Tools

Security maturity self-assessment

Twenty-four statements, six domains. Score each 0 (not at all) to 3 (consistently, measured). You get a level per domain and the two domains to fix first. Honest answers only; nobody else sees this unless you share the link.

Identity & access

MFA is enforced for every remote and privileged access path.
Joiner, mover, leaver changes reach every system within a day.
Privileged accounts are separate, vaulted, and session-recorded.
Access is reviewed by owners at least quarterly, with revocations tracked.

Endpoint & detection

Every managed endpoint runs EDR with tamper protection, and coverage is measured.
Alerts are triaged against a written playbook with defined response times.
Detections are tested regularly with adversary emulation or purple-team exercises.
Log sources needed for the top ten attack paths are onboarded and monitored.

Vulnerability & exposure

Internet-facing assets are inventoried and scanned at least weekly.
Critical vulnerabilities on exposed systems are fixed inside a defined SLA, and misses are reported.
Patching covers third-party software and firmware, not only the OS.
An external attack-surface view is reconciled with the internal inventory.

Cloud & data

Cloud accounts have guardrails: no public storage, no root keys, mandatory logging.
Sensitive data is classified and its locations are known.
Backups are immutable, tested by restore, and separated from production credentials.
Secrets live in a vault, not in code or tickets.

Governance & vendors

A risk register exists, is owned, and is reviewed with leadership.
Third parties with data access are assessed before onboarding and re-assessed on a cycle.
Security spending is tied to named risks rather than to renewals.
Policies are short, current, and known by the people they apply to.

Resilience & response

An incident response plan exists with named roles and was exercised in the last year.
Ransomware recovery time is known and has been tested end to end.
Legal, communications, and leadership know their part in a breach.
Lessons from incidents and near misses change controls within a quarter.