Pre-Engagement Security Scoping (Onboarding)
A checklist with 7 steps: Inventory every asset the client expects the agency to touch before signing the retainer.
By InnovaAI ResearchPublished
What are the steps?
Pre-Engagement Security Scoping (Onboarding)
- 01
Inventory every asset the client expects the agency to touch before signing the retainer
List ad accounts, CRM instances, repositories, cloud buckets, and any AI agent pipelines. Anything unnamed at scoping becomes an unbounded liability later.
- 02
Classify each asset by data sensitivity and regulatory exposure
Separate public marketing assets from systems holding PII, payment data, or health records. A regulated-industry client using Tresorit-style encrypted storage has different obligations than a B2C brand running open web forms.
- 03
Map which third-party tools already hold client credentials
Document every integration with API access, including AI coding assistants and automation platforms. Exposed keys in client-facing apps have produced four-figure unauthorized usage bills in documented cases.
- 04
Define the security scope boundary in writing, including what the agency does not cover
State plainly that the agency monitors, scans, and remediates within named systems only. Absolute security guarantees are uninsurable; scope language is the substitute.
- 05
Assign a named owner for security incidents on the account
One person, reachable, with a documented escalation path. Shared ownership means no ownership when a breach window opens at 2am.
- 06
Price the security work as a line item, not a bundled courtesy
Proactive threat modeling and periodic scanning are recurring deliverables. Bundling them into general retainer hours hides the cost and invites scope creep.
- 07
Confirm the client's own incident response contact and notification obligations
If the client has regulatory breach-notification duties, the agency needs their legal contact before work starts, not after an incident.