Nathan Whittacre Check availability

Digital Risk Readiness Scorecard

Draft copy — questions and report copy need Nathan's approval

Ten questions about decisions you already own

For Owners and executives at companies with real technology risk and no full-time technology staff

This is a snapshot of decisions, not a security audit. It cannot see your network, and it does not need to — the failures that cost small companies the most are usually decisions nobody made rather than controls nobody bought.

Answers stay in this browser tab. The score is calculated here, not on a server, and no result is sent anywhere unless you ask for the report by email.

The questions

0 of 10 answered

Question 1 Who can change where your company sends money?

Payroll accounts, vendor bank details, wire instructions.

Question 2 When someone leaves, how long until their access is actually gone?
Question 3 How many months since someone restored a system from backup and did real work in it?

Not since the backup reported success — since a person opened the restored system and used it. Enter 999 if it has never happened.

Question 4 What does your recovery plan actually cover?
Question 5 Do you know which vendors could reach your data if their own systems were breached?
Question 6 Which of these have you asked a vendor for in the last year?

Select every one that applies.

Question 7 If a system broke at 6am on a Saturday, who decides whether to take it offline?
Question 8 Within an hour, your team could tell you which systems were affected and which were not.
Question 9 Is there a written answer to what staff may paste into an outside AI tool?
Question 10 Which of these has your leadership team actually decided about AI?

Related