Skip to content
FioSec Consulting

3-minute roadmap

Where should you start?

You can’t fix everything at once. Tell us how covered you are across the seven layers of defence, two questions per layer, and we’ll put them in order, so you know what to tackle first for the biggest risk reduction. Nothing is sent anywhere: your answers are scored right here in your browser.

Roadmap questions

01 · Human

Do staff get security-awareness training more than once a year?
Are staff tested with simulated phishing campaigns?

02 · Devices

Do laptops and servers run endpoint detection & response (EDR), which detects and can stop an attack in progress, not just known malware?
Do you keep a current inventory of every device that connects to your systems?

03 · Network

Is your network protected by a firewall you actively manage, not just the default box from your internet provider?
Is your network segmented, so one compromised device can’t reach everything?

04 · Identity

Is multi-factor authentication (MFA) enforced on every account?
Are admin and privileged accounts separated from everyday logins and tightly controlled?

05 · Data

Are your backups immutable or air-gapped, so ransomware can’t encrypt or delete them?
Have you test-restored from backup recently, so you know recovery actually works?

06 · Monitoring

Are security logs from your key systems collected in one place (e.g. a SIEM)?
Is someone, in-house or a managed service, actually watching those logs and alerts?

07 · Response

Do you have a written incident response plan that names who does what?
Has that plan been tested with a tabletop exercise in the past year?

Fourteen questions. Answer “Partly” when something is true for only part of your environment; “Not sure” is a valid answer too. No email required; scored in your browser, never sent anywhere.

Already taken the Security Posture Check? Open the roadmap from your results page and these answers fill in automatically; the same fourteen questions drive both tools.