All resources

Cybersecurity / Operational guide

Questions to start a cybersecurity assessment

A starting point that connects exposure, critical assets, visibility and response capability with business priorities.

For
Leadership, technology, security and risk owners.
Objective
Define an initial scope without turning the assessment into a brand inventory.
01

Understand what must be protected

Identify processes, information, identities and services whose compromise or unavailability would cause relevant impact.

  • Critical assets and services.
  • Users, third parties and privileged access.
  • Recent changes that altered exposure.
02

Review available visibility

Determine which events can be observed today, who reviews them and how a signal becomes an action.

  • Available logs and alerts.
  • Analysis, escalation and communication owners.
  • Evidence from prior exercises or incidents.
03

Agree on the assessment outcome

Define whether you need executive prioritization, technical validation, architecture design or an implementation roadmap.