McPhail Security | Partner-Craft POV | Log every gap as it surfaces — same day is best
| Column | Description |
|---|---|
| # | Row number |
| Date | Date gap was surfaced |
| Session | Which session it emerged from |
| Gap Description | What the gap is, in plain language |
| Category | Select from category list below |
| Severity | Critical / Significant / Minor |
| Owner | Who is responsible for resolution |
| Resolution Status | Current state of the gap |
| Notes | Context, workarounds, related gaps |
| Archetype | Which archetype this gap applies to |
| Days Open | Auto-calculated from date column |
Links each gap to a specific resolution type, action, owner, due date, and completion date.
Aggregated and anonymized view for sharing with the vendor at engagement close. Populated from the Gap Log.
Counts of Critical, Significant, and Minor gaps per category, with auto-totals and space for key themes and recommended actions per category.
Up to eight numbered action rows, each capturing:
Pre-populated gap checklist to use at engagement open. Use these as your starting checklist — add rows as new gaps emerge during the engagement.
e.g. Mimic and similar established security vendors
| Gap Area | Validation Question | Default Severity |
|---|---|---|
| Japan-specific threat landscape positioning | Does vendor material reference APJ threat actors and incident patterns? | Significant |
| Proof of concept support | Can the vendor provide a credible POC framework for this partner’s client environment? | Critical |
| Competitive displacement | Does the vendor have clear positioning against the incumbent the partner is likely displacing? | Significant |
| Local language materials | What exists in Japanese and what needs to be developed? | Significant |
e.g. WI-SUN Alliance, Toyota Tsusho context
| Gap Area | Validation Question | Default Severity |
|---|---|---|
| OT-specific reference architecture | Does one exist and is it credible to an OT engineering audience? | Critical |
| Sector-specific compliance alignment | Does vendor material address relevant Japanese industrial and critical infrastructure standards? | Significant |
| IT/OT boundary documentation | Can the vendor clearly articulate where their product sits relative to the OT environment? | Critical |
| Operational impact language | Does the vendor speak in terms of operational continuity, not just security posture? | Significant |
e.g. WitnessAI and AI governance vendors
| Gap Area | Validation Question | Default Severity |
|---|---|---|
| Data residency documentation | Can the vendor clearly answer where data lives and who can access it? | Critical |
| Japanese regulatory alignment | Does vendor material address APPI, FISC, or FSA AI guidance? | Critical |
| Executive risk narrative | Is there a board-level AI risk story that works in a Japanese corporate governance context? | Significant |
| Localization depth | Beyond translation, is the product and its privacy posture actually adapted for Japan? | Significant |
e.g. Keyfactor, OmniTrust
| Gap Area | Validation Question | Default Severity |
|---|---|---|
| PQC regulatory timeline documentation | Does the vendor have material aligned to NIST, JFSA, and G7 PQC guidance? | Critical |
| Certificate discovery methodology | Is there a clear process for helping a client understand their current crypto exposure? | Critical |
| Non-technical executive narrative | Can the quantum risk story be told without assuming cryptographic literacy? | Significant |
| Migration roadmap templates | Does the vendor provide a structured path from current state to quantum-safe posture? | Significant |
e.g. Northern Tech Mender
| Gap Area | Validation Question | Default Severity |
|---|---|---|
| Device coverage documentation | Does the vendor clearly articulate what environments and device types are supported? | Significant |
| Managed service packaging | Is there a clear model for the partner to deliver this as a recurring managed service? | Critical |
| Hygiene baseline methodology | Does the vendor provide a structured way to assess and document a client’s current hygiene posture? | Significant |
| Escalation and exception handling | What happens when a patch cannot be applied and how is that governed? | Minor |
e.g. Agentic SOC vendors, autonomous detection and response
| Gap Area | Validation Question | Default Severity |
|---|---|---|
| Agentic capability documentation | Is there clear, credible material on what the product decides autonomously versus what requires human approval? | Critical |
| MSSP transition methodology | Does the vendor provide a structured approach to transitioning a client away from an incumbent MSSP? | Critical |
| Detection engineering enablement | Can the partner’s client team actually build and own detection content, or does it require vendor dependency? | Significant |
| Japan FISC alignment | Does the vendor’s architecture and data handling support FISC compliance requirements for Japanese FSI clients? | Critical |