Free — no card required

Mini Gap-Scan

10 questions on governance and asset visibility — the Govern and Identify functions of NIST CSF 2.0. Takes about 5 minutes and gives you a basic risk snapshot.

0 of 10 answered

Govern

Do you have written information security policies that staff have acknowledged?

Acceptable use, password, remote work, and data handling policies.

Is a specific person accountable for cybersecurity and compliance?

An owner, IT manager, or an outsourced provider named in writing.

Do you maintain a list of vendors that handle your data, with security terms in their contracts?

Payroll, cloud apps, MSPs, accountants, marketing tools.

Do you review cybersecurity risk with leadership at least annually?

A documented review of top risks, budget, and decisions.

Are you subject to contractual or regulatory requirements (e.g. NIST 800-171, CMMC, state privacy law)?

Government contracts and enterprise customers often flow these down.

Identify

Do you keep a current inventory of all laptops, servers, phones, and network devices?

Including personal devices used for work.

Do you maintain an inventory of software and cloud services in use?

Shadow IT is a leading source of unmanaged risk.

Have you identified where sensitive data (customer, financial, health, PII) is stored?

A simple data map naming systems and owners.

Have you performed a documented risk assessment in the last 12 months?

Threats, likelihood, impact, and treatment decisions.

Do you have cyber liability insurance and know what it requires of you?

Most policies require MFA and backups to pay a claim.

No sign-up, no card. Snapshot only — no PDF or remediation plan.