New Jersey cybersecurity consultingNJSTART registeredNew Jersey SBEGeneral & professional liability insured

Free, ungated resource

New Jersey Cybersecurity Readiness Checklist

Use these 18 questions to identify decisions, controls, and operating practices that deserve closer review. This is a conversation starter—not an audit, certification, or compliance determination.

How to use it

Mark each item Yes, Partly, No, or Unknown. Treat repeated “Unknown” answers as a visibility problem. Prioritize gaps by service impact, exposure, exploitability, and feasibility—not by count alone.

1. Governance & accountability

  1. A named leader is accountable for cybersecurity risk and improvement priorities.

  2. Leadership receives plain-language cyber risk, progress, and exception reporting on a defined cadence.

  3. Critical policies, standards, and response documents have owners and scheduled review dates.

  4. The organization maintains a prioritized cybersecurity roadmap tied to owners, timing, and budget.

2. Identity, access & assets

  1. Multi-factor authentication protects privileged, remote, email, and other high-impact access paths.

  2. Privileged accounts are separated, limited, reviewed, and removed promptly when no longer needed.

  3. The organization can identify supported systems, endpoints, externally exposed assets, owners, and critical services.

  4. Joiner, mover, and leaver processes reliably change or remove access on time.

3. Vulnerability & configuration risk

  1. Scanning or other discovery covers the assets and environments that matter—not only the easiest systems to scan.

  2. Remediation priority considers exposure, exploitability, known exploitation, asset importance, and business impact.

  3. Findings have accountable owners, target dates, escalation paths, and a documented exception process.

  4. Closure includes validation rather than relying only on ticket status or self-attestation.

4. Incident readiness & continuity

  1. The incident response plan defines decision authority, escalation, legal, communications, insurance, and external contacts.

  2. A realistic tabletop exercise has tested the plan and produced tracked improvement actions within the past year.

  3. Backups for critical services are protected, monitored, and tested through meaningful restoration exercises.

  4. Critical services have documented dependencies, recovery priorities, and manual or alternate operating procedures.

5. Third parties & measurable progress

  1. Critical providers are inventoried and contracts address security, incident notification, access, data handling, and exit needs.

  2. Metrics show whether meaningful exposure and control gaps are decreasing—not only how much activity occurred.

Turn answers into action

  1. Identify gaps connected to critical services or sensitive information.
  2. Separate urgent exposure from important program-building work.
  3. Assign one accountable owner and a realistic target for each priority.
  4. Confirm funding, dependencies, and evidence needed to validate closure.
  5. Review progress with leadership on a defined cadence.

Need help converting the results into a defensible roadmap? Request a readiness review.