Skip to main content
Black Tyger Strategies
Home
Business Health Check-Up
How We Work
Services
Insights
Contact Us
Cybersecurity Operations Assessment
Cybersecurity Operations Assessment — Free Assessment
Assessment Form
Contact Name
(Required)
First
Last
Company Name
(Required)
Contact Email
(Required)
Security Policy Adherence
Do all staff receive security policy training at onboarding and at least annually thereafter?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is policy compliance monitored — through audits, automated controls, or behavioural measurement?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Incident Response Operations
Is there a documented incident response plan covering detection, triage, containment, and recovery?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Has the incident response plan been tested through a tabletop exercise in the last 12 months?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Access Management Operations
Is there a formal access provisioning process — requests, approvals, and provisioning within defined SLAs?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is access revoked within 24 hours of employee departure — across all systems?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Data Handling in Operations
Do all staff understand how to classify and handle sensitive data?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Are there clear, enforced rules for sharing sensitive data externally — approved channels and encryption requirements?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Vulnerability Management Operations
Are critical vulnerabilities patched within 14 days and high within 30 days?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is vulnerability scanning conducted at least monthly across all internet-facing and internal systems?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Security Monitoring & SOC
Is a SIEM or equivalent log aggregation and alerting platform in use covering all critical systems?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Does security monitoring cover endpoints, network, identity, and cloud — not just perimeter?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Phishing & Social Engineering Awareness
Do all staff complete phishing awareness training at least annually?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Are phishing simulations conducted at least quarterly to measure and improve staff resilience?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Endpoint Operations Security
Is endpoint patch compliance tracked — what percentage of endpoints are on the current OS and application versions?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is EDR health monitored — are all endpoints covered and all agents current?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Change Management Security
Does the change management process require security review for changes that affect security controls?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is there an emergency change process that maintains security review — even under time pressure?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Third-Party Operational Security
Is third-party access controlled — time-limited, least-privilege, and monitored?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is there a current inventory of all third parties with access to systems or data?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Physical Security & Clean Desk
Are physical access controls in place for server rooms, network infrastructure, and sensitive areas?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Is a clean desk policy enforced — no sensitive documents or credentials left visible?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Operational Security Culture
Do staff feel comfortable reporting security concerns or mistakes without fear of blame?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Do leaders visibly model security-positive behaviours — locking screens, using MFA, following clean desk policy?
(Required)
Not at all
Basic / Partial
Mostly
Fully
Menu