Twenty-eight plain-English questions across asset inventory, scanning, prioritisation, remediation, patching, cloud workloads, exceptions, and reporting. You get a scored snapshot of where your programme sits on the four-tier maturity spectrum. About ten minutes. No email required.
Plain-English security — without us ever seeing your answers. Everything stays in your browser. Nothing is transmitted or tracked.
The eight working parts of a programme. The assessment follows the lifecycle. It starts with asset inventory (knowing what you run) and scanning (coverage and cadence). Then comes prioritisation — severity scores, the Known Exploited Vulnerabilities (KEV) catalogue, exploit-likelihood signals, and business context. It finishes with remediation and deadlines, patch operations, and cloud and container workloads. Exceptions and risk acceptance and metrics and governance close the loop.
What you get. A weighted score out of 68, plus a maturity band. The band uses the same four-tier spectrum as our Vulnerability Management book series. You also get a breakdown by area and plain-English priority actions.
What it isn't. This is general guidance. It is not a professional audit, not a penetration test, and not legal advice. Every recommendation is optional. Following it reduces common risks but does not guarantee any outcome. Responsibility for your programme remains with you.
Everything behind this free assessment — the working documents, templates, runbooks, and depth to put it into practice. Three editions to fit how you work.
See the full toolkit & pricing →One-time purchase · files you own forever · 30-day money-back guarantee.