Back to the library
Diagnostic previewIntermediate

Cybersecurity Diagnostic

Assesses identity management, vulnerability management, incident response and data protection.

69-110 min
137 questions
21 domains

A preview of the first questions

Click an answer to see what a Kaliteq assessment feels like. Nothing is ever saved here.

1

Les règles de votre/vos pare-feu font-elles l'objet d'une revue périodique pour supprimer les règles obsolètes ou trop permissives ?

2

Quel niveau de contrôle appliquez-vous sur les connexions VPN de vos collaborateurs et prestataires ?

3

Les services exposés sur Internet (site web, API, messagerie) sont-ils isolés du réseau interne via une zone démilitarisée (DMZ) ?

4

Votre réseau Wi-Fi professionnel est-il isolé du réseau Wi-Fi invité et sécurisé par une authentification forte ?

Another 133 questions await you

This is only a preview of the diagnostic

Continue to discover all the questions and get your personalized analysis.

Start my free trial
Over 137+ questions
AI-assisted analysis
Personalized recommendations
Full report
Risk matrix
Smart Hub
Data Room
7-day trial

15+ diagnostics available · 1000+ maturity questions · AI built in

What is the Cybersecurity Diagnostic ?

Assesses identity management, vulnerability management, incident response and data protection.

Objective : Évaluer le niveau de maturité cybersécurité de mon organisation.

A cybersecurity diagnostic assesses an organization's overall security posture, beyond purely technical vulnerabilities: security governance, identity and access management, endpoint and server protection, employee awareness, monitoring and continuity planning. Unlike a penetration test, which seeks to exploit specific flaws within a limited technical scope, this diagnostic covers the full set of organizational and technical practices that determine a company's real resilience against a cyberattack.

For an SME or mid-sized company without a dedicated security team, this diagnostic is often the first structured assessment of its cyber posture, ahead of more specific efforts: preparing for ISO 27001 certification, anticipating NIS2 compliance, or drafting an Information Security Policy (ISSP). It produces a factual risk map, ranked by impact, rather than a vague sense of vulnerability that is hard to turn into an action plan.

What this diagnostic gives you

An objective risk map

Identify, within a few hours, the most critical organizational and technical gaps in your information system, ranked by impact rather than in alphabetical order.

A shared language with your stakeholders

Get a structured, sourced report usable both internally (management committee) and externally (cyber insurer, client, investor).

A direct base for your compliance efforts

Reuse the answers collected to prepare for ISO 27001 certification, anticipate NIS2, or draft an ISSP, without starting from scratch.

A prioritized action plan, not a wish list

Every identified risk comes with a concrete recommendation and a criticality level, automatically turned into a Progress Plan tracked over time.

An approach accessible without a dedicated security team

No prior technical expertise is required to get started: the questions guide the user, and the AI digs deeper into the risk areas it identifies.

Who is it for?

A diagnostic designed to be run without prior expertise, though each profile draws different value from it.

CISO / Security lead

Backs their security roadmap with a structured assessment, to prioritize investments and justify budgets to management.

IT Director / CIO

Gets a view of cyber posture beyond their own technical scope, including governance and user awareness.

Executive / Management

Understands real cyber exposure without technical jargon, to arbitrate priorities and meet insurer or client requirements.

CTO / Technical lead

Checks that security practices (encryption, monitoring, DevSecOps) keep pace with the organization's technical growth.

Compliance / Legal lead

Anticipates regulatory obligations (NIS2, GDPR, client contractual requirements) from a factual assessment rather than a declarative one.

Domains assessed

Each domain is made up of factual questions, with no unnecessary jargon.

Réseau, pare-feu et VPN

Règles de filtrage, accès distant, DMZ, Wi-Fi et protection DDoS

Conformité fournisseurs

Audits et clauses sécurité dans la chaîne d'approvisionnement

Conformité & RGPD

Respect des obligations légales sur les données personnelles

Continuité d'activité

Capacité à maintenir l'activité en cas de crise IT

Mobile & Télétravail

MDM, BYOD, sécurité du télétravail et procédures en cas de perte/vol

Plan de reprise

Continuité métier, RTO/RPO et plans de reprise après incident

Identités et accès

Cycle de vie des comptes, authentification, SSO et gestion des accès privilégiés

Sécurité

Protection endpoints, gestion des accès, secrets et sécurité API

Gestion des actifs

Inventaire, classification et cycle de vie des équipements et logiciels

Gestion des vulnérabilités

Scan récurrent, priorisation, délais de remédiation et veille

Gouvernance cybersécurité

Pilotage, politique de sécurité, budget et analyse de risques

Sécurité des emails

Authentification du domaine, filtrage, phishing et protection BEC

Sécurité des serveurs

Durcissement, exposition, correctifs, conteneurs et isolation des environnements

Sécurité opérationnelle

Monitoring, gestion des incidents et opérations de sécurité

Sensibilisation des utilisateurs

Formation à l'arrivée, formation continue, publics à risque et culture du signalement

Données & Sauvegardes

Classification, protection, chiffrement, sauvegardes et récupérabilité

Chiffrement

Données au repos, sauvegardes, gestion des clés et classification

Sécurité des développements & APIs

Secure coding, tests dynamiques, sécurité des APIs et gestion des secrets

Cloud

IAM cloud, configuration, exposition des données et dépendance fournisseur

Postes de travail & EDR

Durcissement, chiffrement, protection endpoint et droits d'administration

Journalisation & détection

Centralisation des logs sécurité, SIEM, supervision des alertes et détection des incidents

Methodology

The Cybersecurity Diagnostic is inspired by the main practice areas of CMMI v3 (governance, development, operations, cybersecurity, product…), to provide a pragmatic maturity diagnostic — without claiming official CMMI conformity.

What you get

A per-domain analysis report

An AI-generated summary for each domain assessed: maturity level, findings, identified risks and sources.

A prioritized risk matrix

A consolidated view of every identified risk, ranked by impact and remediation effort, to arbitrate priorities at a glance.

Actionable recommendations

Concrete recommendations tied to each risk, directly usable by your technical teams or vendors.

A Progress Plan tracked over time

Every recommendation becomes a tracked action with a status and a comment, turning the report into a living roadmap rather than a static document.

Ready to get started?

Start this diagnostic now and get your first recommendations after just a few questions.

Start my free trial

Frequently asked questions

What is the difference between this diagnostic and an ISO 27001 certification audit?

An ISO 27001 certification audit is conducted by an independent accredited body and results in an official certificate. The Kaliteq diagnostic is an AI-assisted self-assessment: it issues no certification, but it objectively measures the gap with the standard's main domains and effectively prepares for a certification audit ahead of time.

Does the diagnostic replace a penetration test?

No. The diagnostic assesses declared organizational and technical practices, while a penetration test actively exploits vulnerabilities within a specific technical scope. The two approaches are complementary: the diagnostic identifies risk areas, the pentest tests them under real conditions.

Do my data and answers stay confidential?

Yes. The answers, documents and reports generated belong to your organization and are neither shared nor used to train third-party models. A private, time-limited sharing link can be generated if you want to pass the results to a third party (insurer, client, investor).

Is the diagnostic suited to a company without a CISO yet?

Yes, that is in fact one of the most common use cases. The questions remain understandable without prior cybersecurity expertise, and the executive or IT director can answer alone, drawing on their IT vendors for the more technical aspects if needed.

How long does it take to get actionable results?

The first recommendations appear as soon as a domain is completed and analyzed, without waiting for the full diagnostic to finish. Most users get an actionable first risk map within one or two working sessions.

How long does the Cybersecurity Diagnostic take?

The Cybersecurity Diagnostic includes around 137 questions across 21 domains, roughly 69 to 110 minutes for a first pass. Answers remain editable as long as the diagnostic has not been finalized.

Which domains does the Cybersecurity Diagnostic cover?

The Cybersecurity Diagnostic covers the following domains: Réseau, pare-feu et VPN, Conformité fournisseurs, Conformité & RGPD, Continuité d'activité, Mobile & Télétravail, Plan de reprise, Identités et accès, Sécurité, Gestion des actifs, Gestion des vulnérabilités, Gouvernance cybersécurité, Sécurité des emails, Sécurité des serveurs, Sécurité opérationnelle, Sensibilisation des utilisateurs, Données & Sauvegardes, Chiffrement, Sécurité des développements & APIs, Cloud, Postes de travail & EDR, Journalisation & détection.

Who should answer the Cybersecurity Diagnostic in my organization?

Typically, management answers the governance-related questions, while operational leads answer the questions in their domain (e.g. CISO or IT director for cybersecurity, CTO for development). Kaliteq lets you invite several contributors on the same diagnostic, each answering the domains that concern them.

What methodology is the Cybersecurity Diagnostic based on?

The Cybersecurity Diagnostic is inspired by the main practice areas of CMMI v3 (governance, development, operations, cybersecurity, product…), to provide a pragmatic maturity diagnostic — without claiming official CMMI conformity.

What does the report generated at the end of the Cybersecurity Diagnostic contain?

At the end of the diagnostic, Kaliteq generates a report structured by domain: maturity level, identified strengths, risks prioritized by impact and remediation effort, and recommendations automatically turned into a tracked Progress Plan. The report is based exclusively on the answers provided and any associated documents, with full traceability to their source.

Is the Cybersecurity Diagnostic suited to a small or mid-sized business?

Yes. The Cybersecurity Diagnostic is rated "intermediaire" difficulty. Its intermediate level assumes operational knowledge of the domain being assessed, without requiring deep expertise. Kaliteq is designed for organizations of any size, with no dedicated team required to run the diagnostic.

Does the Cybersecurity diagnostic help write an information security policy (ISSP)?

The diagnostic covers all the domains an information security policy needs to document: security governance, identity and access management, vulnerability management, encryption, awareness, monitoring and continuity planning. The answers and the risk report provide a base that can be used directly to draft or update a security policy.

One engine shared by every diagnostic

Adaptive questionnaires, intelligent Data Room, Smart Hub RAG engine and automated reports: discover the tools shared by every Kaliteq diagnostic.

Discover Kaliteq's solutions