Sylvan Assurance Vulnerability Management · Free Edition ← Free assessments
Free vulnerability management maturity assessment

How mature is your vulnerability management programme?

Twenty-eight plain-English questions across asset inventory, scanning, prioritisation, remediation, patching, cloud workloads, exceptions, and reporting. You get a scored snapshot of where your programme sits on the four-tier maturity spectrum. About ten minutes. No email required.

Plain-English security — without us ever seeing your answers. Everything stays in your browser. Nothing is transmitted or tracked.

Don't take our word for it — verify in 30 seconds.
  1. Right-click this page and choose Inspect, then open the Network tab.
  2. Start the assessment and answer a few questions.
  3. Watch the list: nothing leaves the page while you answer — your answers stay on your device.
What does this assessment cover?

The eight working parts of a programme. The assessment follows the lifecycle. It starts with asset inventory (knowing what you run) and scanning (coverage and cadence). Then comes prioritisation — severity scores, the Known Exploited Vulnerabilities (KEV) catalogue, exploit-likelihood signals, and business context. It finishes with remediation and deadlines, patch operations, and cloud and container workloads. Exceptions and risk acceptance and metrics and governance close the loop.

What you get. A weighted score out of 68, plus a maturity band. The band uses the same four-tier spectrum as our Vulnerability Management book series. You also get a breakdown by area and plain-English priority actions.

What it isn't. This is general guidance. It is not a professional audit, not a penetration test, and not legal advice. Every recommendation is optional. Following it reduces common risks but does not guarantee any outcome. Responsibility for your programme remains with you.

Start here — the free edition

Version 1 · Updated 2026-07-21

For whoever has ended up owning security and wants the map before the tooling.

When you have worked through this, you will have: your free result on where you stand, and the five moves that start a real programme without a budget. Download this as a PDF.

The one guide
Your First Vulnerability Management Wins
PDF · 30–40 min to read · Whoever has ended up owning security
A nine-page plain-English on-ramp covering the five moves — an inventory, an authenticated scan, a weekly known-exploited check, three deadlines and a one-page report — that start a real programme without a budget.
Reach for it when: First. It is the free starter, and the map the paid documents fill in.
You finish with: A five-step plan you can start this week, and a printable one-page checklist to track it against.
The interactive assessment — a short questionnaire that scores where you stand and points at the gaps.

When you outgrow the free tier, the Solo toolkit turns these five into a worked programme — the asset inventory, the authenticated scan, and the known-exploited check — with a Start here catalog to sequence them. See the Solo, Team and Enterprise editions →

When you're ready for the full toolkit

The full edition gives you the complete toolkit.

Everything behind this free assessment — the working documents, templates, runbooks, and depth to put it into practice. Three editions to fit how you work.

See the full toolkit & pricing →

One-time purchase · files you own forever · 30-day money-back guarantee.