
Answer 10 controls across configuration, protection, and response. Each "Yes" scores 1 point. Your total determines your resilience classification.
🔒 Progress is stored in your browser only — never sent to any server.
Multi-Factor Authentication (MFA)
MFA is enforced for all access to this system, including user accounts and service accounts used for administration.
Immutable Backups & Testing
Backups for this system are off-site/immutable (air-gapped), and a documented monthly restoration test specific to this system is performed.
Privileged Access Management (PAM)
All privileged accounts for this system are strictly separated, managed via a PAM solution, and only utilise Just-in-Time (JIT) access.
Hardened Security Baseline
The underlying Operating System (OS) and application configuration adhere to a defined, hardened security baseline (e.g., CIS Benchmarks).
Data Mapping & Classification
The data stored/processed by this system is formally classified and mapped, detailing its dependencies and downstream flows.
Security Logging & Alerting
System logs feed to the SIEM, generating real-time alerts for unusual sign-in activity and mass file encryption/change events.
Defined Incident Plan Roles
A system-specific incident response card is maintained, clearly assigning remediation and recovery roles.
Vendor Escalation Path
The key vendor/support contact is documented with validated, immediate 24/7 technical escalation procedures.
Network Segmentation
This system is hosted within a network segment protected by strict egress filtering, limiting lateral attack paths.
Tested System Recovery Time
The system has been included in a recent tabletop or live drill that validated its documented Recovery Time Objective (RTO) against a simulated adversary scenario.
Looking for an organisational view?
This tool assesses a single system. The 2026 Resilience Scorecard rates your organisation's overall security maturity across 11 strategic controls.