SMB Cyber Risk Score

20 questions — risk score and the top things to fix first.

Advertisement
728x90 placeholder · configure client + slot IDs in wp-admin

SMB Cyber Risk Score

20 questions — get an actionable risk score and the top things to fix first.

Privacy: answers stay in your browser. We do not record your responses.
Multi-factor authentication is the single highest-impact control. Turn it on everywhere administrative.
Modern EDR (Windows Defender for Business, SentinelOne, CrowdStrike) is table stakes.
A backup you haven't tested to restore is a backup you don't have.
Deploy 1Password / Bitwarden / Dashlane company-wide. Password policies alone don't work.
A lost laptop becomes a breach without disk encryption. Both Windows and macOS ship with it free.
Even basic free training (KnowBe4 free tier, Hoxhunt) reduces click-through on real phishing.
Most ransomware exploits known vulnerabilities patched months ago. Close the window.
When a breach happens you don't want to be googling "what to do." Write it now.
Dormant accounts are a favourite attacker pivot. Automate offboarding checklists.
Most business routers support VLAN or guest-network separation. Turn it on.
SSO means one place to disable access for departed employees, and one place to enforce MFA.
Insurance is a financial safety net, not a control. Read the exclusions before an incident.
Least-privilege access on anything sensitive: HR, finance, customer PII.
Your weakest vendor is your effective security floor. Ask for SOC 2 + DPA at minimum.
BEC is the #1 financial cyber loss. Require out-of-band verification for any money movement.
Without logs you can't investigate anything. Most platforms log for free — just enable it.
Walk your Google Drive / OneDrive — would a new hire see things they shouldn't?
Free tools like SSL Labs, SafeCadence's Security Headers Checker cover the basics.
Rotate privileged creds + review access logs once a month; takes 20 minutes.
If security is "everyone's job" it's no-one's job. Name one person accountable.
Score
Answer the questions above to see your score.
Advertisement
300x250 placeholder · configure client + slot IDs in wp-admin