Free · instant score · no signup needed

How Cyber-Ready Is Your Business?

18 plain-English questions — no jargon, no trick questions. Get an instant score, see exactly where you're exposed, and know what to fix first.

Takes about 4 minutesBuilt on the Essential Eight
0 of 18 answered0%

Logins & access

Does every important account use multi-factor authentication — especially email?

Stolen passwords are the #1 way attackers get in. MFA stops most of it cold.

Do staff use a password manager instead of reusing the same passwords?

One reused password leaking on another site shouldn't open your business.

When someone leaves, are all their accounts switched off the same day?

Old accounts of ex-staff are a favourite quiet way in.

Devices & updates

Do Windows and Mac updates install automatically, without waiting for someone to get around to it?

Most attacks exploit holes that a patch already existed for.

Is every computer on a supported operating system (no Windows 7/8 or ancient servers)?

Unsupported systems stop receiving security fixes — permanently open doors.

Is there business-grade protection on every device, visible in one place?

You can't respond to what you can't see across your fleet.

Backups

Are backups automatic and running every day?

Backups that rely on someone remembering are backups that stop.

Have you actually tested restoring from backup in the last six months?

An untested backup is a hope, not a plan.

Is at least one backup copy kept where ransomware on your network can't reach it?

Modern ransomware hunts and encrypts backups first.

Email & scams

Is your email domain protected so criminals can't send emails pretending to be you?

SPF/DKIM/DMARC records stop crooks invoicing your customers as 'you'.

Has your team had any scam-awareness training in the past year?

Most breaches start with one click on one convincing email.

Does everyone know exactly who to tell the moment they click something suspicious?

Fast reporting turns a disaster into a non-event. Shame and silence do the opposite.

Data & response

Do you know where your important data lives, and what would hurt most if it leaked?

You can't protect what you haven't mapped.

Can staff only open the files they need for their job, rather than everything?

If one login is stolen, it should unlock a room — not the whole building.

Is there a written plan for the first hour of a cyber incident?

The first hour decides how bad it gets. Improvising it goes badly.

Network & remote

Is guest and visitor Wi-Fi separated from your business network?

A visitor's infected laptop shouldn't be able to see your server.

Is remote access through a secure VPN or managed tool — nothing like Remote Desktop open to the internet?

Exposed remote desktop is one of the most attacked doors in Australia.

Does someone review who has admin rights at least twice a year?

Admin rights quietly accumulate — attackers love finding them.

Your answers stay in your browser — nothing is sent anywhere unless you choose to email yourself the results. Questions are informed by the Australian Cyber Security Centre's Essential Eight and what we see in real Sydney businesses.

Call Now — 02 9071 0333