Cyber Security Assessment

Cyber Security Self-Assessment 2026 (#31)

What To Expect

You can take easy and sometimes FREE steps to make sure your systems are secure and your data is safe. Browse through each of these areas to ensure that your company’s systems and data are safe. Our team is offering a FREE self-assessment to help you identify potential holes in your business. No sales gimmicks or follow up harassments. Use this tool to see where you can improve. If you need help, we’re here to help you get secure.

1. Secure Your Facilities

Have you completed the following?

  • Is your firewall current, supported by the manufacturer, and receiving security updates?
  • Do you subscribe to the Advanced Security Licensing for your firewall?
  • Are updates applied regularly to software and firmware?
  • Are default passwords changed on routers, firewalls, access points, and other network devices?

2. Secure Your Website

Have you done the following?

  • Is your website protected against DDoS attacks and other malicious traffic?
  • Do you have a backup of your website?
  • Are forms protected against spam and automated abuse?
  • Do you have https:// encryption implemented?
  • Is your web site hosting actively managed by a professional?
  • Are website administrator accounts protected with multi-factor authentication?
  • Are website plugins, themes, and other components regularly reviewed and updated?

3. Secure Your Remote Connectivity

Have you done the following?

  • Have you replaced outdated or unsupported cellular/networking devices, including legacy 3G equipment?
  • Are your 4G connections on individual private IP Addresses?
  • Are your devices’ software actively upgraded?
  • Are your devices’ firmware actively upgraded?
  • Are port settings managed for optimal security and access control?
  • Are remote connectivity devices centrally monitored for security, connectivity, and configuration issues?
  • Have default credentials been changed on all remotely connected devices?

4. Secure Your Systems

Have you done the following?

  • Are all servers and critical systems running currently supported operating systems and software?
  • Are business files stored in secure, centrally managed locations rather than individual devices?
  • Do your remote users access the network via secure VPN tunnels?
  • Have you eliminated all Windows XP & Windows 7 PC’s?
  • Do you have zero day malware & intrusion protection implemented and managed?
  • Do you have managed endpoint protection capable of detecting malware, ransomware, and other emerging threats
  • Are security patches for critical systems applied promptly?
  • Do users have only the system access necessary for their job responsibilities?

5. Secure Your Passwords

Have you done the following?

  • Have you implemented multi-factor authentication everywhere possible?
  • Do you use a password manager like LastPass?
  • Does every user have their own account (no shared logins)?
  • Do you use different passwords for business & personal items? Financial & general sites?
  • Are your passwords unique and long?
  • Have you changed your passwords in the past year?
  • Have you reviewed your user list to ensure employees no longer employed are removed?
  • Are employees trained to deny and report unexpected MFA prompts or authentication requests?
  • Are employee accounts promptly disabled when someone leaves the organization?
  • Are user accounts and access permissions reviewed regularly to remove unnecessary access?
  • Are administrator accounts separate from employees’ everyday user accounts?

6. Secure Your Backup

Have you done the following?

  • Are critical workstations, servers, files, and databases included in your backup strategy?
  • Do you have a backup policy for your files and databases?
  • Have you implemented a secure backup like Veeam or Backblaze?
  • Is your local backup stored on a different network than your files?
  • Have you successfully tested restoring data from your backups within the past six months?
  • Do you monitor alerts from your backup system?
  • Are backups protected from ransomware and unauthorized access?
  • Are backup failures and security alerts actively monitored?
  • Do you know how quickly critical systems and data could be restored following an attack or outage?

7. Secure Your MS 365 Office Apps

Have you done the following?

  • Do you maintain a separate backup of critical Microsoft 365 data?
  • Have you created separate admin accounts from users?
  • Are Microsoft 365 security and threat-protection features appropriately configured?
  • Have you implemented Multi-factor Authentication on user accounts?
  • Have you adjusted the standard Office 365 settings to improve overall security instead of the default settings?
  • Are file and folder sharing permissions regularly reviewed to prevent unnecessary external or internal access?
  • Are sensitive files shared through approved, secure methods rather than personal email, personal cloud storage, or unapproved apps?
  • Are inactive accounts, unnecessary permissions, and external sharing links regularly reviewed and removed?

8. Secure Your Computers

Have you done the following?

  • Are all company computers running currently supported operating systems?
  • Are antivirus subscriptions kept up to date?
  • Is managed endpoint security/antivirus installed on all company computers and servers?
  • Do you monitor and update all other applications as required?
  • Have you eliminated Windows XP & Windows 7 machines from your network?
  • Are third-party applications regularly patched and updated?
  • Are devices automatically locked after a period of inactivity?
  • Are company laptops and other portable devices encrypted?
  • Are users prevented from installing unauthorized software when appropriate?

9. Secure Your E-Mail

Have you done the following?

  • Have you implemented multi-factor authentication on your e-mail accounts?
  • Are email security controls configured to help detect spoofing, impersonation, phishing, and malicious attachments or links?
  • Are your spam filters managed to blacklist bad domains?
  • Have employees been communicated with about avoiding clicking on external links?
  • Are you using a cloud based e-mail service like Microsoft or Google?
  • Have employees received security awareness training within the past year?
  • Are employees trained to recognize phishing, social engineering, fake login pages, and suspicious attachments or links
  • Do employees know how to report a suspected phishing email or security incident?
  • Are employees trained to verify unexpected requests involving payments, password resets, account changes, sensitive information, or urgent requests from executives/vendors?
  • Does your organization conduct periodic phishing simulations or other security-awareness exercises?
  • Are employees aware that AI can make phishing emails, impersonation attempts, fake images, and voice scams more convincing?

Get Your Score Now

Enter the details below to instantly receive your Cyber Security Score and recommendations.

Scroll to Top