Get a quick picture of your current security foundations and where you may need to focus next.

A few short questions to see where your startup or small business stands today, so you know what to prioritise next.
Answer based on what is true today, not what you plan to fix next.
Question 1

Is there a clear person who owns security and compliance decisions, even if it is only part of their job?

This does not need to be a full-time role or a hire. It just means someone is clearly accountable.

Question 2

If a customer, partner, or new hire asked for your security policies and documentation today, could you produce them?

Think about a customer security questionnaire or a new team member landing tomorrow.

Question 3

Is access to production infrastructure, the codebase, and admin panels protected by MFA and limited to people who need it?

Think about your cloud environment, your repository, and any internal admin tools.

Question 4

When someone leaves the team or changes role, is their access to production systems and customer data revoked promptly?

This includes staff, contractors, and any third parties with standing access.

Question 5

Do you know what customer data you collect, where it is stored, and who can access it?

Think about your data flows end to end, not just where the database lives.

Question 6

Are your APIs and third-party integrations reviewed for security before they go live?

Think about API design, authentication, and what access third-party tools and services hold.

Question 7

Do you know which of Cyber Essentials, ISO 27001, GDPR, the EU AI Act, or the EU Cyber Resilience Act actually apply to your product and market?

Most founders do not know this until a customer or regulator raises it.

Question 8

If asked, by a customer, an auditor, or as part of a certification process, could you evidence your compliance posture with real documentation?

A verbal answer is not the same as evidence a formal review will accept.

Question 9

If you had a data exposure or breach tomorrow, would you know your ICO notification obligations and what to tell your users and stakeholders?

You do not need a thick document. A short, usable plan is enough.

Question 10

Do you have logging and monitoring in place that would let you detect and investigate a security incident in your product?

Think about whether you would know something was wrong before a customer told you.

Book a Discovery Call.

30 minutes, no obligation. We will talk through where you are, what is coming up, and what would actually help at your stage.

Book a discovery call