Free self-assessment

Cyber readiness scorecard

Eighteen questions, about five minutes. See your score and your three biggest gaps straight away, each with a first step, linked to the Essential Eight and SMB1001:2026. No email needed.

Written by our security teamFrom the controls in SMB1001:2026 and the Essential Eight. Reviewed October 2026.

01The scorecard

Answer what you know, mark the rest not sure

Partly means it is in place for some people or systems but not all. If you do not know, send the questions to whoever looks after your IT once you have your score.

1 of 5Sign in and accounts

01Does everyone need a second step, such as an app prompt or code, to sign in to email?

Answer Partly if some mailboxes, such as shared or older accounts, only need a password.

02Do remote access, admin accounts and your other business apps also need that second step?

Answer Partly if some of them do and some do not.

03Do staff work day to day in accounts without admin rights?

Answer Partly if some staff still have admin rights on their own computer.

04Does the business give staff a password manager that it manages centrally?

Answer Partly if some staff use one but shared logins still live in spreadsheets or browsers.

05When someone leaves, is their access to every system removed on their last day?

Answer Partly if email is turned off but other apps or shared passwords are missed.

2 of 5Computers and software

06Do security updates install automatically on every computer and server, with urgent fixes applied within two days?

Answer Partly if updates are automatic but nobody checks that they finished, or some machines fall behind.

07Does every computer run endpoint detection and response (EDR) that someone watches day and night?

EDR is security software that spots and stops an attack in progress. Answer Partly if you have antivirus or EDR but nobody watches the alerts around the clock.

08Are computers set up so only approved software can run?

This is called application control. Answer Partly if it is on some computers, or only reporting rather than blocking.

09Are Office macros blocked in files that come from the internet or by email?

Macros are small programs inside Word and Excel files. Answer Partly if they are blocked for some staff only.

10Are web browsers managed centrally, with security settings staff cannot change?

Answer Partly if browsers update themselves but nobody manages their settings.

3 of 5Data and Microsoft 365

11In the last six months, have you test restored files from a backup that cannot be changed or deleted from your network?

Answer Partly if you have backups but have not tested a restore, or someone on your network could delete them.

12Do you keep an up to date list of your devices, software and cloud services?

Answer Partly if the list exists but is not kept up to date.

13Has Microsoft 365 been checked against a security baseline?

For example blocking old sign in methods, limiting external sharing and turning on alerts and audit logs.

4 of 5Email and people

14Is your email domain protected with SPF, DKIM and DMARC, with DMARC set to quarantine or reject?

These settings stop criminals sending email that looks like it came from you. Answer Partly if DMARC is set to monitor only.

15Do all staff complete security awareness training, including phishing, at least once a year?

Answer Partly if only some staff do it, or it happens once at induction only.

5 of 5Plans and policies

16Do you have a written incident response plan that names who decides and who to call?

Answer Partly if you have a plan but have never practised it.

17Do you hold current cyber insurance?

Answer Partly if you are not sure your policy covers cyber incidents.

18Do you have a written policy on which AI tools staff can use and what information they can put into them?

Answer Partly if there are rules but they are not written down.

OptionalAbout your business

Not scored. It helps us tailor your result, and tells a technical consultant who they are talking to if you ask for the full report.

How many staff do you have?
Who looks after your IT today?
What made you check today?

0 of 18 answeredYour answers stay in your browser.

0 of 18 answered

03About the scorecard

What it is and what it is not

01

Is this an Essential Eight assessment?

No. It asks about the controls behind each strategy so you can see roughly where you stand. A maturity assessment needs evidence and testing of every requirement, and a score here does not mean you meet a maturity level.

02

Does a good score mean we could get SMB1001 certified?

Not on its own. SMB1001:2026 has more controls at each tier than these questions cover, such as a firewall and a named technical support provider at Bronze. The tier summary shows how many of the questions linked to each tier you answered yes to, which is a useful place to start.

03

What happens to my answers?

Your score is worked out in your browser and is not sent anywhere. Your answers are kept in this browser so you can come back to them, and the link you can send to your IT person carries them in the link itself. If you ask for the full report, your answers go to our team with your details through the form, and we use them only to respond to you.

04

Who wrote the questions?

Our security team, from the controls in SMB1001:2026 and the Essential Eight Maturity Model. We review them when either changes. The last review was in October 2026.

04Next step

Want a second opinion
on your results?

A technical consultant will go through your answers with you, tell you which gaps matter for your business and send a fixed quote to close them.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.