Sentinel Vault
Cyber Checkup

Cybersecurity Culture Self-Check

Rate how well each statement describes your organization. You’ll get an overall culture score plus a breakdown across three pillars — Leadership & Culture, Human Readiness, and Technical Basics — with the specific things to fix first. Takes about three minutes.

For each statement, choose how well it describes your organization. 1 = Strongly disagree · 5 = Strongly agree.

Leadership & Culture

Our leadership talks about cybersecurity in terms of specific risks to the business, not as a generic IT concern.

Employees can report a mistake (clicking a bad link, sharing credentials, sending to the wrong person) without fear of blame or punishment.

Our written cybersecurity policies are current, easy to find, and understood by the people they apply to.

Our leaders visibly model the security behavior they expect from others, using MFA, verifying requests, and reporting issues openly.

We know which outside vendors and partners can reach our systems or data, and we hold them to clear security expectations before and during the relationship.

Human Readiness (AI-era)

Any request that moves money, grants access, or changes payment details is verified on a pre-established channel (a known phone number, in-person, or a separate secure system), not just through the channel the request came in on.

Our people get short, frequent security practice throughout the year, not a single annual training module.

We have clear guidance on what employees may and may not paste into public AI tools (ChatGPT, Claude, Gemini, etc.), and the rules are understood.

If a stranger called our IT or help desk today claiming to be a senior executive and asked for a password reset, we have a process that would catch it.

Our people are alert to scams that arrive by text, QR code, or phone, not just email, and they know to slow down and check when a message pressures them to act fast.

Technical Basics

Multi-factor authentication is required on every system holding money, customer data, or administrative access, with no exceptions.

We have successfully restored critical data from backup within the last 12 months.

Access to sensitive systems is limited to the people who need it, and it is removed promptly when roles change or people leave.

We have a documented incident response plan, and at least one person has actually read it in the last year.

Operating systems, software, and network equipment are kept up to date, and important security patches are applied promptly rather than left for months.

0/15 answered