Skip to content

Free tool

What can your network actually prove?

Eight questions about what your network can currently prove. It takes about two minutes, nothing is sent anywhere, and you get the result immediately.

Question 1 of 8Can you produce a current, accurate list of every device connected to your network?

Enforcement against an inaccurate inventory is the most common cause of a failed rollout.

Question 2 of 8Is your network access control actually denying anything today?

A large share of deployments authorise everything, indefinitely.

Question 3 of 8What proportion of endpoints authenticate with a certificate rather than a MAC address?

A MAC address is broadcast in plaintext and trivially spoofed. It is an inventory lookup, not device trust.

Question 4 of 8When did anyone last review the bypass and exception list?

Exception entries accumulate and are almost never removed. Each one is a permanently authorised identifier.

Question 5 of 8Could a camera or badge reader reach a domain controller if it tried?

Weak authentication is acceptable only when the authorisation scope is correspondingly narrow.

Question 6 of 8Do you know what your policy would deny if you turned enforcement on tomorrow?

This is the single question that determines whether enforcement is a controlled change or a gamble.

Question 7 of 8Is there a rollback for an enforcement change that someone has actually executed?

A rollback that has never been run is an intention, not a rollback.

Question 8 of 8Who owns certificate rotation, and is the calendar written down?

Certificate expiry is the most common self-inflicted outage in this space, and always foreseeable.

Answer all 8 questions to see your result.