Cybersecurity posture assessment, made simple.

Answer adaptive questions about how your organization is set up. Get a prioritized reading of your cybersecurity, referenced to NIST CSF 2.0 and CIS Controls, and a ranked action plan. A 14-question Quick screening or a Full assessment - it runs in your browser, and your answers stay there unless you choose otherwise.

It's a structured self-assessment from your own answers - not a scan, audit or certification. See example reports · How scoring works · Privacy

Discover Transform Optimize

How it works

Four steps, start to finish - and then it runs again.

01 · Data Collection

Answer an adaptive questionnaire shaped by your industry and infrastructure - only relevant questions appear, including a dedicated AI Readiness & Governance track, and all six NIST CSF functions are scored individually.

Outcome: Know exactly where you stand

02 · Analysis

Every answer is cross-referenced against every other answer, so compounding risk gets flagged instead of scored in isolation - with vendor-specific mitigation notes wherever you've named a product.

Outcome: See risks a checklist would miss

03 · Recommendation

A ranked, prioritized action list, not a wall of findings - each item tied to why it matters more than the rest, and mapped back to the specific control it strengthens.

Outcome: Know what to fix first

04 · Transformation

Implement fixes using the matching Runbook or Playbook, then re-assess on a cadence to track real progress and see the score delta since your last run.

Outcome: Prove the change actually worked

Methodology

Every question maps to a real control from a recognized framework - nothing here is invented. These frameworks are the guiding principles behind every score:

Defense in Depth
ISO 27001
SOC 2
Cyber Essentials
PCI DSS
NIST CSF 2.0
CIS Controls v8
ISO 27001
NIS2
GDPR
Cyber Essentials
PCI DSS
+ more in the pipeline

The baseline (NIST CSF + CIS) applies to every organization. The rest layer in based on your industry and the regions you operate in - a healthcare provider and a SaaS company are asked different follow-up questions, scored against different compliance overlays, because the risks and obligations genuinely differ. Operational Technology and DevSecOps modules do the same, appearing only where they're actually relevant. This framework set keeps growing as the tool matures.

Frameworks decide which controls matter; a consistent set of principles decides how the findings get prioritized and explained - proactive over reactive, defense in depth, least privilege, zero trust, and treating improvement as a continuous loop rather than a one-time project, among others.

The three phases of the assessment

Every assessment moves through three stages as a continuous workflow - scroll to watch them unfold, or select a stage for a quick summary of what it involves.

Phase 1

Discovery

You don't have a security program yet so much as a starting point - the goal is visibility: what exists, where it's exposed, and who owns fixing it.

Phase 2

Transformation

Findings become controls, and controls become documented, rehearsed processes - this is where most of the actual engineering and writing happens.

Phase 3

Optimization

The program runs continuously - monitored, tested, and adjusted as the environment and threat landscape change, rather than declared "done."

Risk Score Matrix

Every assessment runs on a scored matrix (see the Metrics page for the full breakdown). Select a number for what that risk level actually means:

76%
Interactive risk scale - the lower the score, the stronger the security posture
1 - Minimal risk10 - Severe risk