Eight questions, about two minutes. You will see where your program stands across the controls that strongly influence whether an incident escalates into a material breach — and which gaps to close first.
1 / 8
Identity
Is multi-factor authentication enforced on all remote and administrative access?
Recovery
Have you actually restored from backup in the last 12 months?
Endpoints
Is endpoint detection and response (EDR) deployed on every endpoint and server?
Incident Response
Do you have a written incident response plan that has been exercised?
Governance
Who owns cybersecurity risk in your organization?
Third-Party Risk
Do you assess the security of vendors before giving them access to your data?
People
How often does staff receive security awareness training or phishing simulation?
AI Governance
Do you know which AI tools your staff are using with company data?
Select an answer to continue
0 / 100
Get your full report by email
Enter your work email and we will send you the control-by-control breakdown, including what we would prioritize first. Your details come to us so a practitioner can follow up once. We do not sell your information or share it with third-party marketers or lead-generation services.
Which compliance, regulatory, or security frameworks apply to you? *
Please complete every required field with a valid value.
Please use your business email address — free providers such as Gmail, Outlook or Yahoo are not accepted.
Please select at least one framework.
Please complete the verification check.
Sent. Check your inbox — your report is on its way.
This does not grant complianceThis self-assessment is an indicative starting point. It is not a risk assessment, an audit, or a compliance determination, and it does not certify, grant, or evidence compliance with HIPAA, NIST, PCI DSS, ISO, SOC 2, IRS Publication 1075, or any other framework.
We could not send the report just now. Please email info@cybernestsec.com and we will send it manually.
Multi-factor authenticationEnforced broadly — one of the highest-value controls an organization can implement.
Multi-factor authenticationPartial coverage is the gap attackers look for. Exempt accounts are usually the privileged ones.
Multi-factor authenticationWithout MFA, one stolen password is enough. This is where we would start.
Backup and recoveryA tested restore is the difference between having backups and being able to recover.
Backup and recoveryUntested backups can fail when they are needed most. A restore test is a half-day exercise.
Backup and recoveryIncomplete or untested backups are a major factor that can turn a ransomware incident into a business-critical recovery event.
Endpoint detectionFull coverage with someone watching the alerts — detection actually works here.
Endpoint detectionAlerts nobody reads are not detection. The tooling is there; the response capacity is not.
Endpoint detectionSignature antivirus does not stop modern intrusions. EDR is the current baseline.
Incident responseA plan that has been exercised is a plan people can actually follow under pressure.
Incident responseAn unexercised plan is a document. The first tabletop always finds broken assumptions.
Incident responseWithout a plan, the first hours of an incident are spent deciding who decides.
Risk ownershipNamed ownership with reporting upward is what turns security into a managed program.
Risk ownershipWhen security sits inside IT's other duties, it loses to whatever is on fire that week.
Risk ownershipUnowned risk is unmanaged risk — and it is the first thing an auditor or regulator asks about.
Vendor riskDocumented vendor review closes one of the most common breach paths into regulated data.
Vendor riskThe smaller vendors are usually the weaker ones, and they often hold the same access.
Vendor riskThird-party compromise is now a leading cause of breaches in healthcare and government.
Security awarenessOngoing training with simulation measurably reduces the click-through that starts most incidents.
Security awarenessAnnual training satisfies a checkbox. It does not change behavior for eleven months.
Security awarenessMany intrusions begin with stolen credentials, phishing, or other attacks aimed at people. Untrained staff is an unmonitored entry point.
AI usage governanceApproved tools plus visibility is ahead of most organizations we assess.
AI usage governanceA policy you cannot measure is a policy you cannot enforce. Visibility comes first.
AI usage governanceShadow AI moves regulated data outside your control, with no record that it happened.
This self-assessment is an indicative starting point, not a formal risk assessment, audit, or compliance determination. Answers are scored in your browser. Your email is used to send your results and follow up once — see our Legal & Policies page for how we handle personal information.