Free · local scoring · no account

Find the next security improvement.

Score 12 operating areas. Answers remain in this browser unless you choose to contact us afterward.

01 / OwnershipCritical services, systems and security decisions have named business and technical owners.
02 / Asset visibilityInternet-facing, cloud, endpoint and certificate inventories are current and reconciled.
03 / IdentityPrivileged access uses strong authentication, least privilege and regular review.
04 / Data protectionSensitive data is classified and movement controls are tested against real workflows.
05 / Secure deliveryThreat modelling, code review, dependency checks and security testing are part of delivery.
06 / Cloud governanceCloud accounts, logging, public exposure, ownership and cost anomalies are reviewed.
07 / DetectionPriority threats have tested detections with useful context and accountable responders.
08 / Incident responseContainment authority, communications and evidence handling have been exercised.
09 / RecoveryBackups are protected and restoration is tested against critical service needs.
10 / Third partiesCritical suppliers are reviewed by dependency, data, access, resilience and exit plan.
11 / AI securityAI use cases, data, models, agents, tools and human approvals have explicit controls.
12 / ImprovementLeaders review evidence, exceptions and corrective work on a defined rhythm.