Assess the operating maturity behind your website, search visibility, business email, measurement, security, resilience and digital governance.
Digital operations field guide
Treat readiness as an operating system, not a checklist score.
The assessment asks whether the business can substantiate key practices across website conversion, search, email, analytics, security, resilience and governance. A low category score points to an operating gap that deserves ownership and evidence; it is not a certification or technical audit.
CHAPTER 01Website and search readiness
A functioning website should explain the offer, support priority customer tasks and remain discoverable through accurate technical signals and market information. Readiness means the business can maintain those conditions and verify important changes rather than relying on a one-time launch.
CHAPTER 02Email and measurement readiness
Business email depends on domain ownership, authentication, routing, account recovery and operating discipline. Measurement depends on defined conversions, lawful collection, campaign context and reconciliation with real business outcomes. Both systems require continuing ownership.
CHAPTER 03Security and recovery readiness
Multi-factor authentication, controlled administrative access, backups, incident handling and recovery procedures reduce avoidable operational exposure. NIST CSF 2.0 organizes cybersecurity risk work around Govern, Identify, Protect, Detect, Respond and Recover; this assessment borrows that lifecycle without claiming NIST certification.
CHAPTER 04Governance turns technical controls into durable practice
Someone must own domains, systems, vendors, access, renewals and change decisions. An undocumented environment can appear healthy until an employee leaves, an account expires or a provider fails. Readiness therefore includes responsibility and recovery, not only installed technology.
Evidence that makes the result more useful
Ownership records
Current owners, administrators, billing contacts and recovery methods for critical systems.
Configuration evidence
Live domain, mail, analytics, backup and security settings that can be verified rather than assumed.
Operating records
Recent tests, change records, incident handling, lead reports and restoration evidence.
Responsibility map
Named roles for maintaining, approving and recovering important digital systems.
Limits that should remain visible
- The score is based on user declarations and does not independently verify technical compliance.
- It is broader than cybersecurity and is not a NIST, accessibility, privacy or security certification.
- Regulatory obligations depend on the organization, data and jurisdiction and require appropriate professional advice.
Questions after using the tool
What should I fix first after a low score?
Start with gaps that can interrupt operations, expose critical access, lose customer enquiries or make recovery impossible. Then sequence improvements by dependency.
Is a high score proof the systems are secure?
No. The assessment records declared practices. Technical testing, configuration review and ongoing monitoring remain separate activities.
How often should readiness be reviewed?
Review when systems, vendors, staff, domains, markets or critical workflows change and on a routine schedule appropriate to the business.
Who should own the roadmap?
Each action needs an accountable business owner even when a specialist provider performs the technical work.
Primary references and next paths