Free Cybersecurity Risk Assessment

Score your business cybersecurity posture in 5 minutes

10 questions. Immediate score. Prioritized action list. No sales pressure — you'll get an honest read of where you stand.

Step 1 of 333%
Identity · Q1
Is multi-factor authentication (MFA) enforced on every Microsoft 365 account?

MFA blocks over 99% of automated account-takeover attempts. 'Enforced' means users cannot bypass it.

Backup · Q2
Do you have tested, off-network backups (including Microsoft 365)?

Ransomware often deletes backups on the same network. Off-network / immutable backups + a real restore test = you can recover.

Endpoints · Q3
Do all workstations and servers run business-grade Endpoint Detection & Response (EDR)?

Consumer or free antivirus doesn't provide the visibility or response actions a business needs.

Email · Q4
Do you use advanced email filtering with anti-phishing and impersonation detection?

Native Microsoft 365 filters catch a lot, but not everything. Advanced filtering + external sender warnings = fewer clicks.

Network · Q5
Do you have a business-grade firewall with an active security services subscription?

Consumer routers don't provide intrusion prevention, threat feeds, or centralized logging.

Network · Q6
Is your business Wi-Fi separated from guest Wi-Fi and secured with modern encryption?

Guest devices should never sit on the same network as your servers and workstations.

Identity · Q7
Does your team use a business password manager (not browser storage)?

Password reuse is a leading cause of business breaches. A password manager makes long, unique passwords effortless.

People · Q8
Do you run ongoing security awareness training with phishing simulations?

Short, frequent training + real simulations catches the phishing emails that filters miss.

Endpoints · Q9
Is disk encryption (BitLocker or equivalent) enabled on every laptop and workstation?

A stolen unencrypted laptop is a data-breach notification event. Encryption makes it a lost asset.

Endpoints · Q10
Are OS, browser, and third-party patches applied within 30 days of release?

Most exploited vulnerabilities have patches available for weeks or months. Cadence matters more than perfection.

Answer all 10 questions to continue.

Your progress is saved automatically as you go.