Please read and accept the terms of use to continue.
What this is
This is a free self-assessment tool. It gauges how ready your business is to receive and handle a security vulnerability report, and offers recommended practices drawn from widely recognised coordinated-vulnerability-disclosure standards. It is general guidance.
What this isn't
It is not a professional security audit and not legal advice. Every recommendation is optional, and following it reduces common risks but does not guarantee security or a successful incident response.
Your responsibility
Responsibility for your business's security and incident handling remains with you.
Verify any recommendation against your own circumstances.
Find out how ready your business is to receive and handle a security vulnerability report — before one arrives. Free edition: all 17 readiness checks.
How This Works
Answer 17 questions across three areas — Governance, Technical, and Communication. Each takes 10–20 seconds. At the end you'll get a readiness score, a band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised coordinated-vulnerability-disclosure practices; which ones fit your business is your call.
Part 1 — Governance (Planning & Structure)
An "Incident Commander" — one decision-maker — keeps a response from descending into confusion.
Naming the standards you align with (e.g. ISO/IEC 29147, NIST SP 800-61) is a recommended baseline.
A documented step-by-step workflow means no one has to improvise under pressure.
A legal-review checkpoint helps avoid saying something legally risky in a public statement or notification.
Root-cause analysis is what stops the same class of issue from recurring.
A simple severity scorecard keeps the team aligned on how urgent the situation is.
Capturing lessons learned in a dedicated section is how a response process improves over time.
A defined verification step prevents declaring "resolved" while a system is still affected.
Part 2 — Technical (Investigation)
Verifying a report (reproducing it where possible) avoids both false alarms and dismissed real issues.
A consistent severity score drives consistent prioritisation across issues.
Knowing the blast radius is what makes notification and remediation decisions possible.
A single incident log keeps the timeline intact and is the basis of the post-incident review.
Part 3 — Communication (Action)
A defined internal-notification channel keeps the team aligned and prevents missteps.
When an issue involves a third-party component, the vendor often needs to know too.
Clear, timely customer notification protects trust — and is often a regulatory expectation.
Breach-notification rules carry deadlines; knowing whether they apply is the starting point. Confirm specifics with legal counsel.
An interim mitigation buys time; the permanent fix resolves it. Both should be a known path, not improvised.
Free Edition snapshot · scored entirely in the browser — answers never leave the device
Your PSIRT Response Readiness Results
0/ 34
—
—
Governance
0 / 16
Technical
0 / 8
Communication
0 / 10
Your Recommended Priority Actions
Free template
A Ready-to-Use Vulnerability Disclosure Policy
A clean, fill-in-the-blanks Vulnerability Disclosure Policy template — the published page that tells security researchers how to report an issue to you, with a safe-harbour clause. Enter your email and we'll send it over.
Optional, and separate from your assessment — your answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Ready to Close These Gaps?
The free assessment shows where you stand. The Full Edition adds a prioritised remediation roadmap, an attacker's-eye annotation on each gap, and a downloadable toolkit — disclosure policy, intake form, communication templates, regulatory decision tree, and more — so you have the documents, not just the score.