Signal Session . AI Data Exposure Audit
90-Minute AI Exposure Diagnostic — Professional Services

You have AI tools
touching client data.
Most firms can name three.
The average is twenty.

Find out exactly which AI tools can access your client data, what they are sending out, and what to fix first. A 90-minute structured diagnostic. Written posture summary in 24 hours.

4 slots remaining in May — 8 sessions per month, one practitioner

90Structured minutes
11Diagnostic questions
24hWritten summary
$497Flat fee
What firms like yours are finding
$4.88M1 Average cost of a data breach in 2024, the highest on record
$670K2 Additional breach cost when shadow AI is present, above the baseline
40%3 Of organizations will face a security incident from unauthorized AI by 2030
Sources cited in footnotes below.
May availability
4 of 8 slots taken. Sessions run once per week.
What this session surfaces

AI Tools and Client Data Risk for Professional Services Firms

Your team adopted AI tools quickly. That was the right call. But most of those tools were never configured for a firm that handles other people's information. Nobody has gone back to check.

"The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it."

Suja Viswesan, VP Security, IBM — IBM Cost of a Data Breach Report, 20252

The question is not whether AI is in your workflow. It is what it can see, where it is sending data, and whether you can answer for it when a client asks.

The Signal Session maps every AI surface in your firm and scores it against a single posture standard. No jargon. No 300-page framework. One written summary, delivered in 24 hours.

Signal Session Posture Summary Prepared by Catalyst Works Consulting

CLIENTMeridian Legal Partners
DATEMay 2026
SESSION90 minutes
ChatGPT (OpenAI)REVIEW NEEDED
Copilot (Microsoft)CONFIGURED
Calendly AIEXPOSED
Otter.aiNOT REVIEWED
Notion AICONFIGURED
0
Posture score out of 100 3 tools require immediate action
Recommended Actions
01Disconnect Otter.ai from shared client meeting calendar immediately.
02Enable tenant isolation in Microsoft Copilot. IT action required within 7 days.
03Review Calendly AI data retention before next client onboarding.

Boubacar, Catalyst Works Consulting

Composite example. Real outputs are firm-specific.

How it works

Three steps. One written summary. No follow-up pitch.

01
Async Intake
20 minutes, before the session

You complete a short intake that maps every AI-adjacent tool your firm uses — email, drafting, scheduling, document review, CRM. This is what makes the 90 minutes precise instead of exploratory.

02
Live Diagnostic
90 minutes, structured

Four phases. Tool mapping validation, data access interrogation across every AI surface, exposure scoring, and prioritization. You describe your workflow. I translate it into a risk picture with specific actions ranked by urgency.

03
Written Summary
Delivered within 24 hours

A one-page posture summary. Scored. Firm-specific. It tells you exactly where you stand, which tools require immediate action, and what to do first. Yours to share or not share.

"When data is entered into a generative AI tool, you are sharing that data with the AI tool's owners and, thus, entrusting them to protect this data. A data breach can have significant financial and reputational consequences for a CPA firm, and a generative AI tool's owner may attempt to disclaim liability."

AICPA / CPAI — Generative AI and Risks to CPA Firms, 20244

One flat fee

"97% of organizations that experienced an AI-related security incident lacked proper AI access controls. 63% had no governance policies for managing AI or detecting unauthorized use."

IBM Cost of a Data Breach Report, 20252
$5,000+/mo Fractional CISO retainer
vs
$497 One session. One summary. One fee.
90-minute live diagnostic session
Written posture summary (delivered within 24 hours)
Scored by tool — specific, not generic
48-hour async follow-up window for questions
Reserve My Diagnostic

If the session surfaces nothing you don't already know, I refund the fee. No paperwork. No questions.

Why these questions

The Signal Session was not designed in a conference room.

It was built from two decades of operational work inside organizations that had the same problem and could not name it yet. The 11 questions were refined across firms that varied in size, sector, and geography but shared the same blind spot about what their AI systems could reach.

Most firms that go through the session discover at least one tool they had not accounted for. Several discover four or five.

"Firms should assess whether their cybersecurity program appropriately contemplates risks associated with the firm's and its third-party vendors' use of GenAI."

FINRA — Regulatory Notice 24-09, June 20245

20+ Years of operational diagnostic work
4 Continents, one diagnostic standard
11 Questions, not a questionnaire
Common questions
Do I need a technical background?

No. The session is a structured conversation, not a technical audit. You describe your workflow. I translate it into a posture assessment you can act on immediately.

What happens if we find something serious?

The summary tells you what it is and what to do first. For firms where the findings require a structured remediation plan, there is a next-step engagement. The Signal Session always delivers value on its own.

Is the written summary confidential?

Yes. Everything discussed in the session and documented in the summary stays between us. The summary is yours to share or not as you see fit.

What if we find nothing significant?

If the session surfaces nothing you don't already know, I refund the fee. No paperwork. That has not happened yet, but the offer stands.

How quickly can I book?

Most sessions are booked within 48 hours. I run 8 sessions per month. When slots are full, they're full.

Find out what your firm's AI tools can reach.

90 minutes. Written summary in 24 hours. $497 flat.

Reserve My Diagnostic

4 slots remaining in May — 8 per month, one practitioner

Not ready to book yet?

Ask a question first.

If you're not sure whether the Signal Session applies to your firm, send a message. One question, one honest answer. No pitch.

Or email directly: catalystworks.ai@gmail.com

No sales sequence. One reply from Boubacar, usually within 24 hours.

Got it. You'll hear back within 24 hours.

Sources

  1. 1IBM Security / Ponemon Institute. Cost of a Data Breach Report 2024. July 2024. newsroom.ibm.com
  2. 2IBM Security / Ponemon Institute. Cost of a Data Breach Report 2025. July 2025. Shadow AI organizations observed $670K higher breach costs. 97% of AI breach victims lacked proper access controls. newsroom.ibm.com
  3. 3Gartner. Predicts 2025: Shadow AI Creates Security and Compliance Risks. October 2024. Arun Chandrasekaran, Distinguished VP Analyst. Reported by Infosecurity Magazine
  4. 4AICPA / CPAI. Generative AI and Risks to CPA Firms. 2024. Also published in Journal of Accountancy
  5. 5FINRA. Regulatory Notice 24-09: Generative Artificial Intelligence. June 27, 2024. finra.org