Interactive Cyber Risk Assessment

How prepared is your business?

Answer twelve business-focused questions to receive an immediate cybersecurity maturity snapshot and identify practical areas for further review.

Before you begin

This assessment is designed for business leaders—not security engineers.

Choose the answer that best reflects how consistently the practice is implemented across the organization. “Yes” means the practice is documented, broadly implemented, owned, and reviewed—not simply that a tool was purchased.

0 of 12 answered

01GovernanceCybersecurity risk has a named executive owner and is reviewed as a business issue.
02VisibilityWe maintain a current inventory of devices, software, cloud services, important data, and responsible owners.
03IdentityMulti-factor authentication is required for email, remote access, administrative accounts, and other critical systems.
04AccessUser and administrator access is based on job need, reviewed regularly, and removed promptly when roles change.
05DevicesCompany devices are centrally managed, patched, securely configured, and protected with modern endpoint security.
06EmailWe use layered email protections and verify sensitive requests such as payment or account changes through a separate channel.
07Data & RecoveryCritical data is backed up, protected from routine user access, and restoration is tested on a defined schedule.
08Incident ReadinessWe have a current incident response plan with leadership roles, communication steps, and at least one exercise or review.
09Third PartiesSecurity and data risk are considered before selecting vendors, and critical providers are reviewed over time.
10PeopleEmployees receive security education at onboarding and regularly thereafter, including phishing and data-handling expectations.
11AssessmentWe have completed a recent cybersecurity risk assessment and maintain a prioritized remediation roadmap.
12AI GovernanceEmployees know which AI tools are approved, what data may be entered, and when human review is required.

This tool provides a high-level educational snapshot only. It is not a formal risk assessment, audit, penetration test, legal opinion, certification, or determination of compliance.

Take the next step

A score creates awareness. A real assessment creates a roadmap.

Citadel Networks can validate the current state, document business risk, and help leadership prioritize the work.

SCHEDULE A CYBERSECURITY BRIEFING