Infrastructure Security Assessment: How Confident Should You Be?
Most technical leaders don’t have an infrastructure security problem they know about. The harder question is what they don’t know about yet.
That’s why we have built the Infrastructure Security Confidence Score, a FREE infrastructure security checklist that takes around ten minutes to complete. It’s a checklist designed for CTOs, technical directors and infrastructure leads who want to take a simple and honest view of their security posture without commissioning a full audit.

Why “no incidents” isn’t evidence of security
Infrastructure that has run for months or years without a security incident feels secure. But the absence of incidents only tells you that nothing has gone wrong yet, or that nothing has been noticed. It doesn’t tell you whether your controls are actually working.
In our experience, the gaps that cause real problems are very rarely dramatic. They are normally pretty quiet: either an admin account that was never removed when someone left, a vulnerability that was identified but never fixed, a backup that completes every night but has never been restored, or a security responsibility that everybody assumed their cloud provider was covering.
A good infrastructure security assessment separates what you can prove from what you are assuming, and that is the purpose of this scorecard.
What the infrastructure security checklist covers
Our scorecard asks 24 questions across six areas of cloud infrastructure security. Each question is scored honestly: 2 points is only acheived when you’re confident something does happen and can prove it, not when it’s supposed to.
1. Know your risk
Do you have a current view of your security posture? Are vulnerabilities regularly assessed and, most importantly remediated through to completion rather than just being identified?
2. Control access
Does your infrastructure access follow the least-privilege principles? Is privileged access tightly controlled, regularly reviewed and promptly removed when someone leaves the organisation or changes role?
3. Understand responsibility
Do you know where your cloud provider’s security responsibility ends and where yours begins? The shared responsibility model is one of the most common sources of unowned risk. This section also covers internal ownership and the security risk from third parties and dependencies.
4. Detect problems
Is your critical infrastructure continuously monitored? Are the alerts actionable, and is someone responsible for responding to them 24/7? Could you reconstruct what happened during an incident?
5. Prepare for failure
Is there a tested response for a compromised account or a critical component? Have backups been tested by actually restoring them, and are they protected from the same event that hits production, such as ransomware?
6. Protect the foundations
Is sensitive data encrypted in transit and at rest, with keys properly managed? Are secrets held in a secrets manager rather than in code, config files or chat? Are any infrastructure changes reviewed and controlled, and do you know where your data lives in line with UK GDPR?
How the scoring works
Each question on the infrastructure security checklist is answered either Yes (we do this consistently and can prove it), Partly (it exists, but with gaps) or No / Don’t know. Your result gives you an overall score out of 48, a score for each of the six areas, your weakest area, and your three highest-priority gaps, pulled automatically from your lowest-scoring answers.
The individual section scores are usually more revealing than the total. A strong overall score can still hide an area where confidence rests almost entirely on assumption.
What this assessment is not
The scorecard is a fast way to challenge assumptions, not a replacement for formal security work. It is not a penetration test, a vulnerability scan, an ISO 27001 audit or a formal security assessment. It does not prove if your infrastructure is secure.
What it does is replace “I think we’re covered” with a clearer view of where you have evidence, where you have uncertainty, and what deserves attention next.
Who the scorecard is for
The scorecard is written for technical leaders who carry the accountability for infrastructure risk, particularly in regulated sectors such as fintech, financial services and edtech, where security posture increasingly needs to be evidenced to customers, auditors and regulators.
It is equally useful whether your infrastructure runs on AWS, Azure, private cloud or on-premise hardware, and whether it’s managed in house, by a provider, or a mix of both.
What to do with your results
Start with your weakest area and your three highest priority gaps. For each one, ask:
- What would happen if this gap were exploited or failed today?
- Who owns closing it?
- What evidence would show that it’s been resolved?
Most gaps don’t need a major project. Many can be closed with a conversation, a review or a small process alteration. The value is in knowing which ones matter the most.
If you’d like a second opinion, you can book a free 20-minute infrastructure risk review with Pipe Ten. We’ll look at your top three gaps and what they mean for your platform. No pitch, just a straight answer.
Take the free Infrastructure Security Confidence Score
Frequently asked questions
How long does the infrastructure security assessment take?
Around ten minutes. There are 24 questions across six areas.
Is the scorecard free?
Yes, completely. You’ll just be asked for your name and email address to see your personalised results.
Is this the same as an ISO 27001 assessment?
No. The scorecard covers many areas that ISO 27001 also addresses, such as access control, monitoring and backup, but it isn’t a gap analysis or audit. If you’re preparing for ISO 27001, our ISO 27001 Infrastructure Readiness Checklist is a better place to start.
What is the cloud shared responsibility model?
This is the division of security responsibilities between a cloud provider and its customer. Providers such as AWS and Azure secure the underlying platform, but configuration, access, the patching of your systems and data protection usually remains your responsibility.
Who built the scorecard?
Pipe Ten, a Sheffield-based, ISO 27001 certified cloud infrastructure and security consultancy. We work as a fractional infrastructure team for businesses in regulated sectors, and the questions reflect the gaps that we come across most often in real infrastructure reviews.
Take the infrastructure security assessment
Ten minutes, 24 questions, and an honest picture of where your infrastructure security confidence is earned and where it’s assumed.
Take the free Infrastructure Security Confidence Score
Author: Gavin Kimpton
A founder and CEO/CFO of Pipe Ten, Gavin has been a leader in the digital sector for over 30 years, specialising in web application hosting, domain registration, and international site launches. He has navigated evolving internet governance, from new top-level domains to security and compliance. Under his leadership, Pipe Ten became a Nominet-accredited channel partner, reflecting his deep expertise in the digital ecosystem.

Author: