulnerability outputs, incident records, architecture.
Requested only after scope and handling rules are agreed. Not used in public AI tools by default.
Approved answers, evidence summaries, disclosure notes, tender or insurer wording.
Written from verified proof and reviewed to avoid overclaiming or oversharing.
Boundaries
The work is evidence readiness support. It is not a legal opinion, audit opinion, certification, managed security service, or technical remediation project.
AI-assisted, human-reviewed
AI can assist with drafting, summarising, and organising non-sensitive material. Client-sensitive evidence is handled under agreed rules, and final outputs are reviewed by a human before use.
Not sure what is safe to share?
Use the first conversation to explain the situation. Sensitive material comes later, only after scope, purpose, and handling rules are agreed.
Ask about evidence handling