Governance, risk and compliance

Know where you stand on cyber security, and what to do next.

GoRaC brings your cyber security assessments, Microsoft 365 monitoring, policies and a clear security score into one secure place, with specialists alongside you to turn it all into a plan.

Invited to GoRaC? Use the link in your email, or sign in with your work email address.

What's included

Everything you need to stay secure and compliant

Start with an assessment, then let monitoring, policies and your score keep you on track.

Assessments

Cyber Essentials readiness and wider cyber threat reviews, answered in a secure portal or completed with one of our specialists.

Microsoft 365 monitoring

A read-only connection to Microsoft 365 and Entra ID that checks the settings that matter, every day, and tells us when something changes.

A security score

One number out of 100, fair to your size and licences, with a ranked list of what would make the biggest difference next.

Policies that fit

Security policies tailored to how you actually work, reviewed and accepted in the portal, with reminders when they're due for review.

Clear reports

Plain-English findings, current threat intelligence and a prioritised plan you can share with your board or insurer.

Everything in one place

Assessments, documents, your score and anything that needs you, with notifications so nothing slips.

Microsoft 365 and Entra ID

Your Microsoft 365 set-up, checked every day

Connect Microsoft 365 once: your administrator approves read-only access, and we check the settings behind most real-world attacks from then on. When something drifts, such as a new administrator or someone without multi-factor sign-in, we know about it and can put it right.

Checks run only where your licences support them, so you're never marked down for features you don't have. Results feed straight into your assessment and your score.

What we check

  • Multi-factor sign-in for everyone, and stronger sign-in for administrators
  • Administrator accounts kept few, separate and, where licensed, only active when needed
  • Older sign-in methods that attackers favour switched off
  • Accounts and guests nobody uses any more
  • Users Microsoft flags as at risk (Entra ID P2)
  • Devices on unsupported systems, out of compliance, or without antivirus running (Intune)

Works with any Microsoft 365 business plan; Entra ID P1/P2 and Intune add more checks.

A score you can trust

  • Measured against what's reasonable for an organisation of your size and licences, so a well-run small business can score as highly as a large one
  • Based on outcomes, not products: any sensible way of getting it right counts
  • The fundamentals come first: missing one caps the score, however well everything else is done
  • Every point is explained, with the actions worth the most listed first

Security score

One number, and exactly how to improve it

Your score out of 100 brings together your assessment, your Microsoft 365 settings and your policies. It comes with a to-do list ranked by what makes the most difference for the effort, and where we can do the work for you, we'll say so: just ask.

It updates as things change, and you can watch it improve month by month.

How it works

From first question to a plan you can act on

Four steps, with GoRaC alongside you the whole way.

  1. Step 1

    Connect and set up

    We set up your assessment and, if you use Microsoft 365, your admin approves a read-only connection once.

  2. Step 2

    Answer, or we do it together

    Your team answers in the portal at their own pace, or we sit down with you and complete it on your behalf.

  3. Step 3

    We review and score it

    Our specialists check every answer alongside what monitoring shows, then work out your security score.

  4. Step 4

    Act, then keep improving

    You get a report, the policies you need and a clear to-do list. Monitoring and reviews keep your score current.

Answer in your own time

We invite the right people at your organisation to a secure portal. There are no right or wrong answers to aim for: just tell us how things are today, and we'll do the rest.

  • Plain-English questions

    Each question comes with a short explanation. If something doesn't apply to you, just say so.

  • Work on it together

    Invite colleagues and answer side by side. You'll see each other's changes as they happen.

  • Saves as you go

    Every answer is saved automatically, so you can stop and pick up where you left off.

  • Attach supporting files

    Add a policy, screenshot or report to any question if it helps explain your answer.

Or let us complete it with you

Short on time, or not sure of the technical detail? One of our specialists can work through the assessment with you, or complete it on your behalf from what we know of your systems.

  • A single conversation instead of a questionnaire
  • Technical questions answered by people who do this every day
  • The same thorough review, score and report either way

Policies and documents

Policies that describe how you really work

Cyber Essentials, insurers and your own customers ask for written policies. We prepare them for you, proportionate to your size, and they count towards your score once accepted.

  • Drafted from a library of proven templates, then tailored to your organisation and how it really works
  • Shorter, plainer versions for small businesses where the owner signs everything off
  • Read, accept or ask for changes in the portal, and download a PDF for your records
  • Ask your staff to read and confirm them with a personal link, and see who has
  • Already have your own? Upload them and we'll count them towards your score
  • Reminders when each document is due for review

Your report

Clear answers, not a wall of jargon

Every report is reviewed by our team before it reaches you, and comes as a document you can share with your board or insurer.

Cyber Essentials readiness

A clear view of whether you're ready to certify, and what stands in the way if not.

Current threat intelligence

The threats active right now against organisations like yours, researched for every report.

A prioritised action plan

What to fix first, why it matters, and practical steps to get there.

Get more from what you pay for

Security features already in your licences, or a small upgrade away, that you may not be using.

Security

Built the way we'd advise you to build it

What you share with us describes your systems in detail, so we protect it accordingly.

  • Hosted in the UK

    Your data is stored and processed in London.

  • Kept apart

    Each organisation's information is isolated at the database level, not just hidden on screen.

  • Read-only Microsoft access

    Monitoring can read settings but never change them, and your admin can remove it at any time.

  • No passwords to manage

    Clients sign in with a one-time code sent to their work email.

  • Two-factor for our team

    Everyone at GoRaC signs in with a password and an authenticator app.

  • Private file storage

    Uploaded files are never public, and download links expire within minutes.

Read our privacy notice for how we use personal information.

Ready to see where you stand?

When your assessment is ready, we'll email you a link straight to it. Already set up? Sign in with your work email.

Sign in