Free · No signup
The Risk Capability Map
Thirty-two capabilities that decide whether an SMB can answer a security question, survive an incident, and close an enterprise deal. Mark what you have. We will show you the gaps and what to do about each one.
Nothing is submitted. Your answers stay in this browser unless you choose to act on a recommendation.
Coverage
0% Limited coverage
Risk capability categories
Cyber Risk
The security basics that decide whether an incident is an inconvenience or an existential event.
Not yet marked
A documented security baseline for laptops, accounts and email
MFA coverage, endpoint protection, patching cadence and admin access written down rather than assumed.
SMB Cyber Health CheckA prioritized cyber checklist someone owns
A single list of security controls with an owner and a status, instead of a scattered set of to-dos.
Cyber Risk moduleVisibility into exposed credentials and breached accounts
Knowing when company email addresses appear in third-party breaches, before attackers use them.
Breach CheckBasic phishing and security awareness for staff
People are the most-targeted control. A light, recurring exercise beats an annual slide deck.
Phishing Simulator
AI Governance
Employees and vendors adopt AI faster than policy catches up. This is where most SMB risk is currently accumulating.
Not yet marked
A written AI usage policy employees have seen
What can and cannot be pasted into public AI tools, and who approves new ones.
Policy GeneratorAn inventory of the AI tools in use across the business
Shadow AI is invisible until it is inventoried. Start with the tools people already pay for.
AI Governance moduleA process for reviewing new AI features in existing vendors
Vendors frequently enable AI processing by default. Someone should be reading those change notices.
Shadow AI PlaybookA current view of overall AI governance exposure
A scored snapshot you can re-run as the business and its tooling change.
Risk Readiness Assessment
Vendor Risk
Most of your data lives in someone else's product. Vendor risk is your risk.
Not yet marked
A list of vendors that touch company or customer data
Name, owner, what data they hold and how critical they are to operations.
Vendor RiskA repeatable vendor assessment for new suppliers
One consistent set of questions, so decisions are comparable and defensible.
Vendor Risk Assessment PlaybookOngoing monitoring of critical vendors
Breach, outage and regulatory signals for the handful of vendors you cannot operate without.
Risk IntelligenceShared understanding of third-party risk on the team
The people signing up for tools should know what makes a vendor higher risk.
Vendor risk basics
Compliance
Knowing which obligations actually apply to you is cheaper than preparing for all of them.
Not yet marked
Clarity on which frameworks apply to your business
SOC 2, HIPAA, CMMC, ISO 27001 and PCI-DSS do not all apply. Scope first, then build.
Scoping CalculatorA gap analysis against your target framework
Current state versus required state, with the gaps ranked instead of listed alphabetically.
GRC & ComplianceA prepared answer set for customer security questionnaires
Sales cycles stall on these. Reusable answers turn a week of work into an afternoon.
SOC 2 Readiness ChecklistPlain-English understanding of your framework requirements
What each framework really asks for, without a consultant translating it for you.
Framework guides
Incident Readiness
The value of a response plan is entirely determined by whether it exists before the incident.
Not yet marked
A written incident response plan
Who decides, who calls whom, and what gets shut off first.
Incident Response playbooksAn up-to-date contact and escalation list
Insurer, counsel, MSP, key vendors and internal decision-makers, reachable out of hours.
Incident Response playbooksAt least one walkthrough or tabletop in the last year
A plan nobody has read out loud is a document, not a capability.
The preparedness gapA reliable offboarding process for departing staff
Lingering access is one of the most common causes of avoidable incidents.
Offboarding Sweeper
Policies & Controls
Policies only reduce risk when they map to controls someone actually operates.
Not yet marked
A current, approved policy set
Security, acceptable use, data handling, access control and vendor management at minimum.
Policy GeneratorDocumented data-handling rules
What data you hold, where it lives, who can see it and how long you keep it.
Compliance 101A risk register that is reviewed, not just created
Named risks, owners, treatment and a review date that has not already passed.
Risk RegisterControls mapped to the frameworks you care about
One control usually satisfies several requirements. Mapping avoids duplicated work.
GRC & Compliance
Executive Reporting
Risk work that cannot be shown to a board, a customer or an auditor tends to get defunded.
Not yet marked
A board- or owner-ready risk summary
One page: what changed, what is exposed, what is being done about it.
Risk Intelligence ReportsEvidence stored somewhere durable and exportable
Screenshots in a chat thread are not evidence. Attach it to the control it proves.
GRC & ComplianceA tracked compliance or posture score over time
A single trend line makes progress and regression visible without a meeting.
Platform overviewA recurring review cadence with an owner
Monthly or quarterly, on a calendar, with a named person responsible.
Intel Briefings
MSP Client Management
For MSPs, advisors and partners managing risk on behalf of multiple clients.
Not yet marked
Client-ready compliance reporting you can hand over
A deliverable the client keeps, rather than a verbal update on a monthly call.
MSP HubA repeatable way to scope and propose risk work
Consistent scoping means consistent margin and fewer surprises mid-engagement.
MSP HubA consistent view of risk across your client base
Comparable posture across clients, so attention goes where exposure is highest.
Partner programA plan for AI governance as a client service
Clients are adopting AI now. Governance is the most requested new advisory line.
MSP guide to AI agents
Do this today
Five-Minute Risk Fixes
Short, concrete actions that reduce real exposure today — no platform, no procurement, no consultant required.
Write down what staff may paste into AI tools
- Problem
- Employees are using public AI tools with company and customer data.
- Why it matters
- It is the fastest-growing source of unmanaged data exposure in small businesses.
- The fix
- Generate a one-page AI usage policy, name the approved tools, and send it round.
Check whether your team's credentials are already leaked
- Problem
- Company email addresses appear in third-party breaches without you knowing.
- Why it matters
- Reused passwords turn someone else's breach into your incident.
- The fix
- Run your domain through a breach check and force resets on any hit.
List the five vendors that would hurt most
- Problem
- Vendor inventories are usually a billing export, not a risk view.
- Why it matters
- Concentration risk is invisible until the vendor has the outage.
- The fix
- Write down the five vendors you cannot operate without and who owns each.
Want this maintained instead of remembered?
Scarlet Risk keeps the same map current — scored, evidenced and monitored — so the answer is ready before someone asks for it.
