Cyber Security Health Check

How well-protected is your business against cyber threats?

Built for Dubai businesses operating in the cloud. This 12-minute diagnostic stress-tests your cyber security posture across eight pillars covering governance, identity, infrastructure, data, and incident response, then connects you with our vetted partner to close the gaps.

Duration
~12 minutes
Questions
41 across 8 pillars
Output
Score + tailored intros

Pillars you'll be assessed against

  • Security Governance & Compliance
  • Identity & Access Management
  • Cloud Infrastructure & Network Security
  • Application Security & Software Development
  • Data Security & Privacy
  • Insider Threat Protection
  • External Threat Detection & Response
  • Incident Response & Disaster Recovery
A few details first

Tell us about you and your business

So we can send your tailored results and connect you with our vetted cyber security partner.

Pillar 1 of 8

Security Governance & Compliance

Without a documented governance baseline, every other security control is improvised. Compliance with recognised standards (ISO 27001, SOC 2, NIST, GDPR) signals that controls are not just present, but auditable. A named owner for security and a regular risk review cadence are the foundations everything else sits on.

1. Do you comply with relevant industry security standards (e.g. ISO 27001, SOC 2, NIST, GDPR, CCPA)?
2. Do you have a Chief Information Security Officer (CISO) or dedicated security team overseeing cloud security?
3. Do you perform risk assessments for your cloud environments at least annually?
4. Do you enforce a zero-trust security model across your cloud infrastructure?
5. Are employees trained on cloud security best practices and social engineering threats?
Pillar 2 of 8

Identity & Access Management

Identity is the new perimeter. Most breaches start with a credential, not an exploit. Multi-factor authentication, least-privilege roles, monitored access logs, and centralised authentication turn identity from your weakest link into your strongest control.

1. Do you enforce multi-factor authentication (MFA) for all critical cloud services?
2. Are IAM roles and permissions configured based on the principle of least privilege (PoLP)?
3. Do you monitor and audit access logs to detect unauthorised access attempts?
4. Are there automated alerts for unusual access patterns, such as logins from unrecognised devices or locations?
5. Do you use federated identity management (e.g. SSO, OAuth, OpenID) for centralised authentication?
Pillar 3 of 8

Cloud Infrastructure & Network Security

Cloud-native security tools, encryption everywhere, network segmentation, and proper firewall rules are the table stakes of running anything in AWS, Azure, or GCP. The default settings are rarely what you want, and misconfiguration is the leading cause of cloud breaches.

1. Do you use cloud-native security tools (e.g. AWS GuardDuty, Azure Security Center, Google Security Command Center)?
2. Is end-to-end encryption enforced for all data in transit and at rest within the cloud?
3. Are VPCs (Virtual Private Clouds) and segmentation used to isolate workloads and sensitive data?
4. Do you enforce strict security groups, firewall rules, and network ACLs for cloud environments?
5. Are you using container security solutions for Kubernetes, Docker, or serverless workloads?
6. Is your application hosted in multiple cloud regions for resilience?
Pillar 4 of 8

Application Security & Software Development

Code shipped without security testing is technical debt with a deadline. Secure coding practices, integrated security testing in CI/CD, secrets management, and automated patching catch problems before they reach production. The cost of fixing a vulnerability post-deployment is exponentially higher than catching it in development.

1. Do you implement secure coding practices (e.g. OWASP Top 10) in your development pipeline?
2. Is security testing integrated into your CI/CD pipeline (e.g. SAST, DAST, and dependency scanning)?
3. Do you monitor and secure APIs against unauthorised access and abuse?
4. Are secrets and credentials managed securely (e.g. HashiCorp Vault, AWS Secrets Manager)?
5. Do you have automated patching processes for cloud-hosted applications and services?
Pillar 5 of 8

Data Security & Privacy

Your data is your liability. Whether under GDPR, the UAE Data Protection Law, or contractual obligations to customers, the question is not whether you'll be held accountable for data exposure but when. Strong encryption, locked-down storage, role-based access, monitored exfiltration, and clear retention policies are the controls that separate operators from targets.

1. Is all sensitive customer and business data encrypted using strong encryption methods (e.g. AES-256)?
2. Are cloud storage buckets and databases configured to prevent public exposure?
3. Do you enforce role-based access control (RBAC) for data access?
4. Do you monitor for unauthorised data exfiltration (e.g. Cloud DLP, CASB solutions)?
5. Do you have a data retention and disposal policy aligned with regulatory requirements?
Pillar 6 of 8

Insider Threat Protection

Most data loss comes from people who already have access. Privilege creep, departing employees with active credentials, unmonitored third-party contractors, and missing audit trails create exposure that outside attackers couldn't dream of. Periodic access reviews and clear offboarding processes close the largest blind spot in most security postures.

1. Are employee access levels reviewed regularly to prevent privilege creep?
2. Do you monitor user behaviour analytics (UBA) to detect anomalies or insider threats?
3. Is there a process to immediately revoke access when employees leave the company?
4. Are internal audit logs maintained for tracking changes to cloud configurations?
5. Do you have strict policies for managing third-party access to cloud infrastructure?
Pillar 7 of 8

External Threat Detection & Response

Attackers don't take days off. SIEM and XDR platforms, DDoS protection, regular penetration testing, threat intelligence feeds, and zero-day response capability separate companies that detect breaches in hours from those that find out months later from a news article. Detection lag is the single biggest determinant of breach cost.

1. Do you use cloud security monitoring solutions (e.g. SIEM, XDR, CSPM)?
2. Do you detect and mitigate DDoS attacks on cloud-based services?
3. Do you regularly conduct penetration testing of your cloud infrastructure and applications?
4. Are you subscribed to threat intelligence feeds to stay ahead of emerging cyber threats?
5. Do you have a solution in place to handle zero-day vulnerabilities in your cloud environment?
Pillar 8 of 8

Incident Response & Disaster Recovery

When (not if) something goes wrong, your incident response plan determines whether the event is a contained operational hiccup or a board-level crisis. Documented IRPs, tabletop exercises, tamper-proof logs, and tested recovery times turn panic into procedure. Geographically distributed backups are your last line of defence against ransomware.

1. Do you have a cloud-specific incident response plan (IRP)?
2. Is your IRP tested using real-world Tabletop Exercises (TTXs) and Red Team simulations?
3. Are security logs stored in a tamper-proof environment for forensic investigations?
4. How quickly can you recover from cloud service failures or ransomware attacks?
5. Do you maintain geographically distributed backups to ensure resilience against regional outages?
Your Cyber Security Score
0/100

Pillar breakdown
Your top cyber security gaps
Your quick win
Do this in the next 7 days

Ready to close these gaps?

Send your full diagnostic to the Dubai Chambers Business Growth Team. We'll connect you with Mantas, our vetted cyber insurance partner for cloud outage coverage, and follow up within 5 working days.

Request a partner introduction →