SCARLET RISK

Free · No signup

The Risk Capability Map

Thirty-two capabilities that decide whether an SMB can answer a security question, survive an incident, and close an enterprise deal. Mark what you have. We will show you the gaps and what to do about each one.

Nothing is submitted. Your answers stay in this browser unless you choose to act on a recommendation.

Coverage

0% Limited coverage

0 of 32 capabilities marked

Risk capability categories

Cyber Risk

The security basics that decide whether an incident is an inconvenience or an existential event.

Not yet marked

  • A documented security baseline for laptops, accounts and email

    MFA coverage, endpoint protection, patching cadence and admin access written down rather than assumed.

    Status for: A documented security baseline for laptops, accounts and email
    SMB Cyber Health Check
  • A prioritized cyber checklist someone owns

    A single list of security controls with an owner and a status, instead of a scattered set of to-dos.

    Status for: A prioritized cyber checklist someone owns
    Cyber Risk module
  • Visibility into exposed credentials and breached accounts

    Knowing when company email addresses appear in third-party breaches, before attackers use them.

    Status for: Visibility into exposed credentials and breached accounts
    Breach Check
  • Basic phishing and security awareness for staff

    People are the most-targeted control. A light, recurring exercise beats an annual slide deck.

    Status for: Basic phishing and security awareness for staff
    Phishing Simulator

AI Governance

Employees and vendors adopt AI faster than policy catches up. This is where most SMB risk is currently accumulating.

Not yet marked

  • A written AI usage policy employees have seen

    What can and cannot be pasted into public AI tools, and who approves new ones.

    Status for: A written AI usage policy employees have seen
    Policy Generator
  • An inventory of the AI tools in use across the business

    Shadow AI is invisible until it is inventoried. Start with the tools people already pay for.

    Status for: An inventory of the AI tools in use across the business
    AI Governance module
  • A process for reviewing new AI features in existing vendors

    Vendors frequently enable AI processing by default. Someone should be reading those change notices.

    Status for: A process for reviewing new AI features in existing vendors
    Shadow AI Playbook
  • A current view of overall AI governance exposure

    A scored snapshot you can re-run as the business and its tooling change.

    Status for: A current view of overall AI governance exposure
    Risk Readiness Assessment

Vendor Risk

Most of your data lives in someone else's product. Vendor risk is your risk.

Not yet marked

  • A list of vendors that touch company or customer data

    Name, owner, what data they hold and how critical they are to operations.

    Status for: A list of vendors that touch company or customer data
    Vendor Risk
  • A repeatable vendor assessment for new suppliers

    One consistent set of questions, so decisions are comparable and defensible.

    Status for: A repeatable vendor assessment for new suppliers
    Vendor Risk Assessment Playbook
  • Ongoing monitoring of critical vendors

    Breach, outage and regulatory signals for the handful of vendors you cannot operate without.

    Status for: Ongoing monitoring of critical vendors
    Risk Intelligence
  • Shared understanding of third-party risk on the team

    The people signing up for tools should know what makes a vendor higher risk.

    Status for: Shared understanding of third-party risk on the team
    Vendor risk basics

Compliance

Knowing which obligations actually apply to you is cheaper than preparing for all of them.

Not yet marked

  • Clarity on which frameworks apply to your business

    SOC 2, HIPAA, CMMC, ISO 27001 and PCI-DSS do not all apply. Scope first, then build.

    Status for: Clarity on which frameworks apply to your business
    Scoping Calculator
  • A gap analysis against your target framework

    Current state versus required state, with the gaps ranked instead of listed alphabetically.

    Status for: A gap analysis against your target framework
    GRC & Compliance
  • A prepared answer set for customer security questionnaires

    Sales cycles stall on these. Reusable answers turn a week of work into an afternoon.

    Status for: A prepared answer set for customer security questionnaires
    SOC 2 Readiness Checklist
  • Plain-English understanding of your framework requirements

    What each framework really asks for, without a consultant translating it for you.

    Status for: Plain-English understanding of your framework requirements
    Framework guides

Incident Readiness

The value of a response plan is entirely determined by whether it exists before the incident.

Not yet marked

  • A written incident response plan

    Who decides, who calls whom, and what gets shut off first.

    Status for: A written incident response plan
    Incident Response playbooks
  • An up-to-date contact and escalation list

    Insurer, counsel, MSP, key vendors and internal decision-makers, reachable out of hours.

    Status for: An up-to-date contact and escalation list
    Incident Response playbooks
  • At least one walkthrough or tabletop in the last year

    A plan nobody has read out loud is a document, not a capability.

    Status for: At least one walkthrough or tabletop in the last year
    The preparedness gap
  • A reliable offboarding process for departing staff

    Lingering access is one of the most common causes of avoidable incidents.

    Status for: A reliable offboarding process for departing staff
    Offboarding Sweeper

Policies & Controls

Policies only reduce risk when they map to controls someone actually operates.

Not yet marked

  • A current, approved policy set

    Security, acceptable use, data handling, access control and vendor management at minimum.

    Status for: A current, approved policy set
    Policy Generator
  • Documented data-handling rules

    What data you hold, where it lives, who can see it and how long you keep it.

    Status for: Documented data-handling rules
    Compliance 101
  • A risk register that is reviewed, not just created

    Named risks, owners, treatment and a review date that has not already passed.

    Status for: A risk register that is reviewed, not just created
    Risk Register
  • Controls mapped to the frameworks you care about

    One control usually satisfies several requirements. Mapping avoids duplicated work.

    Status for: Controls mapped to the frameworks you care about
    GRC & Compliance

Executive Reporting

Risk work that cannot be shown to a board, a customer or an auditor tends to get defunded.

Not yet marked

  • A board- or owner-ready risk summary

    One page: what changed, what is exposed, what is being done about it.

    Status for: A board- or owner-ready risk summary
    Risk Intelligence Reports
  • Evidence stored somewhere durable and exportable

    Screenshots in a chat thread are not evidence. Attach it to the control it proves.

    Status for: Evidence stored somewhere durable and exportable
    GRC & Compliance
  • A tracked compliance or posture score over time

    A single trend line makes progress and regression visible without a meeting.

    Status for: A tracked compliance or posture score over time
    Platform overview
  • A recurring review cadence with an owner

    Monthly or quarterly, on a calendar, with a named person responsible.

    Status for: A recurring review cadence with an owner
    Intel Briefings

MSP Client Management

For MSPs, advisors and partners managing risk on behalf of multiple clients.

Not yet marked

  • Client-ready compliance reporting you can hand over

    A deliverable the client keeps, rather than a verbal update on a monthly call.

    Status for: Client-ready compliance reporting you can hand over
    MSP Hub
  • A repeatable way to scope and propose risk work

    Consistent scoping means consistent margin and fewer surprises mid-engagement.

    Status for: A repeatable way to scope and propose risk work
    MSP Hub
  • A consistent view of risk across your client base

    Comparable posture across clients, so attention goes where exposure is highest.

    Status for: A consistent view of risk across your client base
    Partner program
  • A plan for AI governance as a client service

    Clients are adopting AI now. Governance is the most requested new advisory line.

    Status for: A plan for AI governance as a client service
    MSP guide to AI agents

Do this today

Five-Minute Risk Fixes

Short, concrete actions that reduce real exposure today — no platform, no procurement, no consultant required.

  • Write down what staff may paste into AI tools

    Problem
    Employees are using public AI tools with company and customer data.
    Why it matters
    It is the fastest-growing source of unmanaged data exposure in small businesses.
    The fix
    Generate a one-page AI usage policy, name the approved tools, and send it round.
    Policy Generator
  • Check whether your team's credentials are already leaked

    Problem
    Company email addresses appear in third-party breaches without you knowing.
    Why it matters
    Reused passwords turn someone else's breach into your incident.
    The fix
    Run your domain through a breach check and force resets on any hit.
    Breach Check
  • List the five vendors that would hurt most

    Problem
    Vendor inventories are usually a billing export, not a risk view.
    Why it matters
    Concentration risk is invisible until the vendor has the outage.
    The fix
    Write down the five vendors you cannot operate without and who owns each.
    Vendor Risk

Want this maintained instead of remembered?

Scarlet Risk keeps the same map current — scored, evidenced and monitored — so the answer is ready before someone asks for it.