Skip to content

Free self-check / 15 questions

Security Reality Snapshot

What could you show evidence for today? Work through these questions to identify the records to request and the responsibilities to clarify.

This is a checklist you complete yourself. It does not access your systems, verify evidence or generate a security rating. No email is required, and there are no answers to submit.

How to use it

Read online or use your browser's Print menu to save a PDF or make a paper copy. Keep your answers in your own notes. For questions 3-15, choose:

  • Yes, with a record
  • Yes, but no record available
  • Partly
  • No
  • Not sure

Use “Not applicable” only where indicated. “Not sure” means there is something to clarify; it does not establish a failed control.

Go to the next-step guide when you have worked through the questions.

Part 1 of 3

Your decision and who owns it

Start with the decision ahead, then check who can provide the answers.

  1. What prompted this check?

    Provider renewal, an insurance or client request, AI adoption, a concern, or a general review.

    Your starting point: Write down the decision you need to make. A reason to review is context, not a security rating.

    Your note:

  2. When is your next relevant decision?

    Within 30 days, in 31-90 days, later, or no date yet.

    Your starting point: Use the date to decide when you need answers. A short deadline does not itself mean your controls are weak.

    Your note:

  3. Is a business owner named for security decisions?

    What to look for: Look for a named business role with authority to accept risk, approve priorities and resolve responsibilities with the provider.

    Your note:

  4. Is there a current list of important systems and their providers?

    What to look for: Ask for the inventory, who maintains it and when it was last checked. Include the services the business needs to keep operating.

    Your note:

  5. Are provider responsibilities and exclusions documented?

    What to look for: Compare the service agreement with a responsibility list. Look for who handles alerts, changes and incidents, including what is excluded.

    Your note:

Part 2 of 3

Access, approvals and payments

Check what people and providers can do, and which actions need another person to approve them.

  1. Can your provider show where multi-factor authentication is enforced and which accounts are exempt?

    What to look for: Ask for a current coverage record and the exception list, including administrator and remote-access accounts. Having MFA available does not establish that it is enforced.

    Your note:

  2. Is there a reviewed list of people and providers with administrator access?

    What to look for: Ask who has elevated access, why they need it and who last approved it. Include provider accounts as well as your own staff.

    Your note:

  3. Do important system changes require an identified approver?

    What to look for: Request the approval process and an example change record. Check who can authorize a change and who confirms its outcome.

    Your note:

  4. Are new or changed payment instructions independently verified using a known contact method?

    Choose not applicable if your organization does not make payments.

    What to look for: Look for a documented verification step using contact details already known to be genuine, and a record of that check. For a law firm, include wire and escrow instructions.

    Your note:

  5. Is someone responsible for removing access when people or providers leave?

    What to look for: Ask for the offboarding checklist and a completed example showing who confirmed removal. Include shared access, remote tools and connected applications.

    Your note:

Part 3 of 3

Recovery, response and new tools

Find out what happens when something goes wrong and how new ways of working are governed.

  1. Is there a recorded restore exercise for a business-critical system?

    What to look for: Ask for the last exercise date, the system restored, the outcome and who accepted the result against business recovery needs. A completed backup job does not establish that recovery was tested.

    Your note:

  2. Has your provider documented how backup copies are protected if a production administrator account is compromised?

    What to look for: Ask for an explanation of access separation and deletion protection, with supporting configuration records. Establish who can change those protections.

    Your note:

  3. Is someone explicitly responsible for responding to security alerts outside business hours?

    What to look for: Check the agreed coverage hours, escalation contacts and who can authorize containment. Receiving an alert and responding to it are different responsibilities.

    Your note:

  4. Does leadership have an incident contact and decision plan that has been exercised?

    What to look for: Look for current contacts, named decision makers and an exercise record. Check how the plan can be reached when normal systems are unavailable.

    Your note:

  5. If staff use AI tools or automations, are their permitted data, access and actions defined and reviewed?

    Choose not applicable if no AI tools or automations are used. Choose not sure if you do not know whether staff use them.

    What to look for: Ask which tools are approved, what information they may use, what actions they may take and which actions require human approval. A detailed AI security review would need a separately agreed scope.

    Your note:

Your next step

Turn your answers into three useful actions.

Yes, with a record
You report a practice with supporting records. Check that the records are current and cover the systems you rely on. We have not reviewed them.
Yes, but no record available
Ask the responsible person for the evidence described above. A missing record is a question to resolve.
Partly or no
Clarify what is missing, who owns it and what action is needed. Agree how completion will be checked.
Not sure
Find the person who can answer. If most answers are unknown, this checklist cannot establish your position.
Not applicable
Leave the item out of your action list and note why it does not apply. Revisit it if the business changes.
  1. Start with an explicit gap involving payments, administrator access or recovery. If you have not identified one, start with an unclear responsibility or missing record.
  2. Choose up to three actions. For each, name an owner, the record or change needed, and a date to check back.
  3. Use your decision date to set the pace. If the records are current and responsibilities are clear, agree when to review them again.

This is a starting order for a conversation, not a risk score or an independent assessment.

Need an independent view before a decision?

If several answers remain unresolved, The Security Reality Check can review the supporting records and clarify who needs to act. We agree the scope and fixed fee before work begins.

You do not need to send completed answers or confidential documents to start a conversation. See our privacy policy for hosting and correspondence handling.

Checklist version: 19 September 2026. securityrealitycheck.com/snapshot