Siberson
Partnership Contact Request a Demo
Resources · Free assessment

Corporate Data Risk Score

A two-minute, self-guided assessment of how well your organisation discovers, classifies, protects and monitors its sensitive data. Get an indicative maturity score, a breakdown by area, and a prioritised action plan you can download.

2 minutes No sign-up Nothing stored Downloadable report
Methodology

How the score is calculated

The tool is transparent by design — here is exactly what it measures and how the number is produced.

1 · Data Visibility & Discovery · 20%

Whether you know where sensitive data lives across endpoints, servers, cloud and email — including shadow and stale data.

2 · Classification & Labeling · 18%

Whether data is labeled by sensitivity, and whether that classification is automated and drives downstream controls.

3 · Data Loss Prevention · 22%

Whether you control sensitive data leaving through email, web/HTTPS, cloud, removable media, printing and GenAI tools.

4 · Insider Risk & Endpoint · 14%

Whether you can detect risky user actions on endpoints — including offline — and deter and evidence insider misuse.

5 · Integrity & Ransomware · 12%

Whether you monitor the integrity of critical files and configurations and would get an early warning on ransomware behaviour.

6 · Compliance & Governance · 14%

Whether you can evidence controls for KVKK, GDPR, PCI DSS and ISO 27001, and respond to data-subject and incident requests in time.

Each answer maps to a 0–100 maturity value. A dimension's score is the average of its answers; the overall score is the weighted average of the six dimensions using the weights above. Bands: 78–100 strong, 58–77 developing, 38–57 elevated, 0–37 critical. The result is indicative guidance, not an audit.

FAQ

About the assessment

Is this a binding audit?
No. It is a self-assessment intended to give you a quick, honest sense of where your data-security programme is strong and where it is exposed. It is not an audit, a certification or a legal assessment, and it creates no obligation. Treat the score as a conversation starter, not a compliance verdict.
Do you store my answers or contact details?
No. The assessment runs entirely in your browser and makes no network request. Your answers are held in memory only for the length of your visit and are never written to cookies or local storage, never sent to us, and never shared. The report you download is generated on your own device. We only hear from you if you choose to click through to contact us.
How is the score calculated?
Every answer carries a maturity value from 0 (highest risk) to 100. Each of the six dimensions is scored as the average of its questions, and the overall score is a weighted average across the dimensions — Data Loss Prevention and Discovery carry the most weight because they have the largest impact on real-world exposure. The full weighting is shown in the methodology section above.
What do I get at the end?
An overall score with a risk band, a radar and bar breakdown across the six dimensions, your lowest-scoring areas highlighted with specific recommendations, and a prioritised 0–30 / 30–90 day action plan. You can download the whole thing as a self-contained report or save it as a PDF.
Is it specific to Siberson products?
The questions are vendor-neutral — they describe capabilities every data-security programme needs, whatever tools you use. Where a weak area maps naturally to something Siberson does well, we point you to the relevant product, but the assessment is just as useful if you never talk to us.
Who is it for?
CISOs, DPOs, IT and security leaders, and anyone responsible for protecting sensitive data — in finance, public sector, defense, telecom, energy, healthcare or any regulated enterprise. It is deliberately quick enough to run in a meeting and shareable enough to send to a colleague.