
Protect client information across teams and engagements
Limit access to client information to assigned teams, protect devices used remotely, and maintain records for client security reviews.
Or email hello@teclara.tech
Security risks
Manage client access from kickoff to closeout.
Each client engagement has its own access, sharing, and retention requirements. Review those requirements when work begins, when team members change, and when the engagement ends.
Proposal
The questionnaire comes with the RFP
Larger clients send a security questionnaire before the work is awarded. Use current records to confirm that your answers accurately describe the controls in place.
Kickoff
Access is granted in both directions
Confirm which client systems your team needs to access and which folders your firm will share. Give associates and subcontractors individual accounts with appropriate permissions.
Delivery
Work happens away from the office
Consultants use the same accounts and devices at client sites, while travelling, and at home. Device protection and sign-in controls need to cover those working arrangements.
Closeout
The client asks for its data back
Contracts often require return or destruction of client material. At closeout, review guest accounts and shared links, remove access that is no longer required, and record the changes.
Security controls
A finished engagement should not leave access behind
We limit access by engagement, protect accounts and devices, and maintain security records. Access is reviewed and removed when the work ends.
Engagements
Separate access by client
Where client material lives in Microsoft 365 or Google Workspace, access is limited to the people assigned to the engagement. We review external links and inherited permissions to identify access beyond the assigned team.
Associates
Use named accounts for external contributors
Associates and subcontractors use named accounts with access limited to the work they need. Their sessions can be revoked and permissions removed without affecting the rest of the engagement team.
Devices
Protect work away from the office
The laptops and phones we manage receive managed endpoint protection, encryption, and security updates. The controls follow the device and account whether work happens at home, at a client site, or while travelling.
Sign-ins
Watch for account takeover
Multi-factor authentication, administrator controls, and sign-in monitoring help prevent unauthorized access using a stolen password. Suspicious sessions and inbox-rule changes are investigated through the agreed response process.
Evidence
Keep control records current
Scheduled reporting documents the security controls Teclara operates. The consulting firm uses that evidence to respond to client questionnaires, RFPs, insurance applications, and internal reviews.
Closeout
End access when the engagement ends
Accounts, active sessions, external links, and guest access are reviewed at closeout.
Security documentation
Clients ask how you handle their information before they sign and after an incident.
Current security records help the firm answer client questions accurately during procurement, contract reviews, and incident investigations.
- Client procurement
- Do you enforce MFA, encrypt laptops, and remove access when staff leave? Can you show it?
- Policy and coverage reports for MFA, device encryption, and endpoint protection, with offboarding records for recent departures.
- Client IT or security team
- Who monitors your environment, and what can they see?
- Documentation of who can access monitoring tools and which data those tools collect from the systems covered by the service.
- Cyber insurer, at renewal
- Are backups tested? Is sign-in activity monitored? How quickly is access removed?
- The backup scope and restore test results, sign-in monitoring records, and the documented offboarding process.
Your responsibilities
The consulting firm remains responsible for its client contracts, questionnaire answers, incident-notification decisions, and retention or destruction commitments. Teclara operates and documents the security controls we manage. Client systems, project applications, source repositories, and other platforms are included only when named in the engagement.
Managed Security & Compliance
Ongoing security for your accounts, devices, and data.
The security controls on this page run on the platform you use, with access controls, reporting, and maintenance schedules adapted to your firm.
On Microsoft 365
- SharePoint and OneDrive restricted to the team working on each engagement
- Guest and associate access reviewed at closeout
- MFA, Conditional Access, and administrator controls
- Managed endpoint protection on supported devices
On Google Workspace
- Shared drives restricted to the team working on each engagement
- External links and guest access reviewed at closeout
- MFA and administrator access controls
- Admin and sign-in reporting retained as evidence
Configuration updates are part of the service. When our security baseline changes, your environment is updated without a separate project fee.
Frequently asked questions.
How do you manage access when our team changes?
Coverage is based on the users and supported devices included in your agreement. We follow a documented process to set up new accounts. When staff, associates, or guests leave, we disable their accounts, revoke active sessions, and remove access from the systems we manage. Timing and responsibilities are agreed before the service begins.
Can consultants work securely from client sites?
Yes. Account security policies and managed device protection can remain in effect outside the office. The exact coverage depends on whether the device is enrolled, which sign-in policies are licensed, and whether a client network or application imposes its own requirements.
Can you help with a cyber insurance application or renewal?
Yes. We review the insurer’s questions and provide current evidence for the security controls we manage. Requirements vary by insurer and policy, so the work supports the application but does not guarantee approval or coverage.
What happens when a security alert is raised outside business hours?
The security team reviews alerts and follows the agreed response and escalation process around the clock. Before monitoring begins, we document which systems we cover, what access we have, and which response actions you authorize.
Can you help with client security questionnaires?
We provide written evidence for the controls Teclara operates, such as sign-in policies, device coverage, monitoring, backup, access reviews, and response records. The consulting firm remains responsible for its questionnaire answers, client commitments, and any supporting legal or compliance interpretation.
Client feedback
What a client says about working with us.
“Teclara materially improved both our operational responsiveness and our security posture.”
E.C.
Senior Leadership, GTA Consulting Firm

Led by Wadhah Hussain, Teclara's founder
20+ years enterprise IT · Big Four alumnus · Microsoft & Google Cloud specialist
Short on time? Let your favourite AI sum up Teclara.
Review the controls before the next client questionnaire
In a 30-minute conversation, we discuss client information, engagement access, and security questionnaires. We agree on the next step. Technical checks and written findings belong to a separately scoped engagement.
