How it works

Assess. Verify.
Improve. Prove it.

Four things happen here, and the second one is what separates this from every questionnaire you have filled in before.

  1. 01

    Answer questions about how your business actually runs

    The assessment covers more than 130 questions across 15 areas — identity and access, email, endpoints and network, backup and recovery, cloud and data, monitoring, incident response, vendors, physical operations, people and process, and more.

    It adapts. Cloud-only businesses never see on-premises server questions. No development team means no application security questions. You answer what applies to you.

    Questions are written for business owners, not engineers. Where something genuinely needs technical confirmation, the platform writes the question for you to forward to your provider.

    “I'm not sure” is a real answer. It is not a blank and it is not a penalty. A gap in visibility is one of the most important findings there is — especially around backups, administrative access, and who owns incident response. A business that cannot answer those questions calmly will not answer them during an incident either.
  2. 02

    Prove the answers that matter

    This is where it stops behaving like a questionnaire.

    For answers that carry real weight, the platform asks you to back them up — a configuration screenshot, a backup job report, an exported policy, a statement from your provider. You upload it. The platform reviews it and tells you whether it supports what you said.

    Three things can happen, and all three are useful.

    • The evidence confirms it. Now it is verified rather than assumed, and it stays that way in your record.
    • The evidence shows something different. The most valuable outcome on the platform. You believed MFA covered everyone; the export shows four accounts excluded. You believed backups covered a critical system; the job report does not list it.
    • Nobody can produce it. Also a finding. If no one can demonstrate a control exists, treat it as unverified — because during an incident, that is exactly how it will behave.
    Do not upload secrets. No passwords, no keys, no account numbers. The platform does not need them and you should not send them anywhere. Evidence is encrypted and private to your organisation.
  3. 03

    Get findings that explain themselves

    Every finding tells you what it means for the business, not just which control is missing. You get the likely attack path — the most plausible way in, what it reaches once inside, and what would interrupt it. You get an honest read on whether you could recover.

    You also get what you are already doing well, with the proof behind it. An assessment that returns nothing but problems is easy to write and easy to dismiss.

    Confidence is reported separately from readiness. A strong result built on unverified answers is not the same as one built on evidence, and the platform will never blur the two.

  4. 04

    Work a short list, in order

    Not a hundred-item checklist. A prioritized sequence ordered by what would most change the outcome if you were attacked tomorrow.

    Each item names who owns it, what result to expect, and what evidence closes it out. You can hand an item to your IT provider and both of you know what “done” looks like.

    Critical gaps are never averaged away. A business can be strong across a dozen areas and still be one missing control from an unrecoverable incident.

  5. 05

    Come back and show the difference

    When the work is done, reassess against your baseline. This is where readiness becomes something you can demonstrate rather than assert — to leadership, to a customer running a vendor review, or to your insurance broker.

    Staff change, tools change, providers change, configurations drift. The platform is built to be returned to.

What you end up with

A record you can act on — and show to someone else.

  • Executive readiness statementA direct, qualified answer on how your business would likely fare.
  • Likely attack narrativeThe plausible entry path, what it reaches, and what would interrupt it.
  • Recovery confidenceWhether you could restore operations, stated separately from evidence strength.
  • Verified strengthsWhat is working, with the proof attached.
  • Critical unknownsWhat is preventing a confident answer, and what would resolve it.
  • Prioritized action planOwnership, expected outcome, and proof of completion.
  • Provider discussion guidePlain-language questions for your IT team, MSP, or broker.
  • Reassessment baselineA dated record to measure against.

Practical questions

Before you start.

How long does it take?

Most businesses work through it across a few sittings rather than in one. The pace depends on how much you need to verify with your provider — and needing to check is a good sign, not a bad one.

Do I need to be technical?

No. Where technical confirmation is required, the platform writes the question for you to forward.

What if I have no IT person?

Plenty of businesses do not. The assessment is answerable by an owner or office manager, and the provider discussion guide works as well for a part-time contractor as for a full MSP.

What if I already work with an MSP?

Good. This makes that relationship more productive by making explicit what is in place, what is assumed, and who owns the next step.

What happens to my data?

It is encrypted and private to your organisation. Access requires multi-factor authentication. Evidence is used only to evaluate your readiness.

Is this a scan or a penetration test?

No. Nothing is installed and nothing touches your systems. This is an assessment of how your business is set up and run, supported by evidence you provide.

See it before
you buy it.

Six questions. Two pieces of evidence. Seven days.

Start your Guided Preview

Free. No credit card. No sales call.