Could you prove it today?
Thirteen questions, under five minutes, no email needed to see your result. It scores two things separately: whether you have the controls, and whether you could produce the evidence if a client, insurer or regulator asked.
Is your business likely to exceed $3 million in annual turnover?
Do you handle personal or sensitive information such as client records, financial details, identity documents, or health information?
Would your business need to answer cyber or privacy questions from clients, insurers, auditors, or regulators?
Do you have current written cyber, privacy and data-handling policies?
Could you show when each policy was approved, by whom, and that staff received it?
Do the people who handle personal or client information receive cyber security training?
Could you produce a per-person record of who completed that training and when?
Is access to client and sensitive information limited to the people who need it?
Could you show a dated access review, and the date each departing person lost access?
Is there a written process people would follow if a breach or phishing incident happened?
Could you produce an incident log with dated entries and the decisions taken?
Does management formally review cyber security at a defined cadence?
Could you show dated evidence that those reviews happened over the last 12 months?