Skip to content

Free tool

AI Security Readiness Self-Assessment

Twelve questions, two minutes. Score your organization's readiness to adopt AI securely againstThe AI-Native Security Framework — and get a tailored set of next steps. Nothing is stored; your result is calculated in your browser.

Phase 1 Discover

You maintain an inventory of the AI tools, assistants, and agents in use — including shadow AI discovered across the organization.

You have assessed what data your AI can actually reach (an oversharing / data-exposure assessment such as DSPM or access governance).

Phase 2 Reduce

You have remediated oversharing and over-permissioned access on your most sensitive data before enabling AI on it.

Sensitive and regulated content is classified and labelled so it can be protected from AI processing.

Phase 3 Constrain

Runtime guardrails (DLP for AI/Copilot, prompt and label controls) prevent sensitive data from being processed or grounded on by AI.

Risky external and generative-AI tools and connectors are blocked or governed by default.

Phase 4 Instrument

AI interactions — prompts, responses, and accessed resources — are logged, retained, and searchable for investigation and eDiscovery.

You can detect risky AI use by user and behaviour (insider risk / anomaly monitoring), not just by file.

Phase 5 Govern

AI agents, connectors, and tools are governed with least privilege, named ownership, and approval — including MCP and third-party integrations.

You have an approved AI acceptable-use policy and a defined AI governance owner or committee.

Phase 6 Assure

You run safe, authorized red-team and validation testing of your AI systems (oversharing, prompt injection).

AI rollout is gated behind explicit, evidence-based criteria and mapped to ISO 27001/42001 and NIST frameworks.