Local session · no data sent

Cyber readiness for organizations that serve people

Protect the mission.
Prioritize the next move.

A plain-language readiness assessment that converts twelve security conversations into a practical 30–60–90 day roadmap—designed for nonprofits, clinics, mutual-aid groups, houses of worship, and other small community organizations.

Built around six outcomes

Security that supports service.

The assessment organizes practical questions across the six NIST Cybersecurity Framework 2.0 Functions. It is an educational starting point, not a certification or compliance score.

GO

Govern

Set responsibility, policy, and risk decisions.

ID

Identify

Know the services, data, people, and technology that matter.

PR

Protect

Reduce the likelihood and impact of compromise.

DE

Detect

Notice meaningful activity early enough to act.

RE

Respond

Coordinate decisions, evidence, and communication.

RE

Recover

Restore trusted services and learn from disruption.

Guided readiness review

Twelve useful conversations.

0/12answered

No organization name, email, systems, or sensitive details are requested.

GO

Govern

Set responsibility, policy, and risk decisions.

0%
Govern 1

A named leader owns cybersecurity risk and reports important decisions to leadership.

Without accountable ownership, urgent work becomes everybody’s concern and nobody’s job.

Current maturity
Govern 2

Technology vendors are reviewed for security, access, data handling, incident notice, and offboarding.

Small organizations often inherit risk through cloud, payment, case-management, and fundraising providers.

Current maturity
ID

Identify

Know the services, data, people, and technology that matter.

0%
Identify 1

The organization maintains a usable inventory of accounts, devices, software, cloud services, and owners.

You cannot protect, remove, or investigate technology that no one knows exists.

Current maturity
Identify 2

Sensitive data and mission-critical services are mapped to where they live, who can access them, and how long they are kept.

Priorities become clearer when technology is connected to people, services, and legal or contractual duties.

Current maturity
PR

Protect

Reduce the likelihood and impact of compromise.

0%
Protect 1

Multi-factor authentication is required for email, administrators, remote access, finance, and other high-impact accounts.

A stolen password should not be enough to take over the organization’s most powerful accounts.

Current maturity
Protect 2

Supported software and devices receive security updates on a defined schedule, with faster action for urgent flaws.

Known vulnerabilities are routinely exploited when ownership and deadlines are unclear.

Current maturity
DE

Detect

Notice meaningful activity early enough to act.

0%
Detect 1

High-value services produce useful login, administrator, endpoint, and security alerts that someone actually reviews.

Logs have little value if retention is too short, clocks disagree, or no one receives an alert.

Current maturity
Detect 2

Staff and volunteers know a simple, practiced way to report suspicious messages, account activity, lost devices, or mistakes.

People often see the first sign of an incident before any security tool does.

Current maturity
RE

Respond

Coordinate decisions, evidence, and communication.

0%
Respond 1

A short incident plan names decision-makers, technical help, legal or insurance contacts, evidence steps, and communication roles.

A contact list and decision structure are more useful during a crisis than a long generic policy.

Current maturity
Respond 2

Leadership and technical partners have practiced at least one realistic cyber incident together in the last year.

Exercises expose missing access, assumptions, and authority while mistakes are still inexpensive.

Current maturity
RE

Recover

Restore trusted services and learn from disruption.

0%
Recover 1

Critical data has protected backups separated from normal administrator access, with documented retention and ownership.

A backup reachable through the same identity or network may fail with the production system.

Current maturity
Recover 2

The organization has restored critical data or services from backup and recorded the time, gaps, and recovery sequence.

A successful backup job is not evidence that people can restore a trusted service under pressure.

Current maturity
12 answers remaining

Choose the closest honest answer. This is a planning conversation, not a grade.

Designed for constrained teams

Good security can be right-sized.

$

Budget-aware

Prioritize ownership, settings, contacts, and tests before buying another dashboard.

Mission-aware

Connect controls to client safety, community trust, and the services people depend on.

Evidence-aware

Call a practice mature only when it is documented, exercised, and producing useful evidence.

Official starting points

Take the plan further.

MissionReady Cyber is educational and does not provide a NIST assessment, audit, certification, legal opinion, or guarantee of security.

NISTSmall Business Quick-Start GuidesOpen resource ↗CISASmall and Medium-Sized Business ResourcesOpen resource ↗