Data as of Aug 25, 2026 · Based on 318 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Your brand can be here too.
The best way for a CTO to hire and vet a specialized cybersecurity consulting firm is to **define the exact scope and technical outcomes needed** , then evaluate candidates through **targeted technical deep-dives, reference checks from similar-sized peers, and real-world scenario…
The best way for a CTO to hire and vet a specialized cybersecurity consulting firm is to define the exact scope and technical outcomes needed , then evaluate candidates through targeted technical deep-dives, reference checks from similar-sized peers, and real-world scenario testing.
Vetting Steps
If you'd like, let me know:
I can provide a custom list of specific interview questions to ask their engineering lead.
The best approach is to treat the consulting firm itself as a **high-risk third party**—not just as a vendor you're buying expertise from. NIST’s current supply-chain guidance explicitly recommends due diligence based on factors such as provenance, resilience, foundational cyber practices, and supply-chain tiers.…
The best approach is to treat the consulting firm itself as a high-risk third party—not just as a vendor you're buying expertise from. NIST’s current supply-chain guidance explicitly recommends due diligence based on factors such as provenance, resilience, foundational cyber practices, and supply-chain tiers.
Before soliciting proposals, write a 1–2 page statement of work answering:
For example, don't ask for "a cybersecurity assessment." Ask for:
"Assess our AWS environment, identity architecture, CI/CD pipeline, and production application against our defined threat model; identify exploitable weaknesses; prioritize findings by business impact; and provide an executive remediation roadmap plus technical evidence." That makes firms much easier to compare.
Don't optimize for the biggest logo. Look for demonstrated experience with your specific problem.
For each candidate, ask:
A boutique firm with five excellent people who routinely perform your type of assessment can be much better than a giant consultancy where the partner sells the engagement and a junior team executes it.
This is the part CTOs often underweight.
Ask for evidence covering:
Corporate
Security
Supply chain
NIST's newly published 2026 due-diligence guide specifically calls out foreign ownership/control/influence, provenance, resilience, foundational cyber practices, and supply-chain tiers as areas to assess.
Don't let the sales team be your primary evaluation.
Have your CISO/security lead, architect, or senior engineers spend 60–90 minutes with the proposed engagement team. Give them a realistic scenario and ask them to reason through it.
For example:
"Our production environment is AWS. Developers have broad IAM permissions, we use GitHub Actions for deployment, customer data is in RDS, and we recently had an anomalous credential-use event. Walk us through how you would investigate and what you'd want from us." You're looking for how they think, not whether they can recite security terminology.
Good consultants will ask clarifying questions about:
Be wary of people who immediately prescribe tools or produce a giant checklist.
This is probably the highest-signal part of the process.
Give the finalists a sanitized architecture diagram, sample cloud configuration, or hypothetical incident and ask for a 60-minute assessment/outbrief.
Score them on:
| Dimension | What you're looking for |
|---|---|
| Technical depth | Can they identify meaningful attack paths? |
| Business judgment | Can they distinguish critical from merely interesting? |
| Methodology | Is there a reproducible assessment process? |
| Communication | Can executives understand the risk? |
| Pragmatism | Do recommendations fit your environment? |
| Independence | Will they tell you uncomfortable things? |
| Evidence | Can they substantiate findings? |
Don't ask them to perform free consulting. Give every finalist the same limited exercise.
Don't simply ask, "Were you happy?"
Ask references:
That last question is particularly useful.
This is where the CTO should involve legal/procurement early.
At minimum, address:
NIST specifically recommends putting supplier cybersecurity requirements, information-sharing rules, responsibilities, verification mechanisms, and performance requirements into contracts.
A beautiful 150-page PDF isn't necessarily a good security engagement.
Require deliverables that are actionable:
For a penetration test, for example, I'd want the firm to demonstrate what an attacker could actually accomplish, not just produce a vulnerability scanner export.
I'd use something like:
The low price weighting is intentional.
A $150K assessment that finds the thing your $50K assessment missed is usually the cheaper engagement.
I'd be particularly cautious if a firm:
I'd run the procurement roughly like this:
Week 1: Define problem, scope, threat model, success criteria ↓ Week 2: Shortlist 3–5 specialists ↓ Week 3: NDA + technical interviews + security due diligence ↓ Week 4: Finalists submit proposals and perform the same technical exercise ↓ Week 5: Reference checks + commercial/legal negotiation ↓ Week 6: Select firm and finalize rules of engagement ↓ Engagement: Require weekly working sessions, not just a final report ↓ Afterward: Remediation + independent retest
The overarching principle is: hire the firm that demonstrates the best judgment about your actual risk, not the firm with the most impressive credentials deck.
For a useful external benchmark, NIST's current C-SCRM material is particularly applicable here: its CSF 2.0 guidance says supplier requirements should be commensurate with the supplier's criticality and potential impact if compromised, and CISA likewise recommends evaluating vendor security posture and putting cybersecurity obligations into supplier contracts.
If you're actually preparing to hire one, I can also give you a CTO-grade RFP template + 100-point vendor scorecard + interview questions + reference-check script you can use verbatim.
For a useful external benchmark, NIST's current C-SCRM material is particularly applicable here: its CSF 2.0 guidance says supplier requirements should be commensurate with the supplier's criticality and potential impact if compromised, and CISA likewise recommends evaluating vendor security posture and putting cybersecurity obligations into supplier contracts.
At minimum, address:
NIST specifically recommends putting supplier cybersecurity requirements, information-sharing rules, responsibilities, verification mechanisms, and performance requirements into contracts.
Hiring and vetting a specialized cybersecurity consulting firm requires `a structured, strategic approach that looks past flashy marketing and focuses on proven capabilities, architectural alignment, and cultural…
Hiring and vetting a specialized cybersecurity consulting firm requires a structured, strategic approach that looks past flashy marketing and focuses on proven capabilities, architectural alignment, and cultural fit.
Here is a step-by-step framework for a CTO to navigate the process effectively:
Would you like me to expand on:
The best approach is to treat the firm like a **high-risk technical supplier**, not like a normal professional-services vendor. Your goal isn't to find the firm with the biggest logo; it's to establish that they have the **specific expertise, independence, methodology, people, and operational maturity** to solve your…
The best approach is to treat the firm like a high-risk technical supplier, not like a normal professional-services vendor. Your goal isn't to find the firm with the biggest logo; it's to establish that they have the specific expertise, independence, methodology, people, and operational maturity to solve your problem.
NIST's current guidance explicitly recommends due diligence on prospective suppliers, including their cybersecurity capabilities, risk-management practices, supply-chain exposure, and resilience.
Don't start with "we need a cybersecurity assessment."
Define the actual decision you need help making:
Write a one-page problem statement containing:
Current state → business risk → questions to answer → scope → expected deliverables → success criteria.
This prevents consultants from selling you their favorite service rather than solving your problem.
I'd favor depth over breadth.
For each candidate, ask:
That last question is surprisingly revealing.
A strong specialist will usually have opinions and boundaries. A generic consultancy tends to say some variation of "we can do all of that."
This is one of the biggest CTO traps.
The person who impresses you during the sales process may not do the work.
Make the proposed engagement lead and key technical people participate in the evaluation. Ask them to walk you through a sanitized example of a comparable engagement:
"Show me what you discovered, how you determined severity, what evidence you collected, what you recommended, and what changed afterward." You want to see whether they think like practitioners.
For a technical engagement, I'd also give finalists a small hypothetical scenario relevant to your environment and ask them to explain their approach. Don't ask them to perform free consulting; you're testing methodology and judgment.
Certifications are useful signals, but they're not proof of competence.
Look for evidence such as:
For a firm that will receive privileged access to your systems or sensitive information, perform vendor due diligence proportional to that access. NIST CSF 2.0 specifically recommends assessing suppliers based on criticality and continuing to monitor them throughout the relationship.
The 2026 NIST SP 1326 is particularly useful here: its due-diligence model considers areas including foreign ownership/control, provenance, resilience, foundational cyber practices, and supply-chain tiers.
Don't just ask:
"Were you happy with them?" Ask the reference:
The "what went wrong?" question is particularly valuable.
Ask finalists for a redacted sample report.
A good report should generally distinguish:
Observation → evidence → risk → business impact → severity → remediation → owner/prioritization.
Be wary of reports that are essentially:
"You have 47 vulnerabilities. Upgrade X, enable Y, implement Z." The CTO-level value is in understanding which risks actually matter and what to do about them.
For executive work, the firm should be capable of translating technical findings into things like:
Ask whether they:
None of these automatically disqualifies a firm, but you want the conflicts disclosed and understood.
If you're asking a firm to determine whether your existing security stack is effective, I'd strongly prefer an evaluator without a financial incentive to replace it.
The SOW should specify:
For especially sensitive engagements, address what happens when the engagement ends—including credentials, data, logs, reports, tooling, and access. NIST's supply-chain guidance explicitly treats the end of the supplier relationship as part of the risk lifecycle.
I'd score finalists roughly like this:
| Criterion | Weight |
|---|---|
| Relevant technical expertise | 25% |
| Quality of proposed delivery team | 20% |
| Methodology / technical rigor | 15% |
| Relevant references | 15% |
| Quality of deliverables | 10% |
| Independence / conflicts | 5% |
| Security & operational maturity | 5% |
| Price | 5% |
Don't let price dominate.
A $100K engagement that correctly identifies a catastrophic risk can be dramatically cheaper than a $40K engagement that produces a beautiful but useless report.
Before signing, I would want the finalist to be able to answer these five questions crisply:
1. Why are you particularly good at this problem? 2. Who exactly will do the work? 3. What will you do that our internal security team can't easily do themselves? 4. What will the final deliverable enable me to decide or change? 5. Under what circumstances would you tell me that your own proposed approach isn't working? If the answers are vague, marketing-heavy, or dependent on the firm's brand, I'd keep looking.
For a highly specialized cybersecurity engagement, I'd generally choose a smaller specialist with exceptional practitioners over a large generalist consultancy—provided the specialist has adequate operational maturity, references, insurance, data-handling controls, and the ability to deliver at your scale.
The ideal firm leaves your organization with better security decisions and capabilities, not merely a 150-page PDF.
And if you're evaluating a particularly critical supplier, the current NIST guidance gives you a useful independent framework for structuring the due-diligence process rather than relying solely on the firm's own claims.
A CTO should hire a cybersecurity consulting firm the same way they would hire a critical engineering partner: define the problem precisely, validate technical depth, test the people who will actually do the work, and structure the engagement around measurable outcomes. A common failure mode is selecting the firm with…
A CTO should hire a cybersecurity consulting firm the same way they would hire a critical engineering partner: define the problem precisely, validate technical depth, test the people who will actually do the work, and structure the engagement around measurable outcomes.
A common failure mode is selecting the firm with the strongest brand or the cheapest proposal. The better question is: “Will this team materially reduce our risk, and can they prove it?”
Before talking to firms, define:
Business objective
Reduce breach risk?
Pass SOC 2 / ISO 27001?
Prepare for enterprise customers?
Secure cloud architecture?
Test application security?
Build an incident response capability?
Provide interim CISO leadership?
Scope
Applications
Cloud environments
Identity systems
Endpoints
Network
Data stores
Third-party vendors
Regulatory requirements
Expected outcome
Prioritized remediation roadmap
Vulnerability findings
Architecture recommendations
Policies and controls
Executive risk report
Hands-on fixes
Avoid vague requests like “perform a security assessment.” A penetration test, a maturity assessment, a compliance readiness review, and a security architecture review are very different engagements.
Cybersecurity consulting is highly specialized. Consider separate categories:
| Need | Look for |
|---|---|
| Find exploitable weaknesses | Penetration testing / red team specialists |
| Secure cloud architecture | Cloud security architects |
| Build security program | vCISO / security strategy consultants |
| Achieve compliance | GRC specialists |
| Respond to breaches | Incident response firms |
| Secure software | Application security specialists |
| Review acquisitions/vendors | Cyber due diligence specialists |
A firm that claims to be excellent at everything deserves extra scrutiny.
For each candidate, ask for:
Three customers similar to us in:
industry
size
technology stack
regulatory environment
Examples of problems they found and how they helped fix them.
Ask:
“Who specifically will be assigned to our account?” Then interview those people.
Many firms sell with senior experts but deliver with junior staff. Confirm:
Good firms can explain their methodology clearly.
Ask:
A credible firm should be able to explain tradeoffs rather than simply produce a checklist.
Remember: you are giving them privileged access.
Review:
NIST recommends treating suppliers—including cybersecurity providers—as part of your supply-chain risk management process and evaluating areas such as provenance, resilience, and foundational security practices.
Questions to ask:
A CTO should spend 60–90 minutes with the actual delivery team.
Good questions:
Strong consultants will challenge your assumptions.
Ask for a sanitized example:
A 100-page report full of vulnerabilities is less valuable than a short report that tells leadership what matters and why.
Good statements of work define:
Example:
Example:
Define:
Talk to references without the salesperson present.
Ask:
Be cautious if a firm:
A strong process:
For many organizations, the best partner is not the largest consultancy—it is the firm with the highest concentration of practitioners who have solved your exact class of problems.
Hiring and vetting a specialized cybersecurity consulting firm requires `a structured, engineering-led approach` . As a CTO, your goal is to find a partner who doesn't just check compliance boxes, but genuinely understands your tech stack, threat model, and engineering velocity. Here is a step-by-step framework to…
Hiring and vetting a specialized cybersecurity consulting firm requires a structured, engineering-led approach . As a CTO, your goal is to find a partner who doesn't just check compliance boxes, but genuinely understands your tech stack, threat model, and engineering velocity.
Here is a step-by-step framework to source, evaluate, and onboard the right firm:
Before reaching out to vendors, get crystal clear on what you actually need. Vague requests ("we need a security assessment") lead to bloated, generic proposals.
Don't rely solely on Google searches or Gartner quadrants, which often favor enterprise legacy giants rather than agile, specialized boutique firms.
When you get past the initial sales pitch, demand a technical deep-dive with the actual practitioners who will do the work—not just an account executive.
Before signing, validate their track record under pressure.
If you'd like, let me know:
I can give you a tailored list of specific questions to ask their technical lead during the interview.
No sources cited
The best approach is to treat the firm like a **high-risk technical supplier**, not like a normal professional-services vendor. The key is to evaluate **the actual people who will do the work, the evidence behind their claims, and the quality of their proposed methodology**. NIST’s current guidance explicitly…
The best approach is to treat the firm like a high-risk technical supplier, not like a normal professional-services vendor. The key is to evaluate the actual people who will do the work, the evidence behind their claims, and the quality of their proposed methodology.
NIST’s current guidance explicitly recommends doing supplier due diligence before entering the relationship and tailoring it to the supplier’s criticality and risk. Its July 2026 due-diligence guide breaks this into areas including provenance, resilience, foundational cyber practices, supply-chain tiers, and ownership/control.
Be very specific about what you are buying. For example:
Then define what "good" looks like: deliverables, scope, timeline, access required, severity methodology, remediation guidance, executive reporting, and whether you need independent validation afterward.
This prevents a common failure mode: choosing the firm with the best sales presentation rather than the firm best suited to the actual problem.
Don't start with the biggest cybersecurity consultancies. Start with firms that have demonstrated experience with your exact technology, threat model, and industry.
Ask each candidate:
"Show me two or three engagements you've completed that are substantially similar to ours. What was the problem, what did you actually do, and what changed as a result?"
You want specifics—not logos and generic case studies.
I'd particularly investigate:
This is probably the single most important vetting step.
Have your CTO/CISO/lead engineer spend 60–90 minutes with the proposed technical team. Give them a realistic scenario from your environment and ask them to reason through it.
For example:
"Here's our architecture. Here's what an attacker can reach from the Internet. Here's our authentication model. Walk us through how you'd assess this and what you'd prioritize."
You're looking for how they think, not whether they can recite security terminology.
Good consultants will ask uncomfortable questions about assumptions, attack paths, business impact, compensating controls, and evidence.
Ask for appropriate evidence such as:
Certifications are useful signals, but they aren't substitutes for technical references and examination of the actual team.
NIST's CSF 2.0 specifically contemplates using certifications, self-attestation, inspections, and other evidence of acceptable security practices when assessing suppliers.
Don't ask:
"Tell us why you're the best cybersecurity firm."
Give every finalist the same technical scenario and ask for:
Then score the responses independently.
A useful weighting might be:
| Factor | Weight |
|---|---|
| Technical capability | 30% |
| Relevant experience | 20% |
| Proposed delivery team | 20% |
| Methodology/deliverables | 15% |
| References/reputation | 10% |
| Price | 5% |
Don't let price dominate. A mediocre security assessment can cost vastly more than the consulting fee if it creates false confidence.
Don't accept three hand-picked references and ask whether they "liked the firm."
Ask references:
That last question is particularly valuable.
This is where many otherwise sophisticated companies become surprisingly casual.
The contract should address at least:
For a firm with privileged access, I'd also require named personnel and explicit approval for substitutions.
NIST's CSF guidance specifically recommends contractual requirements covering security performance, vulnerability disclosure, employee vetting, evidence of security practices, and responsibilities across the supplier relationship.
A cybersecurity firm shouldn't automatically receive broad administrative access just because "they need to test things."
Use:
For particularly sensitive engagements, consider a dedicated environment or jump host.
For an important or long-term relationship, I'd strongly consider a small paid engagement before signing a large multi-year contract.
For example:
"Assess this application/cloud environment over two weeks and give us your findings and recommendations."
Then judge:
A $20K–$50K pilot can be extraordinarily cheap insurance against a bad $500K consulting relationship.
I'd be cautious if a firm:
I'd evaluate the firm on three independent axes:
1. Can they do the work?
Technical competence and relevant experience.
2. Can I trust them with the access and information?
Their own security, personnel, controls, and contractual obligations.
3. Will their work change our security posture?
Quality of findings, prioritization, remediation guidance, and ability to work with engineering.
If a firm scores 10/10 on #1 but 4/10 on #2, don't hire them. If it scores 9/10 on #2 but 5/10 on #3, you may simply be buying an expensive compliance exercise.
For a formal procurement process, I'd base the vendor-risk portion on NIST CSF 2.0's GV.SC supplier-risk guidance and NIST SP 800-161 Rev. 1, rather than inventing your own security questionnaire from scratch. NIST's newest SP 1326, finalized in July 2026, is particularly useful for structuring supplier due diligence.
If you tell me what kind of cybersecurity firm you're hiring (e.g., red team, application security, incident response, vCISO, cloud security), I can give you a much more specific CTO interview/vetting scorecard and the 15–20 questions I'd use in the finalist interviews.
Hiring and vetting a specialized cybersecurity consulting firm requires balancing technical precision with business alignment. As a CTO, your goal is to find a partner who doesn't just check compliance boxes, but genuinely understands your threat model, technology stack, and…
Hiring and vetting a specialized cybersecurity consulting firm requires balancing technical precision with business alignment. As a CTO, your goal is to find a partner who doesn't just check compliance boxes, but genuinely understands your threat model, technology stack, and velocity.
Here is a structured, step-by-step approach to finding and vetting the right firm:
If you'd like, let me know:
I can tailor a specific technical interview rubric or list of questions to ask their engineers during your vetting calls.
Hiring and vetting a specialized cybersecurity consulting firm requires `a structured, engineering-led approach` . As a CTO, you need to look past the sales pitch and rigorously evaluate technical depth, alignment with your tech stack, and crisis…
Hiring and vetting a specialized cybersecurity consulting firm requires a structured, engineering-led approach . As a CTO, you need to look past the sales pitch and rigorously evaluate technical depth, alignment with your tech stack, and crisis readiness.
Here is a step-by-step framework to source, evaluate, and select the right partner:
If you'd like to tailor this further, let me know:
I can help you draft a custom RFP template or a technical screening question set for the interviews.
For a CTO, the best approach is to treat a cybersecurity consulting firm like a **high-risk technical supplier**, not like an ordinary professional-services vendor. You are evaluating both their ability to do the work *and* the risk created by giving them privileged access to your systems and sensitive information.…
For a CTO, the best approach is to treat a cybersecurity consulting firm like a high-risk technical supplier, not like an ordinary professional-services vendor. You are evaluating both their ability to do the work and the risk created by giving them privileged access to your systems and sensitive information.
NIST’s current supply-chain guidance explicitly recommends due diligence on suppliers, including their foundational security practices, resilience, provenance, ownership/control, and supply-chain tiers.
Don't issue an RFP saying "improve our cybersecurity." Define the outcomes you actually need.
For example:
Specify scope, systems, assumptions, deliverables, timeline, and what "good" looks like.
A good firm should be able to challenge your scope rather than simply agree to it.
NIST's CSF 2.0 supply-chain guidance recommends establishing supplier requirements in proportion to the supplier's criticality and considering factors such as the importance of the service, sensitivity of data, and degree of system access.
For specialized cybersecurity work, I'd generally prefer 3–5 genuinely relevant firms over a huge procurement exercise.
Look for evidence of:
Ask:
"Who specifically would be on our engagement, and what percentage of the work will each person perform?"
That's often much more revealing than the firm's logo sheet.
For a specialized engagement, the individual consultant can matter more than the firm's overall reputation.
Have your security/engineering leadership interview the proposed lead consultant.
Ask them to walk through a hypothetical scenario relevant to you, such as:
"You discover that our production Kubernetes cluster has an identity boundary problem that could allow lateral movement. How would you validate the finding, determine exploitability, and communicate it?"
You're looking for technical reasoning, not vocabulary.
A strong consultant should be comfortable saying:
Certifications can establish baseline competence, but they're weak evidence of whether a firm will perform well for you.
Ask for anonymized examples of:
You want to see whether their reports are actionable.
A bad report says:
"Implement MFA."
A good report explains where the control is missing, why it matters, how it can be exploited, the affected assets, the realistic business impact, remediation options, and how to validate the fix.
Because you're potentially giving them privileged access, evaluate the consultant as a third-party cyber risk.
Ask about:
A SOC 2 report can provide useful evidence about controls at a service organization, although it shouldn't be treated as proof that the firm is competent at your particular type of cybersecurity engagement.
I'd request the actual SOC 2 Type II report, where applicable—not merely a marketing statement that they are "SOC 2 compliant."
Don't accept references that the salesperson selected solely because they're enthusiastic.
Ask to speak with two or three former/current customers who bought the same service from the same team.
Ask references:
The last two questions are particularly valuable.
For a high-value engagement, don't select based on PowerPoint presentations.
Give finalists a small, sanitized version of your problem and ask them to explain their approach.
For example:
Scenario:
"You have AWS + Kubernetes + Okta + GitHub + SaaS applications, 500 employees, and a small internal security team. We want to understand our realistic ransomware exposure."
Ask each firm:
You can learn a tremendous amount from how they frame the problem.
This is an area where CTO + legal should work together.
Pay particular attention to:
For especially sensitive engagements, explicitly define what the consultant is and isn't authorized to access or test.
NIST's supply-chain guidance emphasizes integrating supplier risk into broader risk management and establishing supplier requirements based on criticality.
I'd score firms roughly like this:
| Dimension | Weight |
|---|---|
| Relevant technical expertise | 25% |
| Quality of proposed team | 20% |
| Methodology & deliverables | 15% |
| References / demonstrated results | 15% |
| Security & third-party risk | 10% |
| Communication / executive fit | 10% |
| Price | 5% |
The exact weights aren't sacred. The point is to prevent procurement from turning a cybersecurity decision into a price comparison.
If you're unsure about a firm, don't immediately give them a year-long vCISO contract.
Consider a small, well-defined paid engagement first.
For example:
2–4 week assessment → executive readout → technical findings → remediation roadmap → decision on larger engagement.
You're evaluating the firm while getting useful work done.
The strongest signal is what happens when they encounter ambiguity, disagreement, incomplete data, or an uncomfortable finding.
I'd become cautious if a firm:
That last point is important: you want an independent expert, not a vendor whose revenue depends on telling you everything is fine.
I'd run the process like this:
Week 1: Define problem, scope, risk tolerance and evaluation criteria.
Week 2: Identify 5–8 candidates and narrow to 3–4.
Week 3: Technical interviews + references + security due diligence.
Week 4: Give finalists the same scenario/RFP and compare proposals.
Week 5: Legal/security review + negotiate SOW and rules of engagement.
Then: Run a bounded pilot or first engagement, measure quality, and decide whether to expand.
The underlying principle is simple: hire the firm that demonstrates the best combination of technical depth, independence, relevant experience, and trustworthy operating practices—not the firm with the best sales presentation.
NIST's newly finalized July 2026 due-diligence guide is particularly useful as a formal framework for this process; it organizes supplier due diligence around foreign ownership/control, provenance, resilience, foundational cyber practices, and supply-chain tiers.
If you tell me what kind of cybersecurity consulting you need (e.g., pen test, red team, cloud security, incident response, vCISO, compliance) and roughly company size/industry, I can also give you a CTO-level vendor evaluation scorecard and interview questions tailored to that engagement.