Free tool

How Mature Is Your Security Program? A 28-Point Self-Check

These are the 28 capabilities a mature security and compliance program has - the same maturity lists we publish on our GRC and Cyber Risk Management pages, in one place. Check what your business actually has in place today. It takes about five minutes.

Your score updates as you go. It's free, and no email is required to see your results.

One rule for honest math: only check an item if you could show evidence of it this week. A policy nobody can find, or a backup nobody has restored, doesn't count yet. If you'd have to guess, leave it unchecked - the unchecked items are the useful ones.

Govern

Who decides, who owns it, and what's written down.

  • Everyone knows who owns security decisions, who approves exceptions, and who answers when something goes wrong.

    What proves it: a named person in writing - an org chart, a job description, or an engagement letter that says who owns security decisions and who approves exceptions.

    Addressed by: Fractional CISO

  • Written, current, and actually followed - not a binder nobody has opened since it was created.

    What proves it: the policy file itself, with a revision date inside the last twelve months and a record of who acknowledged it.

    Addressed by: GRC - Secure phase

  • Changes to systems, software, and access are requested, approved, and recorded, so nothing important happens by accident.

    What proves it: a ticket, a change log, or an approval record for the last significant system change you made.

    Addressed by: SOC 2

  • You know which third parties touch your systems and data, and someone reviews that access on a schedule.

    What proves it: a current list of third parties with access to your systems or data, and the date each one was last reviewed.

    Addressed by: Third-Party Assessments

Manage Risk

How you find, reduce, and prepare for what can hurt you.

  • A current, written list of what could actually hurt your business, ranked by likelihood and impact instead of gut feel.

    What proves it: a written risk register with likelihood and impact ratings, dated within the last twelve months.

    Addressed by: Cyber Risk & Compliance Gap Assessment

  • Every control traces to the risk it reduces and the requirement it satisfies, so nothing is duplicated or missing.

    What proves it: a document that ties each control you run to the risk it reduces and the requirement it satisfies.

    Addressed by: NIST CSF

  • Risk gets re-evaluated on a schedule, because your environment and the threats against it both keep changing.

    What proves it: two dated assessment reports, so there is a before and an after.

    Addressed by: Cyber Risk Management - Ongoing review

  • A written, tested plan for the bad day: who acts, who decides, and who gets called first.

    What proves it: the written plan, plus notes from the last time you tested it.

    Addressed by: Cyber Risk Management - Incident response

  • People can reach what their job requires and nothing more, and access ends the day the job does.

    What proves it: a current user list with roles, and an offboarding record showing access ended the day someone left.

    Addressed by: Helpdesk - Access controls

  • Someone is watching for suspicious activity, so incidents are found in hours instead of months.

    What proves it: an alert your monitoring produced and the record of what someone did about it.

    Addressed by: 24/7 threat monitoring

  • Known vulnerabilities get closed on a defined schedule, not when someone remembers.

    What proves it: a patch status report covering all your devices, not one machine's update screen.

    Addressed by: Helpdesk - Patching

  • Backups are proven by actually restoring from them - an untested backup is a hope, not a control.

    What proves it: a restore test log - the date you last pulled a file back from backup and confirmed it opened.

    Addressed by: Helpdesk - Backup validation

Comply

How you prove all of it to auditors, insurers, and regulators.

  • Your controls map to the frameworks that apply to you - HIPAA, PCI DSS, CMMC, state privacy laws - not to a generic checklist.

    What proves it: a named list of the frameworks that apply to you and a mapping of your controls to each.

    Addressed by: Compliance Finder

  • You could face an audit tomorrow without a scramble, because the preparation already happened.

    What proves it: the evidence folder itself. If you would have to build it first, you are not ready yet.

    Addressed by: GRC - Assess phase

  • Proof of what you do accumulates as you work - logs, records, sign-offs - instead of being reconstructed under deadline.

    What proves it: logs, sign-offs, and records with dates that predate this question.

    Addressed by: GRC - Find gaps

  • Leadership sees risk and compliance status in plain numbers, and open items are tracked to closure.

    What proves it: the last report leadership actually read, and the open-item list with owners and dates.

    Addressed by: GRC - Manage phase

Operate & Defend

The day-to-day machinery: monitoring, protection, response, and review.

  • Identify your most critical threats, misconfigurations, and exposures across people, processes, and technology.

    What proves it: a dated findings report that names specific systems, not a summary.

    Addressed by: Cyber Risk & Compliance Gap Assessment

  • Real-time visibility into suspicious activity, anomalies, and emerging cyber risks before they escalate - across your network, endpoints, and cloud applications like Microsoft 365 and Google Workspace. Monitoring and assessment are separate specialist providers - the team watching your environment isn't the team that graded it.

    What proves it: who you call at 2am, and the record of the last after-hours alert someone acted on.

    Addressed by: Cyber Risk Management - Secure (monitoring)

  • Get alerted when employee credentials, business emails, or domain references appear in breach dumps, leaked databases, or dark web marketplaces - so passwords get rotated before an attacker can use them.

    What proves it: an alert from the last time a company credential turned up in a breach dump, and the record that the password was actually changed.

    Addressed by: Cyber Risk Management - Dark web monitoring

  • Layered security controls that protect your users, devices, applications, and data from modern threats.

    What proves it: a coverage report showing which devices and mailboxes are protected - and which are not.

    Addressed by: Cyber Risk Management - Secure (layered protection)

  • Short, frequent training built around the tools your team actually opens, plus simulated phishing tests and completion records for audits, insurers, and customer security reviews.

    What proves it: a completion report with names and dates, plus the results of the last phishing simulation you ran.

    Addressed by: Cyber Risk Management - Security awareness training

  • Clear, business-friendly risk ratings that show where you stand - and what your leadership must prioritize.

    What proves it: the report a non-technical owner read and could act on without a translator.

    Addressed by: Fractional Leadership

  • Build response procedures, communication plans, and practical action steps your team can follow during an incident.

    What proves it: the playbook, with named roles and phone numbers that are current today.

    Addressed by: Cyber Risk Management - Incident response

  • Proactive detection of unusual patterns and attacker behavior across your environment.

    What proves it: a hunt report - what was looked for, where, and what was found or ruled out.

    Addressed by: Cyber Risk Management - Top threats

  • Step-by-step instructions to fix vulnerabilities and strengthen defenses in the highest-impact areas first.

    What proves it: a prioritized action list with owners and target dates, and evidence that items have closed.

    Addressed by: Cyber Risk & Compliance Gap Assessment

  • Ensure your systems, apps, and cloud environments are hardened against common threats and attack paths.

    What proves it: a configuration baseline document and a scan showing what deviates from it.

    Addressed by: Cyber Risk Management - Secure (hardening)

  • Help your team maintain least-privilege access and reduce the risk of credential-based attacks.

    What proves it: an access review dated within the last quarter, with a record of who approved it.

    Addressed by: NIST CSF - Protect (access control)

  • Quarterly reviews, updated recommendations, and executive decision support for long-term risk reduction.

    What proves it: notes from the last quarterly review, with decisions recorded and owners assigned.

    Addressed by: Cyber Risk Management - Manage phase

You checked 0 of 28.

Govern 0/4 · Manage Risk 0/8 · Comply 0/4 · Operate & Defend 0/12

FAQ

Common questions

Do I need to enter my email to see my score?

No. Your score and result appear on this page as you check items, free, with nothing to fill in. If you want the detailed gap report - your specific missing controls, the evidence that proves each one, and which three to fix first - that's what the short form below your results is for, and we'll email you a copy.

How were these 28 items chosen?

They're the same maturity lists we publish on our GRC and Cyber Risk Management service pages: 16 governance, risk, and compliance capabilities and 12 operational security capabilities. No vendor product lists, no padding - it's the standard we hold customer programs to.

What counts as "having" an item?

Evidence, not intention. If you could produce the policy, the restore log, or the access review this week, check it. If it exists in someone's head or on a to-do list, it isn't a control yet - leave it unchecked.

What happens after I see my score?

Nothing automatic. Every unchecked item links to the page that explains how it gets addressed, and if you want the score verified against your real environment, that's what the Cyber Risk & Compliance Gap Assessment does.