Is your IT actually handled?
In five minutes you will know the three things most likely to stop your organization for a week, and whether whoever handles your IT has them covered. Ten questions, plain English, nothing to install. At the end you choose: work the list yourself, or hand it to us.
Or call 612-656-4162. A person answers, and it is a real conversation, not a script.
Answer what is true today
Point values are hidden while you answer, on purpose. Tap the on any question to see why it matters.
"I am not sure" is a real answer and it scores zero. Not because you are being marked down for it, but because an area nobody can confirm is an area nobody is defending. We report those separately from the things you told us are weak, because the two need different conversations. Guessing is the one thing that makes this useless.
IT Posture Snapshot
What this means for your organization
How the score is banded
Where your score sits
Four zones, 0 to 100Have IT Audit Labs handle it
Send us your result and we will start with your weakest areas. You get back what we would fix first, in what order, and what it takes. We work alongside whoever supports your IT today rather than around them.
No obligation, and no proposal unless you ask for one.
Take the list and go
Everything below is yours to use: what the gap is at each answer, what to do about it, the published guidance behind every question, and three questions to put to whoever handles your IT on Monday.
Show me what to fix firstNothing here is gated, and nothing reaches us unless you send it.
See the full scoring detail, all ten areas
The ten areas, weakest first
Bar length is the share of available points you earned. Start at the top and work down.
| Area | Your answer | Status | Points | Max |
|---|---|---|---|---|
| Total | 0 | 100 | ||
Three questions to ask on Monday
Whatever you scored. Ask them exactly like this, and listen to how long the pause is.
Show me the last successful test restore.
Not the backup log, which only proves a copy was made. Ask to see the day someone pulled data back and confirmed it worked. If they describe the backup instead of the restore, you have your answer.
What is on our network that the manufacturer no longer supports?
Firewalls, VPN appliances, switches, servers: gear that still works but no longer gets security updates. End-of-life equipment never gets a patch, no matter how fast your patching process is.
Walk me through the first hour if this happens at 2am on a Saturday.
Who gets paged, who can unplug things, who calls the insurer, who calls customers. If the plan is "someone notices Monday," the weekend belongs to the attacker.
One question for the leadership team
"For each of the ten areas above, who is accountable by name, and who is watching at 2am when the person or the provider who covers it is asleep?"
If you already pay someone for IT, this list is not a verdict on them. Most agreements do not include half of these, and most buyers never asked which half. The useful question is not whether your provider is good. It is which of these ten they consider in scope today, which are out of scope, and what each out-of-scope item would take to add.
The detail, if and when you want it
Closed by default. Open any area for the gap at your answer, what to do about it, and the published guidance behind the question. This is the part to forward to whoever handles your IT.
Have IT Audit Labs handle it
Most leaders who take this do not want a project plan. They want it off their desk. Send your result and we will start with your weakest areas, tell you what we would do first, and be straight about what you can fix yourself for nothing.
- A person replies, not a sequence
- We work with your current provider
- No obligation, no proposal unless you ask
Or call 612-656-4162.
Prepared with the IT Posture Snapshot by IT Audit Labs. itauditlabs.com · hello@itauditlabs.com · 612-656-4162
To have any of the above handled, or to get the detail behind it, call or write. There is no cost to ask and no obligation. Retake the assessment any time at itsurvey.itauditlabs.com
Where these questions came from
Every question maps to published guidance and to episodes of the two IT Audit Labs podcasts. The Audit goes deep with practitioners. SipCyber explains the same risks without the jargon, which is usually the better place to start if IT is not your job.
Standards and published guidance
The frameworks and advisories these ten questions are drawn from.
The Audit podcast
The technical show, for when you want the practitioner view. New episodes at theaudit.itauditlabs.com.
SipCyber
Plain language, no jargon, hosted by Jen Lotze. Start here if you do not work in IT. Full show at itauditlabs.com.