Security Scorecard
An honest read on your security posture, scored against the NIST Cybersecurity Framework 2.0, with your biggest gaps in priority order. A few minutes.
What is the size of your organization?
Organization size affects security complexity and resource requirements.
A free cybersecurity self-assessment built on NIST CSF 2.0
This free security assessment scores your current practices against the six functions of the NIST Cybersecurity Framework 2.0 and tells you where to start. It is built for companies without a dedicated security team, where the question is not which product to buy but which of the many things you could do actually reduces risk first.
The six NIST CSF 2.0 functions, in plain language
- Govern. Who is responsible for security decisions, and how much risk are you willing to carry. Usually the weakest area in a small company, because it is the only one that cannot be bought.
- Identify. Knowing what you actually have: systems, data, accounts and third-party vendors. You cannot protect an asset nobody has written down.
- Protect. The controls that reduce exposure, including access management, multi-factor authentication, patching and backups.
- Detect. Knowing when something has gone wrong. Commonly the second-weakest area, and the reason incidents run for months before anyone notices.
- Respond. What you do when it happens: who gets called, who decides, and what gets communicated.
- Recover. Getting back to operating, which depends almost entirely on whether your backups have been tested rather than merely configured.
For a prioritized starting point, see our small business cybersecurity checklist, which maps the essentials to these six functions in the order they are worth doing. If you want an outside review rather than a self-assessment, our cybersecurity assessment covers that.
Frequently asked questions
Is this security assessment really free?
Yes. There is no charge, no sales call required, and no credit card. You answer a set of questions about your current security practices and get a scored result with prioritized recommendations. It is a self-assessment, so the value depends on answering honestly rather than aspirationally.
What is NIST CSF 2.0?
The NIST Cybersecurity Framework 2.0 is the US National Institute of Standards and Technology's framework for managing cybersecurity risk, organized into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is voluntary, widely used as a common language between technical and business stakeholders, and it is what this assessment is built on.
What do the six NIST CSF functions actually mean for a small business?
Govern is deciding who is responsible and what your risk tolerance is. Identify is knowing what you have: systems, data, vendors. Protect is the controls that reduce risk, such as access management, patching and backups. Detect is knowing when something has gone wrong. Respond is what you do about it. Recover is getting back to operating. Most small businesses are strongest on Protect and weakest on Govern and Detect, which is usually the wrong way round.
Where should a company with no security team start?
With Identify and Govern, not with tools. You cannot protect systems you have not catalogued, and buying security products before deciding who owns the risk tends to produce spend without reduced exposure. In practice the highest-value early moves are an inventory of systems and data, multi-factor authentication everywhere it is available, tested backups, and a named owner for security decisions.
How is this different from a vulnerability scan?
A scan looks at your systems from the outside and reports technical findings. This assessment looks at your practices: whether you have the processes, ownership and controls that determine your risk over time. They answer different questions and you eventually want both, but a scan on its own tells you what is broken today without telling you why it will break again.
Is this related to SecurityScorecard the company?
No. SecurityScorecard is a separate commercial vendor-risk ratings platform and this tool is not affiliated with them. This is a free self-assessment built on NIST CSF 2.0 for companies evaluating their own security posture, particularly smaller organizations without a dedicated security team.
What do you do with my answers?
Results are generated for you and shown on screen. If you choose to share contact details we may follow up about the results. The assessment is a starting point for a conversation about priorities, not a substitute for a formal audit or a penetration test.