DARINORCold Lab

Assessments / Cybersecurity Exposure Assessment

Cybersecurity Exposure Assessment

20 questions across detection signal, supply chain, identity, adversary validation, and incident response. Answer one at a time — step back whenever you want to change an earlier answer. Nothing is uploaded.

Detection Signal & Alert Fatigue1 / 20

You know the false-positive rate of your individual detection rules, not just an aggregate SOC-wide number.

// About this tool

Cybersecurity Exposure Assessment

This assessment scores a security program across five areas: detection signal and alert fatigue, supply chain and dependency risk, identity and access control, adversary validation and threat-informed defense, and incident response readiness. Each area maps to a maturity tier — Ad hoc, Developing, Managed, or Optimized.

Every question and every piece of advice traces back to a real, published incident or analysis — not a generic checklist. Sections that aren't yet Optimized get a recommendation grounded in the exact failure mode that's costing you points.

Everything runs locally in your browser. Nothing is uploaded, and your answers reset the moment you leave the page. Any section that isn't yet Optimized gets a written recommendation on the results screen, worst-scoring first.

// When to use it

  • Baseline a security program

    Walk through the questionnaire to see which of the five areas is dragging your overall exposure down before an incident finds it for you.

  • Prioritize a security backlog

    Use the per-section breakdown to decide whether detection tuning, supply chain hardening, identity, validation, or IR readiness is the highest-leverage next step.

  • Brief a team or leadership

    The overall score and tier give a quick, defensible summary of where a program stands, grounded in real incidents rather than abstract best practices.

// Questions

Is this a substitute for a real security audit?

No. It's a fast, self-reported baseline to find the biggest gaps and prioritize where to look next — not a replacement for a penetration test or formal audit.

Where does the advice on the results screen come from?

Each section's recommendation is grounded in specific published incidents and analyses — supply chain breaches, alert-fatigue case studies, threat-informed defense research — rather than generic best-practice text.

Is my data uploaded?

No. All scoring runs locally in your browser — nothing is sent to a server, and nothing persists after you close the tab.

What do the maturity tiers mean?

Ad hoc (0-24) means controls are largely absent. Developing (25-49) means some controls exist but are inconsistent. Managed (50-74) means controls are in place and mostly consistent. Optimized (75-100) means controls are consistently applied and verified.

This site uses minimal cookies and local storage to keep features like the chat widget and games working. We do not use third-party tracking cookies. Privacy Policy