Free, ungated resource
New Jersey Cybersecurity Readiness Checklist
Use these 18 questions to identify decisions, controls, and operating practices that deserve closer review. This is a conversation starter—not an audit, certification, or compliance determination.
Mark each item Yes, Partly, No, or Unknown. Treat repeated “Unknown” answers as a visibility problem. Prioritize gaps by service impact, exposure, exploitability, and feasibility—not by count alone.
1. Governance & accountability
A named leader is accountable for cybersecurity risk and improvement priorities.
Leadership receives plain-language cyber risk, progress, and exception reporting on a defined cadence.
Critical policies, standards, and response documents have owners and scheduled review dates.
The organization maintains a prioritized cybersecurity roadmap tied to owners, timing, and budget.
2. Identity, access & assets
Multi-factor authentication protects privileged, remote, email, and other high-impact access paths.
Privileged accounts are separated, limited, reviewed, and removed promptly when no longer needed.
The organization can identify supported systems, endpoints, externally exposed assets, owners, and critical services.
Joiner, mover, and leaver processes reliably change or remove access on time.
3. Vulnerability & configuration risk
Scanning or other discovery covers the assets and environments that matter—not only the easiest systems to scan.
Remediation priority considers exposure, exploitability, known exploitation, asset importance, and business impact.
Findings have accountable owners, target dates, escalation paths, and a documented exception process.
Closure includes validation rather than relying only on ticket status or self-attestation.
4. Incident readiness & continuity
The incident response plan defines decision authority, escalation, legal, communications, insurance, and external contacts.
A realistic tabletop exercise has tested the plan and produced tracked improvement actions within the past year.
Backups for critical services are protected, monitored, and tested through meaningful restoration exercises.
Critical services have documented dependencies, recovery priorities, and manual or alternate operating procedures.
5. Third parties & measurable progress
Critical providers are inventoried and contracts address security, incident notification, access, data handling, and exit needs.
Metrics show whether meaningful exposure and control gaps are decreasing—not only how much activity occurred.
