How it works
Four steps, start to finish - and then it runs again.
01 · Data Collection
Answer an adaptive questionnaire shaped by your industry and infrastructure - only relevant questions appear, including a dedicated AI Readiness & Governance track, and all six NIST CSF functions are scored individually.
Outcome: Know exactly where you stand02 · Analysis
Every answer is cross-referenced against every other answer, so compounding risk gets flagged instead of scored in isolation - with vendor-specific mitigation notes wherever you've named a product.
Outcome: See risks a checklist would miss03 · Recommendation
A ranked, prioritized action list, not a wall of findings - each item tied to why it matters more than the rest, and mapped back to the specific control it strengthens.
Outcome: Know what to fix first04 · Transformation
Implement fixes using the matching Runbook or Playbook, then re-assess on a cadence to track real progress and see the score delta since your last run.
Outcome: Prove the change actually workedMethodology
Every question maps to a real control from a recognized framework - nothing here is invented. These frameworks are the guiding principles behind every score:
The baseline (NIST CSF + CIS) applies to every organization. The rest layer in based on your industry and the regions you operate in - a healthcare provider and a SaaS company are asked different follow-up questions, scored against different compliance overlays, because the risks and obligations genuinely differ. Operational Technology and DevSecOps modules do the same, appearing only where they're actually relevant. This framework set keeps growing as the tool matures.
Frameworks decide which controls matter; a consistent set of principles decides how the findings get prioritized and explained - proactive over reactive, defense in depth, least privilege, zero trust, and treating improvement as a continuous loop rather than a one-time project, among others.
The three phases of the assessment
Every assessment moves through three stages as a continuous workflow - scroll to watch them unfold, or select a stage for a quick summary of what it involves.
Discovery
You don't have a security program yet so much as a starting point - the goal is visibility: what exists, where it's exposed, and who owns fixing it.
Transformation
Findings become controls, and controls become documented, rehearsed processes - this is where most of the actual engineering and writing happens.
Optimization
The program runs continuously - monitored, tested, and adjusted as the environment and threat landscape change, rather than declared "done."
Risk Score Matrix
Every assessment runs on a scored matrix (see the Metrics page for the full breakdown). Select a number for what that risk level actually means:
Things to get you started
Real, current sources - not just this site's own content.
Getting Started With Cybersecurity Controls
The plain-language on-ramp before you touch the assessment
Current Trends
This site's own curated threat-landscape roundup
Exploits
Confirmed actively-exploited CVEs, scored by real-world risk
Runbooks
Incident runbooks and foundational documents
Threat Modeling & Forensics
How to think ahead of an attacker, and how to reconstruct what happened after one
Check Your Own Configuration
Free vendor and open-source tools to test your actual product security baseline - not just answer questions about it
Explore the site
Everything this platform offers, in one map.
Methodology
Exactly how scoring and adaptive questions work.
Maturity Model
The 10-phase journey and NIST's own maturity tiers.
Core Principles
The cybersecurity philosophy this site is built on.
Runbooks
IR plans, backup/DR, and step-by-step incident runbooks.
Trends & News
Current threats, AI-in-security developments, and where to keep learning.
Case Studies
Stuxnet, SolarWinds, Equifax, and other critical incidents - plus a simulated AI security engagement.
Playbooks
OWASP Top 10 and AI-threat playbooks, mapped to MITRE ATT&CK.
Roadmap
What's shipped, in progress, and planned for this site itself.