SecuredShiftBook a call

Readiness check

Would your evidence survive a customer assessment?

Twenty questions on the controls that actually carry points. A few minutes, no email required, and you see your score straight away.

3 minto complete
20scored controls
Instantno email gate

1. Do you have a written information security policy, approved by management?

A policy nobody approved scores as an intention, not a control.

2. Is one named person accountable for security?

Assessors look for a name, not a committee.

3. Is multi-factor authentication enforced on email and remote access?

Enforced for everyone, not available as an option.

4. Do you have a documented process for removing access when someone leaves?

This one is checked against real leaver records.

5. Are laptops and mobile devices encrypted?

Full disk encryption, with a way to prove coverage.

6. Have your backups been tested by an actual restore in the last 12 months?

A tested restore is the single most requested piece of evidence.

7. Is there a documented incident response procedure?

Who is called, in what order, and who decides.

8. Could you notify a customer of a breach within 72 hours?

Contractually, most large buyers require far less than 72 hours.

9. Are audit logs retained and actually reviewable?

Retention with nobody reading them still loses points.

10. For each control above, could you produce dated evidence, not just a policy?

This is where most first submissions lose the score they expected.

11. Are your staff trained on security basics (phishing, passwords, sensitive data) on a regular basis?

A short recurring session counts; ad-hoc reminders do not.

12. Do your subcontractors and external providers carry contractual security obligations?

A clause in their contract requiring them to meet your security rules.

13. Does every employee have a unique named account, with no shared logins?

Shared accounts make it impossible to prove who did what.

14. Are your systems patched within 30 days of a security update?

Critical updates installed promptly, not left pending for months.

15. Is antivirus or EDR deployed across your whole fleet of machines?

Endpoint protection active on every laptop and server, not just some.

16. Is your remote access (VPN, remote desktop) protected by MFA and logged?

A second factor to connect remotely, with a record of who connected.

17. Have you defined the maximum downtime your business can tolerate after an incident?

A stated recovery time objective, not just a rough guess.

18. Have you mapped the personal data you process in a record of processing?

A register of the client, HR and partner data you hold and how you protect it.

19. Do you keep an up-to-date inventory of your equipment and business applications?

A current list of the machines and software in scope.

20. Have you already answered a vendor security questionnaire, or are you doing so now?

Helps calibrate your maturity and how urgent your situation is.

10 questions left

See my readiness score

Your result

0%

 

 

Book the assessment readiness check, 20 minutes

The first conversation is about finding out whether you are actually at risk, and it costs nothing.

Not ready to talk yet?

Get the full breakdown by email

The screen above shows your six weakest controls. The email version covers all ten: the exact evidence an assessor expects for each one, and the order to fix them in. It is written and sent personally, usually the same day.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Your details are used to send this breakdown and to follow up on it. Nothing else, and no mailing list.

contact@securedshift.com