Cyber Index — Free Cybersecurity Maturity Self-Assessment
← Back to overview

Where does your organisation actually stand on cybersecurity?

Answer thirty-seven plain questions and get a measured position across fifty essential controls, the attack paths your answers leave open, the regulations that may apply to you, and three things to start with. Free, no account, and your answers never leave your browser.

Before we begin

Seven questions about your organisation

These decide which incidents you are shown, which regulations are discussed, and which organisations you are compared with. Nothing here identifies you, and nothing is sent anywhere.

Thirty-seven questions, roughly twelve to fifteen minutes. You can stop and come back: your answers stay on this device until you clear them.

How it works

Four answers, and one distinction that matters

A control can be absent, partial, in place, or in place and verified. The gap between the last two is the point: a control nobody checks is one you believe in rather than one you rely on. An organisation that has deployed everything without verifying anything cannot pass sixty-six.

Not knowing is an answer too

If nobody in the organisation can confirm whether a control is in place, say so. Those answers are counted as zero, and they are also shown separately as blind spots, because a question nobody can answer is itself a finding.

The attack paths are not invented

Each step of each scenario names a technique published in MITRE ATT&CK, and a step is only shown as unstopped when the control that guards it is one MITRE itself lists as a mitigation for that technique. You can check every link independently.

Nothing leaves your browser

The questionnaire, the scoring and the report all run on this device. No account, no email address, nothing stored on our side. Clearing your browser data clears the assessment.

Question 1 of 37

Your index
0 / 100

0
blind spots
0
high severity gaps
3
priority actions
50
controls assessed

Coverage by function

Where you are strong, and where you are not

Six functions, from deciding to recovering. The percentages are raw coverage rates, each control counting once. The index above is weighted, so it differs from their average on purpose.

The fifty controls

One square per control

Each square is one control of our framework, filled according to your answer. Click a row to open the detail.

In place and verified In place Partial Not in place Blind spot
0

What would happen here

Four scenarios, rebuilt from your answers alone

Each step names a technique published in MITRE ATT&CK, and is shown as unstopped only when the control MITRE itself lists as a mitigation for that technique is missing from your answers. Pick the one you want to follow.

Gap register

Every insufficient control, its open risk and its regulatory exposure

Grouped by function, in the order a security programme is built, then by decreasing severity inside each function. Severity is calculated, never assigned: it is the size of the gap multiplied by the sum of the control's weight and its regulatory exposure. The weight itself is a count of how many of the eight attack scenarios the control guards.

Severity = gap (1.00 not in place or unknown, 0.67 partial, 0.34 unverified) × (weight 1 to 4 + regulatory exposure 0 to 3). High from 3.5, moderate from 1.75, low below. Every term is a count that can be checked against a published document.

Regulatory coverage by function

Insufficient requirements over requirements concerned

Indicative only. This coverage depends on the whole of your activities and on every market where you operate, which a short questionnaire cannot capture in full. Only an examination of your actual situation can settle whether a regulation applies to you and to what extent.

In your sector, recently

The latest incidents recorded in your sector

Pulled from what Stroople Signal records continuously. No commentary is generated: these are the most recent entries carrying your declared sector.

Follow data breaches by sector or country →

Severity as announced is not severity as experienced

A vulnerability reachable from the internet exposes you far more than the same flaw on an internal component, because the first is found by automated scanning within hours. And a moderate vulnerability on an asset that carries your activity or holds sensitive data is more urgent than a critical one on a component whose failure would change nothing. The vendor's rating describes the flaw, not your exposure.

Track vulnerabilities actually being exploited →

Is your domain name already being imitated?

A fraudulent email works all the better when it comes from an address that looks like yours, one letter apart. Those domain names are registered in minutes and leave public traces before they are ever used. My Exposure of Signal looks for names close to yours, certificates recently issued to them, and addresses of your company already exposed. No account, no signup.

Check your external exposure →

Where to start

Three actions, not ten

The three gaps with the highest severity, with two tie-breaks applied: a gap that guards a step of the scenario shown first comes before one that does not, and an action achieved by configuration comes before one that needs a project. No more than two actions from the same function, so that the plan does not concentrate on a single area.

Everything else

0 actions between you and one hundred

The complete list, grouped by function. Click a line to open the full recommendation.

This assessment is not an audit

It rests on your own statements, which nobody has verified, and it covers a baseline of essential controls rather than the whole of your security. What it gives you is real all the same: an overall view of where you stand, a common language to discuss it with your management and your provider, and a short list of things to start with. It is the first base a security programme is built on, and the natural starting point for an audit if you decide to go further.

Your action plan

The three priority actions, in the order you choose

Reorder the tasks with the arrows, set your own dates, and tick what is done. This plan stays on this device: no account, no address, nothing stored on our side.

0 of 0 tasks completed
Once these three actions are complete, take the questionnaire again: your index will be recalculated on your new answers, and three further priority actions will be proposed, based on whichever gaps are then the most severe. You can repeat the assessment as often as you like.
Cyber Index — Free Cybersecurity Maturity Self-Assessment
Cyber Index — Free Cybersecurity Maturity Self-Assessment