How This Works

Answer 17 questions across three areas — Governance, Technical, and Communication. Each takes 10–20 seconds. At the end you'll get a readiness score, a band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised coordinated-vulnerability-disclosure practices; which ones fit your business is your call.

Part 1 — Governance (Planning & Structure)

An "Incident Commander" — one decision-maker — keeps a response from descending into confusion.

Naming the standards you align with (e.g. ISO/IEC 29147, NIST SP 800-61) is a recommended baseline.

A documented step-by-step workflow means no one has to improvise under pressure.

A legal-review checkpoint helps avoid saying something legally risky in a public statement or notification.

Root-cause analysis is what stops the same class of issue from recurring.

A simple severity scorecard keeps the team aligned on how urgent the situation is.

Capturing lessons learned in a dedicated section is how a response process improves over time.

A defined verification step prevents declaring "resolved" while a system is still affected.

Part 2 — Technical (Investigation)

Verifying a report (reproducing it where possible) avoids both false alarms and dismissed real issues.

A consistent severity score drives consistent prioritisation across issues.

Knowing the blast radius is what makes notification and remediation decisions possible.

A single incident log keeps the timeline intact and is the basis of the post-incident review.

Part 3 — Communication (Action)

A defined internal-notification channel keeps the team aligned and prevents missteps.

When an issue involves a third-party component, the vendor often needs to know too.

Clear, timely customer notification protects trust — and is often a regulatory expectation.

Breach-notification rules carry deadlines; knowing whether they apply is the starting point. Confirm specifics with legal counsel.

An interim mitigation buys time; the permanent fix resolves it. Both should be a known path, not improvised.

Answer all 17 questions to see your report.

Your PSIRT Response Readiness Results

0 / 34
Governance
0 / 16
Technical
0 / 8
Communication
0 / 10

Your Recommended Priority Actions

Ready to Close These Gaps?

The free assessment shows where you stand. The Full Edition adds a prioritised remediation roadmap, an attacker's-eye annotation on each gap, and a downloadable toolkit — disclosure policy, intake form, communication templates, regulatory decision tree, and more — so you have the documents, not just the score.

See the Full Edition + Toolkit →