
Cyber Risk Assessment
Cyber Risk Self-Assessment
Answer a few quick questions. You’ll get a risk score (0–100), a category breakdown, and top fixes.
1. Is MFA enabled for all users?
Area: Identity
Tip: Turn on enforced MFA and conditional access.
2. Do ALL endpoints have anti-virus and endpoint detection response (EDR) with centralized monitoring?
Area: Endpoint
Tip: Deploy a managed EDR across all devices.
3. Are operating systems and application patches deployed within 7 days (critical within 24h)?
Area: Endpoint
Tip: Automate patching.
4. Is there an offsite backup and is it tested quartarly?
Area: Resilience
Tip: Ensure there is an offsite backup and schedule quarterly restoration test. Understand the "mean-time to repair" (MTTR).
5. Do you have advanced email security and backup?
Area: Email
Tip: Enable automatic scanning to quarantine suspicious emails, block spoofing, and isolate harmful attachments and links.
6. Do users get anti-phishing simulations and cyber awareness training at least quarterly?
Area: People
Tip: Run blind phishing campaigns and mandatory cyber training.
7. Is there a written incident response (IR) plan with contacts and playbooks?
Area: Response
Tip: Keep a 1-page IR sheet and run tabletop drills.
8. Is temporary admin access given only when needed (no always-on privileges)?
Area: Identity
Tip: If necessary, allow temporary access and schedule date to auto-remove temporary access.
9. Is all remote desktop access routed through a protected gateway or VPN?
Area: Access
Tip: Lock down RDP and deploy single sign-on (SSO) with MFA.
10. Do you centralize logs with 24×7 alerting and response?
Area: Monitoring
Tip: Employ a real-time Security Operations Centre (SOC) to physically call and send critical logs.
11. Do critical vendors undergo a security review and contract clauses?
Area: Third-Party
Tip: Add security exhibits and review annually.
12. Are cyber KPIs reviewed with company leadership at least quarterly?
Area: Governance
Tip: Show summary results of phishing, patching, backup tests, MTTR, etc. to leadership team.
0 / 100
Low risk
Your answers stay in your browser unless you share or print.
