Home/Free Tools/Risk Assessment

Cybersecurity Risk Self-Assessment

15 questions across access control, backups, phishing readiness, devices, and incident response. Get an instant risk score and a prioritized action list.

🔒 Scored entirely in your browser — nothing is submitted anywhere

1. Access Control

Is multi-factor authentication (MFA) required for email and other critical accounts?

2. Access Control

Does every employee use a unique password for each work account (no reuse)?

3. Access Control

Do you immediately revoke system access when an employee leaves?

4. Backups

Are business-critical files backed up automatically, on a schedule you don't have to remember?

5. Backups

Have you tested restoring from backup in the last 12 months?

6. Backups

Is at least one backup copy stored offsite or in a separate cloud account from your main systems?

7. Phishing Readiness

Have employees received phishing-awareness training in the past year?

8. Phishing Readiness

Do employees know exactly how to report a suspicious email?

9. Phishing Readiness

Do you verify payment or wire-transfer changes by phone before acting on an email request?

10. Software & Devices

Are operating systems and software set to update automatically?

11. Software & Devices

Do all company devices run up-to-date antivirus/endpoint protection?

12. Software & Devices

If employees use personal devices for work, are they covered by a security policy (screen lock, encryption)?

13. Network

Is your business Wi-Fi network separated from a public/guest network?

14. Data & Vendors

Do you know which third-party vendors have access to your customer data?

15. Incident Response

Do you have a written plan for what to do in the first hour after a suspected breach?

Why Small Businesses Need a Risk Assessment

43% of cyberattacks target small businesses, yet most don't have a dedicated IT security team to catch gaps before an attacker does. This assessment covers the six areas that account for the overwhelming majority of small-business breaches: weak access control, missing or untested backups, phishing susceptibility, unpatched software, flat networks, and the absence of an incident response plan.

None of these questions require a security background to answer — they're about whether a practice exists, not how sophisticated it is. A "no" answer isn't a failure, it's a prioritized to-do list, ranked by what attackers exploit most often.

What to Do With Your Score

Work through the flagged items in order — access control and backups first, since they limit both how attackers get in and how much damage they can do once inside. Explore our Checklists for step-by-step guides on each category, and re-run this assessment every quarter as your team and tools change.