Cybersecurity Readiness Score
This is not a compliance questionnaire. It scores the controls that actually stop the incidents small and mid-size businesses actually suffer.
What security controls matter most for a small business?
The incidents that affect small and mid-size businesses are overwhelmingly mundane: a compromised email account through a password with no second factor, ransomware reaching backups that were never tested, and an unpatched internet-facing service. Multi-factor authentication on email and administrative accounts, tested offline backups, and a patching routine cover the majority of realistic risk. Sophisticated tooling matters far less than whether those three are genuinely in place and verified rather than assumed.
Methodology
How this is calculated
Published in full, so you can disagree with it. A tool that hides its model is a lead form.
- Seventeen questions across six categories, scored 0–1 for maturity.
- Access control and backup carry the highest weights because credential compromise and ransomware are the dominant realistic threats to businesses of this size.
- The overall score is the weighted average of category scores, and the priority list shows your weakest answers with a specific corrective action.
Assumptions and limits
- This is a practical readiness check, not an audit, a penetration test or a compliance assessment. It does not certify anything.
- It focuses on commonly exploited weaknesses rather than comprehensive framework coverage. A good score is not a claim of ISO 27001 or SOC 2 readiness.
- Self-reported answers. "Not sure" should be scored as the weaker option — uncertainty about a control usually means it is not working.
FAQ
Questions about this tool
If you want this built
Turn the number into a plan.
Send us the workflow behind your result. We will come back with how we would automate it, what stays human, and what it takes to build.