Frontline-derived

IR Readiness Assessment.

Twelve questions across seven gaps that consistently break incident response plans under pressure. Answer honestly — your team's dwell time depends on it.

🧪Evidence Preservation·Question 1 / 12
How long are firewall, identity, and application audit logs retained?
🧪Evidence Preservation·Question 2 / 12
Is 'live-response snapshot before rebuild' written into runbooks?
🏛️Cross-Unit Coordination·Question 3 / 12
Can security deploy tooling into subsidiary / BU environments without contractual negotiation?
📞Help-Desk Hardening·Question 4 / 12
What happens on a second failed help-desk challenge question?
📞Help-Desk Hardening·Question 5 / 12
How often does the help desk face red-team social-engineering drills?
🪪Identity & SaaS Visibility·Question 6 / 12
Do you have detection coverage for Entra/Okta, vCenter/ESXi, and top SaaS admin actions?
🪪Identity & SaaS Visibility·Question 7 / 12
Are MFA exemptions and trusted-network exceptions audited?
☁️Cloud Control-Plane·Question 8 / 12
How is CloudTrail / equivalent control-plane logging ingested and alerted on?
☁️Cloud Control-Plane·Question 9 / 12
How are cloud IAM roles and dormant keys managed?
🔗Third-Party / MSP Trust·Question 10 / 12
What controls apply to MSP / integrator accounts?
🕵️Insider & Fake-Hire Risk·Question 11 / 12
Does hiring include live identity + environment verification for remote engineers?
🕵️Insider & Fake-Hire Risk·Question 12 / 12
How fast is offboarding revocation across identity + SaaS + code hosts?