How exposed is your business, really?
Most small businesses are not attacked by sophisticated nation-state actors. They are attacked by automated tools looking for the most common, preventable gaps. This assessment checks whether the nine fundamentals are in place — the controls that eliminate the overwhelming majority of risk for businesses your size.
0 of 9 questions answered
1. Is multi-factor authentication (MFA) enabled on all accounts — email, cloud tools, line-of-business applications, and remote access?
MFA blocks over 99% of automated account takeover attempts. If any critical system is missing it, that system is the weakest link.
2. Are your backups tested and verified at least once per quarter — not just scheduled, but actually confirmed to restore?
Unverified backups are not backups. The only thing that matters is whether a restore actually works when you need it.
3. Is endpoint protection (antivirus, EDR, or equivalent) installed and actively monitored on every employee device, including personal devices used for work?
Unmanaged devices are the most common entry point for ransomware. "It's their personal laptop" is not a security boundary.
4. Are all systems — workstations, servers, network devices, and business software — kept current with security patches and updates on a regular schedule?
Unpatched systems are one of the most consistently exploited attack vectors. Regular patching closes known vulnerabilities before attackers can use them — and it is frequently overlooked once basic tools are in place.
5. Have all employees completed security awareness training in the past 12 months that covered phishing, social engineering, and safe credential practices?
The majority of successful breaches start with a human action, not a technical failure. Training reduces that surface area significantly.
6. Are former employee accounts (email, cloud tools, VPN, building systems) disabled within 24 hours of departure?
Inactive accounts with valid credentials are a persistent and often-overlooked risk. This is a process gap as much as a technical one.
7. Do you have a documented, tested plan for what your business does in the first 24 hours of a ransomware attack or significant data breach?
Incident response under pressure is harder than it looks. Businesses without a plan lose significantly more time and money when an incident occurs.
8. Are third-party and vendor access points (remote support tools, MSP access, contractor accounts) reviewed and limited to the minimum necessary?
Vendor access is one of the most common vectors for supply chain attacks. Most businesses never audit it after the initial setup.
9. Are physical access controls in place to prevent unauthorized individuals from accessing servers, network equipment, or unattended workstations?
Physical access to a device can bypass virtually every digital security control. Server rooms, networking closets, and unlocked workstations are common blind spots — often overlooked because the focus stays on cybersecurity.
