Methodology
How this assessment works
Question set v2 · scoring model v2. Every completed assessment records the version that produced it, so results stay comparable as the questions change.
What it measures
Twelve single-issue questions across six domains, each chosen because it changes the outcome of a real incident rather than because it is easy to answer. The questions cover accountability, insurance-grade evidence, multi-factor authentication, access reviews, cloud and SaaS configuration, tested recovery, vulnerability remediation, endpoint protection, payment-fraud resilience, incident response rehearsal, supplier assurance and governance of AI tools.
How scoring works
- Normalised scales. Questions use different answer ladders — maturity, coverage, tested capability and evidence readiness — and every ladder resolves to the same 0–5 value before anything is combined.
- Documented weights. Each question carries a weight with a stated reason, and each domain carries a weight. Multi-factor authentication coverage and a tested restore weigh most; AI governance weighs least. The full table is below.
- "I don't know" is a visibility gap. It is never counted as zero and never counted as a pass. The question is excluded from the score, counted as a visibility gap, and lowers the confidence rating. A domain answered entirely "I don't know" is reported as "not visible" rather than given a number.
- Deterministic. The score, posture, maturity level, priority exposures and recommended next step are all calculated by fixed rules. AI is used only to write the narrative around those results — it never sets or changes them.
What the result means
The headline is a risk posture band, not a precise number. A single 0–100 figure implies an accuracy that a twelve-question self-assessment cannot have, so the index is shown as supporting detail only.
| Posture | Means |
|---|---|
| Critical | Several controls that decide breach outcomes are missing today. |
| Elevated | Meaningful exposure remains in controls that attackers routinely exploit. |
| Moderate | Core protection holds, with specific weaknesses worth closing deliberately. |
| Contained | Exposure is managed and evidenced; the work now is sustaining and proving it. |
Alongside it sits a maturity level describing how security is run: Reactive → Compliance-Driven → Structured → Proactive → Exposure-Led. Four or more unknown answers cap the posture at Elevated, because unmeasured control state is exposure in its own right.
What it does not mean
This is an indicative self-assessment based entirely on what you tell us. It is not an audit, a certification, a compliance determination, a penetration test, a technical validation of your environment, or a legal opinion. No evidence is inspected and no systems are tested. A low score does not mean you have been breached; a high score does not mean you cannot be.
Relationship to recognised frameworks
Each question maps to a concept in NIST CSF 2.0 and a control theme in ISO/IEC 27001:2022, so results can be discussed in familiar terms. This is a mapping of observations for orientation only — it does not assess, imply or confer conformity with either framework.
Questions, weights and mapping
Governance & Risk
domain weight 1.0Governance sets the ceiling for every other control, but rarely stops an attack on its own.
Is one named person accountable for cyber security, with the authority and budget to act?
Weight 1.0 — Without a single owner, improvements stall — but ownership alone prevents no incident.
GOVERN — Roles, Responsibilities & Authorities (GV.RR) · A.5.2 Information security roles and responsibilities
If you applied for or renewed cyber insurance today, could you evidence the controls an insurer asks for?
Weight 0.9 — A practical proxy for whether controls exist in evidenced form, not just in conversation.
GOVERN — Risk Management Strategy (GV.RM) · A.5.4 Management responsibilities
Identity & Access
domain weight 1.2Account takeover is the most common entry point for organisations of this size.
Across every way someone can sign in — email, remote access, admin consoles and SaaS — how widely is multi-factor authentication enforced?
Weight 1.5 — Highest weight: the single control most likely to stop a real-world breach at this size.
PROTECT — Identity Management & Authentication (PR.AA-03) · A.5.17 Authentication information
Are user and administrator access rights reviewed and revoked on a defined schedule?
Weight 1.1 — Accumulated and orphaned access widens the blast radius of any single compromise.
PROTECT — Access Permissions & Authorisations (PR.AA-05) · A.5.18 Access rights
Data & Cloud Protection
domain weight 1.2Most business data now sits in SaaS, and recoverability decides how bad an incident becomes.
Are the cloud and SaaS services holding your business data configured to a documented security baseline and reviewed?
Weight 1.3 — Most business data now lives in SaaS, where default settings are rarely safe defaults.
PROTECT — Platform Security (PR.PS-01) · A.8.9 Configuration management
In the last 12 months, have you performed and documented a full restore from backup?
Weight 1.5 — Highest weight: an untested backup is an assumption, and it decides ransomware downtime.
RECOVER — Incident Recovery Plan Execution (RC.RP-01) · A.8.13 Information backup
Infrastructure & Endpoints
domain weight 1.1Unremediated exposure and unmanaged devices are the routes attackers actually use.
Are identified vulnerabilities and security patches remediated within a defined timeframe and tracked to closure?
Weight 1.4 — Finding exposure is common; closing it within a deadline is what actually reduces risk.
IDENTIFY — Risk Assessment (ID.RA-01) · A.8.8 Management of technical vulnerabilities
Are the devices used for work covered by managed endpoint protection that someone actually monitors?
Weight 1.2 — Unmanaged or unmonitored devices are both the entry point and the blind spot.
DETECT — Continuous Monitoring (DE.CM-01) · A.8.7 Protection against malware
Detection & Response
domain weight 1.1Detection and rehearsed response shorten dwell time and cut incident cost.
If a convincing email asked to change supplier bank details, would your controls and process stop the payment going out?
Weight 1.3 — Business email compromise causes more direct financial loss than any other attack at this size.
PROTECT — Awareness & Training (PR.AT-01) · A.6.3 Information security awareness, education and training
Has the incident response plan been rehearsed by the people who would actually run it?
Weight 1.4 — An unrehearsed plan fails under pressure; rehearsal is what shortens an incident.
RESPOND — Incident Management (RS.MA-01) · A.5.24 Information security incident management planning
Third-Party & AI Risk
domain weight 0.8Real but usually second-order exposure compared with identity and recovery.
Are suppliers with access to your data or systems security-assessed before onboarding and contractually bound?
Weight 1.0 — Supplier compromise becomes your incident, but is usually slower-moving than direct attack.
GOVERN — Cybersecurity Supply Chain Risk Management (GV.SC-06) · A.5.19 Information security in supplier relationships
Is staff use of AI tools governed — approved tools, rules on what data may be entered, and visibility of what is in use?
Weight 0.8 — A fast-growing route for data leaving the business, though rarely the cause of an incident yet.
GOVERN — Policy (GV.PO-01) · A.5.1 Policies for information security
