Before requesting a proposal
Frequently asked questions before an assessment.
Does an assessment guarantee we will not have an incident?
No. Cybersecurity reduces and manages risk; it does not eliminate it. The report states scope, evidence, limitations and residual risk to avoid a false sense of protection.
Is this the same as a penetration test?
No. A strategy may cover governance, inventory, identities, protection, detection, response and recovery. A penetration test validates certain technical scenarios under specific authorization and scope.
Do you work with confidential information?
The scope defines evidence minimization, access, transfer, storage, retention and disposal. We do not request unnecessary secrets, and credentials are never included in ordinary deliverables.
Can you review cloud services and providers?
Yes, within the organization’s authority and provider terms. We review dependencies, available configuration, access, agreements and recovery paths; third-party infrastructure is never tested without permission.
Do you issue certification or a compliance guarantee?
Certification or conformity is claimed only under a formal service, applicable criteria and authority to issue it. A Motovolo assessment provides findings and recommendations within the contracted scope.
Do you handle emergencies or active incidents?
A preventive assessment does not automatically include emergency response. During an active incident, availability, authority, secure channels and a separate scope must first be confirmed to avoid destroying evidence or increasing impact.