Self-check · 2 minutes

Six questions. The same six areas as the Communication.

For each of these six areas, the Report asks you to state your risk exposure, how adequate your controls are, and where the gaps are. Answer honestly: your result stays on your screen. We don't even ask for your email.

  1. 1 · Governance

    Does your risk appetite framework already cover frontier-technology risk, and does your board include ICT and AI expertise?

  2. 2 · Cyber hygiene

    Are your networks and operating environments segmented, with granular access management and continuous activity monitoring?

  3. 3 · ICT assets

    Do you have a complete, up-to-date inventory where criticality reflects direct internet exposure and cloud use?

  4. 4 · Vulnerabilities and patching

    Could you say today, without asking around, which open vulnerabilities sit on critical or internet-facing assets?

  5. 5 · Monitoring and defence

    Is monitoring synced with your inventory, so every asset is watched according to its criticality class?

  6. 6 · Testing

    Is your digital operational resilience testing programme aligned with DORA Articles 24 and 25, including crisis management?

From the Communication to the Report

What it asks, area by area.

The CMDB doesn't cover all six areas on its own, but it underpins four of them and supplies the evidence that makes them provable. Here's what the Communication asks for, and what SinergIA provides.

Governance

A risk appetite framework updated for frontier-technology risk, clearly assigned responsibilities, contractual safeguards over suppliers.

A defensible picture of the ICT perimeter for the board to act on, with an owner and an accountable function for every asset.

Cyber hygiene

Defence in depth, granular access management, network and environment segmentation.

A map of networks, environments, and dependencies to design segmentation around, then verify it over time.

ICT asset management

Complete, up-to-date, reliable inventories; criticality classification that reflects internet exposure and cloud use; replacement of legacy technology.

The core of the CMDB: discovery, classification, dependencies, and automatic flagging of anything out of support.

Vulnerabilities and patching

Fast detection, timely remediation prioritised by criticality, with open source and internet-facing systems first.

Links your scanner findings to the actual asset, so the remediation queue is ranked by criticality and exposure, not score alone.

Monitoring and defence

Monitoring systems “synchronised with the ICT asset inventory”, so every asset is watched according to its criticality class.

The inventory as the source of truth for coverage: which critical assets are unmonitored, and for how long.

Testing

A digital operational resilience testing programme under DORA Articles 24 and 25, realistic scenarios, crisis management.

The perimeter you pick scenarios from and prove test coverage against, one critical or important function at a time.