Skip to content
Cybersecurity analyst reviewing a readiness score and prioritized actions
Self-check

Two minutes for an indicative readiness score.

This uses the same six weighted modules as the full sprint, in simplified form. It is a directional signal, not a full assessment.

0 / 18 answered0%

Microsoft 365 security

25% weight
Is multi-factor authentication enforced for all Microsoft 365 users?
Are administrator accounts separated from everyday user accounts?
Are SPF, DKIM and DMARC configured for your sending domains?
Do you use conditional access rules (location, device or risk based)?

Incident readiness

20% weight
Do you have a written incident response plan with named roles?
When did you last successfully test restoring from backup?
Is there an out-of-hours escalation and contact chain everyone can find?

External exposure

20% weight
Do you maintain an inventory of internet-facing systems and domains?
Is remote access (VPN, RDP, portals) restricted and monitored?
Has an external exposure review been done in the last 12 months?

AI usage risk

15% weight
Do you have a written policy for using AI assistants at work?
Do staff know which data must never be pasted into AI tools?
Do you know which AI tools are actually being used in the company?

Supplier risk

10% weight
Do you have a list of suppliers with access to your systems or data?
Do supplier contracts include security and breach-notification terms?

Governance & compliance evidence

10% weight
Are your security policies documented, owned and reviewed?
Can you answer a customer security questionnaire within a week?
Do employees receive security awareness training at onboarding?
Indicative score
--/ 100
Awaiting answers

Answer every question to reveal your weighted score and category breakdown.

Microsoft 365 security--
Incident readiness--
External exposure--
AI usage risk--
Supplier risk--
Governance & compliance evidence--
Save & get the breakdown

We use this only to send your breakdown and to follow up once. No newsletter signup or sale of your data. We use your information only as described in our Privacy Policy.

Important

What this self-check is not.

It relies on self-reported answers with no evidence review. The full sprint reviews configuration evidence, external exposure and supplier-access evidence, and every customer-facing finding is reviewed by the Cybnivo cybersecurity lead.