Readiness check
Ten questions on the controls that actually carry points. Three minutes, no email required, and you see your score straight away.
1. Do you have a written information security policy, approved by management?
A policy nobody approved scores as an intention, not a control.
2. Is one named person accountable for security?
Assessors look for a name, not a committee.
3. Is multi-factor authentication enforced on email and remote access?
Enforced for everyone, not available as an option.
4. Do you have a documented process for removing access when someone leaves?
This one is checked against real leaver records.
5. Are laptops and mobile devices encrypted?
Full disk encryption, with a way to prove coverage.
6. Have your backups been tested by an actual restore in the last 12 months?
A tested restore is the single most requested piece of evidence.
7. Is there a documented incident response procedure?
Who is called, in what order, and who decides.
8. Could you notify a customer of a breach within 72 hours?
Contractually, most large buyers require far less than 72 hours.
9. Are audit logs retained and actually reviewable?
Retention with nobody reading them still loses points.
10 questions left
See my readiness scoreYour result
0%
Book the assessment readiness check, 20 minutes
The first conversation is about finding out whether you are actually at risk, and it costs nothing.
Not ready to talk yet?
The screen above shows your six weakest controls. The email version covers all ten: the exact evidence an assessor expects for each one, and the order to fix them in. It is written and sent personally, usually the same day.
Your details are used to send this breakdown and to follow up on it. Nothing else, and no mailing list.