How Strong Is Your Cybersecurity Foundation?

Complete the interactive Cyber Essentials Checklist to uncover security gaps, clarify ownership, and identify the improvements that deserve attention first.

14 questions. Instant scoring. Practical next steps.

No downloads required. Complete the assessment directly on this page.

shield scaled

Turn Cybersecurity Questions Into Clear Priorities

It can be difficult to know where your organization is well protected—and where an overlooked gap could create unnecessary risk.

This interactive checklist gives you a clearer view of your current cybersecurity baseline. Score your organization across essential security areas, see your results immediately, and use the recommendations to guide your next steps.

The original checklist is designed to help organizations identify gaps, establish ownership, and prioritize practical improvements based on what is in place today—not what is planned or assumed.

YOUR SCORE
0 /42
0/14 answered
0–14High priority 15–28Making progress 29–42Strong foundation

Complete all items for your readiness result.

Your answers stay in this browser tab and are not submitted by this module.
01 Governance and ownership A leader owns cybersecurity. Policies, key risks, and review dates are documented.
02 Asset inventory Devices, apps, cloud services, data, and critical systems are listed and kept current.
03 Identity and access Multi-factor authentication (MFA) covers email, remote access, admin, and cloud accounts. Access is reviewed.
04 Secure configuration Systems use secure settings. Default passwords, unused accounts, and unused services are removed.
05 Patch management Critical updates are tracked and installed on time.
06 Endpoint protection Devices have current endpoint protection. Alerts are reviewed and escalated.
07 Email and web protection Email, phishing, web, and domain protections are turned on and monitored.
08 Data protection Sensitive data is identified, limited to the right people, protected, and deleted when no longer needed.
09 Backup and recovery Backups run automatically, are protected, stored separately, and tested.
10 Logging and monitoring Key systems send logs to one place. Important events are reviewed and escalated.
11 Incident response A current response plan names contacts, decisions, and next steps. The plan is practiced.
12 Security awareness People get practical training and know how to report suspicious activity.
13 Vendor risk Critical vendors are tracked, have security expectations, and are included in response plans.
14 Compliance and reporting Security work is documented for leadership, insurance, audits, customers, or other requirements.
NEXT STEP

PRIORITY VIEW

What to focus on next

Assessment incomplete

Complete all 14 areas to see your highest-priority gaps and a practical 30/60/90-day plan.

Scoring Disclosure

The readiness score is calculated from 14 self-reported responses, with each area scored from 0 to 3 for a maximum score of 42. The score is intended to help prioritize areas for review and improvement; it is not a measure of compliance or a guarantee of cybersecurity readiness.

Disclaimer: This self-assessment is for informational purposes only and does not constitute a formal cybersecurity audit, compliance assessment, certification, or guarantee of security. Results are based on self-reported information and should be validated by qualified cybersecurity professionals. Do not submit confidential or sensitive information. 

 

Need Help Turning Your Score Into a Plan?

A cybersecurity readiness review can help your team validate current controls, identify meaningful priorities, and create a practical roadmap based on your risks, resources, and business requirements.

Talk Through My Results

Get a second set of eyes on your access, monitoring, backups, incident response, and everyday security operations.

See what our SOC team does →