Free assessment · 3 minutes

Find out where your IT is actually exposed.

Eighteen weighted questions across six control areas. You get a readiness score, a breakdown by area, and a prioritised action list — no email required, nothing leaves your browser.

Question 1 of 18 · 0 answered

Identity & access

How is multi-factor authentication applied across your organisation?

Conditional access lets you enforce MFA without punishing trusted scenarios.

What we assess

Six control areas, weighted by real-world impact.

The questions mirror the checks we run during a PINE discovery session — the same areas the Australian Cyber Security Centre points small businesses at first.

01

Identity & access

MFA, admin separation, joiner/leaver process

A common way small businesses get compromised.

02

Data & backup

Backup scope, restore testing, recovery objectives

Microsoft doesn't back up your 365 data — you do.

03

Devices & endpoints

Patching, encryption, EDR, central management

Unmanaged laptops are the hardest thing to recover from.

04

Network & connectivity

Firewall, VLANs, Wi-Fi, remote access

A flat network turns one infection into an outage.

05

Documentation & governance

Assets, licences, procedures, awareness

Knowledge stuck in one person's head is a business risk.

06

Support & resilience

Response targets, monitoring, incident plan

The plan matters most in the first hour of a bad day.

FAQ

About this assessment.

How long does it take?

About three minutes. Eighteen questions, one at a time, and you can jump back to change any answer before you see your results.

Do I need to give you my details?

No. Everything is calculated in your browser. Nothing is submitted, stored, or emailed unless you choose to contact us afterwards.

How is the score weighted?

Not every control carries the same risk. Multi-factor authentication, restore testing, patching, admin privilege and incident readiness are weighted highest because they are the controls most often missing when an incident becomes expensive.

Is this an audit?

No — it's a structured self-assessment to show you where to look first. An intro call verifies the answers against your actual tenant, devices and network.

Next step

Want the results validated properly?

A discovery session reviews your actual environment — devices, cloud, network, backups — and turns it into a sequenced plan with owners and dates.