Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Ransomware Readiness Scorecard

Answer 10 questions about your defenses and recovery capability. Get a readiness score and a prioritized list of the gaps to close first.

0%
Prioritized gaps
    How scoring works. Each question maps to a control that affects whether ransomware spreads and whether you can recover without paying. Backups, segmentation and recovery testing carry the most weight because they decide the outcome.

    Questions

    What does the ransomware readiness score measure?

    It measures how well you can prevent, contain, and recover from a ransomware incident across ten practical areas: backups, segmentation, MFA, patching, email security, endpoint detection, least privilege, logging, an incident response plan, and recovery testing.

    Why are backups weighted so heavily?

    Tested, isolated, offline backups are the single most reliable defense against ransomware because they let you recover without paying. We weight backup and recovery questions higher because they determine whether an incident is a bad day or a business-ending event.

    Is paying the ransom ever the right call?

    Paying is a last resort with no guarantee of recovery, and it may carry legal risk depending on who the attacker is. A tested recovery capability removes the question entirely. That is what this scorecard pushes you toward.

    How often should I retest?

    Retest your restore process at least quarterly and after any major infrastructure change. A backup you have never restored is a guess, not a plan.

    Is this scorecard free?

    Yes, it is free and requires no signup. If you want help closing the gaps it surfaces, book a call with our team.

    Not ready for a call yet?

    Get the security playbook

    A few short notes from Jacob on locking down your startup without a big security team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Incident Response Retainer

    A retained IR team and a tested playbook.

    Explore Incident Response Retainer →

    Close the gaps before an attacker finds them.

    We help teams harden against ransomware with continuous vulnerability management and stand up a recovery plan they have actually tested, alongside our broader security services. Talk to a CVE researcher about your real exposure.

    See incident response Book a call

    Want the full picture on NIST CSF 2.0?

    This gives you the shape of the problem. The full picture is all 106 subcategories of NIST CSF 2.0, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free NIST CSF 2.0 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.