6 domains · 50 questions · PRA

CQUEST cyber resilience self-assessment

A self-assessment built on the Bank of England's public CQUEST questionnaire — the cyber resilience maturity check PRA-regulated firms know well. Answer 50 questions across 6 domains and get a RAG heat-map, domain spider diagrams, and your priority gaps. Progress saves as you go.

GL · Governance and Leadership0 / 50 · domain 1/6

0/8 in this domain · pick the closest description (A strongest → D weakest)

Q1 Does a formally documented cyber security strategy exist and who is it approved by within the organisation?

Q2 Does a formally documented framework (including policies, standards, and delivery programme) exist to maintain your security posture and to deliver the cyber security strategy?

Q3 Has a senior executive been appointed who is accountable for the oversight and delivery of cyber security within the organisation?

Q4 What level of cyber security knowledge and skills exists at the senior executive level?

Q5 Are risks to cyber security managed effectively?

Q6 To what extent are cyber and related skills held across the security, risk, and audit functions?

Q7 Has the effectiveness of cyber controls been independently assessed against the control objective?

Q8 To what extent is management information (MI), including Key Risk Indicators (KRIs), used to inform decision makers on the residual risk levels against risk appetite for cyber defined risks?

Progress saves automatically — you can come back later.