Skip to content
Cybersecurity and MSSP

Your free security assessment is a commodity now

Twelve yes-or-no questions and a traffic light. Every firm in this market gives one away, and the managing director taking yours has taken two others this month. Meanwhile they are stuck on question 14 of a supplier security questionnaire, about to lose the tender, and a traffic light does not help them answer it.

Not open yet. Ours scores your funnel rather than an estate, and it is the quickest way to see one of these from the answering side.

Nobody loses a tender because their assessment was amber. They lose it because they could not evidence anything.

Today

Fear brings them to the page and the page then asks for an email

Four sources, and all four hand the same sequence to two very different people. A chief executive who was mildly worried, and a finance director three weeks from a contract renewal.

Content and events

A breach webinar fills a room. A registration list is a list of people who were free on a Thursday, and the follow-up sequence treats all of them the same.

Search

Somebody types a framework name and a question mark. They arrive mid-research, which is the worst possible moment to ask for a name and an email.

Paid media that leads with fear

It works well enough to keep buying and it attracts the people most alarmed rather than the people most exposed. Those are different lists.

The partner channel

An IT provider passes you a client. You inherit a relationship, a half-finished picture of the estate, and no evidence of what is already covered.

67%

of B2B buyers now prefer a rep-free experience, up from 61%n=646Gartner, March 2026

A managing director who is being audited by their own customer does not want a discovery call about it. They want to know where they stand, this afternoon, without telling anybody yet. Your paid media is buying that buyer and then handing them a contact form.

What we would build

Score them against a framework somebody else publishes

Your NIST CSF 2.0 Posture Score. Control-level questions across the framework’s six functions, with a peer band by sector and headcount. The remediation plan is written against what an insurer and a tender pack actually ask for.

The six functions

Govern
Who owns this, what has been decided, and where is it written down?
Identify
What do you actually have, and which parts of it would hurt to lose?
Protect
What stops an ordinary Tuesday from becoming an incident?
Detect
If it started this morning, when would anybody notice?
Respond
Who is called, in what order, and has any of them practised it?
Recover
How long until the business is trading again, and who has tested that number?

Govern is the function that arrived with 2.0 and it is the one that separates a customer with security products from a customer with a security position. It is also the one a managing director can answer without help, which makes it a good place to start rather than a good place to hide.

The scale is not ours. It is published, it is free to read, and the respondent’s insurer and their largest customer have both heard of it. A maturity model invented in-house asks a sceptical reader to trust a number nobody can check.

Why a named framework beats an in-house scale

What they get

A document that survives being sent to a procurement team

Function-level scores, a peer band, and the remediation plan in the order an underwriter and a buyer would want it done.

The output is not a marketing asset that happens to be useful. It is the paragraph they paste into the tender response. It is the summary they attach to the insurance renewal, with the gaps and the dates they close them by.

That is why it gets forwarded. A finance director sends it to the procurement lead asking the awkward questions, and your name is on the document that won them the contract.

Placeholder

A sample posture report goes here. RampFunnels is pre-launch, so there is no real one to show and an invented one would be the thing this whole page argues against.

Why it keeps working

Four dates are doing the asking for you this year

None of them is ours and none of them needs a scare campaign. They are simply the reasons a managing director starts answering questions about their own posture in the next two quarters.

April 2026

Cyber Essentials changes

The scheme moves and every readiness checker built against the old question set quietly starts giving the wrong answer. Most of them will not be updated, because nobody owns them.

In force

NIS2

Managed security providers are named in it, and its supply-chain duties push security questions down from in-scope customers to everybody who serves them.

In force

DORA

Financial entities and the ICT providers they depend on. If your prospect sells anything into financial services, somebody is already asking them for evidence.

10 November 2025

CMMC in the acquisition rule

The 48 CFR rule took effect, so the clause starts appearing in US defence contracts rather than in guidance. Anybody in that supply chain now has a date rather than an intention.

Which is why the mapping is a standing job rather than a launch. Three things move after it goes live, and all three decide whether it is still producing leads in year two.

  1. The framework moves

    A public framework gets revised and the mapping behind the scoring has to follow it. That is a scheduled job, not an accident somebody notices in year two.

  2. The peer band thickens

    Every response makes the comparison more useful, which is the only part of this that a competitor cannot copy by reading your page.

  3. The questions get re-scored

    Once a few hundred people have answered, some questions turn out to separate nobody. Those come out. The ones that predict a closed deal get weighted up.

Routing

The score decides who gets a vCISO and who gets a sequence

Every respondent gets the report. What changes is what happens in the hour afterwards.

Exposed and under a deadline

Weak on Detect and Respond, plus a tender or a renewal with a date on it. The calendar goes on the result page while the buyer is still reading their own gaps, which is the only moment they will book.

Exposed, no deadline yet

The same picture without the pressure. A sequence built from the functions they came out worst on, so the follow-up is about their recovery time rather than about your monitoring contract.

Covered already

Say so plainly. The buyers who come out well are the ones a peer is most likely to ask for a recommendation. They remember which firm did not try to frighten them.

Packages

Three packages, fixed scope, nothing open ended

Security firms tend to need the third one, because a framework-mapped score with nobody maintaining the mapping has a shelf life of about a year.

Prices are not published yet because they are not final. When they are, they go on the pricing page as numbers.

Questions

What security firms push back on

So does most of the market. Our own sweep of this category found more live examples here than in any other vertical we looked at. (RampFunnels, Quiz Funnel Opportunity Atlas, 2026) A dozen yes-or-no boxes and a traffic light is now table stakes, which is why it no longer wins a deal. What nobody in that sweep ships is a rating mapped to a named public framework with a peer band under it. Nobody is maintaining that mapping when the framework moves either.

Your turn

Judge it from the answering side

Ours scores your own funnel on the four things that decide whether traffic converts, and names the one costing you the most leads.

Not open yet. When it opens, the score and the report are yours whether or not we ever speak.