Free Tool
Compliance Gap Mini-Assessment
Ten questions, ninety seconds, zero signup. Score your current readiness against ISO 27001 and Cyber Essentials and walk away with the three highest-impact gaps to close first.
Access Control
Does every user have a unique account, and are admin privileges separated from day-to-day accounts?
ISO 27001:2022 A.5.15 / A.5.16 · Cyber Essentials: User Access Control
Multi-Factor Authentication
Is MFA enforced on all cloud admin consoles, email, and remote access?
ISO 27001:2022 A.5.17 / A.8.5 · Cyber Essentials: User Access Control
Patch Management
Are operating systems, browsers, and third-party software patched within 14 days of vendor release?
ISO 27001:2022 A.8.8 · Cyber Essentials: Security Update Management
Endpoint Protection
Do all endpoints (laptops + servers) have a managed EDR with central visibility?
ISO 27001:2022 A.8.7 · Cyber Essentials: Malware Protection
Backup & Recovery
Are critical systems backed up and have you tested a restore in the last 12 months?
ISO 27001:2022 A.8.13 · Cyber Essentials: (supplementary)
Logging & Monitoring
Are security-relevant logs collected centrally with alerting on suspicious activity?
ISO 27001:2022 A.8.15 / A.8.16 · Cyber Essentials: (supplementary)
Asset Inventory
Do you maintain an up-to-date inventory of devices, applications, and data flows?
ISO 27001:2022 A.5.9 · Cyber Essentials: Firewalls / Secure Configuration
Risk Management
Do you have a documented information security risk register reviewed quarterly?
ISO 27001:2022 Clause 6.1.2 / 8.2 · Cyber Essentials: (supplementary)
Incident Response
Is there a tested incident response plan with named roles and external contacts?
ISO 27001:2022 A.5.24 – A.5.27 · Cyber Essentials: Incident Management
Awareness & Training
Do all staff complete information security training at induction and annually?
ISO 27001:2022 A.6.3 · Cyber Essentials: (supplementary)