What this assessment covers

This is a self assessment of the security basics that matter most for small and medium businesses in Australia. It asks twenty plain English questions about how your business actually operates day to day, then scores you across four areas and shows you where your biggest gaps are.

It takes about four minutes and needs no technical knowledge. You see your score straight away.

The four areas we score

Identity, devices, data and network are the same four pillars we assess in depth for clients, because they are where real world attacks actually land, a stolen password, a lost laptop, an untested backup, an unwatched network.

Identity. Who can log in, and how well those logins are protected. This covers multi factor authentication, what happens to accounts when staff leave, whether administrator rights are handed out to everyday accounts, and whether passwords get reused across services. Most breaches start with a login rather than a clever exploit.

Devices. The laptops, desktops and phones your business data sits on. This covers whether operating systems and everyday applications are patched automatically, whether devices are encrypted, whether personal devices can reach business data, and whether you can wipe a device that walks out the door.

Data and resilience. What happens on your worst day. This covers whether backups are actually tested rather than assumed, how long you would take to recover from ransomware, whether sensitive information is restricted to the people who need it, and whether anyone knows what to do in the first hour of an incident.

Email and network. How attackers get in and whether you would notice. This covers phishing reporting, DMARC and email spoofing protection, guest wifi separation, and whether anything is watching for unusual activity.

Who this is for

Business owners, operations managers and office managers who are responsible for IT decisions without necessarily being technical. If you have an IT provider already, it is a useful way to check what you are actually getting. If you manage things internally, it will show you what to prioritise next.

What you get at the end

Your score across the four areas, your biggest gaps explained in plain English, and the three actions that would improve your position most, ordered by impact.

If you would like it in writing, you can request a report by email. There is no obligation and no follow up beyond a single message.

Because this is a self assessment, your score reflects what you told us rather than a technical audit. It cannot verify that a control is configured correctly, still applies to every device, or has not drifted since it was set up. Treat it as a starting point for a conversation about cyber security, not a clean bill of health.