Question Title

1. Does your Organization have a documented, agency-wide cybersecurity policy? (Required.)

Question Title

2. To what extent have you implemented the NIST Cybersecurity Framework (CSF), NIST 800-53, or a similar recognized framework (e.g., CIS Controls)? (Required.)

Question Title

3. Does your organization have a formally documented incident response plan? (Required.)

Question Title

4. How would you rate your organization’s current ability to quickly restore critical services following a cyberattack? (Required.)

Question Title

5. What are the top cybersecurity threats your organization currently faces? (Select up to 3) (Required.)

Question Title

6. Which types of systems are most vulnerable in your environment? (Required.)

Question Title

7. Does your organization regularly conduct automated scanning or penetration testing to identify external vulnerabilities? (Required.)

Question Title

8. To what extent does your organization maintain a comprehensive and up-to-date inventory of all public-facing assets (e.g., websites, servers, remote access portals)? (Required.)

Question Title

9. How would you describe your organization’s inventory of OT (e.g., SCADA, PLC) and IoT devices (video cameras, conference room equipment, VOIP phones, etc.)? (Required.)

Question Title

10. Are OT and IT networks at your agency segmented from one another? (Required.)

Question Title

11. How frequently are firmware and software patches applied to your OT and IoT devices? (Required.)

Question Title

12. What are your top three biggest challenges in securing your OT and IoT environment? (number as 1 for biggest challenge, 2 for second, 3 for third) (Required.)

Question Title

13. How is remote access to your organization’s internal networks and applications managed? (Required.)

Question Title

14. How does your organization manage remote access for third-party vendors or contractors (e.g., equipment manufacturers, maintenance providers)? (Required.)

Question Title

15. Do you use a "just-in-time" or "least privilege" approach for remote access, where permissions are granted only when needed and for a limited duration? (Required.)

Question Title

16. Which strategies have proven successful in mitigating cybersecurity concerns around critical infrastructure resilience? Tick your top three. (Required.)

Question Title

17. What is the single most important action your organization plans to take in the next 12 months to improve your cybersecurity posture? (Open-ended)

T