Free cybersecurity assessment

Eight questions that show where you're exposed.

No jargon and no sales pitch. Answer honestly and you get a score, plus the specific things we would fix first and why they matter. You see all of it before we ask who you are.

8 questions
About 2 minutes
Your score before any form
Cybersecurity readiness
Question 1 of 8

Is multi-factor authentication enforced on email and remote access for every single user?

Not offered — enforced, with no exceptions for executives or service accounts.

Enforce MFA across Microsoft 365 and every remote-access path.

This is the single highest-value control available to you, and the one most often left partly deployed. Exceptions are where breaches start.

Are your backups immutable, and has a restore actually been tested in the last 90 days?

Ransomware now targets backups first. An untested backup is an assumption.

Move to immutable backups and schedule quarterly restore tests.

Immutable means the backup cannot be altered or deleted, even with stolen admin credentials. A restore you have never performed is not a recovery plan.

Is managed EDR running on every endpoint, monitored by someone outside your own team?

Detection nobody is watching is just logging.

Deploy managed endpoint detection with 24/7 human monitoring.

Antivirus stops known threats. EDR catches behaviour — but only helps if someone responds at 3am, which is not a job for your internal team.

Do you have a written incident response plan that names who to call at 2am?

The worst time to design a response is during the incident.

Write and rehearse an incident response plan with named contacts.

It needs names and numbers, not roles: who declares an incident, who talks to staff, who calls your insurer, and in what order.

Do staff get security awareness training with simulated phishing at least quarterly?

Most successful attacks still begin with one person clicking one link.

Start quarterly awareness training with phishing simulation.

Annual training is forgotten by March. Quarterly simulation gives you a measurable click rate you can actually drive down.

Do you know which systems hold personal or payment data, and where that data physically lives?

You cannot protect, or report on, data you haven’t mapped.

Map your data: what is held, which system holds it, which country it sits in.

This is the first question any regulator, insurer or enterprise client asks — and increasingly the first one your own customers ask.

Is administrative access limited by role, with no shared admin passwords?

Shared credentials mean no accountability and no clean revocation.

Scope administrative access by role and eliminate shared credentials.

When everyone has admin, one compromised account compromises everything — and you cannot tell afterwards who did what.

Have you had an independent security review or penetration test in the last 12 months?

No team can credibly audit its own work.

Commission an independent security review.

An outside test finds the assumptions your own people cannot see, and gives you something concrete to show clients and insurers.

Your result

Your result

01
Action

Detail

Significant exposure

Enough of the basics are missing that one convincing email could cost you a week. The first three items below take most of that risk away, and none of them are big projects.

Partially covered

You are not starting from nothing, but there are gaps someone would find before you did. Work through the list in order and you go from probably fine to genuinely defensible.

Broadly solid

Better run than most businesses your size. What is left is the gap between being secure and being able to prove it, which matters the first time an insurer, auditor or client asks.

Well covered

Genuinely strong. The value now is an outside pair of eyes to confirm the configuration matches the intention, and to keep it that way as you grow.

Want this written up properly?

We will turn your answers into a short written plan: what to fix first, what it involves, and what it costs. A named engineer writes it, not a template, and it arrives within two business days.

Your score is already yours — the form is only for the written plan. We do not share your data.

Thanks — that's booked in. Your roadmap will arrive within two business days. If something is urgent before then, call 647.476.5259.
That didn't send. Please check your email address and try again, or call us on 647.476.5259.
Action
Covered
0
/8
Not started
Covered
Gap
Unanswered

Priority actions

Anything you answer “No” to appears here straight away, most important first.

What the eight questions test

Security is layered, so the questions are too.

Each question maps to one of four layers. A gap in any single layer is survivable. Gaps in several at once is how a bad afternoon turns into a bad quarter.

Identity
2 of 8
Who can get in

Multi-factor authentication with no exceptions, and administrative access scoped by role instead of shared around.

Endpoint
1 of 8
What runs on the machines

Managed detection on every device, watched by someone outside your own team so an alert at 3am reaches a human.

Data
2 of 8
What you would actually lose

Backups that cannot be altered even with stolen credentials, restores that have genuinely been tested, and knowing which country the data sits in.

Response
3 of 8
What happens at 2am

A plan with names and numbers in it, staff who recognise a phishing attempt, and an outside review to catch what your own people cannot see.

The other half of the picture

Security is one half of it. The other half is whether the day to day actually works — tickets, planning, cost, and who turns up when something breaks. That is the IT health check: ten questions, about three minutes.

Take the IT health check