Security risk assessment
Twelve questions across four domains. You get a weighted risk score, a per-domain breakdown and the findings to act on first.
What the system holds and who can reach it.
Pick the highest classification, even if it is only a small part of the data.
How users and admins authenticate.
Backups, logging and incident readiness.
Vendors, dependencies and third-party access.