Answer thirty-seven plain questions and get a measured position across fifty essential controls, the attack paths your answers leave open, the regulations that may apply to you, and three things to start with. Free, no account, and your answers never leave your browser.
These decide which incidents you are shown, which regulations are discussed, and which organisations you are compared with. Nothing here identifies you, and nothing is sent anywhere.
Thirty-seven questions, roughly twelve to fifteen minutes. You can stop and come back: your answers stay on this device until you clear them.
A control can be absent, partial, in place, or in place and verified. The gap between the last two is the point: a control nobody checks is one you believe in rather than one you rely on. An organisation that has deployed everything without verifying anything cannot pass sixty-six.
If nobody in the organisation can confirm whether a control is in place, say so. Those answers are counted as zero, and they are also shown separately as blind spots, because a question nobody can answer is itself a finding.
Each step of each scenario names a technique published in MITRE ATT&CK, and a step is only shown as unstopped when the control that guards it is one MITRE itself lists as a mitigation for that technique. You can check every link independently.
The questionnaire, the scoring and the report all run on this device. No account, no email address, nothing stored on our side. Clearing your browser data clears the assessment.
Six functions, from deciding to recovering. The percentages are raw coverage rates, each control counting once. The index above is weighted, so it differs from their average on purpose.
Each square is one control of our framework, filled according to your answer. Click a row to open the detail.
Each step names a technique published in MITRE ATT&CK, and is shown as unstopped only when the control MITRE itself lists as a mitigation for that technique is missing from your answers. Pick the one you want to follow.
Grouped by function, in the order a security programme is built, then by decreasing severity inside each function. Severity is calculated, never assigned: it is the size of the gap multiplied by the sum of the control's weight and its regulatory exposure. The weight itself is a count of how many of the eight attack scenarios the control guards.
Severity = gap (1.00 not in place or unknown, 0.67 partial, 0.34 unverified) × (weight 1 to 4 + regulatory exposure 0 to 3). High from 3.5, moderate from 1.75, low below. Every term is a count that can be checked against a published document.
Indicative only. This coverage depends on the whole of your activities and on every market where you operate, which a short questionnaire cannot capture in full. Only an examination of your actual situation can settle whether a regulation applies to you and to what extent.
Pulled from what Stroople Signal records continuously. No commentary is generated: these are the most recent entries carrying your declared sector.
Follow data breaches by sector or country →A vulnerability reachable from the internet exposes you far more than the same flaw on an internal component, because the first is found by automated scanning within hours. And a moderate vulnerability on an asset that carries your activity or holds sensitive data is more urgent than a critical one on a component whose failure would change nothing. The vendor's rating describes the flaw, not your exposure.
Track vulnerabilities actually being exploited →A fraudulent email works all the better when it comes from an address that looks like yours, one letter apart. Those domain names are registered in minutes and leave public traces before they are ever used. My Exposure of Signal looks for names close to yours, certificates recently issued to them, and addresses of your company already exposed. No account, no signup.
Check your external exposure →The three gaps with the highest severity, with two tie-breaks applied: a gap that guards a step of the scenario shown first comes before one that does not, and an action achieved by configuration comes before one that needs a project. No more than two actions from the same function, so that the plan does not concentrate on a single area.
The complete list, grouped by function. Click a line to open the full recommendation.
It rests on your own statements, which nobody has verified, and it covers a baseline of essential controls rather than the whole of your security. What it gives you is real all the same: an overall view of where you stand, a common language to discuss it with your management and your provider, and a short list of things to start with. It is the first base a security programme is built on, and the natural starting point for an audit if you decide to go further.
Declarative self-assessment based on the Stroople framework, itself built on the major international cybersecurity standards. It constitutes neither an audit nor a certification. At no point did your answers leave your browser.
Reorder the tasks with the arrows, set your own dates, and tick what is done. This plan stays on this device: no account, no address, nothing stored on our side.