All insights
Published 15 July 2026 5 min read

Design a cyber assessment that asks for less data

A small-business cyber assessment should help someone decide what to improve without collecting the sensitive information it is meant to protect. Start by asking whether each input is necessary for scoring, routing or a clearly explained follow-up. If it is not, remove it.

Use broad choices, not incident narratives

Questions about MFA coverage, restore testing or supplier review can be answered with structured choices. There is usually no need to request passwords, customer records, system logs, health information, bank details or confidential incident descriptions. Make the prohibition visible before the first question.

Keep scoring deterministic

  • Version the questions, choices, weights and score bands.
  • Reject missing or unknown answers instead of inventing a result.
  • Use stable tie-breaking for priorities so results are reproducible.
  • Explain limitations: a self-assessment is not an audit, certification or guarantee.
  • If a model rewrites guidance, prevent it from altering scores or adding unsupported findings.

Choose the smallest useful storage boundary

A browser-local assessment can produce an immediate plan without creating a new database. If accounts, history or protected reports are genuinely required, document the responsible organisation, purpose, hosting, access, retention, deletion and processor boundaries before accepting real submissions.

Make privacy part of the workflow

Privacy risk assessment is not only a final policy task. Review the data flow when questions change, when an external provider is introduced and when a new follow-up or analytics use is proposed. The user should be able to see what changed and choose whether to continue.

Want help applying this?

Yefosec helps NZ & AU teams turn frameworks into operating discipline and evidence.