The Cyber Readiness Method

One question,
answered honestly.

If this business were attacked tomorrow, what would actually happen? Everything in the Method exists to answer that.

Not whether you own the right products. Not whether you would pass someone's checklist. Whether you would still be operating, whether you could recover, and how much of that answer you can actually prove.

The questions a leader needs answered

Five questions. Most businesses
cannot answer any of them with confidence.

  1. Could an attacker get in, and how?

    Not theoretically. Through which door, given how this specific business is set up.

  2. What would they reach once inside?

    Access rarely stays where it starts. What is connected to what, and where does that path end.

  3. Would we know it was happening?

    Detection is the difference between an incident and a catastrophe. Most small businesses discover a breach when something stops working.

  4. Could we recover, and how quickly?

    Backups that have never been restored are an assumption. So is a recovery plan nobody has read.

  5. How confident should we be in these answers?

    The most important question, and the one nobody else asks. An answer built on evidence is not the same as an answer built on what someone told us.

The principles

How it reasons.

Reality over compliance

Meeting a standard and surviving an attack are different achievements. Recognised frameworks are useful sources of good practice, and the Method draws on them — but the measure is whether your business keeps operating, not whether you would satisfy an auditor. A business can be compliant and unable to recover. It happens regularly.

Evidence over assertion

What you believe about your security and what is true are different things, and the distance between them is where incidents happen. Every claim that carries weight is tested against evidence wherever evidence can exist.

Confidence is reported, not implied

Every conclusion carries a confidence level based on the strength of what supports it. A strong result from unverified answers is reported as exactly that. An assumption is never presented with the authority of a fact.

Unknowns are findings

“We don't know” is not a blank to be filled in later. If a business cannot determine whether a control exists, that uncertainty is itself a serious result — because it will behave exactly like a missing control during an incident.

Critical failures are never averaged away

A single number hides the thing that matters most. A business can be strong in twelve areas and one missing control from an unrecoverable event. Critical gaps are surfaced on their own terms rather than diluted into a blended score.

Plain language, always

A finding that needs technical translation to be understood is a finding that will not get acted on. Everything is written so the person who controls the budget understands what is at stake.

Reported vs verified

The Method tracks two numbers.
The gap between them is the point.

Reported readiness

What you told us. Your understanding of your own business, and a legitimate starting point.

Verified readiness

What the evidence supports.

When those two are close, you have an accurate picture of your own security — which is genuinely valuable and rarer than you would expect. When they diverge, you have found something: the control you were confident about that turns out to be partially deployed, the backup covering everything except the system that matters most, the access that was supposedly revoked.

Every assessment that produces only one number is producing the first one and presenting it as the second.

What gets assessed

Fifteen areas, weighted by
what actually determines outcomes.

Identity and access · Email and Microsoft 365 · Endpoints and network · Backup and recovery · Data and cloud services · Monitoring and detection · Incident response and continuity · Vendors and supply chain · Assets and technology · People and process · Physical and operational · Application security · Organisational risk · Validation and improvement · Controlled unclassified information

Coverage is not even, and that is deliberate. Areas that most determine whether a business survives and recovers — identity, backups, detection, response — carry more weight than areas that matter less at this size. The Method reflects how incidents actually unfold rather than distributing questions evenly for the appearance of completeness.

On recognised frameworks: the Method draws on established security guidance, including NIST 800-171 for businesses handling controlled unclassified information. That guidance is a source of good recommendations. It is not a certification, and completing this assessment does not make a business compliant with any framework.

Boundaries

What the Method does not do.

It is not a certification, and it is not proof of compliance. No assessment can honestly tell you that you are compliant with a framework. Compliance determinations are made by qualified assessors against a defined scope. A strong readiness result does not make you compliant, and the Method will never imply otherwise.

It is not a penetration test or a vulnerability scan. Nothing is installed and nothing touches your systems. Those are valuable and different exercises, and a strong readiness result is not a substitute for either.

It is not a legal opinion or an insurance coverage determination. It can make your conversation with a broker or underwriter far more specific and evidence-backed. It cannot tell you what a carrier will decide.

It is not a guarantee. No assessment can promise an outcome. A business that does everything the Method recommends can still be attacked successfully. What changes is how likely you are to detect it, contain it, and recover.

It cannot verify what you cannot evidence. Where no evidence exists, the Method reports the finding as unverified rather than assuming the best.

An assessment that flatters you
is worse than no assessment.

It is easy to build a tool that returns a comfortable score. Ask general questions, accept every answer, weight it generously, produce a number above eighty, and the customer feels good. That tool is actively harmful — it converts assumptions into false confidence, and false confidence is what stops a business fixing the thing that would have saved it.

This will never tell you what you want to hear.

See how it reasons.

Six questions and two evidence uploads. If the reasoning does not hold up, you will know in ten minutes.

Start your Guided Preview

Free. No credit card. No sales call.