Digital Risk Readiness Scorecard
Draft copy — questions and report copy need Nathan's approvalTen questions about decisions you already own
For Owners and executives at companies with real technology risk and no full-time technology staff
This is a snapshot of decisions, not a security audit. It cannot see your network, and it does not need to — the failures that cost small companies the most are usually decisions nobody made rather than controls nobody bought.
The questions
Your result
Tier
—
The full report
The full report adds the category breakdown, what your tier means, and the three things worth doing first. Email it to yourself and you will have it when you need it in a meeting.
Report
Result
—
Most of this has not been decided yet. At your size that is ordinary rather than negligent, and it is the cheapest position to improve from, because you are still making decisions rather than unpicking systems. The order matters more than the speed.
Where to start
- Pick the one system whose loss would stop revenue, and restore it against a clock this quarter. The elapsed time is your recovery plan; everything before it was a purchase.
- Write down who can change where money goes, and require a second confirmation from someone who knows the vendor.
- Name the person who can take a system offline on a Saturday, and name their backup.
The decisions exist. What is missing is evidence that they hold when someone is tired, on a weekend, or being rushed by a convincing email. Testing is unglamorous and it is where the remaining risk is concentrated.
Where to start
- Time a restore end to end and write down what was missing. Then put the next test on the calendar before the current one has cooled off.
- Take your three most connected vendors and ask each how fast they will tell you if they are breached. Keep the answers.
- Run one thirty-minute tabletop on a Saturday-morning scenario. The output is a list of decisions nobody had made yet.
This works when the right people are paying attention. The remaining exposure is dependence on specific individuals and on memory. Turning what you already do into something that happens without being remembered is the last expensive step.
Where to start
- Move recovery testing and access review onto a schedule with a named owner, so neither depends on anyone remembering.
- Write down what an outside AI tool may never receive, and tell the people who would otherwise have to guess.
- Identify the one task only one person can do, and have someone else do it once while they watch.
The basics are habits rather than projects. The useful work now is at the edges: the vendor you inherited, the system nobody owns, and the assumption that has not been revisited since it was made. Spend attention where nobody is looking.
Where to start
- Audit the assumptions you have not revisited in two years, starting with the vendor you inherited rather than chose.
- Have someone outside the team attempt the recovery, using only the written plan.
- Decide what you would do differently if the answer to a question here changed for the worse, and who would tell you.
By category
Weight ×2
Weight ×3
Weight ×2
Weight ×2
Weight ×1
The same scores as a table
| Category | Weight | Points | Score |
|---|---|---|---|
| Access control | ×2 | — | — |
| Backup and recovery | ×3 | — | — |
| Vendor risk | ×2 | — | — |
| Incident response | ×2 | — | — |
| AI governance | ×1 | — | — |
What this is, and is not
This is a snapshot of decisions, not a security audit. It cannot see your network, and it does not need to — the failures that cost small companies the most are usually decisions nobody made rather than controls nobody bought.
Next steps
Related