Methodology

How this assessment works

Question set v2 · scoring model v2. Every completed assessment records the version that produced it, so results stay comparable as the questions change.

What it measures

Twelve single-issue questions across six domains, each chosen because it changes the outcome of a real incident rather than because it is easy to answer. The questions cover accountability, insurance-grade evidence, multi-factor authentication, access reviews, cloud and SaaS configuration, tested recovery, vulnerability remediation, endpoint protection, payment-fraud resilience, incident response rehearsal, supplier assurance and governance of AI tools.

How scoring works

  • Normalised scales. Questions use different answer ladders — maturity, coverage, tested capability and evidence readiness — and every ladder resolves to the same 0–5 value before anything is combined.
  • Documented weights. Each question carries a weight with a stated reason, and each domain carries a weight. Multi-factor authentication coverage and a tested restore weigh most; AI governance weighs least. The full table is below.
  • "I don't know" is a visibility gap. It is never counted as zero and never counted as a pass. The question is excluded from the score, counted as a visibility gap, and lowers the confidence rating. A domain answered entirely "I don't know" is reported as "not visible" rather than given a number.
  • Deterministic. The score, posture, maturity level, priority exposures and recommended next step are all calculated by fixed rules. AI is used only to write the narrative around those results — it never sets or changes them.

What the result means

The headline is a risk posture band, not a precise number. A single 0–100 figure implies an accuracy that a twelve-question self-assessment cannot have, so the index is shown as supporting detail only.

PostureMeans
CriticalSeveral controls that decide breach outcomes are missing today.
ElevatedMeaningful exposure remains in controls that attackers routinely exploit.
ModerateCore protection holds, with specific weaknesses worth closing deliberately.
ContainedExposure is managed and evidenced; the work now is sustaining and proving it.

Alongside it sits a maturity level describing how security is run: Reactive → Compliance-Driven → Structured → Proactive → Exposure-Led. Four or more unknown answers cap the posture at Elevated, because unmeasured control state is exposure in its own right.

What it does not mean

This is an indicative self-assessment based entirely on what you tell us. It is not an audit, a certification, a compliance determination, a penetration test, a technical validation of your environment, or a legal opinion. No evidence is inspected and no systems are tested. A low score does not mean you have been breached; a high score does not mean you cannot be.

Relationship to recognised frameworks

Each question maps to a concept in NIST CSF 2.0 and a control theme in ISO/IEC 27001:2022, so results can be discussed in familiar terms. This is a mapping of observations for orientation only — it does not assess, imply or confer conformity with either framework.

Questions, weights and mapping

Governance & Risk

domain weight 1.0

Governance sets the ceiling for every other control, but rarely stops an attack on its own.

  • Is one named person accountable for cyber security, with the authority and budget to act?

    Weight 1.0 — Without a single owner, improvements stall — but ownership alone prevents no incident.

    GOVERN — Roles, Responsibilities & Authorities (GV.RR) · A.5.2 Information security roles and responsibilities

  • If you applied for or renewed cyber insurance today, could you evidence the controls an insurer asks for?

    Weight 0.9 — A practical proxy for whether controls exist in evidenced form, not just in conversation.

    GOVERN — Risk Management Strategy (GV.RM) · A.5.4 Management responsibilities

Identity & Access

domain weight 1.2

Account takeover is the most common entry point for organisations of this size.

  • Across every way someone can sign in — email, remote access, admin consoles and SaaS — how widely is multi-factor authentication enforced?

    Weight 1.5 — Highest weight: the single control most likely to stop a real-world breach at this size.

    PROTECT — Identity Management & Authentication (PR.AA-03) · A.5.17 Authentication information

  • Are user and administrator access rights reviewed and revoked on a defined schedule?

    Weight 1.1 — Accumulated and orphaned access widens the blast radius of any single compromise.

    PROTECT — Access Permissions & Authorisations (PR.AA-05) · A.5.18 Access rights

Data & Cloud Protection

domain weight 1.2

Most business data now sits in SaaS, and recoverability decides how bad an incident becomes.

  • Are the cloud and SaaS services holding your business data configured to a documented security baseline and reviewed?

    Weight 1.3 — Most business data now lives in SaaS, where default settings are rarely safe defaults.

    PROTECT — Platform Security (PR.PS-01) · A.8.9 Configuration management

  • In the last 12 months, have you performed and documented a full restore from backup?

    Weight 1.5 — Highest weight: an untested backup is an assumption, and it decides ransomware downtime.

    RECOVER — Incident Recovery Plan Execution (RC.RP-01) · A.8.13 Information backup

Infrastructure & Endpoints

domain weight 1.1

Unremediated exposure and unmanaged devices are the routes attackers actually use.

  • Are identified vulnerabilities and security patches remediated within a defined timeframe and tracked to closure?

    Weight 1.4 — Finding exposure is common; closing it within a deadline is what actually reduces risk.

    IDENTIFY — Risk Assessment (ID.RA-01) · A.8.8 Management of technical vulnerabilities

  • Are the devices used for work covered by managed endpoint protection that someone actually monitors?

    Weight 1.2 — Unmanaged or unmonitored devices are both the entry point and the blind spot.

    DETECT — Continuous Monitoring (DE.CM-01) · A.8.7 Protection against malware

Detection & Response

domain weight 1.1

Detection and rehearsed response shorten dwell time and cut incident cost.

  • If a convincing email asked to change supplier bank details, would your controls and process stop the payment going out?

    Weight 1.3 — Business email compromise causes more direct financial loss than any other attack at this size.

    PROTECT — Awareness & Training (PR.AT-01) · A.6.3 Information security awareness, education and training

  • Has the incident response plan been rehearsed by the people who would actually run it?

    Weight 1.4 — An unrehearsed plan fails under pressure; rehearsal is what shortens an incident.

    RESPOND — Incident Management (RS.MA-01) · A.5.24 Information security incident management planning

Third-Party & AI Risk

domain weight 0.8

Real but usually second-order exposure compared with identity and recovery.

  • Are suppliers with access to your data or systems security-assessed before onboarding and contractually bound?

    Weight 1.0 — Supplier compromise becomes your incident, but is usually slower-moving than direct attack.

    GOVERN — Cybersecurity Supply Chain Risk Management (GV.SC-06) · A.5.19 Information security in supplier relationships

  • Is staff use of AI tools governed — approved tools, rules on what data may be entered, and visibility of what is in use?

    Weight 0.8 — A fast-growing route for data leaving the business, though rarely the cause of an incident yet.

    GOVERN — Policy (GV.PO-01) · A.5.1 Policies for information security