VIGIL uses cookies to maintain session security and measure anonymous usage. No assessment data is shared with third-party analytics. Privacy Policy

Security Risk & Investment
Readiness Diagnostic
A practitioner-led assessment that surfaces where security programmes drift out of alignment — and what that means for the investment case you need to build.
5 sections
Assessment areas
~5 minutes
Completion time
Free
No account needed
Asset profile Threat environment Security posture Security culture Business drivers
Section 1 of 5 — Asset profile
Tell us about the asset you are assessing
Your sector calibrates the peer benchmark. A premium hotel and a budget property share a sector classification but carry fundamentally different risk profiles — be specific.
What sector does this organisation operate in?
Hospitality — hotels, resorts, events, food and beverage
High public access · brand-sensitive · VIP exposure
Commercial real estate — offices, business parks, mixed-use
Mixed access · information assets · executive exposure
Healthcare — hospitals, clinics, medical campuses
Vulnerable occupants · 24/7 operations · regulatory obligations
Education — schools, universities, research campuses
Duty of care · open environment · evolving threat profile
Retail and leisure — shopping, entertainment, leisure venues
High footfall · shrinkage · public-facing incidents
Manufacturing, industrial and logistics
Asset-heavy · supply chain risk · production continuity
Critical infrastructure — utilities, energy, water
National importance · insider threat · cascading consequences
Data centres and digital infrastructure
SLA-critical · third-party access · cyber-physical convergence
Transportation and logistics hubs
Throughput pressure · supply chain complexity · variable controls
Government and public sector
Public access · distributed accountability · perception vs preparedness gap
If this site were disrupted for 48 hours, what would the business impact be?
This anchors the financial framing in the output — not the risk score.
Minimal — operations can be paused or relocated without material impact
Noticeable — measurable revenue or operational cost impact
Significant — losses in the hundreds of thousands; operational and contractual exposure
Severe — millions at risk; reputational, regulatory and financial consequences combined
How visible is this organisation externally?
Low profile — limited public or media presence
Regional brand — known within its geography or sector
National brand or listed entity — broad public recognition
High visibility — media scrutiny, hosts VIPs, or politically sensitive environment