Skip to main content

Free assessment · 24 questions · ~4 minutes

how mature is your IT, really?

Most IT problems are not technology failures — they are process gaps that only show up on a bad day. This scores eight areas the way an auditor would, tells you where you actually stand, and orders what to fix by risk rather than by noise.

Vendor neutral Nothing leaves your browser No sign-up
out of 100
Answer to begin
Your score appears as you go.
0 of 24 answered
By domain — weakest first

Domain scores appear once you start answering.

Fix in this order

    The priority list is ordered by risk-weighted gap, not by score alone.

    Want the full version? The complete assessment covers 60+ controls with evidence, and produces a scored report and a costed remediation roadmap.

    Book a full assessment →

    Method

    how this is scored

    Four levels, not a checklist

    Every question offers four maturity levels rather than yes/no, because almost nobody is a straight yes or no. "We have backups" and "we have tested that we can restore them" are different worlds, and only the second one helps on the day it matters.

    LevelMeansPoints
    1 · Ad hocNot in place, or depends on one person remembering0
    2 · PartialExists but inconsistent, undocumented or incomplete33
    3 · StandardConsistent, documented and applied across the estate67
    4 · MeasuredStandardised, monitored, reviewed and improving100

    Domains are weighted by consequence

    An overall average would let strong governance hide a missing backup. Each domain therefore carries a weight reflecting how badly its failure hurts: data protection and identity weigh most, because they are where incidents start and where recovery ends.

    Weights range from 0.90 to 1.30. They are an editorial judgement, stated openly so you can disagree with them — not a standard.

    Priorities are risk-weighted, not lowest-first

    The order to fix things is the gap to level 4 multiplied by the domain's weight. A middling score in data protection outranks a poor one in governance, because the consequences are not comparable.

    Bands

    0–30 Exposed — largely running on luck; a single common incident would be disruptive and possibly unrecoverable.

    31–55 Reactive — things work until they break, then people improvise. The most common band for organisations without dedicated IT.

    56–75 Managed — consistent and documented, mostly proactive. Gaps are known rather than discovered.

    76–100 Optimised — measured, reviewed and improving. Failures are contained rather than escalating.

    What this is not

    It is not an audit and not a compliance certificate. It is a structured self-assessment: the answers are yours, and it will faithfully reflect an over-generous one. A real assessment verifies evidence rather than taking the answer at face value.

    It is deliberately vendor-neutral. Nothing here depends on which firewall, hypervisor or cloud you run, because maturity does not.