How it works

From checklist to executive report in about 15–20 minutes

  1. 01

    Tell us about the business

    Name, industry, headcount, and which framework applies. Two minutes.

  2. 02

    Answer 27 guided questions

    Grouped by the six NIST CSF 2.0 functions. Each question has a plain-English explanation, and answers save as you go.

  3. 03

    Get scored on every function

    Answers are weighted by risk impact, producing a 0–100 maturity score per function and overall.

  4. 04

    Receive your report

    An executive summary, key findings with severity, quick wins, and a prioritised remediation plan with owners and timelines.

  5. 05

    Remediate, then reassess

    Work the roadmap, re-run the assessment, and evidence the improvement to insurers and customers.

What the checklist covers

Govern

Policies, ownership, and third-party oversight.

5 questions

Identify

Knowing your assets, data, and risks.

5 questions

Protect

Safeguards that reduce the chance of an incident.

6 questions

Detect

Seeing problems before they become breaches.

4 questions

Respond

What happens in the first 24 hours of an incident.

4 questions

Recover

Getting the business running again.

3 questions