The cyber security test worth running on your own organisation

A cyber security test, for a small organisation, should test the organisation rather than the quiz-taker: the phrase's search results fill with certification practice and trivia, while the tests that change outcomes are drills an owner can run this month without a vendor. Four self-tests cover the ground where real incidents decide themselves: the restore test, can the critical system actually come back from backup; the access test, do the leavers' accounts actually die; the procedure test, does the payment confirmation rule actually operate when a plausible request arrives; and the escalation test, does the after-hours alarm actually reach a human who acts. Beyond the four sits paid testing, vulnerability scans and penetration tests, with its own right timing. This guide gives the four drills in runnable form, the cadence that keeps them honest, and the point at which paying professionals to attack you becomes worth the fee.

The four drills, runnable this month

Restore: pick the system whose death stops work, restore it to a spare machine or sandbox from last week's backup, and time it; the finding is either confidence or a discovery worth any price. Access: list last year's leavers, then check every system's user export for them; findings are almost guaranteed on the first run. Procedure: with one trusted colleague, send a plausible internal payment-change request and watch whether the confirmation rule fires; brief the team afterwards, warmly, it is a drill, not a sting. Escalation: at a planned awkward hour, trigger the path that should page whoever responds, provider or person, and time the human's arrival. Each drill takes an hour or less; each tests a join where incidents actually turn.

Cadence, and reading the results

Quarterly for access and escalation, twice yearly for restore and procedure, rotated so something is tested most months. Results are read as deltas and dated: restore time versus last run, leaver findings trending toward zero, procedure drills passed without prompting. Failures are the product, a failed drill in private costs an hour, the same failure in an incident costs the quarter, so the drill log records failures without ceremony and fixes with dates. The drill log itself joins the evidence file the audit guides on this site describe: dated proof that the organisation tests itself, which insurers and client questionnaires increasingly ask for in exactly those words.

When to pay for testing

Paid testing enters in two steps. A scheduled vulnerability scan, cheap and monthly, belongs in every firm's kit once the four drills run; it finds the technical gaps the drills do not look for. A penetration test, humans paid to chain weaknesses into a real intrusion, is worth its fee when three conditions hold: the four drills pass routinely, the scan findings are triaged to near-zero, and a client, insurer or regulator will read the report, because a penetration test of an organisation that has not done the basics documents the obvious expensively. Sequence matters: drills, then scans, then the professionals. The written procedures the drills test come from the programme this site's product maintains, counted by the free sheet, generated and dated by Hardenvo Pro.

Questions people ask about cyber security test

How can a small organisation test its own cyber security?

Four drills: restore a critical system from backup and time it, check every platform's user lists for last year's leavers, run a consented payment-change drill against the confirmation rule, and trigger the after-hours escalation path once, planned. Each takes about an hour.

How often should security drills run?

Access and escalation quarterly, restore and procedure twice yearly, rotated so most months test something. Log results with dates and read deltas; a failed drill in private is the cheapest security finding that exists.

When is a penetration test worth it?

After the drills pass routinely and scan findings are triaged: paying professionals to document missing basics is expensive confirmation. It earns its fee when the basics hold and a client, insurer or regulator will read the report.

Sources

Related answers

Start Hardenvo ProGet Hardenvo Pro, $29 a month