1. Assessment
We run structured interviews and technical evaluations covering the critical security disciplines, from identity management to incident response.
The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.

OITENTA20®: IT RISK ASSESSMENT
The greatest risk is the one you don't know about. oitenta20® maps your business's vulnerabilities, measures your security maturity, and hands you a prioritized plan backed by data instead of guesswork.
HOW IT WORKS
Interviews and technical assessments across the core information security disciplines, consolidated into an executive decision map.
We run structured interviews and technical evaluations covering the critical security disciplines, from identity management to incident response.
Each discipline receives a maturity and exposure score. The analysis shows you where immediate attention delivers the greatest return in risk reduction.
You receive the map of the 20 highest-impact controls, capable of mitigating about 80% of the risks in your environment, with sequencing, estimated effort, and arguments ready to take to the boardroom.
SELF-ASSESSMENT
Objective questions about what your company can see of its own environment. The result shows where visibility is real and where risk is running without an owner.
Servers, endpoints, applications, cloud and whatever else processes business data. A spreadsheet counts, as long as someone maintains it.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
Without a reliable inventory, everything else stands on sand: you cannot protect, monitor or recover what you do not know exists. Start with whatever processes critical data and accept that the first version will be incomplete. It already changes the conversations.
50 to 79
The inventory exists but has blind spots, and blind spots are exactly where incidents like to be born. Assign an owner and an update cadence, and reconcile the inventory against what the network actually shows.
80 or above
Asset visibility is among the strongest fronts in your answers. The next gain is connecting the inventory to decisions: business criticality per asset, not just the technical list.
Below 50
Access is the modern attacker's favorite door: walking in with a valid password is cheaper than exploiting a flaw. Leaver reviews, MFA on administrative accounts and the end of shared accounts are the three highest-return moves.
50 to 79
The basics exist but depend on people remembering. The jump in this range is taking access review out of goodwill: defined deadline, defined owner, and verification that it happened.
80 or above
Well-managed identities in your answers. The next refinement is usually temporary privileged access: nobody should carry a permanent privilege they use once a month.
Below 50
Without a vulnerability process, the company discovers its own flaws at the same time as the attacker, and the attacker searches harder. A regular scan with remediation deadlines by criticality is the best-value control on this list.
50 to 79
Scanning exists, but remediation moves at its own pace, and the distance between finding and fixing is exactly the attacker's window. Measuring that window by criticality, and reporting it, tends to shorten it on its own.
80 or above
A mature process in your answers. The natural next step is validation by test: a pentest confirms whether what the process says is closed resists someone trying to open it.
Below 50
Today, an incident at your company would probably be discovered by a third party: a customer, a bank, the attacker asking for ransom. Storing the logs of critical systems is the first step, and it is cheaper than it looks.
50 to 79
The logs exist, but response is a muscle, and unexercised muscle atrophies. One tabletop exercise per year, with leadership in the room, reveals in two hours what the written plan hides.
80 or above
Structured detection and response. The next gain is shortening the time between signal and action: automate the isolation of the obvious and train judgment for the rest.
Below 50
Untested backups and unknown recovery times mean the cost of a bad day is unknown. Before any new tool: actually restore a critical backup and time it. The number that comes out defines the conversation.
50 to 79
Recovery exists, but the deadlines are estimates, not measurements. Aligning what IT can do with what the business can survive, per system, is the missing exercise, and it tends to surprise both sides.
80 or above
Mature continuity in your answers. Keep test restorations on cadence and include the fastest-growing scenarios: ransomware with reachable backups and dependence on a critical third party.
Below 50
Without risk assessment, the security budget goes to whoever shouts loudest, and the latest scare always shouts loudest. A structured picture of exposure changes the nature of the boardroom conversation.
50 to 79
Reporting exists and criteria exist, but the bridge between technical risk and business decision is still handmade. Standardizing that translation, exposure in impact language, is what stops the budget from oscillating.
80 or above
Governance working: risk assessed, leadership informed, investment with criteria. The challenge is freshness, because the assessment ages faster than its report.
Schedule a conversation, see a real sample oitenta20® report, and picture what it would reveal about your environment.