The security maturity check in 3 minutes

The check assesses four domains that decide detection and response in practice: central monitoring, endpoint security, incident response and governance. You receive a score from 0 to 100, a maturity level and one concrete next action per domain.

Your answers stay in your browser. We store nothing and set no cookie for this.

Question 1 of 10Are security-relevant logs collected and analysed centrally?
Question 2 of 10How is the coverage of your detection rules documented?
Question 3 of 10Who reviews alerts outside business hours?
Question 4 of 10What protection runs on your endpoints?
Question 5 of 10Can compromised systems be isolated at short notice?
Question 6 of 10Do you have a documented incident response plan?
Question 7 of 10Are forensic capabilities contractually secured?
Question 8 of 10How quickly could you act during a ransomware incident?
Question 9 of 10Is your security level aligned to a standard (ISO 27001, BSI, NIS2)?
Question 10 of 10Are vulnerabilities captured regularly and remediated by priority?

Recommended next steps

Monitoring & SIEM

Build monitoring: onboard central log sources, develop use cases along your risks and secure 24x7 analysis.

Sharpen monitoring: measure detection coverage against MITRE ATT&CK, cut false positives and close use-case gaps.

SIEM (monitoring) · SIEM consulting / use cases

Endpoint & EDR

Create the endpoint baseline: roll out EDR and put it into operation — detection without operations has no effect.

Optimise endpoint: use response actions, allow-listing and audit trails consistently.

EDR management · EDR operations & response

Incident response

Secure response capability: write the incident response plan, define escalation and contract forensic capacity.

Rehearse response: tabletop exercises, containment automation and regular compromise assessments.

Incident response · Compromise assessment

Governance, NIS2 & ISO 27001

Close the governance gap: gap analysis against ISO 27001 or NIS2 plus solid vulnerability management.

Strengthen evidence: continuous vulnerability management with SLA, reporting and awareness campaigns.

Vulnerability management · Consulting

Frequently asked questions

Answers about the security maturity check.

What does the security check cost?
Nothing. It runs entirely in your browser, at no cost and with no obligation.
Do I have to provide my e-mail address?
No. The result appears immediately. Only if you want to discuss it does a button take you to the contact form.
Are my answers stored?
No. Scoring happens locally in your browser; no answers are transmitted and no cookie is set.
How reliable is the result?
It is a self-assessment and gives first orientation. For a reliable rating we run an assessment covering logs, configuration and processes.
What happens after the check?
On request we walk through the result in a short call and prioritise the measures together.

Your question is not listed? Ask us