Identity & access
MFA, admin separation, joiner/leaver process
A common way small businesses get compromised.
Free assessment · 3 minutes
Eighteen weighted questions across six control areas. You get a readiness score, a breakdown by area, and a prioritised action list — no email required, nothing leaves your browser.
Conditional access lets you enforce MFA without punishing trusted scenarios.
What we assess
The questions mirror the checks we run during a PINE discovery session — the same areas the Australian Cyber Security Centre points small businesses at first.
MFA, admin separation, joiner/leaver process
A common way small businesses get compromised.
Backup scope, restore testing, recovery objectives
Microsoft doesn't back up your 365 data — you do.
Patching, encryption, EDR, central management
Unmanaged laptops are the hardest thing to recover from.
Firewall, VLANs, Wi-Fi, remote access
A flat network turns one infection into an outage.
Assets, licences, procedures, awareness
Knowledge stuck in one person's head is a business risk.
Response targets, monitoring, incident plan
The plan matters most in the first hour of a bad day.
FAQ
About three minutes. Eighteen questions, one at a time, and you can jump back to change any answer before you see your results.
No. Everything is calculated in your browser. Nothing is submitted, stored, or emailed unless you choose to contact us afterwards.
Not every control carries the same risk. Multi-factor authentication, restore testing, patching, admin privilege and incident readiness are weighted highest because they are the controls most often missing when an incident becomes expensive.
No — it's a structured self-assessment to show you where to look first. An intro call verifies the answers against your actual tenant, devices and network.
Next step
A discovery session reviews your actual environment — devices, cloud, network, backups — and turns it into a sequenced plan with owners and dates.