Free · 3 minutes
Cybersecurity Risk Snapshot
Ten questions → a preliminary rating of Low, Moderate, High or Critical, plus the gaps to close first.
This is a preliminary informational assessment and not a formal security audit.
0/10 answered
- 1.Is multi-factor authentication enforced for email, admin and remote access?
- 2.Are backups taken regularly, stored offline/immutable, and tested for restore?
- 3.Is modern endpoint protection (EDR/AV) deployed on all devices?
- 4.Is security monitoring (SOC/SIEM) in place with someone responding to alerts?
- 5.Are critical patches applied within 14 days?
- 6.Is there an approved information security policy communicated to staff?
- 7.Do staff receive security awareness training at least annually?
- 8.Is there a written, tested incident response plan?
- 9.Is VAPT performed at least annually on internet-facing systems?
- 10.Are user access rights reviewed at least quarterly?