ServicesVantageIndustriesCase StudiesInsightsAboutContactSchedule a Consultation
Home / Services / Self-assessment

Security posture self-assessment

Twelve questions an executive can answer without asking IT. You get a maturity level for each of six domains on the scale we use in real assessments, and what to do first. Nothing you answer leaves your browser unless you choose to email it.

03 Self-assessmentSelf-assessment · not an audit
Is there one named person accountable for security, with the authority to make decisions?
Does leadership or the board receive a security update at least quarterly, in business terms?
Is multi-factor authentication required for every employee on email, remote access, and cloud admin accounts?
When someone leaves, is their access removed everywhere within a day, from a written checklist?
Do you know which systems hold your most sensitive data (customer, financial, health, or personal) and who can reach it?
Are backups of critical systems tested by actually restoring from them at least twice a year?
Are vendors that hold your data or connect to your systems reviewed for security before signing and again at renewal?
Do your key vendor contracts state security obligations and who is notified, and when, after a breach?
Is there a written incident response plan that says who decides, who is called, and what gets reported to whom?
Has leadership walked through a realistic incident scenario (a tabletop exercise) in the last year?
Is there a written rule for which AI tools employees may use, and what company or customer data may go into them?
Do you know which AI features your vendors have switched on inside the tools you already use?

This site