Gap Analysis Tracker

↓ Download

McPhail Security | Partner-Craft POV | Log every gap as it surfaces — same day is best


How to Use This Tracker


Tab 1 — Gap Log

Column Definitions

ColumnDescription
#Row number
DateDate gap was surfaced
SessionWhich session it emerged from
Gap DescriptionWhat the gap is, in plain language
CategorySelect from category list below
SeverityCritical / Significant / Minor
OwnerWho is responsible for resolution
Resolution StatusCurrent state of the gap
NotesContext, workarounds, related gaps
ArchetypeWhich archetype this gap applies to
Days OpenAuto-calculated from date column

Category Options

Severity Definitions

Resolution Status Options


Tab 2 — Resolution Tracker

Links each gap to a specific resolution type, action, owner, due date, and completion date.

Resolution Type Options

Status Options


Tab 3 — Vendor Summary

Aggregated and anonymized view for sharing with the vendor at engagement close. Populated from the Gap Log.

Engagement Overview Fields

Gaps by Category Summary

Counts of Critical, Significant, and Minor gaps per category, with auto-totals and space for key themes and recommended actions per category.

Up to eight numbered action rows, each capturing:


Tab 4 — Archetype Flags

Pre-populated gap checklist to use at engagement open. Use these as your starting checklist — add rows as new gaps emerge during the engagement.


A1 — Classic Enterprise Cyber

e.g. Mimic and similar established security vendors

Gap AreaValidation QuestionDefault Severity
Japan-specific threat landscape positioningDoes vendor material reference APJ threat actors and incident patterns?Significant
Proof of concept supportCan the vendor provide a credible POC framework for this partner’s client environment?Critical
Competitive displacementDoes the vendor have clear positioning against the incumbent the partner is likely displacing?Significant
Local language materialsWhat exists in Japanese and what needs to be developed?Significant

A2 — Industrial / OT / IIoT

e.g. WI-SUN Alliance, Toyota Tsusho context

Gap AreaValidation QuestionDefault Severity
OT-specific reference architectureDoes one exist and is it credible to an OT engineering audience?Critical
Sector-specific compliance alignmentDoes vendor material address relevant Japanese industrial and critical infrastructure standards?Significant
IT/OT boundary documentationCan the vendor clearly articulate where their product sits relative to the OT environment?Critical
Operational impact languageDoes the vendor speak in terms of operational continuity, not just security posture?Significant

A3 — Emerging / Sensitive AI

e.g. WitnessAI and AI governance vendors

Gap AreaValidation QuestionDefault Severity
Data residency documentationCan the vendor clearly answer where data lives and who can access it?Critical
Japanese regulatory alignmentDoes vendor material address APPI, FISC, or FSA AI guidance?Critical
Executive risk narrativeIs there a board-level AI risk story that works in a Japanese corporate governance context?Significant
Localization depthBeyond translation, is the product and its privacy posture actually adapted for Japan?Significant

A4 — PKI / PQC / Crypto Lifecycle

e.g. Keyfactor, OmniTrust

Gap AreaValidation QuestionDefault Severity
PQC regulatory timeline documentationDoes the vendor have material aligned to NIST, JFSA, and G7 PQC guidance?Critical
Certificate discovery methodologyIs there a clear process for helping a client understand their current crypto exposure?Critical
Non-technical executive narrativeCan the quantum risk story be told without assuming cryptographic literacy?Significant
Migration roadmap templatesDoes the vendor provide a structured path from current state to quantum-safe posture?Significant

A5 — Remediation / Hygiene at Scale

e.g. Northern Tech Mender

Gap AreaValidation QuestionDefault Severity
Device coverage documentationDoes the vendor clearly articulate what environments and device types are supported?Significant
Managed service packagingIs there a clear model for the partner to deliver this as a recurring managed service?Critical
Hygiene baseline methodologyDoes the vendor provide a structured way to assess and document a client’s current hygiene posture?Significant
Escalation and exception handlingWhat happens when a patch cannot be applied and how is that governed?Minor

A6 — SOC Modernization / Agentic D&R

e.g. Agentic SOC vendors, autonomous detection and response

Gap AreaValidation QuestionDefault Severity
Agentic capability documentationIs there clear, credible material on what the product decides autonomously versus what requires human approval?Critical
MSSP transition methodologyDoes the vendor provide a structured approach to transitioning a client away from an incumbent MSSP?Critical
Detection engineering enablementCan the partner’s client team actually build and own detection content, or does it require vendor dependency?Significant
Japan FISC alignmentDoes the vendor’s architecture and data handling support FISC compliance requirements for Japanese FSI clients?Critical