Home/Assessments/Cyber Risk
Find out what your AI estate is actually exposed to.
Fifteen questions across model security, data protection, supply chain, access and detection, mapped to the NIST AI Risk Management Framework and ISO/IEC 27001. You get your score and a prioritized list of what to fix first, on this page, immediately. Scoring happens in your browser — nothing leaves it unless you ask for the report by email at the end.
0 / 15 answered
This assessment needs JavaScript to score itself. The questions below are worth reading either way — they are the five things that decide whether an AI estate can be defended. If you would rather talk them through, book a strategy call, or see the Data Platform Accelerator, where we verify these against your systems rather than your answers.
Data Products · AI Security Posture Report
AI & Data Cyber Risk Screen
Reference —
Scored in your browser
Your result
Posture by area
Each bar is your score out of 6. The marker sits at 4, the level where a production build usually stops being rework. Hover or focus a row to see which of its three answers pulled it down.
What is holding up
Nothing scored at or above 4 yet. That is the honest read, and it means the sequencing below matters more than usual.
Where the risk sits
No dimension scored 2 or below. Your exposure is depth rather than absence — see the sequencing below.
What to fix first
Ordered by where you scored lowest, with ties broken toward the more foundational layer. Fixing these in another order usually means doing the work twice.
View the scores as a table
| Dimension | Score | Of | Standing |
|---|---|---|---|
| Total | 0 | 36 | — |
Prefer to keep a copy? — it is a PDF, not a mailing list.
The two-week version
The version that is not self-reported.
A screen tells you where you are exposed. It does not close the gap, and it rests on your own account of your systems — which is the first thing a security review will test. The Cyber Risk Sprint verifies these five areas against the systems themselves and closes what it finds, starting where you scored lowest.
01 Posture audit
The same five areas, verified against your actual systems, agents and vendor terms rather than your account of them.
02 Gap register
Where a build actually breaks, named specifically enough that someone can put a number against fixing it.
03 Order-of-magnitude cost view
What each path costs to stand up and to run, sized at your volumes — enough to know whether the number is five figures or seven.
04 Prioritized next steps
One sequence with the reasoning attached, so the order can be argued with rather than taken on faith.
Two weeks, fixed fee. It is designed as a low-risk way in, and the output is yours to use whether or not you take the work further with us. When a decision needs more than that, there is a longer engagement above it.
See the Cyber Risk SprintWhat this is, and what it is not.
It is a structured self-assessment
Eighteen questions drawn from the reasons builds actually fail — thin data foundations, no review path, no evaluation harness, unmodeled cost, no adoption, unexamined exposure. Answering honestly is the whole method.
It is not a diagnosis
It scores what you tell it. It cannot see your architecture, read your contracts or interview your people, and it will not catch a problem you do not know you have.
Nothing is collected unless you ask
Scoring happens in your browser. Your individual answers are never transmitted. The one exception is deliberate: if you ask for the report by email at the end, your address and the six dimension scores are sent to us so we can send it. Skip that and nothing leaves your machine.
Your report
Take this with you.
We will email this exact report as a PDF — your score, all five areas and the sequencing — so you can forward it to whoever controls the budget. No mailing list, no follow-up sequence.
Your address and the six dimension scores are sent to contact@dataproducts.io so we can send the report. Your individual answers are not transmitted. Privacy policy.
On its way.
Check your inbox in the next few minutes, and your spam folder if it is not there. The report stays on this page either way.