Skip to main content

Cybersecurity Architecture Assessment

Cybersecurity Architecture Assessment — Free Assessment

Assessment Form

Contact Name(Required)
Is threat modelling conducted for new systems and significant architecture changes?(Required)
Are security design principles — least privilege, defence in depth, fail-safe defaults — applied consistently?(Required)
Is static application security testing (SAST) integrated into the CI/CD pipeline?(Required)
Is software composition analysis (SCA) used to identify vulnerable open source dependencies?(Required)
Is Single Sign-On (SSO) implemented for all internal applications?(Required)
Is phishing-resistant MFA (hardware keys, passkeys, or app-based TOTP) enforced for all user accounts?(Required)
Is sensitive data classified and labelled across all systems — databases, file stores, and SaaS?(Required)
Is sensitive data encrypted at rest and in transit using current standards?(Required)
Is the network segmented to limit lateral movement — production, development, and admin traffic separated?(Required)
Are firewall rules documented, reviewed, and right-sized — no permissive rules without business justification?(Required)
Is a Cloud Security Posture Management (CSPM) tool in use to detect misconfiguration?(Required)
Is cloud IAM configured on least-privilege principles with no standing high-privilege access?(Required)
Is Endpoint Detection and Response (EDR) deployed on all managed endpoints?(Required)
Is full-disk encryption enforced on all laptops and mobile devices?(Required)
Is there a current inventory of all APIs — internal, external, and third-party — with their data exposure?(Required)
Are all APIs authenticated — no unauthenticated endpoints in production?(Required)
Are cryptography standards documented — approved algorithms, key lengths, and deprecated cipher prohibition?(Required)
Is TLS 1.2 minimum enforced everywhere — no SSL or TLS 1.0/1.1 in use?(Required)
Are backups architecturally separated from production — immutable and offline or air-gapped copies?(Required)
Are RTO and RPO defined for all critical systems and validated through tested recovery?(Required)
Are third-party software vendors assessed for security posture before onboarding?(Required)
Is a Software Bill of Materials (SBOM) maintained for critical applications?(Required)
Is there a security architecture review process for new systems, major changes, and third-party integrations?(Required)
Is a security architecture review conducted at least annually across the full technology estate?(Required)