Skip to content

Free self-assessment · 20 questions

How defensible is your business?

Twenty questions, answered honestly, give you a score and a short list of what to fix first. Results show instantly on this page. No email required.

  1. Is multi-factor authentication enforced for everyone, on email, VPN, remote access, and admin accounts?
  2. Are administrator accounts separate from everyday accounts, with access limited to what each role actually needs?
  3. When someone leaves the company, are their accounts disabled the same day?
  4. Do your computers run modern endpoint detection and response, not just traditional antivirus?
  5. Is your email protected with filtering, anti-phishing, and domain protections like SPF, DKIM, and DMARC?
  6. Do employees get regular, realistic phishing and security-awareness training?
  7. Are software updates applied on a schedule, with someone accountable for it?
  8. Do you scan for vulnerabilities and prioritize fixes by real-world risk, not guesswork?
  9. Is your network segmented, so guest, vendor, and critical systems aren't all on one flat network?
  10. If you run plant or warehouse systems, is there a controlled boundary between business IT and operational technology?
  11. Is outside vendor remote access controlled, time-limited, and logged?
  12. Do you have at least one backup copy an attacker can't alter or delete?
  13. Have you actually restored from a backup recently, with the procedure documented?
  14. Have you defined how fast each key system must come back, and how much data you can afford to lose?
  15. If you discovered a breach at 2am, is there a written plan for what happens next?
  16. Is someone or something watching your systems for threats around the clock?
  17. Do you have a current list of every device and account connected to your network?
  18. Is your Microsoft 365 or cloud secured with Conditional Access, device policies, and least-privilege access?
  19. Are security logs collected and retained long enough to investigate an incident?
  20. Can you answer a customer, insurer, or regulator's security questionnaire with evidence, not hope?