Client Session Worksheet

↓ Download

[Partner name] | Partner-Craft POV | Client Session Worksheet | Confidential

[Field: Client name] | [Field: Session number] | [Field: Date]

Instructions for the partner


Part 1 — Client Context

FieldResponse
Organization name[Field]
Primary sector[Field]
Session date[Field]
Client attendees and roles[Field]
Partner attendees[Field]

Part 2 — The Problem as the Client Sees It

Use the archetype-specific version of this section from the Archetype Variants below

Select your archetype and use the relevant questions from the Archetype Variants section at the end of this document. The questions there replace questions 1–4 in this part.


Part 3 — Current State

5. What tools, processes, or services are currently in place to address this area?

[Answer field]

6. What is working well enough to keep?

[Answer field]

7. Where are the most visible gaps or points of failure?

[Answer field]

8. What is the cost of not solving this: operational, regulatory, or reputational?

[Answer field]


Part 4 — Constraints and Considerations

9. What budget or procurement constraints should we understand early?

[Answer field]

10. Are there existing vendor relationships or contracts that affect what is possible?

[Answer field]

11. Are there regulatory, compliance, or data residency requirements that shape the solution?

[Answer field]

12. What internal stakeholders need to be involved or informed before a decision can be made?

[Answer field]


Part 5 — Session Output

Complete this section together in the last 10 minutes of every session

FieldResponse
Key agreements reached today[Field]
Open questions requiring follow-up[Field]
Owner of next action[Field]
Date of next session[Field]

Archetype Variants

Part 2 — The Problem as the Client Sees It

Use the version below that matches your engagement. Replace questions 1–4 in Part 2 with the relevant archetype variant. Parts 1, 3, 4, and 5 remain identical across all archetypes.


A1 — Classic Enterprise Cyber

e.g. Mimic and similar established security vendors

1. What threat scenarios are you most concerned about, and why those specifically?

[Answer field]

2. Where do you feel most exposed right now: endpoints, network, identity, cloud, or somewhere else?

[Answer field]

3. How confident are you in your current detection and response capability if something happened today?

[Answer field]

4. What does your board or leadership currently understand about your security posture, and is that accurate?

[Answer field]


A2 — Industrial / OT / IIoT

e.g. WI-SUN Alliance, Toyota Tsusho context

1. Where does your IT environment end and your operational technology environment begin?

[Answer field]

2. What would a security incident in your OT environment actually cost you in operational terms?

[Answer field]

3. How much visibility do you currently have into devices and traffic on the OT network?

[Answer field]

4. Who owns security decisions for OT in your organization, and are they part of this conversation?

[Answer field]


A3 — Emerging / Sensitive AI

e.g. WitnessAI and AI governance vendors

1. Where is AI currently being used in your organization, formally approved or otherwise?

[Answer field]

2. What governance or oversight exists around how AI systems access and use your data?

[Answer field]

3. What is your organization’s current position on AI risk from a regulatory or board perspective?

[Answer field]

4. What would need to be true about a vendor’s data handling for this conversation to be safe to have internally?

[Answer field]


A4 — PKI / PQC / Crypto Lifecycle

e.g. Keyfactor, OmniTrust

1. How much visibility do you have into your current certificate inventory and expiry timelines?

[Answer field]

2. Have you experienced a certificate-related outage or incident, and what was the impact?

[Answer field]

3. Has post-quantum cryptography come up in any internal or regulatory conversation yet?

[Answer field]

4. Who in your organization owns cryptographic infrastructure decisions today?

[Answer field]


A5 — Remediation / Hygiene at Scale

e.g. Northern Tech Mender

1. How do you currently discover and track vulnerabilities across your environment?

[Answer field]

2. What is your average time from vulnerability identification to remediation, and is that acceptable?

[Answer field]

3. Where does the remediation process most often break down or stall?

[Answer field]

4. How confident are you that your most critical systems are consistently patched and up to date?

[Answer field]


A6 — SOC Modernization / Agentic D&R

e.g. Agentic SOC vendors, autonomous detection and response

1. What does your current detection and response capability look like: in-house, outsourced, or hybrid?

[Answer field]

2. What visibility do you actually have into what your MSSP or SOC provider is doing on your behalf?

[Answer field]

3. Where have you felt most exposed by slow or inadequate response to a security event?

[Answer field]

4. What would it mean for your organization to own its detection engineering and response capability internally?

[Answer field]