
A published scoring model, not a black box.
Six modules, fixed weights, and a human sign-off on every finding. You can see exactly why your score is what it is — and what would move it.
How the weighted readiness score is calculated.
Each module is scored on its own evidence, then combined using the published weights below.
Microsoft 365 security
The heaviest reading on the panel: identity, tenant configuration and admin hygiene across the platform most SMEs actually run on.
- MFA and conditional access coverage
- Admin account separation and privilege review
- Email authentication (SPF, DKIM, DMARC)
- Sharing, guest access and data-loss settings
- Logging, retention and alerting baseline
Incident readiness
Whether a real incident would be handled or improvised — roles, contacts, escalation, backups and restore confidence.
- Documented incident plan and named roles
- Escalation and out-of-hours contact chain
- Backup coverage and last verified restore
- Customer, authority and insurer notification path
- Tabletop walk-through of one realistic scenario
External exposure
What the internet can see and reach. Permission-based, non-intrusive checks against your authorized scope only.
- Internet-facing asset and domain inventory
- Exposed services, portals and remote access
- Certificate and DNS hygiene
- Known credential and data leak signals
- Written scan authorization before any test
AI usage risk
Which AI tools are used, what data goes into them, and which rules are missing — a rapidly evolving SME risk area.
- Inventory of AI tools and real use cases
- Confidential, customer and source-code data flows
- Approval, retention and human-review practice
- Written AI usage policy and staff guidance
- Vendor terms and training-data settings
Supplier risk
Third parties with access to your systems and data — MSPs, SaaS vendors, contractors and integrators.
- Critical supplier and access inventory
- Contractual security and breach-notice terms
- Offboarding and access revocation practice
- Concentration risk on a single IT provider
Governance & compliance evidence
Mapping the evidence you already have against what customers, auditors and frameworks keep asking for.
- Existing policies, owners and review dates
- Evidence mapping for NIS2 / ISO 27001 / SOC 2 questions
- Security responsibilities and decision rights
- Awareness training and onboarding records
Current Cybnivo methodology — the scoring model will be refined as we validate it through pilot assessments.
Safe Industrial / OT readiness add-on
For manufacturing, automation and robotics SMEs. A safe, non-intrusive readiness review of industrial systems — no active testing on production lines, designed to avoid operational disruption.

- Industrial asset and network segmentation overview
- Remote maintenance and integrator access review
- Downtime and production-impact scenario checklist
- Legacy machine and unsupported-system inventory
- Handover language that engineers and management both accept
No active testing on production or safety-relevant systems — designed to avoid operational disruption.
What lands on the management table on day ten.
Want to see the report structure before you commit?
We will walk you through the sample report structure on the discovery call — including findings, scoring and the roadmap.
Permission-based · Reviewed before delivery
