UK-based • Supporting growing and regulated organisations

Private, no-email self-assessment

IT & Cyber Readiness Scorecard

Answer 15 practical questions to identify where your organisation has strong foundations and where attention may be needed. Your answers and result stay in this browser.

No registration. No email address. No submitted answers.

This tool performs the calculation on your device. EaseThat does not receive or store your selections or score.

Progress0 of 15 answered
0 of 15

Leadership & Governance

Ownership, roadmap and supplier accountability.

1A documented technology roadmap is reviewed against business priorities at least annually.
2Accountability for technology decisions, risks, budgets and suppliers is clearly assigned.
3Technology assets, services, contracts and lifecycle risks are maintained in a current inventory.

Cybersecurity

Identity, devices and incident protection.

4Multi-factor authentication is required for users, with stronger controls for administrators.
5Business devices are supported, encrypted, patched and managed to an agreed standard.
6Security alerts and incidents have named owners, escalation steps and an exercised response plan.

Resilience & Recovery

Continuity priorities, backups and tested recovery.

7Critical services have agreed Recovery Time and Recovery Point Objectives.
8Backups are protected from normal administrator access and include critical cloud data where required.
9Restores and continuity scenarios are tested, evidenced and followed by tracked improvement actions.

Data & Reporting

Reliable information, consistent measures and efficient reporting.

10Important reports use agreed data sources, owners and consistently defined KPIs.
11Material data-quality issues are visible, investigated and assigned to accountable owners.
12Repeated manual reporting and spreadsheet processes are reviewed for controlled automation.

Compliance & Controlled Change

Proportionate control for regulated, contractual and privacy obligations.

13Technology-related legal, regulatory, contractual and privacy obligations are documented.
14Access and material technology changes are approved, tested and recorded proportionately to risk.
15Critical or regulated systems have defined owners, review cycles and supported lifecycle plans.

See your readiness result

You must answer every question. The result is guidance rather than a certification, audit or guarantee.