Free Small Business Cybersecurity Self-Assessment (2026)
The 10-minute scorecard
Check each: MFA everywhere, tested offline backups, prompt patching, endpoint protection, least-privilege access, staff training, a breach plan, and an updated asset list. Each missing item is a priority.
Reading your score
Mostly yes = strong; a few gaps = quick wins; mostly no = you're exposed and should act this month. The biggest risks are missing MFA and untested backups.
Turn it into action
Fix the highest-impact gaps first (MFA, backups), then the rest. For a deeper, hands-on review, IT Cares offers a professional security assessment.
Action checklist
- ✅ MFA on all accounts?
- ✅ Tested offline backup?
- ✅ Operating systems and apps patched?
- ✅ Business endpoint protection installed?
- ✅ Admin rights limited?
- ✅ Staff trained on phishing?
- ✅ Written breach-response plan?
FAQ
How do I assess my small business's cybersecurity?
Score yourself on MFA, tested backups, patching, endpoint protection, access control, staff training and a breach plan. Missing MFA or untested backups are the highest-priority fixes.
What is the biggest small-business security gap?
Usually missing MFA and untested backups. Together they cause and worsen most breaches, and both are inexpensive to fix.
Get a free assessment
Tell us where you are — we send back a clear, no-pressure plan. Leads only, no payment.