Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Answer 10 questions about your defenses and recovery capability. Get a readiness score and a prioritized list of the gaps to close first.
It measures how well you can prevent, contain, and recover from a ransomware incident across ten practical areas: backups, segmentation, MFA, patching, email security, endpoint detection, least privilege, logging, an incident response plan, and recovery testing.
Tested, isolated, offline backups are the single most reliable defense against ransomware because they let you recover without paying. We weight backup and recovery questions higher because they determine whether an incident is a bad day or a business-ending event.
Paying is a last resort with no guarantee of recovery, and it may carry legal risk depending on who the attacker is. A tested recovery capability removes the question entirely. That is what this scorecard pushes you toward.
Retest your restore process at least quarterly and after any major infrastructure change. A backup you have never restored is a guess, not a plan.
Yes, it is free and requires no signup. If you want help closing the gaps it surfaces, book a call with our team.
Not ready for a call yet?
A few short notes from Jacob on locking down your startup without a big security team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Incident Response Retainer
A retained IR team and a tested playbook.
Explore Incident Response Retainer →We help teams harden against ransomware with continuous vulnerability management and stand up a recovery plan they have actually tested, alongside our broader security services. Talk to a CVE researcher about your real exposure.
See incident response Book a callThis gives you the shape of the problem. The full picture is all 106 NIST CSF 2.0 subcategories, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the workspace.