How mature is your IT, really? A BioTech self-assessment

25 questions, about seven minutes, no email address required. The scoring happens right here in your browser either way. By default we also record your answers so we can see how this lands – one click on the checkbox below the score button turns that off, and the score still shows exactly the same.

Running a BioTech business

1. Which ELN / LIMS do you run?
2. Is your ELN / LIMS vendor-supported and on a current version?
3. Is primary research data backed up somewhere a ransomware event could not reach?

Irreplaceable is the operative word – you cannot re-run a three-year study.

4. Do any of your systems need to be validated for GxP or 21 CFR Part 11?
5. Could you pass a partner's or investor's IT diligence questionnaire today?
6. Are instrument PCs on supported operating systems?
7. Are the instruments on their own network segment, separate from the office computers?

Analysers and sequencers routinely run operating systems no longer supported and cannot take a security agent. That is usually unavoidable. Leaving them on the same flat network as the laptop that opens email is not.

8. Is your method development and research data protected any differently from ordinary files?

Irreplaceable is the operative word. A competitor or a departing employee taking method work is a loss no backup and no notification letter puts right.

The basics

9. Are your systems and data backed up automatically, every day?

File sync is not backup. OneDrive, Dropbox, Google Drive and SharePoint copy your mistakes and your ransomware to the cloud just as faithfully as your work. What counts here is a separate, versioned copy you could restore from after the original was encrypted.

10. When did somebody last actually RESTORE from a backup to prove it works?

A backup nobody has restored from is a hypothesis, not a backup.

11. Is multi-factor authentication switched on for email and remote access?

Partial MFA is not partial compliance. Almost every rule that applies to you treats this as a yes or no, so this answer can cap the whole result on its own.

12. Do you carry cyber-liability insurance?
13. How do computers and servers get their security updates?
14. What protects the laptops and desktops?
15. Is there anything in front of your email beyond the built-in spam filter?

Phishing is still how most of these firms actually get hit.

16. When somebody leaves, how quickly do their accounts get shut off?
17. Who owns IT day to day?
18. If your main systems were unavailable tomorrow morning, is there a written plan?
19. Do people here get security training, and does anyone test whether it stuck?

Almost every incident starts with somebody being convinced to do something reasonable-looking. Training that is watched once at induction and never tested is a record that it happened, not a defence.

20. When did somebody last check WHO can reach what, and take away the access they no longer need?

Access accumulates. People change roles and keep the old permissions, and the account that gets compromised is usually the one that could reach far more than that person's job required.

21. Do you know which apps and cloud services your team signed up for without telling anyone?

Not a discipline question. Client data ends up in whatever tool made somebody's week easier, and you cannot protect, back up or hand back data you do not know exists.

Where you stand on compliance

22. Where do you operate?

We are Seattle based, so where a rule below is named, it is the Washington one. If you work elsewhere there is almost always a state equivalent and the question is the same. This answer is not scored.

23. Do you have a written information security program covering HIPAA/FDA (subset)?
24. When was your last written risk assessment?
25. If a client, an auditor or an insurer asked you to evidence your controls this week, could you?

Not whether the controls exist – whether you can PROVE they do.

26. Is there an incident-response plan naming who does what, and by when?
27. Do you check the security of the vendors who touch your client data?