Four steps, start to finish - and then it runs again.
Answer an adaptive questionnaire shaped by your industry and infrastructure - only relevant questions appear, including a dedicated AI Readiness & Governance track, and all six NIST CSF functions are scored individually.
Outcome: Know exactly where you standEvery answer is cross-referenced against every other answer, so compounding risk gets flagged instead of scored in isolation - with vendor-specific mitigation notes wherever you've named a product.
Outcome: See risks a checklist would missA ranked, prioritized action list, not a wall of findings - each item tied to why it matters more than the rest, and mapped back to the specific control it strengthens.
Outcome: Know what to fix firstImplement fixes using the matching Runbook or Playbook, then re-assess on a cadence to track real progress and see the score delta since your last run.
Outcome: Prove the change actually workedEvery question maps to a real control from a recognized framework - nothing here is invented. These frameworks are the guiding principles behind every score:
The baseline (NIST CSF + CIS) applies to every organization. The rest layer in based on your industry and the regions you operate in - a healthcare provider and a SaaS company are asked different follow-up questions, scored against different compliance overlays, because the risks and obligations genuinely differ. Operational Technology and DevSecOps modules do the same, appearing only where they're actually relevant. This framework set keeps growing as the tool matures.
Frameworks decide which controls matter; a consistent set of principles decides how the findings get prioritized and explained - proactive over reactive, defense in depth, least privilege, zero trust, and treating improvement as a continuous loop rather than a one-time project, among others.
Every assessment moves through three stages as a continuous workflow - scroll to watch them unfold, or select a stage for a quick summary of what it involves.
You don't have a security program yet so much as a starting point - the goal is visibility: what exists, where it's exposed, and who owns fixing it.
Findings become controls, and controls become documented, rehearsed processes - this is where most of the actual engineering and writing happens.
The program runs continuously - monitored, tested, and adjusted as the environment and threat landscape change, rather than declared "done."
Every assessment runs on a scored matrix (see the Metrics page for the full breakdown). Select a number for what that risk level actually means:
Real, current sources - not just this site's own content.
The plain-language on-ramp before you touch the assessment
This site's own curated threat-landscape roundup
Confirmed actively-exploited CVEs, scored by real-world risk
Incident runbooks and foundational documents
How to think ahead of an attacker, and how to reconstruct what happened after one
Free vendor and open-source tools to test your actual product security baseline - not just answer questions about it
Everything this platform offers, in one map.
Exactly how scoring and adaptive questions work.
The 10-phase journey and NIST's own maturity tiers.
The cybersecurity philosophy this site is built on.
IR plans, backup/DR, and step-by-step incident runbooks.
Current threats, AI-in-security developments, and where to keep learning.
Stuxnet, SolarWinds, Equifax, and other critical incidents - plus a simulated AI security engagement.
OWASP Top 10 and AI-threat playbooks, mapped to MITRE ATT&CK.
What's shipped, in progress, and planned for this site itself.