Cyber Risk Management Program

EvidenceEdge Cyber

From a one-time assessment to a continuous, evidence-backed cybersecurity management program for your Microsoft 365 environment.

EvidenceEdge Cyber — From cyber risk identification to continuous improvement

More than a scan. A defensible risk management program.

EvidenceEdge turns your Microsoft 365 tenant review into a repeatable, evidence-backed workflow. Unlike Microsoft Secure Score, EvidenceEdge builds a client-specific Risk Register — mapping 58 identified risks to 64 Microsoft controls, collecting live evidence, and using AI to evaluate gaps and produce auditor-ready output.

The platform is evidence-first. Every control evaluation begins with raw Microsoft configuration data — not assumptions. AI scoring is applied to grounded summaries, reducing hallucination risk and producing rationale that is tied to actual tenant settings.

The result: management-ready, auditor-friendly output with a traceable path from raw evidence to risk score to remediation action.

58
Cybersecurity Risks
Mapped to SEC regulations including Reg S-P, S-ID, Rule 17a-4, and SEC 2023 Cybersecurity Rules
64
Microsoft Controls
Specific M365 and Azure configuration points evaluated across 11 control domains
11
Control Domains
From Identity & Access to Cloud App Governance — comprehensive M365 coverage
14
Exam Domains
SEC Cyber Sweep Readiness matrix covering governance, access, data, training, IR, and more

64 controls across 11 Microsoft 365 domains

Every control is mapped to a client risk, tied to NIST/CSF framework elements, and backed by live evidence collected from Microsoft Graph, Exchange, Purview, Intune, Defender, and SharePoint.

Identity & Access 21 controls
Email Security 10 controls
Endpoint 8 controls
Data Protection 6 controls
Retention 5 controls
External Access 4 controls
Monitoring 3 controls
Cloud Apps 3 controls
Archiving 2 controls
Hold 1 control
Governance 1 control

Evidence sources: Entra ID • Conditional Access • Intune • Exchange Online • Defender for Office 365 • Defender for Endpoint • Microsoft Purview • SharePoint Online • Defender for Cloud Apps

Evidence first. AI second.

EvidenceEdge collects live Microsoft configuration data before AI is involved. Deterministic summaries are computed from raw evidence — then AI evaluates those summaries against the control's NIST/CSF framework context.

This approach keeps the AI grounded in actual tenant data, not assumptions. Every AI output includes a rationale, gap analysis, and concrete remediation guidance — scored 0–5 for control effectiveness.

Control Evaluation Statuses
OK — Control effective PARTIAL — Notable gaps GAP — Missing or weak REVIEW — Delegated evidence required
Control Scoring Scale
0 No evidence — control missing
1 Weak or partial evidence
2 Control exists but has major gaps
3 Mostly effective — minor gaps remain
4 Strong control
5 Strong — mature — well-scoped — validated

A managed, streamlined path from gap to closure

EvidenceEdge gives your MSP or any third-party provider a structured way to own remediation, submit evidence, and prove the gap is actually closed, not just marked done.

1
Assign to Provider
Each gap is assigned to the MSP or third party responsible for fixing it, with scoped portal access
2
Remediate & Submit Evidence
The provider implements the fix and submits structured evidence directly against the gap
3
Reevaluate & Close
The Microsoft control is reevaluated and the gap is closed only once the fix is verified

For the Firm

  • Full visibility into third-party remediation progress, no more chasing the MSP for status
  • Every closed gap comes with evidence, not just a verbal confirmation
  • Controls are reevaluated before a gap is marked closed, so closure means something
  • One consistent, structured process across every provider you work with

For the Provider

  • A clear, structured workflow for what's expected on every gap, no ambiguity
  • Scoped access to only the assigned remediation, not the firm's full Microsoft tenant or EvidenceEdge itself
  • Submit evidence once, in one place, tied directly to the specific gap
  • Remediation work is backed by an objective, reevaluated result the firm and its examiners can trust

Cyber Sweep Readiness

EvidenceEdge includes a second operating layer that answers a different — but equally critical — question:

"If an SEC examiner asked for cybersecurity materials today, what can you produce, where is it, and what is still missing?"

The Cyber Sweep Readiness matrix covers 14 exam domains — from governance and access controls to incident response, vendor risk, training records, and AI governance. It combines system-collected evidence, platform-generated reports, and manual artifact tracking (WISP, IR plans, vendor reviews, training records) into a single readiness scorecard.

Governance & Cybersecurity Program
Cybersecurity Risk Assessment
Access Rights & Controls
Account Management
Data Loss Prevention & NPI Protection
Email Security & Phishing Defense
Incident Response & Ransomware
Vendor & Third-Party Risk
Training & Awareness
Records Retention & Audit Logs
Reg S-P & Reg S-ID Readiness
AI & Emerging Technology Risk
Operational Resiliency & BCP
Remediation & Corrective Action

Single-tenant. Evidence-first. Client data stays in your environment.

EvidenceEdge deploys inside your Azure tenant. WesTech never holds your client data. Each engagement uses a dedicated client service principal with short-lived credentials, Azure Key Vault secret storage, and least-privilege access.

How an EvidenceEdge engagement works

1
Onboard Client
Create Business record, configure service principal in client tenant, store credentials in Key Vault
2
Initialize Register
Create Risk Register from 58-risk default library with NIST/CSF mappings and SEC Exam Readiness matrix
3
Collect Evidence
Graph API collection for standard controls; premium collectors for Exchange, Purview, SharePoint
4
AI Evaluation
AI scores each control on grounded evidence — effectiveness, residual risk, gaps, remediation
5
Risk Scoring
Control scores roll up to risk-level scoring; management overview narrative generated
6
Report & Act
HTML/PDF reports, SEC Sweep Readiness scorecard, remediation action plan, Power BI dashboards

Built for the SEC regulatory environment

EvidenceEdge maps every risk and control to the specific SEC regulations that matter most to RIAs and registered investment advisers.

📋
Regulation S-P
Safeguarding customer records and information — privacy notice, opt-out, data protection
🪪
Regulation S-ID
Identity theft red flags rule — detection, prevention, and response requirements
📁
Rule 17a-4
Electronic records retention — write-once storage, accessibility, and examiner-production requirements
🔒
SEC 2023 Cyber Rules
Cybersecurity risk management, strategy, governance, and incident disclosure requirements for RIAs

One Trusted View. One Clear Path to Results.

Real visibility only matters when it leads to action.

EvidenceEdge brings leadership, compliance, and IT together around the same gaps, the same priorities, and the same evidence. Each remediation is assigned to the responsible provider, tracked through completion, and reevaluated before the issue is considered closed.

No disconnected spreadsheets No uncertainty about ownership No gap closed on opinion alone
Real evidence. Real accountability. Real peace of mind.
From discovery to verified results.
rm.westech-solutions.com / Provider Portal
EvidenceEdge Provider Portal — Assigned Remediation Gaps
Provider Portal

Your MSP or another third party signs into a scoped portal, sees only the gaps assigned to them, and works each one through to Verified. No access to your Microsoft tenant or the rest of EvidenceEdge.

A Managed Process, Not a Spreadsheet Export

Every gap becomes a tracked remediation record with an owner, a provider, a target date, and a status, not a line item you have to chase down yourself.

Runs Through Your Existing Providers

Your MSP or another third party remediates inside the structure you already have, no rip-and-replace, no new vendor relationship required.

Reevaluation Closes the Loop

A gap isn't marked closed because someone said so. The Microsoft control is reevaluated, and that result is what closes it.

What the output looks like

Every engagement produces a full suite of web-based and downloadable reports — from executive management summaries to raw technical evidence and SEC exam readiness scorecards.

rm.westech-solutions.com / Executive Summary Report
EvidenceEdge Executive Summary Report
Executive Summary Report

Management-ready overview: 58/58 risks evaluated, 64/64 controls scored, residual risk distribution, control evaluation results (OK / GAP / REVIEW / PARTIAL), remediation pipeline status, and regulatory exposure summary. Delivered as a multi-page PDF and web report.

rm.westech-solutions.com / Client Risks
EvidenceEdge Risk Register
Risk Register

All 58 client risks displayed with probability, impact, inherent risk score, and filtering by risk level. Downloadable as PDF or Excel. "Evaluate All Controls" triggers a full AI-powered re-evaluation run.

rm.westech-solutions.com / Risk Detail
EvidenceEdge Risk Detail
Risk Detail

Per-risk view: mapped controls, AI evaluation status, residual risk calculation, remediation actions, and regulatory framework linkage.

rm.westech-solutions.com / Control Detail Report
Control Detail Report
Control Detail Report

All 64 controls with OK / GAP / PARTIAL / REVIEW status, mapped risks, residual risk, confidence score, last evaluation timestamp, and AI gap rationale. Filterable by status, residual level, and remediation state.

rm.westech-solutions.com / Open Gaps Report
Open Unique Gaps Report
Open Unique Gaps Report

All open control gaps in one view — GAP, PARTIAL, and REVIEW statuses — with risk mappings, confidence levels, and AI-generated summary recommendations for each gap. Filtered to show only actionable items.

rm.westech-solutions.com / Controls by Risk
Controls by Risk
Controls by Risk

Every risk shown alongside its mapped Microsoft controls and evaluation status — making it easy to see which risks have full control coverage and which have unresolved gaps.

rm.westech-solutions.com / Technical Evidence
Technical Evidence Detail
Technical Evidence Detail

Per-control technical view: raw Microsoft Graph API collector JSON, normalized evidence summary, AI evaluation rationale, scoring breakdown (effectiveness, probability, impact, residual, confidence), and the exact evidence used to drive the AI result.

rm.westech-solutions.com / Evidence History
Evidence Logging
Evidence Collection & AI Evaluation Log

Full audit trail of every evidence collection run and AI evaluation — run ID, timestamps, collector source, evidence IDs, AI token usage, and status. Every evaluation is traceable and reproducible.

rm.westech-solutions.com / Framework Compliance Report
Framework Compliance Report
Framework Compliance Report (NIST SP 800-53)

All 148 mapped NIST framework elements shown with GAP / REVIEW / OK status, residual risk level, mapped risks, evaluated control counts, and AI gap summaries. Covers NIST CSF 2.0 and NIST SP 800-53 Rev. 5 across all Access Control, Identity Management, and other families.

rm.westech-solutions.com / MS Controls to Standards
MS Controls to Standards
Microsoft Controls → Standards Mapping

Each Microsoft control cross-referenced to NIST, SEC, and framework elements — showing exactly which regulatory standards a given M365 configuration supports.

rm.westech-solutions.com / Risk to Standards
Risk to Standards Mapping
Risk → Standards Mapping

Every identified risk mapped to the applicable regulatory standards and framework elements — providing the traceability examiners and auditors need.

rm.westech-solutions.com / Remediation Actions
Remediation Action List
Remediation Action List

All proposed remediation actions across the register — prioritized by score, assigned to owners, with target dates and pipeline tracking from Proposed → Accepted → In Progress → Implemented → Verified.

rm.westech-solutions.com / Remediation Detail
Remediation Detail
Remediation Detail

Per-action view: AI-generated source summary with specific gap descriptions and fix instructions, ownership assignment, target date, estimated effort and cost, estimated risk reduction, and implementation/verification tracking with evidence attachment.

rm.westech-solutions.com / SEC Cyber Sweep Readiness
SEC Cyber Sweep Readiness Report
SEC Cyber Sweep Readiness Report

Domain-by-domain readiness scorecard aligned to the SEC Cyber Sweep exam framework — 14 domains, 34 total request items, each rated Ready / Mostly Ready / Partial / Needs Review / Not Ready. Shows exactly what an examiner can request, what's producible, and what's still missing. Combined system evidence, platform-generated reports, and manually tracked artifacts (WISP, IR plan, training records, vendor reviews) in a single consolidated view.

Ready to see where your Microsoft 365 controls stand?

Get a defensible risk register, AI-scored control evaluation, and a clear remediation path — built on live evidence from your own tenant.

Get in Touch
info@wns-tech.com