Skip to content
Client risk management

Give every client a clear risk picture and a plan.

Manage security findings, compliance activity and risk decisions across your client portfolio. Fig Group helps your team turn the information into assigned work and keep a record of the progress you discuss with each client.

Connect risk records to the work behind them.

A risk register is more useful when your team can see the affected systems, supporting evidence, agreed actions and responsible people.

Understand the client environment

Build asset visibility and review vulnerabilities, security findings and supplier dependencies. Keep scope and ownership clear so the right team can assess the risk.

Asset discovery

Agree the response

Assign owners, record risk decisions and track remediation. Use structured incident and change workflows where the work requires escalation, approval or coordination.

Remediation workflows

Keep evidence current

Connect policies, controls, staff training and audit activity to the client record. Use the supporting evidence in reviews instead of reconstructing the history from email and spreadsheets.

Compliance and evidence

Make the client review useful.

Use a repeatable process that distinguishes the technical finding, the business decision and the action your team is responsible for.

  1. Review the findings

    Confirm affected systems, business context and the evidence available. Separate items that need investigation from those ready for a remediation decision.

  2. Agree priorities and ownership

    Discuss the risk with the client. Record the agreed treatment, responsible person and target date, including any acceptance or deferral that needs approval.

  3. Track and explain the outcome

    Follow the work through, retain completion evidence and review anything overdue or unresolved. Use the next client meeting to agree the remaining priorities.

Service scope

Keep the client relationship. Add specialist delivery.

Your MSP remains the client-facing provider. Fig Group supports the platform work and offers white-label security services, including vulnerability scanning, code reviews and penetration testing. We also work with MSPs to certify their clients.

Platform monitoring and workflow automation support your team; they do not by themselves provide a staffed 24/7 security operations service or a certification. Agree the software, specialist services, responsibilities and reporting your client requires.

Questions before you start

How the platform supports your service and where specialist engagements fit.

Can we manage more than one client?

Yes. Fig Group supports MSP client management. Agree the access model and reporting responsibilities during onboarding so your team and each client have the appropriate view.

Does a risk score prove that a client is secure?

No. A score is a way to prioritise and discuss information within its scope. Review the underlying findings, business context and evidence before deciding what action to take.

Can Fig Group help us certify clients?

Yes. Fig Group works with MSPs to provide Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification services. The relevant organisation must meet the scheme requirements; platform use alone does not confer certification.

Can we offer the service under our own brand?

Yes. MSPs can white-label Fig Group services and retain the customer relationship. Agree the delivery scope, reporting format and client communication responsibilities before work begins.

Build a risk service your clients can understand.

Tell us how you manage client risk today and where you need stronger visibility, clearer workflows or specialist support.

Discuss your MSP service