Free cyber-risk screening tool
Small Business Cyber-Risk Score
Estimate a preliminary cyber-risk level and identify the security improvements most likely to reduce risk first.
Simple cyber-risk screen
0–100 risk indexRate ten foundational controls
Maturity scale
0 Not in place1 Ad hoc2 Partial3 Mostly implemented4 Enforced & reviewed
Core controls
ControlWeightMaturity
Multi-factor authenticationMFA on email, remote access, cloud systems and privileged accounts.
15%/ 4
Backups & recovery testingProtected backups exist and restores are actually tested.
14%/ 4
Patching & software updatesOperating systems, applications and network devices are updated promptly.
12%/ 4
Endpoint protectionManaged anti-malware / endpoint protection covers company devices.
10%/ 4
Email & phishing defensesSpam filtering, domain protection and phishing-resistant practices.
10%/ 4
Privileged access controlAdmin access is limited, separated and reviewed.
10%/ 4
Employee security awarenessStaff are trained to recognize phishing, credential theft and payment fraud.
8%/ 4
Incident response planContacts, responsibilities and first-response steps are documented and tested.
8%/ 4
Vendor & remote-access securityThird-party and remote access is controlled, limited and protected by MFA.
7%/ 4
Asset inventory & account offboardingDevices, software and user accounts are known and removed when no longer needed.
6%/ 4
Business exposure
Exposure factor1 = low5 = high
Sensitive customer / employee / financial data
/ 5
Dependence on systems being continuously available
/ 5
Remote / cloud / third-party access footprint
/ 5
Internet-facing systems or online transactions
/ 5
Third-party / supplier dependency
/ 5
Simple methodControl maturity produces a weighted 0–100 security-control score. Control gap is 100 minus that score. Business exposure converts the five 1–5 exposure ratings into a 20–100 index. Preliminary cyber risk = 70% control gap + 30% exposure. This is a screening score, not breach probability or compliance status.
Advanced cyber-risk model
NIST CSF-style functionsAdd coverage and prioritize the largest control gaps
Maturity scale
0 Not in place1 Ad hoc2 Partial3 Mostly implemented4 Enforced & reviewed
Control maturity & coverage
Control / functionMaturityCoverageWeight
Security ownership & policyGOVERN · named responsibility, policy and risk review.
/4
%
%
Asset & account inventoryIDENTIFY · devices, software, accounts and owners are known.
/4
%
%
MFA & identity protectionPROTECT · MFA and strong identity controls on critical accounts.
/4
%
%
Privileged-access controlPROTECT · admin rights limited, separated and reviewed.
/4
%
%
Patching & secure configurationPROTECT · supported software, prompt updates and safer defaults.
/4
%
%
Endpoint protectionPROTECT · managed endpoint security across business devices.
/4
%
%
Email & phishing defensesPROTECT · filtering, domain protection and safer authentication.
/4
%
%
Employee security awarenessPROTECT · role-relevant training and phishing/payment-fraud awareness.
/4
%
%
Logging & security monitoringDETECT · useful logs are retained and meaningful alerts are reviewed.
/4
%
%
Incident response plan & contactsRESPOND · first actions, escalation and external contacts are documented.
/4
%
%
Backup protection & restore testingRECOVER · protected backups, restore testing and recovery ownership.
/4
%
%
Vendor & remote-access securityGOVERN / PROTECT · third-party access is limited, reviewed and MFA-protected.
/4
%
%
Business exposure
Risk context
Advanced methodEffective control strength = maturity ÷ 4 × coverage. Weighted control maturity is normalized by the entered control weights. Preliminary risk = 70% weighted control gap + 30% business exposure. Improvement priority is driven by each control’s normalized weight × remaining control gap; the table also estimates the risk-index reduction if that control alone reached maturity 4 with 100% coverage.
Highest-priority improvements
Top priorities firstControl gaps ranked by potential risk reduction
| Priority | Control | Function | Effective strength | Normalized weight | Priority score | Risk-index reduction if fully implemented |
|---|
Control breakdown
All modeled controlsMaturity, coverage and remaining gap
| Control | Function | Maturity | Coverage | Effective strength | Weight | Weighted contribution |
|---|
Framework-function view
Framework-inspired groupingControl strength across six risk-management functions
| Function | Modeled controls | Average effective strength | Largest gap |
|---|
Exposure sensitivity
Control maturity unchangedRisk index at different business-exposure levels
| Exposure scale | Exposure score | Control score | Risk index | Preliminary level |
|---|
Scope
A cyber-risk score is a screening tool, not a security audit
This tool provides a preliminary planning score only. It does not measure breach probability, certify compliance, test technical controls, replace a vulnerability assessment, or determine insurance eligibility. Security requirements differ by industry, data type, contracts, jurisdiction and technology. Use the score to prioritize questions for your IT/security provider and to identify controls that deserve verification.
Framework note: the control categories are informed by the NIST Cybersecurity Framework 2.0 functions and CISA small-business cyber guidance, including emphasis on MFA, patching and tested backups.
