INTERACTIVE TOOL · CYBER READINESS SCORECARD

HOW READY ARE YOU, REALLY?

Score eight operational domains from 1 to 5 to see where policy, technology and real-world readiness may be out of alignment. Free, with no login required.

Low / ad hocStrong / repeatable
Clear accountability, risk decisions, policy ownership and measurable security objectives.
Low / ad hocStrong / repeatable
Strong identity lifecycle, MFA, privileged access controls and access governance.
Low / ad hocStrong / repeatable
Asset visibility, logging, telemetry, detection coverage and actionable monitoring.
Low / ad hocStrong / repeatable
Documented roles, playbooks, communications, decision rights and exercised response.
Low / ad hocStrong / repeatable
Recovery objectives, tested backups, continuity and restoration of critical services.
Low / ad hocStrong / repeatable
Role-based training, executive readiness, exercises and technical skill development.
Low / ad hocStrong / repeatable
Supplier visibility, contractual controls, assurance and concentration-risk management.
Low / ad hocStrong / repeatable
Security architecture, cloud guardrails, segmentation, configuration and engineering discipline.
ABOUT THIS TOOL

WHAT THE SCORE CAN AND CANNOT TELL YOU.

The scorecard gives leaders a quick picture across governance, identity, detection, response, recovery, people, third parties and cloud architecture. It is based entirely on your own answers, so it is an initial indication of priorities, not a certification, audit or verified security score.

C3SA's value starts where the tool stops: testing self-reported answers against evidence, then turning the priority gaps into a funded, sequenced improvement roadmap.

COMMON QUESTIONS
Who should complete it?

Ideally a security leader and an operational or executive stakeholder, separately. Differences between their answers are often the most useful finding.

What should I do with the result?

Use the lowest-scoring domains to frame your next conversation. You can print the result or request a detailed copy, and C3SA can validate it through evidence review, technical testing or exercises.

Is my information shared?

Your answers are processed in your browser. The site may record an anonymous completion event (tool name and score) in its analytics. Your contact details and full result are only sent to C3SA if you choose to request detailed results through the form. Do not enter sensitive, classified or controlled information into public web forms.

THE C3SA DIFFERENCE

FROM SELF-ASSESSMENT TO EVIDENCE.

WHAT YOU GET NOW

Domain scores that show where your self-reported readiness is weakest, with the limitations stated.

WHAT C3SA ADDS

C3SA tests the answers against evidence, architecture and technical validation, then prioritizes what to fix first.

THE NEXT STEP

An improvement roadmap with owners, sequence and measures of progress.

UNDER ATTACK? CYBERFIRE →