VENTRiQ Cyber Readiness Scorecard

A self-assessment for chambers and legal practices

What does your practice look like from the outside?

Every chambers publishes more about its own systems than it realises. Email records, certificates, security headers. In a few minutes, this assessment shows you what is already visible from outside, asks a handful of questions about the inside, and gives you a clear readiness score with practical next steps.

The checks are non-invasive. We only read the public records and homepage that any visitor or mail server already sees, and only on the domain you submit yourself. Nothing is scanned, probed or tested.

Start the assessment

How it works

1. Enter your domain

You submit your own domain and confirm you want it checked. That consent is the gate. No check runs without it.

2. Answer seven questions

Short, plain questions about how your practice runs. No jargon, no trick questions. The outside view only tells half the story.

3. Get your score

A readiness score out of 100, what it means, and where practices like yours most commonly close gaps first.

Your assessment

We check one domain per submission. Your answers are used only to calculate your score. If you choose to receive the full report, your email is used to send it and to follow up once. Nothing else.

Is your case and client data stored somewhere ?

For example, managed cloud storage where each person only sees what they need, rather than shared drives open to everyone.

Is in place across the practice?

A second step at sign-in, such as an app prompt or code, on email and the systems that hold client data.

Does client onboarding follow a structured with an ?

Identity checks recorded in a consistent process, rather than handled manually case by case.

Is there a documented ?

A written plan for who does what if something goes wrong, including regulatory notification.

Does one named person own security across the practice?

Someone accountable for keeping systems maintained, whether in-house or a trusted provider.

Is client payment handling ?

Card payments taken through a compliant provider, with no card details written down or held in inboxes.

Are devices and software kept up to date on a regular cycle?

Updates applied promptly across the machines that touch client work, not left to individuals.

Are complaints handled through a documented process, independent of the practitioner?

A route a client can use with confidence, rather than complaints going to the person complained about.

Are entity-level policies maintained and kept current as requirements change?

Written policies that are reviewed and updated, not drafted once at authorisation and left.

Is it clear who reports what to the regulator, and when?

Named responsibility for regulatory notifications and returns, rather than working it out when something arises.

Are and compliance records stored somewhere structured and retrievable?

If the regulator asked tomorrow, the records could be produced without a search through inboxes.

Your readiness score

0 / 100
05075100

Unlock your full report

Your score is yours to keep. The full breakdown sits underneath: what is visible from the outside, the internal picture, and where to start. Tell us who you are and it opens here, with your personalised report ready to download.

Used to follow up about your results. Your details are never shared.

Thank you. Your full results are open below, and your personalised report is ready to save.