Free tool

Do we need SecAI to protect our servers?

Twenty-one questions a business owner can answer without a terminal. Honest answers give you an honest picture of where your server security stands, and what a service like SecAI would and would not add. Nothing is uploaded and there is no signup.

Who can get in
SSH login uses keys, not passwords
Nobody logs in directly as root
The control panel and hosting account use two-factor authentication
When someone leaves, their access is removed the same day
Keeping it patched
Security updates are installed within a week of release
Security updates install automatically
The operating system version is still supported
WordPress, plugins and other web software are kept current
What the internet can reach
A firewall is switched on and only needed ports are open
Databases are not reachable from the internet
Every website uses HTTPS with a certificate that renews itself
Knowing when something is wrong
Someone or something watches the server around the clockSecAI does this
Attacking addresses are blocked automaticallySecAI does this
You would know if a file, account or scheduled task changed unexpectedlySecAI does this
You are told when a website goes down, before customers tell youSecAI does this
When something does happen
You know who to call, and they answer
Backups run automatically and are stored somewhere else
A restore has been tested in the last six months
Logs are kept long enough to work out what happenedSecAI does this
Proving it
You have a list of every server and what runs on it
You could show a customer or insurer a security report from the last monthSecAI does this
Answer at least six questions to see where you stand.

Questions

Do I need to be technical to answer these?

No. Each item is written so the person who pays for the server can answer it, or knows who to ask. "Unsure" is a valid answer and counts as a gap, because if nobody knows, nobody is doing it.

Is anything sent to SecAI?

No. Your answers are stored only in this browser so you can come back later. Nothing is uploaded, and there is no signup.

What is the difference between this and the automatic assessment?

This checklist is about your practices. The automatic assessment is one command you run on the server itself; it checks the actual configuration and tells you GREEN, AMBER or RED.

What do the results mean for SecAI?

Green means you are ready to add continuous monitoring and response. Amber means a few foundations should be fixed first, and we can help. Red means it is worth a review before switching anything on, because a server in that state may already be compromised.