Understand the client environment
Build asset visibility and review vulnerabilities, security findings and supplier dependencies. Keep scope and ownership clear so the right team can assess the risk.
Asset discoveryManage security findings, compliance activity and risk decisions across your client portfolio. Fig Group helps your team turn the information into assigned work and keep a record of the progress you discuss with each client.
A risk register is more useful when your team can see the affected systems, supporting evidence, agreed actions and responsible people.
Build asset visibility and review vulnerabilities, security findings and supplier dependencies. Keep scope and ownership clear so the right team can assess the risk.
Asset discoveryAssign owners, record risk decisions and track remediation. Use structured incident and change workflows where the work requires escalation, approval or coordination.
Remediation workflowsConnect policies, controls, staff training and audit activity to the client record. Use the supporting evidence in reviews instead of reconstructing the history from email and spreadsheets.
Compliance and evidenceUse a repeatable process that distinguishes the technical finding, the business decision and the action your team is responsible for.
Confirm affected systems, business context and the evidence available. Separate items that need investigation from those ready for a remediation decision.
Discuss the risk with the client. Record the agreed treatment, responsible person and target date, including any acceptance or deferral that needs approval.
Follow the work through, retain completion evidence and review anything overdue or unresolved. Use the next client meeting to agree the remaining priorities.
Service scope
Your MSP remains the client-facing provider. Fig Group supports the platform work and offers white-label security services, including vulnerability scanning, code reviews and penetration testing. We also work with MSPs to certify their clients.
Platform monitoring and workflow automation support your team; they do not by themselves provide a staffed 24/7 security operations service or a certification. Agree the software, specialist services, responsibilities and reporting your client requires.
How the platform supports your service and where specialist engagements fit.
Yes. Fig Group supports MSP client management. Agree the access model and reporting responsibilities during onboarding so your team and each client have the appropriate view.
No. A score is a way to prioritise and discuss information within its scope. Review the underlying findings, business context and evidence before deciding what action to take.
Yes. Fig Group works with MSPs to provide Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification services. The relevant organisation must meet the scheme requirements; platform use alone does not confer certification.
Yes. MSPs can white-label Fig Group services and retain the customer relationship. Agree the delivery scope, reporting format and client communication responsibilities before work begins.
Tell us how you manage client risk today and where you need stronger visibility, clearer workflows or specialist support.