01 · Free self-assessment
Where is your coverage actually thin?
Ten questions, about sixty seconds. Answer honestly and get an estimated coverage number for your stack. It runs entirely in your browser. Nothing you answer is sent to us or anyone else.
COVERAGE GAP SELF-CHECK · 0/10 ANSWERED~ 60 seconds · private, not sent anywhere
01
Do you aggregate logs from prod, cloud, and SaaS into one place?
02
Is there an EDR / endpoint agent on every workstation and server?
03
Are AWS/GCP/Azure CloudTrail + GuardDuty events normalized and monitored?
04
Are privileged role changes alerted within minutes?
05
Is MFA enforced everywhere - including break-glass?
06
Do you review third-party OAuth grants weekly?
07
Does someone triage CVEs within 72 hours of disclosure?
08
Do you have a tested incident-response runbook (not just a doc)?
09
Would an alert at 03:00 UTC on Sunday actually be seen?
10
Can you produce 90 days of audit evidence in under an hour?
ESTIMATED COVERAGE
0%
BLIND SPOT
100%of your attack surface is estimated uncovered
10 questions remaining
Answer honestly - the goal is a useful number, not a pretty one.
Answer honestly - the goal is a useful number, not a pretty one.
Secure Sleuths