Cybersecurity Readiness Assessment
Eight control areas that determine whether an incident becomes an inconvenience or an existential event. Answer as your organization operates today, not as policy says it should.
Multi-Factor Authentication
Stolen credentials are the most common way organizations get breached. MFA is the single highest-return control you can enforce.
- MFA is enforced on all email accounts.
- MFA is enforced on every administrator account.
- MFA is required for VPN and remote access.
- MFA is enabled on financial and critical SaaS applications.
- We use phishing-resistant methods (app or hardware key, not SMS).
- There are no standing MFA exceptions for executives or vendors.
Disclaimer
Nothing on this page or in any accompanying template, assessment, checklist, or report constitutes legal, financial, or compliance advice. These materials are general-purpose starting points drawn from professional experience. Review all information thoroughly against your own internal needs, company structure, contractual obligations, and regulatory environment, and have your legal counsel review anything you adopt before you rely on it.