Resources
Cybersecurity Readiness Assessment
A self-assessment tool covering 40 critical security controls across five domains.
Identify gaps in your security posture before an auditor or attacker does. This checklist covers the essential controls every organization should have in place — organized by domain, prioritized by risk impact, and designed to be completed by an IT generalist in under two hours.
Identity & Access
MFA enforcement, privileged access reviews, service account inventory, password policies, SSO coverage, and inactive account cleanup procedures.
Endpoint Security
EDR deployment coverage, patch management SLAs, mobile device management, encryption status, application whitelisting, and BYOD policy enforcement.
Network Security
Firewall rule review, network segmentation, VPN configuration, wireless security, DNS filtering, and intrusion detection coverage assessment.
Data Protection
Data classification inventory, backup verification, encryption key management, DLP policy coverage, data retention compliance, and secure disposal procedures.
Incident Response
IR plan documentation, tabletop exercise schedule, detection tool coverage, escalation procedures, forensic readiness, and communication templates.
Compliance & Governance
Policy documentation status, third-party risk assessments, security awareness training completion rates, audit log retention, and board reporting cadence.
