Skip to content
Obfuscation Hub

For business leaders

Technology risk, in the language of the business

You do not need to become a security expert to lead a well-defended organization. You need a clear picture of where you stand, a short list of what matters most, and honest guidance about what to do in-house versus with help. Start with the ten-question self-assessment below.

Take the self-assessment

Sound familiar?

Four situations that bring most leaders to this page. All four are normal, fixable, and better addressed before an incident or an auditor forces the timeline.

A customer sent a security questionnaire

A big deal now depends on questions nobody on staff was hired to answer. You need credible responses quickly — and a plan for the gaps they expose.

A contract or market requires SOC 2 or CMMC

The acronyms arrived before the budget did. You need to know what these frameworks actually demand, what they cost in effort, and what order to do things in.

IT grew organically — and it shows

Accounts, devices, and vendors accumulated faster than process. Everything works, mostly, but nobody can say with confidence who has access to what.

Security is on your plate without a security team

You are the founder, the COO, or the office manager who also "does IT." You need pragmatic priorities, not enterprise frameworks scaled down badly.

Self-assessment

Where does your security program stand?

Ten questions, about three minutes. Your answers are scored in your browser and are never stored or sent anywhere — reloading the page clears everything. The result is educational guidance, not a formal audit or assessment.

  1. 01 Is there a clearly assigned owner for IT and security decisions — internal or external?

    Someone accountable for technology risk, even part-time or outsourced.

  2. 02 Do you maintain a current inventory of your laptops, servers, and the SaaS applications your team relies on?

    You cannot protect, patch, or offboard what you have not listed.

  3. 03 Are user accounts centrally managed, with access removed promptly when someone leaves or changes roles?

    Central identity plus a working joiner-mover-leaver process.

  4. 04 Is multifactor authentication (MFA) enforced for email, remote access, and all administrative accounts?

    Enforced by policy — not just available for those who opt in.

  5. 05 Are company devices centrally managed with baseline protections — automatic updates, disk encryption, and screen lock?

    A consistent baseline you can verify, not settings left to each user.

  6. 06 Are your critical systems backed up — and have you successfully tested a restore in the past year?

    An untested backup is a hope, not a control.

  7. 07 Do you have a written incident response plan with named contacts, and does your team know where it is?

    Even one page with roles, first steps, and phone numbers counts.

  8. 08 Do you know which vendors and contractors currently have access to your systems and data — and at what privilege level?

    Including managed service providers, developers, and integrations.

  9. 09 Do you have basic written security policies — acceptable use, access control, and data handling — that staff have actually seen?

    Short, real documents that match how you operate.

  10. 10 Have you identified the security requirements that apply to you — customer contracts, cyber insurance, SOC 2, CMMC, or regulations?

    Requirements often arrive through sales contracts before regulators.

Educational self-check only — not a formal audit, a compliance determination, or a substitute for professional review. No answers leave your browser.

Prefer to talk it through?

A scoped professional assessment replaces self-reported answers with verified findings — and ends in a prioritized roadmap, not a lecture.

Request an Assessment