How secure is your business?
Ten questions, three minutes: a 0-100 score on your basic cyber hygiene, built on the essential controls (CIS Controls IG1) that stop most real-world attacks on SMEs.
- Free
- Instant result
- No email required
- 2-3 minutes
Your result
Mature security
Excellent level: the essential controls are in place and looked after. You are ahead of the vast majority of SMEs.
The next step isn’t buying more, it’s verifying: a periodic vulnerability assessment and a real test of your response plan (a half-day tabletop exercise) tell you whether the defences actually hold. From here on the theme is consistency, not ambition.
Good foundation
Solid foundation with a few open gaps: your remaining weak spots are few, but attackers know them too — they are the first things tried.
At this level improvements are cheap and high-yield: mostly extending what you already do (MFA everywhere, restore tests, active alerts) rather than introducing anything new. Priorities are listed below.
Basic protection
Some defences exist, but a targeted attack — or even just a well-crafted phishing email — would find more than one open door.
The priority is closing the fundamentals in the right order: MFA, tested backups, updates. These three measures have the best cost/benefit ratio and together stop most opportunistic attacks — the real threat to an SME. Everything else comes after.
At risk
Today your business is an easy target: no sophisticated attack needed — one phishing email or one reused password is enough to do serious damage.
The good news: starting from zero, the first measures are also the cheapest and most effective. In a week you can enable MFA and automatic backups; in a month, updates, managed antivirus and minimum access rules. It’s not a grand project — it’s routine maintenance that’s currently missing. Priorities are listed below.
This test measures baseline cyber hygiene and does not replace a technical assessment: a high score reduces risk, it doesn’t eliminate it.
Want a professional opinion?
This test is a first orientation. If you want to know what to actually do in your situation, let’s talk: 30 minutes, no commitment.
Request an assessmentFrequently asked questions
Who is this test for?
SMBs, professional practices and freelancers without a structured IT department. The questions are inspired by the baseline controls of CIS Controls and the NIST Cybersecurity Framework, translated into plain language.
Do I need technical skills to answer?
No: the questions cover everyday practices — backups, updates, passwords, training — and take a couple of minutes. If you cannot answer a question, that in itself says something useful about your level of control.
Do I have to leave my email to see the result?
No: the score and outcome are shown immediately. Your email is only needed to receive the full report with intervention priorities.
Is the score a certification?
No: it is an indicative self-assessment, not an audit or a certification. A high score indicates good baseline practices, not the absence of risk; a low score shows where to act first.
My score is low: where do I start?
With the measures offering the best cost/benefit ratio: multi-factor authentication on email and critical accounts, automatic backups tested with a real restore, and regular updates. These alone cover a huge share of the most common incidents.