Leave with a proposal structure with scope, responsibilities and decision requirements.
Start with a real buying situation
For the worked example, the audience is an IT manager preparing a supplier review. Their problem is that the team has a long list of findings with no agreed business priority. The desired practical outcome is an owned remediation plan linked to specific systems and risks.
The example is deliberately bounded: testing needs written scope, permission and an agreed change window. That condition should influence the promise, scope and next step rather than disappear from the marketing copy.
| Illustrative offer | a scoped security assessment and remediation workshop |
|---|---|
| Buyer question | Which systems are in scope, and which business process depends on each one? |
| Possible evidence | a redacted example of evidence, severity rationale and remediation verification |
| Useful asset | a supplier security review preparation checklist |
How to complete your proposal brief
- Restate the buyer’s verified problem and desired result.
- Specify deliverables, responsibilities and exclusions.
- Describe the sequence and required client inputs.
- Separate fees and third-party costs.
- List acceptance criteria, open questions and the approval process.
Worked example
These entries are illustrative planning material, not research findings or customer results. Keep the structure and replace the content with verified details.
| Problem and desired outcome | Problem: the team has a long list of findings with no agreed business priority. Desired result: an owned remediation plan linked to specific systems and risks. Confirm both with the buyer. |
|---|---|
| Deliverables and exclusions | a scoped security assessment and remediation workshop. Document permitted testing, data handling, exclusions and reporting recipients. List exclusions rather than relying on assumptions. |
| Responsibilities and dependencies | testing needs written scope, permission and an agreed change window. Name the client and supplier owners for each required input. |
| Fees and commercial assumptions | Use approved prices only. Document permitted testing, data handling, exclusions and reporting recipients. The worksheet deliberately contains no invented market rate. |
| Acceptance and approval | Agree how to review a redacted example of evidence, severity rationale and remediation verification and the number of agreed priority findings with owners and verification dates. List open questions, approvers and the next decision. |
Review before using it
A useful operational measure in this example is the number of agreed priority findings with owners and verification dates. That does not automatically make it a marketing attribution metric. Define the source, period and owner before drawing conclusions.
- Could delivery begin from this document without relying on undocumented promises?
- Check the delivery assumptions: Document permitted testing, data handling, exclusions and reporting recipients.
- Use evidence rather than promises. Never offer testing without authorisation or promise complete protection.
- Discuss the draft with someone who understands the buying situation. Start with: “Which systems are in scope, and which business process depends on each one?”
- If the next step is a trial, define its purpose. One possible starting point is to assess one explicitly authorised system and review the reporting format.
Common mistakes and a better review
Do not fill a missing fact with an impressive-sounding number. Mark it as an assumption, explain how you will check it and give that check an owner. A short, honest document is easier to use than an elaborate plan built on unknowns.
| Watch for | A persuasive proposal can still fail if nobody knows what is included. |
|---|---|
| A real buyer concern | Can you guarantee we will not be breached? |
| Useful response direction | No assessment can remove every risk. We can agree what we will examine, the evidence we will deliver and how remediation will be checked. |
| Evidence to collect | The buyer’s own account, a redacted example of evidence, severity rationale and remediation verification, and records relevant to the number of agreed priority findings with owners and verification dates. |
Your working sheet
Write your own version below. Notes are saved on this browser when local storage is available. Use Download to keep a separate copy; avoid adding confidential information on a shared device.
Example: Problem: the team has a long list of findings with no agreed business priority. Desired result: an owned remediation plan linked to specific systems and risks. Confirm both with the buyer.
Example: a scoped security assessment and remediation workshop. Document permitted testing, data handling, exclusions and reporting recipients. List exclusions rather than relying on assumptions.
Example: testing needs written scope, permission and an agreed change window. Name the client and supplier owners for each required input.
Example: Use approved prices only. Document permitted testing, data handling, exclusions and reporting recipients. The worksheet deliberately contains no invented market rate.
Example: Agree how to review a redacted example of evidence, severity rationale and remediation verification and the number of agreed priority findings with owners and verification dates. List open questions, approvers and the next decision.
Review your work
Tick only what you can support with your answer or practice. This is a reflection checklist, not an automated assessment.
Questions about this resource
How do I adapt this for my cybersecurity services business?
Replace the audience, offer and evidence with your actual information. Begin with a recent buyer conversation about why the team has a long list of findings with no agreed business priority, then check which assumptions match your business.
Is the filled example ready to publish?
No. It is a working example. Verify claims, permissions, prices, current capabilities and any customer information before using it externally. Never offer testing without authorisation or promise complete protection.
What should I do after completing the worksheet?
Use it to make one decision or have one focused conversation. The intended output is a proposal structure with scope, responsibilities and decision requirements. Set a review date and update it when the evidence changes.
Illustrative business worksheet. No customer results, market rates, traffic volumes or performance benchmarks are implied. About these resources.