Detailed Assessment

Detailed Cyber Security Assessment

Review 40 security controls for a more complete view of your organisation’s cyber resilience. Allow approximately 10–15 minutes.

1. Do you have a firewall protecting your network?

2. Do you use multi-factor authentication (MFA) for critical systems?

3. How often are systems and software patched/updated?

4. Do you maintain tested, offsite/cloud backups?

5. Do employees receive security awareness training?

6. Do you monitor network traffic for intrusions (IDS/IPS)?

7. Do you have a documented incident response plan?

8. Do you restrict admin/privileged access on a least-privilege basis?

9. Do you provide a secure VPN or zero-trust remote access solution for remote/hybrid workers?

10. Is sensitive data encrypted both at rest and in transit?

11. Is your network segmented (e.g. VLANs) to isolate critical systems from general traffic?

12. Do you assess the security practices of third-party vendors before granting them access?

13. Do you run antivirus/EDR (endpoint detection & response) on all company devices?

14. Do you have a written security / acceptable use policy for employees?

15. Do you use a password manager and enforce strong password requirements?

16. Are accounts for departed employees disabled promptly?

17. Do your internet-facing services have DDoS protection?

18. Do you use email security controls (SPF/DKIM/DMARC, anti-phishing filtering)?

19. Are IoT and smart devices on your network patched and hardened?

20. Do you have a documented data retention and secure disposal policy?

21. Do you conduct regular vulnerability scans or penetration tests?

22. Does your business carry cyber insurance coverage?

23. Do you monitor for company credentials leaked or sold on the dark web?

24. Are laptops and mobile devices encrypted (e.g. BitLocker/FileVault)?

25. Do you provide a separate guest Wi-Fi network isolated from your corporate network?

26. Do you require a security review before adopting new SaaS or cloud apps?

27. Are security logs centralized and monitored (e.g. a SIEM)?

28. Do you have physical security controls protecting servers and network equipment?

29. Do you regularly test backups by performing full recovery drills?

30. Is there a clearly designated owner responsible for cybersecurity in your business?

31. Do you restrict or control the use of USB drives and removable media on company devices?

32. Do you have a patch management process covering third-party apps and browser plugins (not just the OS)?

33. Do you maintain a current inventory of devices, software, cloud services, and their owners?

34. Are cloud platforms and SaaS configurations reviewed for security misconfigurations?

35. Are mobile devices and BYOD access managed through an enforced security policy or MDM?

36. Are your domain registrar and DNS accounts protected against unauthorized changes?

37. Are API keys, service credentials, and other secrets stored and rotated securely?

38. Do you have a tested business continuity and disaster recovery plan beyond data backups?

39. Are privacy, breach notification, and regulatory obligations documented and assigned?

40. Does leadership receive regular security metrics and risk reporting?

Please answer every question before submitting.

Your result is ready.

Your Cyber Security Score

0%

    Important: This is an indicative self-assessment, not a security audit, certification or guarantee. Read the Assessment Disclaimer.

    Want help closing the gaps?

    Sprint Networks can walk through your results and build a plan that fits your business.