Business Tools/ Risk & Operations
Free cyber-risk screening tool

Small Business Cyber-Risk Score

Estimate a preliminary cyber-risk level and identify the security improvements most likely to reduce risk first.

Simple cyber-risk screen

Rate ten foundational controls

0–100 risk index
Maturity scale 0 Not in place1 Ad hoc2 Partial3 Mostly implemented4 Enforced & reviewed
ControlWeightMaturity
Multi-factor authenticationMFA on email, remote access, cloud systems and privileged accounts.
15%
/ 4
Backups & recovery testingProtected backups exist and restores are actually tested.
14%
/ 4
Patching & software updatesOperating systems, applications and network devices are updated promptly.
12%
/ 4
Endpoint protectionManaged anti-malware / endpoint protection covers company devices.
10%
/ 4
Email & phishing defensesSpam filtering, domain protection and phishing-resistant practices.
10%
/ 4
Privileged access controlAdmin access is limited, separated and reviewed.
10%
/ 4
Employee security awarenessStaff are trained to recognize phishing, credential theft and payment fraud.
8%
/ 4
Incident response planContacts, responsibilities and first-response steps are documented and tested.
8%
/ 4
Vendor & remote-access securityThird-party and remote access is controlled, limited and protected by MFA.
7%
/ 4
Asset inventory & account offboardingDevices, software and user accounts are known and removed when no longer needed.
6%
/ 4
Exposure factor1 = low5 = high
Sensitive customer / employee / financial data
/ 5
Dependence on systems being continuously available
/ 5
Remote / cloud / third-party access footprint
/ 5
Internet-facing systems or online transactions
/ 5
Third-party / supplier dependency
/ 5
Simple methodControl maturity produces a weighted 0–100 security-control score. Control gap is 100 minus that score. Business exposure converts the five 1–5 exposure ratings into a 20–100 index. Preliminary cyber risk = 70% control gap + 30% exposure. This is a screening score, not breach probability or compliance status.