Security questionnaire self-check
Sooner or later a customer sends a security questionnaire, and the honest answers turn out to be worse than anyone assumed. This is that questionnaire, condensed to the questions that actually get asked and scored against how much each one matters.
It is weighted deliberately. Live access for somebody who left outranks a missing policy document, because one is exploitable today and the other is paperwork.
Free, no sign-up, and nothing you enter leaves your browser. There is no server behind this page.
Identity and access
Is multi-factor authentication enforced for every user, with no standing exceptions?
Including service accounts, contractors and senior staff who found it inconvenient.
Do administrators use separate accounts for administrative work?
An account that reads email should not also be able to reconfigure your tenant.
Is access reviewed on a defined schedule, with a record of each review?
Buyers ask to see the last few reviews, not whether you intend to do them.
Offboarding
Is there a written offboarding checklist that is actually executed on the leaving date?
Covering email, code, cloud consoles, VPN and every SaaS application.
Have you verified that nobody who left in the last year still has access anywhere?
This is the single most common finding in technical due diligence.
Devices and data
Are company devices enrolled in management, encrypted and remotely wipeable?
A lost laptop you cannot wipe is a disclosure you cannot bound.
Is company data prevented from sitting on personally owned devices?
A device the company does not own is a device the company cannot wipe.
Has a restore been tested in the last quarter, with a record of who did it?
A backup that has never been restored is a hypothesis.
Is your Microsoft 365 or Google Workspace data backed up by a third party?
The platform protects its infrastructure, not your data from deletion or ransomware.
Detection and response
Are logs centralised, time-synchronised, and retained for a defined period?
You cannot reconstruct an incident from logs that sit on the compromised machine.
Would anybody notice if an account were compromised tonight?
Detection is what separates a contained incident from one discovered by a customer.
Is there an incident response plan with named people and out-of-hours contacts?
Roles are not enough. Incidents need names and phone numbers.
Suppliers and documentation
Do you have a current inventory of every third party holding company data?
Enterprise buyers ask this directly, and departmental SaaS purchases make it hard.
Is third-party and contractor access time-bound and reviewed?
Standing supplier access is a recurring audit finding.
Is there current documentation of your systems, network and data flows?
Absence rarely kills a deal but it lengthens every conversation.
Why these questions
Enterprise security questionnaires vary in length and almost never in substance. Underneath the formatting they ask the same things: can you control who reaches your systems, do you remove access when people leave, are devices managed, is data backed up and tested, would you notice a compromise, and do you know which third parties hold your data.
The questions here are those, phrased the way an engineer would ask them rather than the way a compliance form does.
How to read your score
The percentage is the least useful output. The gap list underneath it is the point, because it is ordered by consequence rather than by the order the questions appeared.
If the first two or three items are about offboarding, backup testing or multi-factor authentication, fix those before anything else. They are cheap, they close most of the realistic risk, and they are the items a buyer is most likely to probe.
Answering honestly is the whole point
Nothing is submitted anywhere and there is no server behind this page, so there is no reason to be generous with yourself. A questionnaire answered optimistically to a customer becomes a contractual problem later, and an assessment answered optimistically here just wastes your own time.
Partly is a legitimate answer and counts as half. Most businesses have a lot of partly, and knowing where is more useful than a binary.
Others you might use
- Downtime cost calculatorWork out what an IT outage actually costs your business, per incident and per year.
- DPDP readiness checkA practical self-assessment against the Digital Personal Data Protection Act, with what to fix first.
- Microsoft 365 plan comparisonWhich plan unlocks conditional access, Intune and data loss prevention, without a price table that goes stale.
Send us your numbers and we will tell you what they mean
No obligation and no sales sequence. If the honest answer is that you do not need us, that is what you will get. Initial reply within 4 business hours.