Fifteen questions across five categories, requiring roughly four minutes. Results are calculated instantly on your device; no email address is required. Your risk profile is dictated by your lowest score, not your average.

Answer honestly. The value lies in the uncomfortable truths.

I. Access: Who can actually get in

The “Ghost” TestA departing employee’s account is disabled at 9:00 AM. By noon, is there a verifiable audit of peripheral systems they could still access?
The “MFA” Reality CheckIs Multi-Factor Authentication a hard-enforced identity perimeter across all users and devices, or do standing exceptions exist for executives who find it inconvenient?
The “BYOD” LiabilityWhen contractors or remote staff access company data on personal devices, is it sandboxed within a controlled environment, or does it land in a local Downloads folder next to their tax returns?

II. Visibility: What you can actually see

The “Shadow IT” RealityBeyond procured systems, how many unsanctioned SaaS apps (e.g., personal Dropbox, free Trello) is your team using?
The “Shadow AI & Upstream Risk” AuditHow much of your and your clients' proprietary data is feeding unmonitored AI models, whether through employee prompts, embedded SaaS features, or upstream MSP management agents? Do your employees know what behaviors void "zero-data retention" safeguards on pro-tier AI models?
The “Shared Password” RealityWhere do shared administrative credentials actually live? The bank login, the payroll portal, the registrar, the alarm code.

III. Continuity: What survives a bad day

The “Bus Factor” TestIf the single engineer who genuinely understands your environment was unreachable for two weeks, what breaks?
The “Restore” TestA backup that has never been restored is merely a receipt. When was the last time your team executed a full, documented restore of a critical workload?
The “Boring Failover” AuditYour core data might be highly available in the cloud, but what about physical chokepoints? If a laptop dies, the edge firewall fails, or the internet circuit drops, does work stop?

IV. Ownership: What you would keep

The “Sovereignty” ClauseIf you fired your IT provider or manager tomorrow, do you retain direct administrative ownership of your core IT management tools and documentation, or do they live on a proprietary platform and in someone’s memory?
The “Registrar” QuestionWho owns your domains? Who holds the master credentials and MFA tokens for your DNS registrar?
Portability: the “Cloud Exit Tax”If your primary cloud provider tripled its prices or was compromised, do you know what it would cost, in dollars and in weeks, to move away?

V. Proof: What you could demonstrate

The “Claim Denial” ScenarioHas anyone audited your actual deployed controls against the strict yes/no assertions made on your last cyber insurance application? Insurers verify after a claim, not before.
The “Forensic Trail” TestIf opposing counsel subpoenaed access logs for a specific client file from 14 months ago, could you produce them?
The “Which Standard” QuestionWhen an auditor asks how your cloud tenant or servers are secured, can you produce a conformance report against a published framework (e.g., CIS Benchmarks), or do you rely on a vendor’s claim of “best practices”?

0 of 15 answered

Your Sovereignty Check

Verdict: 24 to 30 · Sovereign

You own your estate. You could change providers on a Tuesday, be fully operational by Wednesday, and prove all of it to an auditor without a scramble. This is rare and intentional.

The work from here is maintenance and growth, not repair. The goal is keeping documentation current, ensuring secondary access keys remain valid, and building your infrastructure to meet new opportunities. Most firms reaching this score regress within eighteen months because nobody owns the configuration drift.

Verdict: 17 to 23 · Governed

You are well managed, but not yet sovereign. This score reveals one of two realities. Either you have a competent baseline with partial controls across the board, or you have a highly mature environment hiding a severe blind spot in a single category.

This is the most common and misleading score for professional firms. Nothing appears broken. Your exposure only surfaces the day you try to change vendors, survive a forensic audit, or recover from a localized failure.

Verdict: 9 to 16 · Dependent

Your IT functions through habit, not architecture. A score in this range points to a systemic lack of engineered controls. You rely on specific people rather than enforced systems, or on default vendor settings rather than deliberate policies. This succeeds until a key person vanishes, a vendor relationship ends, or an auditor demands proof of control.

The upside is that this gap is recoverable, and cheaper to close than to live with. The first step is rarely new technology. It is a strict inventory: what you own, who can access it, and where it lives.

Verdict: 0 to 8 · Exposed

You are carrying unpriced risk. Scoring this low means critical security, ownership, and recovery foundations are entirely missing. Whether the answers were “we do not know” or simply “we have not built this,” the exposure is identical.

This is not a judgment. It is likely the natural result of a business scaling faster than its IT infrastructure, which is how many estates arrive at our door. Address this now while it is a planned project, rather than later when it is an emergency.

Concierge CIO Partners is a Unified Guild of senior technologists providing dedicated, long-term fiduciary IT leadership to mid-market service firms. We are the alternative to a fragile internal IT silo, and to Managed Service Providers who advise you on what to buy and are paid on what you buy. We build inside the Microsoft or Google environments you already own, to published CIS benchmarks, with transparent unit pricing and zero markup. If we leave, your infrastructure stays.

Book a consultation