AREA 01
Access & Identity Controls
Who has access to what — and whether your password and account policies are adequate to prevent unauthorised entry.
AREA 02
Email & Phishing Exposure
How vulnerable your team is to phishing attacks — the primary entry point in 85% of UK business breaches.
AREA 03
Data Storage & Backup
Where your critical data lives, how it’s backed up, and whether you could recover it if ransomware encrypted everything tonight.
AREA 04
Third-Party & Supplier Risk
The access your suppliers and partners have to your systems — and whether a breach at their end could reach you.
AREA 05
Staff Awareness & Behaviour
How well your team understands cyber risks and whether their day-to-day behaviour creates unnecessary exposure.
AREA 06
Incident Response Readiness
Whether you have a plan, whether anyone knows it, and whether you could execute it under pressure at 11pm on a Friday.
AREA 07
Regulatory & GDPR Obligations
Your obligations under UK GDPR and the ICO’s 72-hour notification requirement — and whether your processes meet them.
AREA 08
Device & Network Security
The security of the devices your team uses and the networks they connect to — including remote working arrangements.