// 11 questions · about 2 minutes

Who is watching your environment, and when?

Eleven short questions about how your organisation is run today. At the end you get the areas worth looking at first, in order — and we will say plainly if nothing needs our attention.

This is a self-assessment, not a security audit, and it does not replace a professional risk assessment.

Answer what is true today — “I don’t know” is a useful answer.
1. How many employees are in the organisation?
2. What is your role?
3. Who manages IT today?
4. Who actually monitors security activity?
5. Do you use Microsoft 365 / Entra ID?
6. Is there EDR / XDR on endpoints?
7. When a security alert arrives, who investigates it?
8. Have you completed a cyber risk assessment in the last 1–2 years?
9. Do you have an Incident Response Plan?
10. Do you hold personal or sensitive information about customers or employees?
11. What triggered this review now?
Last step — where should we send the conversation?

Submitting the questionnaire sends ITgalya your contact details together with the assessment context so we can follow up from the result you just generated.

Do not enter passwords, credentials, API keys, logs, incident evidence or other sensitive material.