Skip to content
WorkFree ToolsResourcesCompany
Free · No signup to see your result

Cybersecurity Readiness Score

This is not a compliance questionnaire. It scores the controls that actually stop the incidents small and mid-size businesses actually suffer.

17 questions · about two minutes

1. Is multi-factor authentication enforced on email and admin accounts?
2. Are administrative accounts separate from everyday accounts?
3. What happens to access when someone leaves?
4. Are shared logins used anywhere?
5. Are your systems and data backed up automatically?
6. When did you last restore from a backup to test it?
7. Is at least one backup copy isolated from your main environment?
8. How are servers and applications patched?
9. Do you know what is exposed to the internet?
10. Are staff devices encrypted and centrally managed?
11. Do you have SPF, DKIM and DMARC configured?
12. Have staff been trained to recognise phishing?
13. Is there a verification step for payment or bank-detail changes?
14. Would you know if an account had been compromised?
15. Is there a written incident response plan?
16. Do you know which third parties hold your customer data?
17. Do you review the security of significant vendors?

What security controls matter most for a small business?

The incidents that affect small and mid-size businesses are overwhelmingly mundane: a compromised email account through a password with no second factor, ransomware reaching backups that were never tested, and an unpatched internet-facing service. Multi-factor authentication on email and administrative accounts, tested offline backups, and a patching routine cover the majority of realistic risk. Sophisticated tooling matters far less than whether those three are genuinely in place and verified rather than assumed.

Methodology

How this is calculated

Published in full, so you can disagree with it. A tool that hides its model is a lead form.

  1. Seventeen questions across six categories, scored 0–1 for maturity.
  2. Access control and backup carry the highest weights because credential compromise and ransomware are the dominant realistic threats to businesses of this size.
  3. The overall score is the weighted average of category scores, and the priority list shows your weakest answers with a specific corrective action.

Assumptions and limits

  • This is a practical readiness check, not an audit, a penetration test or a compliance assessment. It does not certify anything.
  • It focuses on commonly exploited weaknesses rather than comprehensive framework coverage. A good score is not a claim of ISO 27001 or SOC 2 readiness.
  • Self-reported answers. "Not sure" should be scored as the weaker option — uncertainty about a control usually means it is not working.

FAQ

Questions about this tool

No. Those frameworks cover far more ground, including governance and documentation. This scores the operational controls that most often determine whether a small business suffers an incident.
Enforced multi-factor authentication on email and admin accounts, a backup you have actually restored from in the last quarter, and out-of-band verification for payment and bank-detail changes. Those three cover most realistic loss scenarios.
It changes it. An automated system needs its own scoped identity, an explicit action allow-list, and audit logging. Done properly that is often tighter than the human process it replaces — where shared logins and broad access are common.
We run managed infrastructure with patching, monitoring, backup testing and incident response for client production systems. We are not a specialist security assessment firm, and for formal audit or penetration testing you should engage one.

Turn the number into a plan.

Send us the workflow behind your result. We will come back with how we would automate it, what stays human, and what it takes to build.