Review 20 controls across Network, Data, Access Control, Endpoint, Awareness, and Incident Response. The result is a planning score and priority list — not a penetration test, audit, compliance verdict, or certification.
Business profile provides context; the 0–100 control score is based on selected controls and recent incidents.
Source and freshness: this is a deterministic planning checklist, not a live threat feed or regulatory database. Verify current authority guidance, breach duties, sector rules, insurance conditions, and technical findings before treating any action as sufficient.
Mark only controls you can verify. The tool scores 20 controls across six domains, applies a limited recent-incident penalty, and highlights priority gaps.
Planning aid. The result is not a penetration test, audit, legal opinion, or compliance certificate.
It measures the 20 controls you mark as present across six domains, with a limited penalty for recent incidents.
No. It is a local self-assessment for planning. Verify technical findings and current legal or sector duties with qualified specialists.
The assessment runs in the browser. Do not enter credentials, customer records, incident evidence, private keys, or other sensitive material.