No jargon and no sales pitch. Answer honestly and you get a score, plus the specific things we would fix first and why they matter. You see all of it before we ask who you are.
Not offered — enforced, with no exceptions for executives or service accounts.
This is the single highest-value control available to you, and the one most often left partly deployed. Exceptions are where breaches start.
Ransomware now targets backups first. An untested backup is an assumption.
Immutable means the backup cannot be altered or deleted, even with stolen admin credentials. A restore you have never performed is not a recovery plan.
Detection nobody is watching is just logging.
Antivirus stops known threats. EDR catches behaviour — but only helps if someone responds at 3am, which is not a job for your internal team.
The worst time to design a response is during the incident.
It needs names and numbers, not roles: who declares an incident, who talks to staff, who calls your insurer, and in what order.
Most successful attacks still begin with one person clicking one link.
Annual training is forgotten by March. Quarterly simulation gives you a measurable click rate you can actually drive down.
You cannot protect, or report on, data you haven’t mapped.
This is the first question any regulator, insurer or enterprise client asks — and increasingly the first one your own customers ask.
Shared credentials mean no accountability and no clean revocation.
When everyone has admin, one compromised account compromises everything — and you cannot tell afterwards who did what.
No team can credibly audit its own work.
An outside test finds the assumptions your own people cannot see, and gives you something concrete to show clients and insurers.
Detail
Enough of the basics are missing that one convincing email could cost you a week. The first three items below take most of that risk away, and none of them are big projects.
You are not starting from nothing, but there are gaps someone would find before you did. Work through the list in order and you go from probably fine to genuinely defensible.
Better run than most businesses your size. What is left is the gap between being secure and being able to prove it, which matters the first time an insurer, auditor or client asks.
Genuinely strong. The value now is an outside pair of eyes to confirm the configuration matches the intention, and to keep it that way as you grow.
We will turn your answers into a short written plan: what to fix first, what it involves, and what it costs. A named engineer writes it, not a template, and it arrives within two business days.
Anything you answer “No” to appears here straight away, most important first.
Each question maps to one of four layers. A gap in any single layer is survivable. Gaps in several at once is how a bad afternoon turns into a bad quarter.
Multi-factor authentication with no exceptions, and administrative access scoped by role instead of shared around.
Managed detection on every device, watched by someone outside your own team so an alert at 3am reaches a human.
Backups that cannot be altered even with stolen credentials, restores that have genuinely been tested, and knowing which country the data sits in.
A plan with names and numbers in it, staff who recognise a phishing attempt, and an outside review to catch what your own people cannot see.
Security is one half of it. The other half is whether the day to day actually works — tickets, planning, cost, and who turns up when something breaks. That is the IT health check: ten questions, about three minutes.