Quick check

Which stage is your weakest?

One question per stage. Answer honestly and in your head. Results appear instantly and nothing is stored or sent anywhere.

01 · ScopingWe have a written definition of which assets and business processes are in scope for exposure management.
02 · DiscoveryWe maintain an asset inventory that reconciles multiple sources (scanner, cloud, EDR, CMDB) and flags unknowns.
03 · PrioritisationExposures are ranked by exploitability in our environment and business impact, not by raw severity score.
04 · ValidationTop-priority exposures are validated as actually exploitable before remediation effort is committed.
05 · MobilisationEvery prioritised exposure has a named owner outside the security team and a target date.