Twelve plain questions about how your business handles accounts, email and data. Answer honestly and you’ll get a score and a prioritised list of what to fix first. Nothing you enter leaves your browser, and we never ask for a password.
Everyone signs in with two-factor authentication (a code or app, not just a password).
Accounts are removed promptly when someone leaves.
Only the few people who genuinely need admin rights have them.
Staff use their own logins, not shared accounts or shared passwords.
You've checked no mailboxes have suspicious auto-forwarding rules set up.
Staff would know how to spot a phishing or invoice-scam email.
Important data is backed up automatically, and you've actually tested a restore.
You know which services actually hold your business data.
Laptops and phones are encrypted and lock themselves when idle.
Software and devices install security updates promptly.
You control who can share files outside the business.
There's a simple plan for what to do if an account is hacked.
0
/ 1000 of 12 answered
A rough indicator, not a full audit. The score weights the things that cause the most damage when they go wrong.