Free tool

How Mature Is Your Security Program? A 26-Point Self-Check

These are the 26 capabilities a mature security and compliance program has - the same maturity lists we publish on our GRC and Cyber Risk Management pages, in one place. Check what your business actually has in place today. It takes about five minutes.

Your score updates as you go. It's free, and no email is required to see your results.

One rule for honest math: only check an item if you could show evidence of it this week. A policy nobody can find, or a backup nobody has restored, doesn't count yet. If you'd have to guess, leave it unchecked - the unchecked items are the useful ones.

Govern

Who decides, who owns it, and what's written down.

  • Everyone knows who owns security decisions, who approves exceptions, and who answers when something goes wrong.

    Addressed by: Fractional CISO

  • Written, current, and actually followed - not a binder nobody has opened since it was created.

    Addressed by: GRC — Secure phase

  • Changes to systems, software, and access are requested, approved, and recorded, so nothing important happens by accident.

    Addressed by: SOC 2

  • You know which third parties touch your systems and data, and someone reviews that access on a schedule.

    Addressed by: Third-Party Assessments

Manage Risk

How you find, reduce, and prepare for what can hurt you.

  • A current, written list of what could actually hurt your business, ranked by likelihood and impact instead of gut feel.

    Addressed by: Cyber Risk & Compliance Gap Assessment

  • Every control traces to the risk it reduces and the requirement it satisfies, so nothing is duplicated or missing.

    Addressed by: NIST CSF

  • Risk gets re-evaluated on a schedule, because your environment and the threats against it both keep changing.

    Addressed by: Cyber Risk Management — Ongoing review

  • A written, tested plan for the bad day: who acts, who decides, and who gets called first.

    Addressed by: Cyber Risk Management — Incident response

  • People can reach what their job requires and nothing more, and access ends the day the job does.

    Addressed by: Helpdesk — Access controls

  • Someone is watching for suspicious activity, so incidents are found in hours instead of months.

    Addressed by: 24/7 threat monitoring

  • Known vulnerabilities get closed on a defined schedule, not when someone remembers.

    Addressed by: Helpdesk — Patching

  • Backups are proven by actually restoring from them - an untested backup is a hope, not a control.

    Addressed by: Helpdesk — Backup validation

Comply

How you prove all of it to auditors, insurers, and regulators.

  • Your controls map to the frameworks that apply to you - HIPAA, PCI DSS, CMMC, state privacy laws - not to a generic checklist.

    Addressed by: Compliance Finder

  • You could face an audit tomorrow without a scramble, because the preparation already happened.

    Addressed by: GRC — Assess phase

  • Proof of what you do accumulates as you work - logs, records, sign-offs - instead of being reconstructed under deadline.

    Addressed by: GRC — Find gaps

  • Leadership sees risk and compliance status in plain numbers, and open items are tracked to closure.

    Addressed by: GRC — Manage phase

Operate & Defend

The day-to-day machinery: monitoring, protection, response, and review.

  • Identify your most critical threats, misconfigurations, and exposures across people, processes, and technology.

    Addressed by: Cyber Risk & Compliance Gap Assessment

  • Real-time visibility into suspicious activity, anomalies, and emerging cyber risks before they escalate. Monitoring and assessment are separate specialist providers - the team watching your environment isn't the team that graded it.

    Addressed by: Cyber Risk Management — Secure (monitoring)

  • Layered security controls that protect your users, devices, applications, and data from modern threats.

    Addressed by: Cyber Risk Management — Secure (layered protection)

  • Clear, business-friendly risk ratings that show where you stand - and what your leadership must prioritize.

    Addressed by: Fractional Leadership

  • Build response procedures, communication plans, and practical action steps your team can follow during an incident.

    Addressed by: Cyber Risk Management — Incident response

  • Proactive detection of unusual patterns and attacker behavior across your environment.

    Addressed by: Cyber Risk Management — Top threats

  • Step-by-step instructions to fix vulnerabilities and strengthen defenses in the highest-impact areas first.

    Addressed by: Cyber Risk & Compliance Gap Assessment

  • Ensure your systems, apps, and cloud environments are hardened against common threats and attack paths.

    Addressed by: Cyber Risk Management — Secure (hardening)

  • Help your team maintain least-privilege access and reduce the risk of credential-based attacks.

    Addressed by: NIST CSF — Protect (access control)

  • Quarterly reviews, updated recommendations, and executive decision support for long-term risk reduction.

    Addressed by: Cyber Risk Management — Manage phase

You checked 0 of 26.

Govern 0/4 · Manage Risk 0/8 · Comply 0/4 · Operate & Defend 0/10

FAQ

Common questions

Do I need to enter my email to see my score?

No. Your score and result appear on this page as you check items. Email is only for sending yourself a copy, and that option appears after your results - never before.

How were these 26 items chosen?

They're the same maturity lists we publish on our GRC and Cyber Risk Management service pages: 16 governance, risk, and compliance capabilities and 10 operational security capabilities. No vendor product lists, no padding - it's the standard we hold customer programs to.

What counts as "having" an item?

Evidence, not intention. If you could produce the policy, the restore log, or the access review this week, check it. If it exists in someone's head or on a to-do list, it isn't a control yet - leave it unchecked.

What happens after I see my score?

Nothing automatic. Every unchecked item links to the page that explains how it gets addressed, and if you want the score verified against your real environment, that's what the Cyber Risk & Compliance Gap Assessment does.