Practical Resource · Leadership and Programme Teams

Cybersecurity and compliance readiness checklist

Use these questions to identify the next practical actions across governance, ISO 27001, DPDPA, technical security, incidents and suppliers.

Published 13 August 2026Reading time: 8 minutesUngated resource

How to use this checklist

For each statement, record Yes, Partly, No or Unknown. Treat “Unknown” as a finding: it normally means ownership or evidence is unclear. Add an owner and target date for every Partly, No or Unknown response.

1. Governance and accountability

  • Leadership has approved the organisation's security objectives and risk appetite.
  • Material cyber risks have named business owners, not only technical owners.
  • Executive reporting shows decisions, overdue actions, incidents and residual risk.
  • Security responsibilities are included in relevant roles, projects and supplier relationships.
  • Policies are reviewed, communicated and supported by operating procedures.

2. Assets, data and risk

  • Essential services, systems, applications, cloud resources and information assets are inventoried.
  • Dependencies and critical suppliers are mapped to important business services.
  • Information-security risks use defined likelihood, impact and acceptance criteria.
  • Treatment actions have accountable owners, dates and evidence of completion.
  • Changes to systems and services trigger security and privacy review.

3. Identity, systems and vulnerability management

  • Privileged access is restricted, reviewed and protected with strong authentication.
  • Joiner, mover and leaver processes remove unnecessary access promptly.
  • Secure configuration standards exist for endpoints, servers, network and cloud services.
  • Vulnerabilities are prioritised by exploitability, exposure and business impact.
  • Independent security testing is scoped, authorised, remediated and retested.

4. Detection, incidents and continuity

  • Logs from priority systems reach an accountable monitoring process.
  • Detection use cases reflect likely threats to essential services and sensitive data.
  • Incident roles, severity levels, escalation contacts and decision authority are documented.
  • Exercises test technical response, leadership decisions, communications and recovery.
  • Backups and recovery procedures are protected and tested against defined objectives.

5. ISO 27001 readiness

  • The proposed ISMS scope, context and interested parties are documented.
  • A repeatable risk assessment and treatment method is approved and used.
  • The Statement of Applicability reflects actual risk treatment and control decisions.
  • Every applicable control has an owner and current operating evidence.
  • Internal audit and management review are planned before certification assessment.

6. DPDPA and privacy operations

  • Personal-data categories, purposes, systems, recipients, processors and retention are mapped.
  • Notices and consent choices accurately describe the processing that occurs.
  • Requests, grievances and withdrawal of consent can be authenticated, assigned and evidenced.
  • Processor contracts and oversight address security, assistance, deletion and incidents.
  • Privacy incidents connect to the organisation's wider response and decision process.

7. Suppliers and assurance

  • Supplier criticality influences due diligence and contractual security requirements.
  • Assurance evidence is reviewed rather than collected without evaluation.
  • Contracts define incident reporting, access, data handling and exit obligations.
  • Material supplier changes and concentration risks reach accountable governance forums.
  • Exit plans protect data availability, return, deletion and operational continuity.

Turn answers into a 30-day action plan

  1. Select the ten gaps with the greatest effect on essential services, sensitive data or regulatory exposure.
  2. Assign one accountable owner and one measurable completion condition to each gap.
  3. Separate quick corrections from changes requiring budget, procurement or architecture decisions.
  4. Collect evidence as work is completed rather than immediately before an audit.
  5. Review progress with leadership at the end of the month and approve the next risk-based cycle.