Loading...
Loading...
Tool
Answer 10 questions on backup, access control, incident response, and awareness. Get your score and the top gaps to address.
Answer yes or no. Your score and top gaps will appear at the end.
Are backups isolated from production (air-gapped or immutable) and tested regularly?
Are critical assets and recovery priorities documented (RTO/RPO)?
Is patch and vulnerability management in place for internet-facing systems?
Are email and endpoint protection (e.g. MFA, EDR) deployed and monitored?
Do staff receive regular security awareness training, including phishing simulation?
Does your incident response plan include a ransomware playbook and offline contact list?
Do decision-makers know who to call (internal lead, insurer, legal, comms)?
Do you have a process to preserve evidence and notify regulators (ICO) if required?
Have you run a tabletop or drill (e.g. NCSC Exercise in a Box) in the last 12 months?
Do you hold or are you working towards Cyber Essentials or equivalent?
It measures how well your organisation is prepared for a ransomware incident: backup and recovery, access controls, patching, incident response planning, and staff awareness. The score is indicative only and does not replace a full security assessment.
Yes. The checklist and score are free with no commitment. We may follow up if you request a discussion about your readiness or take our full StrategyOS Assessment.