Ardcarne Life Assurance: documents logo

Security review: scheduling the closing session

Email thread

Ardcarne Life Assurance: documents logo Ardcarne Life Assurance: documents · sales

Theo Gallagher proposed a closing session for the security review. Declan Furlong accepted Wednesday morning but demanded the written incident account before it, plus sub-processor detail and a retained exit plan document.

What was said

What this says

Current to 11 Oct 26

Theo Gallagher proposed a closing session for the security review. Declan Furlong accepted Wednesday morning but demanded the written incident account before it, plus sub-processor detail and a retained exit plan document.

Ask: Declan agreed to a Wednesday morning session with one ICT risk colleague. He added three conditions: the written incident account first, sub-processors named for the July outage, and an exit plan he can retain.

Customer view: He will not close findings on verbal assurance and reminded Theo he expects the same promptness for any further incident.

Next: Theo cannot date the incident account alone, so he will confirm the delivery date in writing on Monday, before the session.

AI · claude-sonnet-5-5 · 11 Oct 2026

The thread

Updated 9 Oct 26
Typesales
Messages3
First message2026-07-31
Last message2026-07-31

Messages

  1. Theo Gallagher
    Theo Gallagher 31 Jul 2026 16:54
    to Declan Furlong
    Dear Declan, Thank you for your time on the call today. As agreed, I would like to fix a closing session for the security review so we can go through the open findings together and agree what evidence you still need. As I see the open findings and their owners: 1. Incident history and notification times for the July outage: a written account with a timeline. Owner: me, with input from the platform team. 2. Exit plan: the steps and the data return format. Owner: me. 3. Entries for your register of information: your team to confirm the fields you need, and I will map each one to a control reference. Could you let me know whether early next week suits you, Tuesday or Wednesday morning? Please also tell me who from your ICT risk team should join, so I can bring the right people from our side. Thanks, Theo
  2. Declan Furlong
    Declan Furlong 31 Jul 2026 17:22
    to Theo Gallagher
    Theo, Thank you. Your list matches mine, with one addition. 1. Wednesday morning is acceptable. One colleague from ICT risk will join me. 2. Under DORA we need the written incident account before the session, not at it. Please provide a dated commitment for when it will reach me. 3. For the register of information, please also state which of your sub-processors, if any, were involved in the July outage. I will not be able to close that finding on a verbal assurance. 4. Please confirm the exit plan will be a document I can retain, not a walkthrough. I would also remind you that I was told of the outage by your team on the day, and I expect the same promptness for any further incident. Regards, Declan Furlong, CISO
  3. Theo Gallagher
    Theo Gallagher 31 Jul 2026 17:37
    to Declan Furlong
    Declan, Understood, and thank you for being so clear. Taking your points in order: 1. Wednesday morning is booked from my side. I will send the invitation shortly. 2. The written incident account is something I cannot date on my own, as it depends on the platform team. I have asked them for a date this evening. Here is the dated commitment I can give you now: I will confirm the delivery date to you in writing on Monday, and it will be before the session. 3. Sub-processors: I will answer that in the incident account, with evidence attached, so you are not relying on my word. 4. The exit plan will be a retained document, sent with the incident account. On your last point, noted. I will make sure it is recorded as an open item. Thanks, Theo

BB-Demo is a fictional company; every organisation and person here is invented. B-Brain is the tool. Built by site/build_site.py from the site tree, data as of Fri 9 Oct 2026. Help & Support

Help & Support

Open as a page

Help & Support

B-Brain is one place to read everything the company knows about its customers: the CRM, calls, emails, support tickets, product usage, invoices, documents, news and HR. Every page is built from those systems and the data is current to Fri 9 Oct 2026.

How to use the site

How to ask

Press Ask Brain in the header. Type a question, or pick one of the examples.

The site itself does not call an AI model; answers in Claude come from the same figures you see here.

What the data covers

DataRecords
Organisations150
People at customers573
BB-Demo staff48
Calls1,382
Email threads2,122
Support tickets789
Documents850
Deals217
Invoices187
Events49
News items84

Data as of Fri 9 Oct 2026. Text marked AI was written by the brain from the records listed in its made-from link; an AI output that cannot cite its evidence is refused and the previous text kept. Where two systems disagree (for example a contract and the CRM), the key facts show both values and mark the difference.

BB-Demo is a fictional company: every organisation, person and figure here is invented for this demonstration. B-Brain is the tool that reads its data.

Who to contact

Email support@b-brain.example or talk to your B-Brain account team. Tell us the page address and what looked wrong; a screenshot helps.

HelpAsk B

Ask B

B-Brain · read-only