1. Risk identification and qualification
We survey the assets and critical information in the business process, then identify the main risks and weaknesses in the environment, mapping cause and effect.
The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.

CYBER ANTIFRÁGIL®: RESILIENCE AND CONTINUITY
Fragile companies break under crisis. Resilient ones hold on and return to what they were. Antifragile ones come out stronger. Cyber Antifrágil® installs that cycle in your operation while preserving the security investments you have already made.
HOW IT WORKS
We start from your risk appetite and the critical assets of the business process you choose, and carry it through until continuous improvement becomes routine.
We survey the assets and critical information in the business process, then identify the main risks and weaknesses in the environment, mapping cause and effect.
With risks classified and prioritized, we prepare recommendations for treating the weaknesses that can be addressed or eliminated outright.
We review the business continuity and incident response plans covering that process, so they match the risk picture you actually face.
Once the plans are in place, we schedule rounds of testing that check, in practice, whether the process, its assets, and your culture respond the way the plan expects.
The quantified results of the first cycle become your baseline: targets, cadence, and maturity assessment for every cycle that follows.
Each iteration leaves the company stronger. Adversity and incidents stop being pure loss and start feeding your defenses.
SELF-ASSESSMENT
Straight questions about your company's ability to get through a serious outage and come back operating. The result shows where continuity actually stands and where it is still a written hope.
In a crisis, everything feels urgent. The order in which things come back is a business decision, and the time to make it is calmly, in advance.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
Without knowing what cannot stop, how long it can stay down, and how much data can be lost, every continuity plan is a guess. Start with a single critical process: list what it depends on and what each day of downtime costs. The first version fits on one page and already guides decisions.
50 to 79
There is a sense of impact, but part of it lives in people's heads rather than in a formal agreement with the business. Turn it into numbers: maximum tolerable downtime and acceptable data loss per process, validated by whoever answers for the operation. That agreement is what keeps recovery investment from being too much or too little.
80 or above
Impact is mapped and agreed, one of the strongest areas in your answers. The next gain is keeping the map alive: revisit priorities and dependencies when the business changes, because an impact analysis ages along with the company.
Below 50
If no plan exists today, the good news is that the wrong first move would be writing a long document. Start with the essentials: for the most likely scenarios, who does what, in what order, with which contacts. A two-page playbook reachable outside the environment beats a manual nobody opens.
50 to 79
Plans exist, but with the typical gaps: generic scenarios, a single copy stored inside the very environment they protect, content that no longer matches the real systems. Check three things: the plan answers ransomware, survives the network being down, and describes today's environment. It is a one-day check that prevents the worst surprise.
80 or above
Concrete, reachable, current plans. The next refinement is integration: continuity, incident response, and crisis communication telling the same story, so nobody discovers a contradiction between documents mid-crisis.
Below 50
If an attacker with admin access can delete every copy, your backup protects against disk failure, not against the scenario that takes companies down today. An immutable or offline copy is the priority, followed by one end-to-end restoration rehearsal. Everything else can wait; this cannot.
50 to 79
Backups exist and pass isolated tests, but restoring a file is not the same as standing a process back up: restoration order, dependencies, and total time only show themselves in a full rehearsal. Also define how the operation runs in minimal mode while restoration is underway. That combination is what turns backup into recovery.
80 or above
Recovery looks mature in your answers: protected copies, rehearsed restoration, and a fallback way to operate. Keep the full rehearsal on a cadence and time it against the deadlines agreed with the business, because environments change and restoration times change with them.
Below 50
A plan without exercises is a hypothesis. The first test does not need to be big: two hours of tabletop, with the people who decide in the room, on a realistic scenario. What it reveals about decisions, communication, and gaps is usually worth more than months of plan writing.
50 to 79
Exercises happen, but under friendly conditions: known date, systems up, everyone available. The leap is getting closer to reality: less notice, one key person out, one system genuinely unavailable. And record the outcome in numbers, so the next exercise has something to be compared against.
80 or above
Regular, measured exercises, the heart of antifragility. The next step is widening the reach: scenarios with a critical supplier down, multi-day crises, and participation from areas that have not yet sat at the table.
Below 50
In a crisis without defined roles, the first hours are lost figuring out who decides, and those are the most expensive hours. Define three things on one page: who declares the crisis and on what criteria, who talks to customers and authorities, who has authority to shut systems down. Name backups in the same act.
50 to 79
Roles exist but are concentrated in a few people, and availability is never guaranteed in a crisis. Name a backup for every role and secure a communication channel that works with the environment down. The test is simple: if your two most important people are unreachable, does the plan still move?
80 or above
Clear roles, with backups and an alternate channel. The refinement is training the judgment: rehearse the hard calls, like shutting down billing as a precaution or communicating before you are certain, so the first time is not live.
Below 50
Without a review after an incident or exercise, the company pays the price of the failure and throws away its product: the lesson. Start with a short meeting and one rule: hunt for causes, not culprits. The question that organizes everything: what do we know now that we wish we had known before?
50 to 79
Reviews happen, but the actions that come out of them compete with routine and lose. An owner, a deadline, and a check that it happened is what separates a lesson learned from a lesson noted. One cheap warning sign: the same failure appearing in two consecutive exercises.
80 or above
The learning cycle works, and it is what makes the company come out of each round stronger. The next gain is making the curve visible: show leadership the evolution between cycles, because readiness leadership can see is readiness that keeps its budget.
Pick one critical business process and start there. A single cycle already shows you where the weaknesses are and how far your defenses have moved.