How it works
From checklist to executive report in about 15–20 minutes
- 01
Tell us about the business
Name, industry, headcount, and which framework applies. Two minutes.
- 02
Answer 27 guided questions
Grouped by the six NIST CSF 2.0 functions. Each question has a plain-English explanation, and answers save as you go.
- 03
Get scored on every function
Answers are weighted by risk impact, producing a 0–100 maturity score per function and overall.
- 04
Receive your report
An executive summary, key findings with severity, quick wins, and a prioritised remediation plan with owners and timelines.
- 05
Remediate, then reassess
Work the roadmap, re-run the assessment, and evidence the improvement to insurers and customers.
What the checklist covers
Govern
Policies, ownership, and third-party oversight.
5 questions
Identify
Knowing your assets, data, and risks.
5 questions
Protect
Safeguards that reduce the chance of an incident.
6 questions
Detect
Seeing problems before they become breaches.
4 questions
Respond
What happens in the first 24 hours of an incident.
4 questions
Recover
Getting the business running again.
3 questions