Business Technology Risk Navigator
A guided advisory tool for cybersecurity, compliance, Microsoft 365, cloud, backup, network, and managed IT risk conversations.
Open toolUse a professional library of free cybersecurity, compliance, cloud, Microsoft 365, firewall, vulnerability, internal audit, external exposure, CISO governance, and incident response tools to organize what needs attention first.
This library helps business owners, IT managers, CISOs, CIOs, administrators, MSP owners, and Southern California organizations review common security control areas before a deeper professional audit or remediation project. Use it to organize questions, not to certify that systems are secure or compliant.
Cybersecurity audits, Microsoft 365 and Azure reviews, firewall audits, vulnerability management, HIPAA or PCI DSS readiness, cyber insurance questionnaires, incident response planning, internal control reviews, external exposure checks, and vCISO leadership conversations.
Ali Hassani is the cybersecurity and IT professional behind OC Security Audit. These tools reflect practical experience with security audits, Microsoft infrastructure, Office 365 and Microsoft 365 security, Azure, firewalls, vulnerability management, network security, healthcare IT, and executive cybersecurity leadership.
The tools are grouped by the way organizations usually work through security questions: first the broad business risk, then identity and cloud, infrastructure, compliance, CISO governance, external exposure, and internal control review.
Select a main area below and jump directly to the right section of the free OC Security Audit tool library.
Use these higher-level tools when leadership needs a practical view of risk, ownership, priorities, and the daily operating rhythm for cybersecurity work.
A guided advisory tool for cybersecurity, compliance, Microsoft 365, cloud, backup, network, and managed IT risk conversations.
Open toolBuild a practical CISO daily briefing with risk signals, ownership, vulnerability priorities, executive reporting, and vCISO coaching.
Open toolA dedicated CISO leadership tool library for governance, risk, policies, vendor risk, incident readiness, and executive reporting.
Open toolStart here when the organization needs a broad readiness snapshot, a ransomware conversation, incident-response planning, or cyber insurance preparation.
Start with a broad review across identities, endpoints, servers, cloud, networks, backups, and response planning.
Open toolReview overall cybersecurity and IT readiness before deeper technical or compliance work.
Open toolHelp owners, executives, and board-level stakeholders identify governance, accountability, and resilience priorities.
Open toolCheck preparedness for ransomware prevention, containment, backup protection, recovery testing, and continuity.
Open toolReview escalation paths, logging, communication planning, containment readiness, and evidence preservation.
Open toolOrganize common cyber insurance control topics such as MFA, EDR, backups, vulnerability management, and response readiness.
Open toolPrepare practical tabletop scenarios for ransomware, business email compromise, vendor incidents, and response coordination.
Open toolReview the account, cloud, collaboration, email, and administrative access controls that commonly drive breach and compliance risk.
Review Azure, AWS, Google Workspace, SaaS, identity, storage, public exposure, and cloud governance topics.
Open toolEvaluate Microsoft 365 security settings, Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and audit logs.
Open toolReview Azure identity, subscriptions, virtual networks, workloads, storage, monitoring, backup, and governance controls.
Open toolReview AWS account security, identity, network exposure, logging, storage, workloads, and governance practices.
Open toolReview Google Workspace identity, email, sharing, admin roles, logging, mobile access, and data protection controls.
Open toolReview MFA, lifecycle controls, sign-in risk, conditional access, guest access, and identity governance.
Open toolCheck administrator roles, emergency access, monitoring, separation of duties, and privileged access hygiene.
Open toolReview phishing defenses, mailbox rules, authentication, filtering, spoofing controls, and compromise response.
Open toolAssess privileged groups, stale objects, domain controller hardening, service accounts, auditing, and recovery readiness.
Open toolReview practical infrastructure controls across firewalls, wireless, servers, endpoints, virtualization, vulnerability management, recovery, and remote access.
Turn network discovery and vulnerability review data into a practical executive and technical report.
Open toolReview wireless segmentation, guest access, encryption, admin controls, rogue access points, and monitoring practices.
Open toolReview firewall rules, VPN exposure, segmentation, logging, remote access, and risky exceptions.
Open toolCheck server patching, local admin rights, logging, backup, remote access, and baseline hardening.
Open toolReview VMware, Hyper-V, Azure VM, hypervisor, virtual-network, privileged-access, backup, and monitoring readiness.
Open toolEvaluate scanning, prioritization, remediation tracking, asset coverage, exception handling, and validation practices.
Open toolReview endpoint protection, EDR coverage, local privilege, patching, device inventory, isolation, and response visibility.
Open toolCheck backup coverage, restore testing, ransomware resilience, cloud backup, and business recovery objectives.
Open toolReview remote access, MFA, device controls, VPN, endpoint security, data access, monitoring, and user awareness.
Open toolEvaluate identity, device, access, segmentation, monitoring, cloud, and least-privilege foundations.
Open toolUse these tools to prepare for compliance conversations, privacy concerns, vendor review, cyber insurance requirements, and data-protection decisions.
Identify readiness gaps for HIPAA, PCI DSS, SOC 2, NIST CSF, ISO 27001, CMMC, cyber insurance, and related frameworks.
Open toolReview administrative, physical, and technical safeguard readiness for healthcare and PHI-focused environments.
Open toolReview cardholder data scope, segmentation, access control, vulnerability management, logging, and policy readiness.
Open toolReview written information security program readiness for tax, accounting, and financial-information protection.
Open toolReview public website security, privacy exposure, forms, TLS, cookies, CMS risk, and visitor-data concerns.
Open toolReview third-party access, data handling, contracts, SOC 2 evidence, breach notice, and outsourced-service risk.
Open toolUse these CISO-focused tools to review governance, risk ownership, policies, vendor risk, incident readiness, executive scorecards, and security priorities.
Assess cybersecurity governance, security ownership, leadership reporting, policies, and CISO-level oversight with this free OC Security Audit tool.
Open toolUse this free cyber risk management assessment to review risk identification, scoring, ownership, remediation priorities, and executive risk visibility.
Open toolReview cybersecurity policy gaps including MFA, incident response, backups, vendor access, remote work, acceptable use, and data protection.
Open toolAssess vendor and third-party cybersecurity risk, external access, data handling, contracts, breach notification, SOC 2 evidence, and security controls.
Open toolReview incident response planning, ransomware readiness, business email compromise response, escalation, communication, and tabletop exercise maturity.
Open toolGenerate an executive cyber risk scorecard to review cybersecurity visibility, compliance risk, business impact, recovery readiness, and leadership reporting.
Open toolIdentify which cybersecurity compliance frameworks may apply to your business, including HIPAA, PCI DSS, CMMC, IRS WISP, SOC 2, NIST CSF, and ISO 27001.
Open toolAssess employee cybersecurity awareness, phishing training, new hire training, executive training, remote work awareness, and reporting procedures.
Open toolReview sensitive data protection, encryption, access control, backups, file shares, cloud data security, email protection, and DLP readiness.
Open toolBuild a practical cybersecurity roadmap by reviewing security gaps, compliance drivers, current tools, staffing, priorities, and remediation planning.
Open toolReview public-facing systems, DNS, email security, cloud exposure, remote access, vendor portals, and external evidence readiness.
Use free External Audit Tools from OC Security Audit to assess public IP exposure, website security, DNS, email security, cloud exposure, remote access, external vulnerabilities, vendor portals, and incident readiness.
Open toolReview your organization’s overall external security posture across public-facing systems, internet exposure, website security, DNS, email security, cloud exposure, vulnerabilities, and incident readiness.
Open toolAssess public IP inventory, open ports, exposed RDP, SSH, VPN, admin portals, firewall rules, unnecessary services, and internet-facing network device risks.
Open toolReview website CMS security, WordPress and plugin exposure, login protection, web forms, security headers, TLS, client portals, privacy risks, and exposed software versions.
Open toolAssess DNS records, registrar security, DNS hosting, SSL/TLS certificates, SPF, DKIM, DMARC, MX records, phishing exposure, brand impersonation, and lookalike domains.
Open toolAssess Microsoft 365 exposure, Azure, AWS, Google Cloud public resources, public storage, SaaS admin access, external sharing, exposed cloud apps, MFA, conditional access, and guest access.
Open toolReview VPN security, remote desktop exposure, external admin portals, MFA enforcement, conditional access, vendor access, privileged remote access, failed login monitoring, brute-force protection, and risk-based access.
Open toolAssess external vulnerability scanning, attack surface management, internet-facing servers, exposed databases, software version exposure, SSL/TLS weaknesses, known exploitable vulnerabilities, remediation tracking, and review cadence.
Open toolAssess vendor-hosted portals, customer portals, outsourced IT platforms, third-party access, hosted applications, access control, vendor security evidence, SOC 2 or ISO 27001 review, and breach notification readiness.
Open toolAssess externally accessible backups, cloud backup access, ransomware recovery readiness, incident response contacts, cyber insurance contacts, breach notification workflow, external attack escalation, evidence preservation, and recovery testing.
Open toolAssess external audit documentation, compliance evidence, vulnerability scan records, penetration test records, cyber insurance evidence, customer security questionnaires, policy evidence, remediation records, and executive reporting.
Open toolReview the internal control environment across physical security, networks, servers, databases, Active Directory, Wi-Fi, patching, EDR, backups, documentation, and process ownership.
Use free Internal Audit Tools from OC Security Audit to assess physical, technical, administrative, network, server, endpoint, Active Directory, Wi-Fi, backup, monitoring, and incident response controls.
Open toolReview how well your organization protects facilities, work areas, network closets, sensitive media, and visitor access as part of an internal security audit.
Open toolAssess physical, environmental, and operational safeguards around server rooms, network racks, and controlled IT infrastructure spaces.
Open toolEvaluate internal segmentation, east-west visibility, access control, documentation, and internal traffic protection for business networks.
Open toolReview hardening, patching, privileged access, logging, and remote administration controls for Windows and Linux servers.
Open toolAssess database access control, encryption, patching, logging, backup protection, and sensitive-data safeguards across internal business systems.
Open toolReview patching, authentication, file permissions, TLS, logging, and internal application exposure risks for internal-facing web servers.
Open toolAssess the hardening, configuration control, access security, logging, and segmentation discipline of internal network devices and firewall infrastructure.
Open toolEvaluate how well your organization collects, reviews, correlates, and escalates logs from endpoints, servers, network devices, and cloud services.
Open toolAssess backup coverage, restore testing, resilience, access control, and documented recovery planning for internal systems and critical business services.
Open toolReview policies, reviews, ownership, vendor oversight, onboarding controls, and management reporting that support internal security governance.
Open toolAssess how prepared your organization is to identify, escalate, contain, investigate, and document internal cybersecurity incidents.
Open toolUse a scorecard-style assessment to review major internal audit categories and quickly identify top internal cybersecurity control gaps and remediation priorities.
Open toolReview enterprise wireless security, guest segmentation, admin access, rogue access point detection, and monitoring for internal wireless networks.
Open toolAssess employee cybersecurity awareness, phishing readiness, policy acknowledgement, and recurring education across office and remote work environments.
Open toolReview endpoint patching, encryption, EDR, browser security, removable media controls, and inventory discipline for desktops and laptops.
Open toolAssess mobile device management, encryption, BYOD controls, app risk, update discipline, and secure access requirements for smartphones and handheld devices.
Open toolAssess privileged groups, stale objects, domain controller hardening, service accounts, auditing, and recovery readiness for Microsoft Active Directory environments.
Open toolReview whether security baselines, password policies, firewall settings, restrictions, and GPO change control are consistently enforced through Group Policy.
Open toolReview core DNS and DHCP security, redundancy, access control, logging, and documentation that support internal network reliability and control.
Open toolAssess the security, monitoring, administration, and resilience of core internal network services such as NTP, RADIUS, LDAP, VPN, file sharing, and certificate services.
Open toolEvaluate whether critical infrastructure has meaningful redundancy, documented failover procedures, and tested recovery paths for internal operations.
Open toolAssess shared-folder permissions, ransomware resilience, file auditing, sensitive-data exposure, and access review discipline across internal file servers.
Open toolReview privileged account segregation, MFA, shared-admin risk, monitoring, vaulting, and access-review discipline for administrative identities.
Open toolAssess patch coverage, ownership, testing, reporting, exceptions, and vulnerability-based prioritization across servers, endpoints, browsers, and network devices.
Open toolReview EDR deployment coverage, isolation capability, behavioral monitoring, alert handling, retention, and response workflows for endpoints and servers.
Open toolAssess whether security-relevant technology changes are documented, approved, tested, validated, and reviewed across infrastructure and production systems.
Open toolAssess whether hardware, software, servers, network devices, endpoints, and cloud assets are inventoried, owned, classified, and tracked through lifecycle changes.
Open toolReview internal scanning coverage, remediation ownership, exception handling, reporting, and prioritization across servers, endpoints, and network devices.
Open toolAssess VPN security, MFA, zero-trust-style restrictions, vendor access, session logging, and device-compliance checks for remote connectivity.
Open toolReview whether key policies, diagrams, logs, reports, test results, and evidence records are organized well enough to support an internal security audit.
Open toolThese free tools are educational starting points based on self-reported selections. They do not replace a professional cybersecurity audit, compliance assessment, penetration test, vulnerability scan, legal review, cyber insurance review, or technical configuration validation. Do not make production changes solely because of an automated result.
Use the output to explain the business risk, likely impact, and why the topic deserves leadership attention.
Use the questions to identify evidence to collect, systems to inspect, and controls that may need validation.
Use the findings to prioritize owners, dates, dependencies, change windows, and follow-up verification.
Use NIST CSF 2.0 to organize cybersecurity outcomes, governance, risk, and improvement priorities.
Open toolUse NIST SP 1300 as a practical cybersecurity risk-management starting point for smaller organizations.
Open toolUse CISA guidance to frame practical cybersecurity actions for owners, IT managers, and business leaders.
Open toolReview additional no-cost resources and services that can support security improvement efforts.
Open toolReview Microsoft guidance for identity, endpoint, email, Microsoft 365, Azure, and security operations.
Open toolUse Azure security documentation for cloud governance, workload protection, identity, and network controls.
Open toolWhen a tool highlights risk, OC Security Audit can help validate evidence, review configurations, prioritize remediation, and communicate the business impact clearly.
OC Security Audit focuses on cybersecurity assessment, audit, compliance, risk, and vCISO guidance. When findings require hands-on implementation, project work, troubleshooting, managed IT, Microsoft 365, Azure, server, backup, endpoint, or network support, IT Perfection can support the operational work as a separate managed IT company.
If you are unsure, start with the Business Technology Risk Navigator or General Cybersecurity Risk Snapshot. If you already know the topic, choose a specific tool such as Microsoft 365, Azure, firewall, ransomware, HIPAA, PCI DSS, vulnerability management, or internal audit.
No. The tools help organize initial guidance. Important findings should be reviewed through a professional cybersecurity audit, compliance assessment, penetration test, vulnerability scan, or technical configuration review.
The public self-assessment tools are intended for browser-based guidance and should not be used to submit passwords, secrets, private keys, sensitive client data, or confidential system details.
Yes. OC Security Audit can review results, validate evidence, prioritize remediation, and help leadership understand the business and technical impact.
Use the library to organize the first conversation. Contact OC Security Audit when you need professional review, evidence validation, compliance readiness, vulnerability management, firewall review, Microsoft 365 or Azure security guidance, cyber insurance readiness, or vCISO support.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.