Cyber Risk Gap Assessment
Company Name
*
Date Completed
*
-
Month
-
Day
Year
Name
*
First Name
Last Name
Email
*
example@example.com
Phone Number
*
Please enter a valid phone number.
1. Is cyber security discussed at a management / board level?
Yes
No
Not Sure
If no, please provide any equivalent actions:
2. Do you currently have cyber insurance?
Yes
No
Not Sure
3. Do you have an internal person and/or external company who is responsible for your organization's cyber security?
Yes
No
Not Sure
4. Do you have a process to audit 3rd parties for their cybersecurity resilience before sharing confidential information?
Yes
No
Not Sure
If no, please provide any equivalent actions:
5. Do you have an inventory of all devices / phones / computers and details of what confidential information each holds related to our business?
Yes
No
Not Sure
If no, please provide any equivalent actions:
6. Do you have encryption enabled on all devices and a policy to ensure that all new devices have encryption enabled by default?
Yes
No
Not Sure
If no, please provide any equivalent actions:
7. Do you centralize management and configuration of all computers?
Yes
No
Not Sure
If no, please provide any equivalent actions:
8. Do you monitor network traffic for abnormal activity?
Yes
No
Not Sure
If no, please provide any equivalent actions:
9. Do you store access and activity logs for firewalls, servers, workstations and any other network connected devices to investigate a breach should one occur?
Yes
No
Not Sure
If no, please provide any equivalent actions:
10. Have you performed a penetration test in the past 18 months?
Yes
No
Not Sure
If no, please provide any equivalent actions:
11. Do you have any intrusion detection/prevention systems in place?
Yes
No
Not Sure
If no, please provide any equivalent actions:
12. Do you have an internal or external provider regularly applying software patches/system updates?
Yes
No
Not Sure
If no, please provide any equivalent actions:
13. Do you use a Password Manager?
Yes
No
Not Sure
If no, please provide any equivalent actions:
14. Do you have a Password Policy and Procedure in place?
Yes
No
Not Sure
If no, please provide any equivalent actions:
15. Do you enforce two-factor authentication on applications that have access to sensitive information?
Yes
No
Not Sure
If no, please provide any equivalent actions:
16. Do you have SPAM and anti-virus filtering enabled for inbound email?
Yes
No
Not Sure
If no, please provide any equivalent actions:
17. Do you have an acceptable use polices that includes the usage of Company email and internet?
Yes
No
Not Sure
If no, please provide any equivalent actions:
18. Do you have an active next generation anti-virus/malware service?
Yes
No
Not Sure
If no, please provide any equivalent actions:
19. Do your staff complete Cyber Security Awareness/Phishing Training regularly throughout the year (at least quarterly)?
Yes
No
Not Sure
If no, please provide any equivalent actions:
20. Do you have a VPN setup for staff to connect to the office remotely?
Yes
No
Not Sure
If no, please provide any equivalent actions:
21. Do you perform regular backups of computers and servers?
Yes
No
Not Sure
If no, please provide any equivalent actions:
22. Are your backups segregated from network to protect against a ransomware attack?
Yes
No
Not Sure
If no, please provide any equivalent actions:
23. Do you use removable media regularly?
Yes
No
Not Sure
24. Does your organization perform a formal annual risk assessment?
Yes
No
Not Sure
25. Have you specifically investigated your legal risk, related to a cyber security event?
Yes
No
Not Sure
26. Have you specifically investigated your regulatory obligations with relation to cyber security?
Yes
No
Not Sure
27. Do you have a basic plan of action (incident response plan) that outlines roles and responsibilities should you experience a cyber incident?
Yes
No
Not Sure
If no, please provide any equivalent actions:
Thanks for completing Black Bottle IT's Cyber Security questionnaire. Your score is {calculation}
If no, please provide any equivalent actions:
Submit
Should be Empty: