Self-guided check

Cybersecurity Readiness Check

Answer a short set of questions to identify areas that may require verification. This is not a penetration test, vulnerability scan, compliance audit, legal assessment, certification, or complete risk assessment.

1.A named person owns cybersecurity decisions.
2.Multifactor authentication (MFA) is enabled for relevant accounts.
3.Privileged accounts are separated from daily-use accounts.
4.User onboarding and offboarding follow a documented process.
5.Endpoint protection coverage is visible.
6.Patch status can be reviewed.
7.Internet-facing systems are known and reviewed.
8.Backups have appropriate protection from alteration or deletion.
9.Backup restoration has been tested with current evidence.
10.An incident-response plan exists and is current.
11.Leadership and IT have exercised an incident scenario.
12.Important vendors receive a security review.
13.Security policies are maintained.
14.Customer or insurer evidence can be assembled.
15.Leadership receives security reporting.