Cybersecurity Risk Self-Assessment
15 questions across access control, backups, phishing readiness, devices, and incident response. Get an instant risk score and a prioritized action list.
1. Access Control
Is multi-factor authentication (MFA) required for email and other critical accounts?
2. Access Control
Does every employee use a unique password for each work account (no reuse)?
3. Access Control
Do you immediately revoke system access when an employee leaves?
4. Backups
Are business-critical files backed up automatically, on a schedule you don't have to remember?
5. Backups
Have you tested restoring from backup in the last 12 months?
6. Backups
Is at least one backup copy stored offsite or in a separate cloud account from your main systems?
7. Phishing Readiness
Have employees received phishing-awareness training in the past year?
8. Phishing Readiness
Do employees know exactly how to report a suspicious email?
9. Phishing Readiness
Do you verify payment or wire-transfer changes by phone before acting on an email request?
10. Software & Devices
Are operating systems and software set to update automatically?
11. Software & Devices
Do all company devices run up-to-date antivirus/endpoint protection?
12. Software & Devices
If employees use personal devices for work, are they covered by a security policy (screen lock, encryption)?
13. Network
Is your business Wi-Fi network separated from a public/guest network?
14. Data & Vendors
Do you know which third-party vendors have access to your customer data?
15. Incident Response
Do you have a written plan for what to do in the first hour after a suspected breach?
Why Small Businesses Need a Risk Assessment
43% of cyberattacks target small businesses, yet most don't have a dedicated IT security team to catch gaps before an attacker does. This assessment covers the six areas that account for the overwhelming majority of small-business breaches: weak access control, missing or untested backups, phishing susceptibility, unpatched software, flat networks, and the absence of an incident response plan.
None of these questions require a security background to answer — they're about whether a practice exists, not how sophisticated it is. A "no" answer isn't a failure, it's a prioritized to-do list, ranked by what attackers exploit most often.
What to Do With Your Score
Work through the flagged items in order — access control and backups first, since they limit both how attackers get in and how much damage they can do once inside. Explore our Checklists for step-by-step guides on each category, and re-run this assessment every quarter as your team and tools change.