Free Cybersecurity Risk Assessment
Answer 20 quick questions to find out how your business scores across five critical security areas. Takes about 3 minutes.
Identify
Know what you have and where the risks are
- Do you have a complete list of all devices, software, and accounts used in your business?
Yes / No - Have you done a formal risk assessment in the past 12 months?
Yes / No - Do you classify your data by sensitivity (e.g., public vs. confidential vs. regulated)?
Yes / No - Do you vet third-party vendors for security before sharing data with them?
Yes / No
Protect
Guard your systems and data from threats
- Is multi-factor authentication (MFA) required on all business accounts?
Yes / No - Do employees only have access to the systems and data they need for their role?
Yes / No - Is sensitive data encrypted both in storage and when sent over the internet?
Yes / No - Are software updates and security patches applied within 30 days of release?
Yes / No
Detect & Respond
Spot threats early and act fast
- Do all company devices have endpoint protection (antivirus/EDR) that is actively monitored?
Yes / No - Are security logs from your network and systems reviewed on a regular basis?
Yes / No - Do you have a written incident response plan that your team knows how to follow?
Yes / No - Is there a clear process for who to call and what to do if a security event happens?
Yes / No
Recover
Bounce back when something goes wrong
- Do you test your data backups at least quarterly to make sure they actually work?
Yes / No - Do you have a written disaster recovery plan with step-by-step instructions?
Yes / No - Have you defined how quickly your business needs to be back online after an outage (RTO/RPO)?
Yes / No - Is there a documented process for revoking access when an employee leaves the company?
Yes / No
Governance
Build a culture of security with policies and training
- Do all employees complete security awareness training at least once a year?
Yes / No - Does your company have a written acceptable use policy for devices and internet?
Yes / No - Do you track compliance with industry regulations (HIPAA, PCI-DSS, SOC 2, etc.)?
Yes / No - Do you have a documented process for handling data breaches, including notification requirements?
Yes / No
Your Security Score
Get your detailed security report
See exactly which areas need attention, with specific recommendations based on your results.
Your security breakdown by area
Want expert help closing these gaps?
Our team can walk you through your results and build a plan to strengthen your weakest areas.