All tools
Cyber Security Posture Assessment

How defensible is your security posture?

A rigorous, vendor-neutral self-assessment of your enterprise security across the nine domains — from identity and privileged access to encryption, threat modeling, multi-cloud (AWS · Azure · GCP) and resilience — that decide whether an attacker who finds a way in is contained, or compounds. Answer 18 questions and get an instant maturity profile, a residual-risk heatmap, STRIDE threat coverage, your exposure to the attack paths that actually breach organisations, and readiness against ISO 27001, SOC 2, NIST CSF 2.0 and CIS — with a prioritised remediation roadmap.

9 domains18 questions~4 min4 frameworks mapped0 sign-up · 0 data stored
1 · Your industry — sets the threat & regulatory lens on your result
2 · Workforce size — shapes blast radius and impact
3 · Most sensitive data you hold — sets the impact axis of your risk profile
Private & anonymous — everything runs in your browser. Nothing is sent or saved.
DomainQuestion 1 of 18

Question

Pick the option closest to your reality today
Your result

Your security posture profile.

0.0out of 5.0
Threat & regulatory lens

Residual risk profile

Where your inherent risk sits — driven by your sector's threat level and the sensitivity of your data — and how far your current controls pull it down. Strong controls move you down and to the left.

0 / 100 residual exposure
LowModerateElevatedHighCritical
Computed from your sector, data sensitivity and control maturity
Likelihood × impact
Likelihood →
Low Moderate Elevated High Critical
I = inherent   R = residual (after controls)

Domain breakdown

Maturity by domain on a 1–5 CMMI-style scale, each mapped to the controls auditors actually test.

STRIDE threat coverage

How well your controls cover each class of threat in Microsoft's STRIDE model — the lens used to threat-model a system before attackers do it for you.

Attack-path exposure

Your exposure to the five attack paths behind most enterprise breaches — weighted by your sector's threat level. Higher means a determined attacker has more room to run.

Framework readiness

Indicative readiness against four frameworks, derived from the domains each one weights most heavily. A directional view to size the gap — not a certification audit.

Priority remediation roadmap

Your four weakest domains, sequenced by risk into Now / Next / Later — each with the control move that closes it and the frameworks it satisfies.

Discuss closing these gaps
How this assessment is calculated

A transparent, defensible model — no black box, no data leaves your browser:

  1. Each of the 9 domains is assessed by 2 behaviourally-anchored questions on a 1–5 scale (Initial → Optimised). A domain score is their average; your overall score is the mean of the nine.
  2. Residual risk starts from inherent risk — your sector's threat likelihood × your data-impact — and is reduced by control maturity (up to a realistic ceiling; controls reduce risk, they never zero it).
  3. STRIDE coverage maps each threat class to the domains that mitigate it (e.g. Spoofing → IAM + PAM; Elevation of Privilege → PAM + vulnerability management).
  4. Attack-path exposure inverts the maturity of the domains each path exploits, weighted by sector threat.
  5. Framework readiness is a weighted blend of the domains each framework emphasises.
1.0–1.8 Initial1.8–2.6 Developing2.6–3.4 Defined3.4–4.2 Managed4.2–5.0 Optimised

Domains map to NIST CSF 2.0, ISO/IEC 27001:2022 Annex A, SOC 2 Trust Services Criteria, the CIS Controls & cloud benchmarks (AWS · Azure · GCP), with the ACSC Essential Eight reflected in the vulnerability and privileged-access domains. This is an indicative model to start a board-level conversation and prioritise investment — not a substitute for a controls audit or penetration test. For a rigorous review, get in touch.

Copied ✓