Onnex
Your business has the answer.
Let Onnex find it.
LOADING
. . .
Completed
0

FREE TOOLS › TOOL 01

AI Security Readiness Scorecard

Fifteen questions across inventory, controls, validation, evidence and governance. Answer honestly, because the only person seeing this is you. Nothing is transmitted anywhere and there is no email field at the end.

Copy needed

Each question's category, its source note and the full scoring method are final, but the fifteen question texts are not. The scoring below is live; the questions are placeholders until those arrive.

  1. 1 / 15 Inventory

    Question 1's wording is not finalised yet.

    You cannot secure what you have not counted. Shadow AI appeared in 43% of breached organizations in IBM's 2026 study, up from 20%.

  2. 2 / 15 Inventory

    Question 2's wording is not finalised yet.

    Excessive Agency moved to third in the OWASP LLM Top 10 for 2026. An agent that can act is a privileged user.

  3. 3 / 15 Inventory

    Question 3's wording is not finalised yet.

    Retrieval turns your own document store into an untrusted input channel. Indirect injection is planted in content you own.

  4. 4 / 15 Controls

    Question 4's wording is not finalised yet.

    A WAF inspects structure. A prompt injection is well-formed text. They are different problems and one control does not cover both.

  5. 5 / 15 Controls

    Question 5's wording is not finalised yet.

    Published research reports evasion of up to 100% against production model-based guardrails (Hackett et al., LLMSec 2025).

  6. 6 / 15 Controls

    Question 6's wording is not finalised yet.

    Invariant Labs demonstrated exfiltration succeeding even with user confirmation, because the interface hid the tool arguments.

  7. 7 / 15 Controls

    Question 7's wording is not finalised yet.

    Sysdig observed roughly $50,000 of stolen compute in 4.5 days from a single monitored proxy. Monthly alerts run too slowly to matter.

  8. 8 / 15 Controls

    Question 8's wording is not finalised yet.

    Sensitive Information Disclosure is second in the OWASP LLM Top 10 for 2026. Egress is half the attack surface.

  9. 9 / 15 Validation

    Question 9's wording is not finalised yet.

    Attack techniques change monthly. MITRE ATLAS now ships monthly content releases. A test from last year describes last year.

  10. 10 / 15 Validation

    Question 10's wording is not finalised yet.

    Models get swapped, agents get new tools and prompts get rewritten. Each of those invalidates the previous test.

  11. 11 / 15 Validation

    Question 11's wording is not finalised yet.

    A guardrail that catches the OWASP sample payloads and fails against character injection is a false sense of security.

  12. 12 / 15 Evidence

    Question 12's wording is not finalised yet.

    Every regulatory regime in force converges on the same demand: evidence, not assurance.

  13. 13 / 15 Evidence

    Question 13's wording is not finalised yet.

    This is the question that starts most AI security programs, usually about a week too late.

  14. 14 / 15 Governance

    Question 14's wording is not finalised yet.

    68% of breached organizations in IBM's 2026 study had no completed AI governance policy, up from 63%.

  15. 15 / 15 Governance

    Question 15's wording is not finalised yet.

    Unowned risk becomes everyone's problem at exactly the wrong moment.

Fifteen questions, each worth up to ten points, 150 points total, normalised to 100. Weighting is even by design. The three-point answer scale (Yes, Partly, No) is our own interpretation of the scoring method — the arithmetic is fixed, the answer options are not.

Unanswered questions count as zero, which is deliberate. Not knowing is a finding.

Where the points went missing

Method. Fifteen questions, each worth up to 10 points, 150 points total, normalized to 100. Weighting is even by design, because we have no defensible basis for claiming inventory is worth 1.4 times validation. This is a structured self-assessment and a conversation starter, not an audit, a certification or a substitute for testing. Statistics cited in the question notes come from IBM's Cost of a Data Breach 2026 (29 July 2026), the OWASP GenAI LLM Top 10 for 2026 (3 August 2026), MITRE ATLAS release 2026.07, Sysdig LLM jacking research, Invariant Labs MCP tool-poisoning disclosure (April 2025), and Hackett et al., arXiv:2504.11168 (LLM Sec 2025).