Answer these 10 questions to see where ownership, coverage, monitoring, and response may need more attention.
Your point-in-time result
Cybersecurity scorecard
Use these questions to identify uncertainty in ownership, coverage, monitoring, and response.
Interactive assessment
How complete is your overall cybersecurity program today?
Answer these 10 questions to see where ownership, coverage, monitoring, and response may need more attention.
Your point-in-time result
Scorecard FAQ
The scorecard reviews ownership, coverage, monitoring, response, and other practical security-program questions to help identify uncertainty and potential gaps.
No. It is a directional self-assessment for discussion and prioritization. It does not certify security, prove compliance, or replace a technical assessment by qualified professionals.
A No or Unsure answer is not a failure. It highlights an area where ownership, evidence, scope, or operating consistency may need to be clarified.
No. Security posture depends on the real configuration and operation of systems, users, vendors, processes, and controls. The score is a starting point for a deeper review.
Use the lower-scoring areas to prioritize validation, assign ownership, gather evidence, and decide which risks require technical, procedural, or governance changes.
Yes. A security stack review can translate the answers into a discussion about current controls, coverage gaps, overlapping tools, responsibilities, and an appropriate managed-service scope.
Review the gaps