Please read and accept the terms of use to continue.
What this is
This is a free self-assessment tool. It gauges the maturity of your cloud security programme — how you secure the accounts, identities, workloads, and services you run in the cloud — and offers recommended practices drawn from widely recognised standards and guidance. It is general guidance.
What this isn't
It is not a professional security audit, not a penetration test, and not legal advice. Every recommendation is optional, and following it reduces common risks but does not guarantee security or any particular outcome.
Your responsibility
Responsibility for your organisation's security remains with you.
Verify any recommendation against your own circumstances.
Find out where your cloud security programme sits on the four-tier maturity spectrum — and which gaps to close first. Free edition: all 28 checks, scored in your browser.
How This Works
Answer 28 questions across ten areas — from identity and inventory through workloads, detection, incident response, vendors, and compliance evidence. Each takes 10–20 seconds. At the end you'll get a weighted maturity score, a tier band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised cloud security practice; which recommendations fit your organisation is your call.
Part 1 — Identity & Access (The Cloud's Perimeter)
The root account sits above every other control. Hardware-backed MFA, no access keys on root, and an alert on any root sign-in are the standard discipline.
A key created years ago still works today unless someone deactivates it. Keys belonging to leavers are a common breach entry point.
Without SSO, every account keeps its own leaver checklist. The accounts missed on that checklist keep live credentials for ex-staff.
Part 2 — Inventory & Configuration Baselines
Most organisations undercount their cloud estate. The monthly bill is the one discovery channel nothing can hide from.
Unintended public access is the most common cloud exposure pattern. Account-level "block public access" settings close most of it in one step.
Cloud security posture management (CSPM) tools — including the providers' free tiers — flag misconfigurations continuously. A finding queue nobody reviews is a tool, not a programme.
Part 3 — Workloads, Containers & Kubernetes
Short-lived workloads inherit their security from the image or template that produced them. Securing the pattern secures every instance built from it.
The cluster is a security surface of its own, and its front door is the API server. Skip if you run no clusters: answer "Yes" to keep scoring fair.
Cluster networks are flat by default. Default-deny network policies contain a foothold to one workload. Skip if you run no clusters: answer "Yes".
Part 4 — Infrastructure as Code
A misconfiguration in code is deployed automatically, again and again, until the code is fixed. Caught in the pull request, it costs a comment instead of an incident. Skip if you define no infrastructure in code: answer "Yes".
A pipeline that can deploy anything is an administrator and deserves the same guarding. Drift between code and the live estate is configuration nobody reviewed. Skip if you run no pipelines: answer "Yes".
Part 5 — SaaS Discovery & Posture
Most organisations find far more SaaS than they ever reviewed. The tools you have not discovered are the tools you cannot secure.
Leavers keep access to every tool outside SSO until someone remembers it exists. Vendors default to convenient sharing, not safe sharing.
A suite super-administrator can read any mailbox and any file. Forgotten app grants are standing access to your data that nobody is watching.
Part 6 — Logging, Detection & Identity Threats
These logs are the forensic record of everything done to your cloud. Attackers work in the regions you forgot to log.
The native detectors catch credential abuse and cryptomining patterns at low cost. An alert in an unwatched console is not detection.
In the cloud, identity is the perimeter. Identity threat detection and response (ITDR) treats a stolen credential as the perimeter breach it is.
Part 7 — Cloud Incident Response & Forensics
Without a written plan, the response is improvised at the worst hour. The first version can be one laminated page.
The attacker's clock runs in seconds; approval chains do not. A written containment-authority note turns the worst hour into procedure.
The cloud deletes evidence on its own schedule. Log retention, snapshots, and one practised capture drill decide whether forensics is possible.
Part 8 — Vendor Due Diligence & Contract Hygiene
Vendor estates grow past their registers quietly. Tiered assessment puts the effort where the sensitive data is.
An assessment without contract terms cannot be enforced. The notification clause decides whether you learn of a vendor's breach from the vendor or from the news.
Exit questions are cheapest before signature. "What could we take with us in ninety days?" is the test.
Part 9 — Multi-Cloud & Hybrid Governance
The providers implement the same concepts differently; a practice built for one does not transfer. Skip if you deliberately run a single provider: answer "Yes".
A contained estate with an owner and a review date is a decision. An unknown one is a finding. Nothing should be simply unaccounted for.
Part 10 — Compliance Evidence & Programme Review
The mapping table is every audit's index. One control, evidenced once, can satisfy several frameworks at the same time.
A timestamped check history proves a control operated all year. A screenshot proves one instant — expensively.
Programmes improve deliberately or drift quietly. One page a quarter to the people who fund the work is what keeps it alive.
Free Edition snapshot · scored entirely in the browser — answers never leave the device
Your Cloud Security Maturity Results
0/ 68
—
—
Identity & access
0 / 10
Inventory & configuration
0 / 10
Workloads, containers & clusters
0 / 6
Infrastructure as code
0 / 4
SaaS discovery & posture
0 / 6
Logging, detection & identity threats
0 / 8
Incident response & forensics
0 / 8
Vendor due diligence & contracts
0 / 6
Multi-cloud & hybrid governance
0 / 4
Compliance evidence & review
0 / 6
The book series scores a programme by its weakest dimension, not its average. Whatever your overall band, your lowest bars above are the recommended place to start.
Your Recommended Priority Actions
Free guide
Your First Cloud Security Fixes
A short, plain-English guide to the five moves that take cloud security from "we should look at that" to a working routine — the account list, identity first-fixes, logging everywhere, closing public access, and the one-page incident card. Enter your email and we'll send it over.
Optional, and separate from your assessment — your answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Ready to Close These Gaps?
The free assessment shows where you stand. The paid editions add the working documents — account register, identity runbook, baseline and exception packs, incident runbooks, vendor questionnaires, board-report templates and more — so you have the artefacts, not just the score.