NIS2 Quick Assessment Answer 18 quick questions to see where you stand. Current risk score 0 of 18 answered 0.0 /100 Low risk Governance & risk management Governance & risk management Policies, accountability, and how risk decisions get made. Not answered Has management formally approved an information security policy? NIS2 makes management bodies personally accountable for approving risk-management measures. Yes, approved and reviewed at least annually A policy exists but has never been formally approved No policy exists Not sure Is there a named person accountable for cybersecurity? A specific individual, not "IT in general". Yes, a dedicated security role (CISO or equivalent) Yes, but combined with other IT duties Handled entirely by an external provider Nobody is formally accountable Do you maintain a documented risk register? Identified risks, their owners, and treatment decisions. Yes, reviewed on a defined schedule An informal or outdated list exists No risk register Not sure Incident handling Incident handling Detection, response, and the 24-hour reporting obligation. Not answered Do you have a documented incident response plan? Roles, escalation paths, and communication steps written down in advance. Yes, and it has been tested in the last 12 months Documented but never tested No documented plan Not sure How would you detect a compromise today? Consider whether anyone is actually watching the alerts outside office hours. 24/7 monitored SOC or managed detection service Central log collection reviewed during business hours Antivirus alerts only We would most likely find out from a third party Could you file an early warning to the authorities within 24 hours of a significant incident? NIS2 requires an early warning within 24 hours and a full notification within 72 hours. Yes, the process and contacts are defined We know the obligation exists but have no process No, we would not meet that deadline Not sure Business continuity & backup Business continuity & backup Backups, recovery targets, and crisis management. Not answered How are your backups protected against ransomware? Backups reachable with normal admin credentials get encrypted along with everything else. Offline or immutable copies, separate credentials Cloud backups with the same admin credentials On-site only, always connected No reliable backups When did you last successfully restore from backup as a test? An untested backup is a hypothesis, not a control. Within the last 6 months Within the last year Never tested Not sure Are recovery time and recovery point objectives defined for critical systems? How much downtime and how much data loss the business has agreed it can absorb. Yes, agreed with the business and documented Informally understood but not documented Not defined Not sure Supply chain security Supply chain security Supplier risk, contracts, and third-party access. Not answered Do you maintain an inventory of suppliers with access to your systems or data? Including SaaS vendors and managed service providers. Yes, with a criticality rating per supplier A partial list exists No inventory Not sure Do supplier contracts include security requirements and breach notification duties? NIS2 pushes obligations down the supply chain to your vendors. Yes, in all critical supplier contracts In some contracts No security clauses Not sure How is third-party remote access to your network controlled? Vendor remote access is a recurring initial access vector. Time-limited, MFA-protected, and logged Standing VPN accounts with MFA Standing accounts, no MFA No third-party access / not sure Access control & cryptography Access control & cryptography Authentication, privilege management, and encryption. Not answered Is multi-factor authentication enforced on remote access and email? NIS2 Article 21(2)(j) explicitly names multi-factor authentication. Yes, on all accounts including administrators On some systems or some users only Not enforced Not sure How are administrator accounts managed? Shared admin passwords make attribution impossible after an incident. Separate named accounts, vaulted, access reviewed regularly Separate named accounts, no formal review Shared administrator credentials Not sure Is sensitive data encrypted at rest on laptops and servers? Full-disk encryption on endpoints, plus encryption for sensitive databases. Yes, enforced by policy and verified On some devices No encryption at rest Not sure Cyber hygiene & training Cyber hygiene & training Patching, vulnerability handling, and staff awareness. Not answered How quickly are critical security patches applied? Measured from vendor release to deployment on production systems. Within 14 days, tracked and reported Within a month, best effort Irregularly, when someone gets to it Not sure Do you run vulnerability scanning or penetration testing? Article 21(2)(e) covers vulnerability handling and disclosure. Regular scanning plus annual penetration testing Vulnerability scanning only Occasionally, no schedule Neither Do staff receive security awareness training? NIS2 requires training for management bodies specifically, not just staff. Yes, including management, with phishing simulations Staff only, management exempt Only at onboarding No training How can we reach you? How can we reach you? Our team reviews every assessment and follows up personally. Organisation * Your name * Email * Phone * Company size * Sector * Anything else we should know? Your answers and contact details go to our team, who will review them and get in touch. Your score is shown on screen as soon as you submit. I would also like to receive occasional emails about services and security guidance. (Optional) By submitting this assessment you agree to our Privacy Policy. Reference Get my assessment Scoring your answers…