We turned our 45-point security audit checklist into an interactive scorecard — free, and it runs entirely in your browser. Nothing is uploaded, nothing is stored; the state lives in your own localStorage.
How it works
Tick every control that is verifiably true — the evidence rule applies even to yourself: screenshot or it did not happen. The scorecard computes:
- Six zone scores — identity & access (10), devices (7), network (6), data & backups (8), vendors & SaaS (8), incident readiness (6)
- A live total out of 45 with a percentage
- The zone-4 critical flag — if data & backups scores under 10 of 16, the zone turns red regardless of your total. An untested backup is the difference between a bad Tuesday and an extinction event
- A printable one-page summary to bring to whoever owns the fixes
The reading scale
- 80–90 (green): top band. Keep the twice-a-year cadence, batch the remaining hygiene.
- 55–79 (amber): normal. Sequence the unchecked items by zone order — identity first.
- Under 55 (red): the estate is running on luck. Don't buy tooling; close the identity and backup gaps — that's a week of focused work.
Why a scorecard and not just a list
Two reasons we built it:
- Checking is evidence. A list gets skimmed; a checkbox forces a yes/no, and "I think so" is a no.
- Zone shape beats total score. A team at 70% overall with a 30% backups zone is in far more danger than a team at 60% flat — the scorecard shows the shape, not just the number.
When you want the same 45 points walked by an outside pair and written into a report with owners and dates, that's the fixed-fee Small-Team Ops Audit (A$149, five days). If the 2am call is what worries you, the Custom Incident Runbook (A$249, 48h) is built from your actual stack. The full price map: what a security audit costs.
The scorecard: hive80-lab.github.io/ops-notes/security-audit-scorecard.html
Top comments (0)