Home/IT Risk Self-Assessment

How exposed is your business, really?

Eight plain-English questions. No email required to see your score. You'll get an instant read on where your IT and cybersecurity posture is solid — and where the gaps are that owners usually don't find out about until something breaks.

2 min to complete 8 questions Instant score & action list No sales sequence
Question 1 of 8
When did you last actually restore from a backup to confirm it works?
Question 2 of 8
Is multi-factor authentication (MFA) enforced on every email and admin account?
Question 3 of 8
What's protecting the computers your team uses every day?
Question 4 of 8
How are operating-system and application updates handled?
Question 5 of 8
Has your team been trained to spot phishing in the last 12 months?
Question 6 of 8
Do you have a written, tested disaster-recovery plan?
Question 7 of 8
When something breaks, who do you actually call?
Question 8 of 8
Do you handle regulated data (HIPAA, PCI, CJIS, or financial)?

All eight answers are needed to score it.

0/100 risk

Your tailored action list

Ordered by what we'd fix first. Each links to a plain-talk guide if you want the detail.

Want this as a one-page action plan in your inbox?

We'll email your score, a prioritized fix list ordered by what to tackle first, and the matching plain-talk guide for each gap — a one-pager you can hand to whoever runs your IT. One email with your results, no drip sequence; the monthly brief below is separate and only if you tick the box.

Prefer to just talk it through? That's usually faster.

This self-assessment is an educational tool, not a formal security audit or a guarantee of compliance. Your answers are scored entirely in your browser and are never sent anywhere unless you enter your email above. For a real evaluation of your environment, book a discovery call.

What this IT risk assessment checks

The assessment walks through the eight areas where small and mid-sized businesses most often carry hidden risk — the same areas a cyber-insurance carrier, an auditor, or an incident responder asks about first:

Why a risk assessment is worth ten minutes

Most breaches at small businesses don't exploit anything exotic — they walk through a gap the owner didn't know was open: an un-MFA'd mailbox, a backup no one ever restored, an endpoint running antivirus from a decade ago. A risk assessment is simply the fastest way to find those gaps before an attacker, an auditor, or an insurer does.

Your result is an instant, plain-English score with a tailored action list — no email required to see it, and no sales sequence. If you'd rather have a person walk your environment with you, the call below is free, and there's no slide deck.

Rather have a human look at it? Book a 20-minute intro call.