ClearSecurity VISION
EN / RO

01 — Self-assessment

Where you stand on security, honestly.

20 questions, 8 areas, about 10 minutes. You answer on your own, no account — the score is calculated in your browser and goes nowhere without your consent.

What is this self-assessment?

01

What it measures

The basic practices that stop most incidents: who has access to what, whether tested backups exist, whether people recognise a trap email. No technical jargon — the questions are written for someone who runs the company, not for IT.

02

How it works

You answer 20 questions honestly, all on the same 0 to 3 scale. Honesty matters more than the grade: an admitted 0 is worth more than an optimistic 3. The score is calculated on the spot, in your browser.

03

What you get

A score for each of the 8 areas, so you can see at a glance where you are exposed — plus, if you want, the concrete first steps for your weak areas and a link with your analysis you can reopen anytime.

This is not an audit and does not replace an assessment by a specialist — it is an honest starting picture you take yourself, in about 10 minutes.

Interactive tool Security self-assessment 8 areas · 20 questions

How to answer — one scale, 0 to 3:

0

Doesn't exist

We don't have this.

1

On paper

A written rule or intention exists, but nobody applies it.

2

Inconsistent

It happens, but not everywhere and not always.

3

Applied & verified

Applied everywhere, and someone actually checks.

01 Asset and data inventory

Do you keep an up-to-date list of the equipment and software your company uses (laptops, servers, applications, cloud services)?

Do you know what important data you hold, where it is stored, and who can access it?

02 Access control (passwords & MFA)

Is there a clear password rule (length, uniqueness) that employees actually follow?

Do you use two-factor authentication (phone code or app) for email and important applications?

When an employee leaves, are their accounts closed immediately?

03 Security updates

Do computers and software receive security updates regularly, not "when we get to it"?

Does someone check that critical updates were actually installed, not just announced?

04 Backups and restore

Do you make regular backups of your important data?

Is at least one copy kept separate from the company network (another location or cloud), out of ransomware reach?

Have you ever tested that you can actually restore data from a backup?

05 Network and endpoint protection

Is your network protected by a firewall configured for you, not just the router "out of the box"?

Do all computers have active protection (antivirus/EDR) that someone monitors?

Is remote access (from home, from the field) done securely, for example through a VPN?

06 Incident response plan

Is there a written plan: who does what if tomorrow your files are encrypted or an account is hijacked?

Do employees know who to report an incident or a suspicious email to, immediately?

07 Employee training

Do employees get periodic security training (at least once a year)?

Have you ever tested their reaction in practice, for example with a phishing test?

08 Governance and accountability

Is there one person clearly responsible for security in the company, even part-time?

Does leadership discuss security risks periodically, not only after incidents?

Are security policies written down, known by employees, and reviewed periodically?

0 of 20 questions answered

Do you fall under NIS2? Then the self-assessment above is just the beginning — the law requires an assessment against the official CyberFundamentals framework, documentation and reporting deadlines. CERTO keeps your whole NIS2 file in one place.