01 — Self-assessment
Where you stand on security, honestly.
20 questions, 8 areas, about 10 minutes. You answer on your own, no account — the score is calculated in your browser and goes nowhere without your consent.
What is this self-assessment?
01
What it measures
The basic practices that stop most incidents: who has access to what, whether tested backups exist, whether people recognise a trap email. No technical jargon — the questions are written for someone who runs the company, not for IT.
02
How it works
You answer 20 questions honestly, all on the same 0 to 3 scale. Honesty matters more than the grade: an admitted 0 is worth more than an optimistic 3. The score is calculated on the spot, in your browser.
03
What you get
A score for each of the 8 areas, so you can see at a glance where you are exposed — plus, if you want, the concrete first steps for your weak areas and a link with your analysis you can reopen anytime.
This is not an audit and does not replace an assessment by a specialist — it is an honest starting picture you take yourself, in about 10 minutes.
How to answer — one scale, 0 to 3:
Doesn't exist
We don't have this.
On paper
A written rule or intention exists, but nobody applies it.
Inconsistent
It happens, but not everywhere and not always.
Applied & verified
Applied everywhere, and someone actually checks.
Your result
Overall score
0 / 3
Areas that need attention
Areas scoring below 2 are the easiest way in. For each one there is a free step-by-step guide and a service we can help with:
- Asset and data inventory Free guide → Security Assessment — See the service →
- Access control (passwords & MFA) Free guide → Security Assessment — See the service →
- Security updates Free guide → Security Assessment — See the service →
- Backups and restore Free guide → Continuity & Incident Response — See the service →
- Network and endpoint protection Free guide → Security Assessment — See the service →
- Incident response plan Free guide → Continuity & Incident Response — See the service →
- Employee training Free guide → Security Training — See the service →
- Governance and accountability Free guide → Virtual CISO (vCISO) — See the service →
No critical area — everything scores 2 or above. The steps below help you move from "it happens" to "it is verified".
Want the detailed report, with the first steps?
We send it to your email: the full analysis across all 8 areas and the first actions for each weak area — written for leadership, not for vendors.
We send only what you see here: name, company, email and your per-area score. Nothing else leaves the browser.
Sent! The report reaches your inbox in a few minutes — if you don't see it, check your Spam folder too.
First steps, for your weak areas
Ordered from your weakest area up. Each step is meant to take days, not months.
Asset and data inventory
- Make a simple list (a spreadsheet is fine) of every device and application in use — including cloud accounts.
- For each one, note what data it holds, who can access it, and who is responsible for it.
Detailed step-by-step instructions: Asset and data inventory: build it in a day
If you would rather not do it alone: Security Assessment
Access control (passwords & MFA)
- Turn on two-factor authentication for email first — it is the account every other password resets through.
- Set a simple, verifiable password rule (minimum 12 characters, unique per account, password manager).
- Create a leaver checklist: who closes the accounts and on which day — not "when we get to it".
Detailed step-by-step instructions: How to enable MFA in Microsoft 365
If you would rather not do it alone: Security Assessment
Security updates
- Turn on automatic updates on every computer — it is free and covers most of the risk.
- Once a month, spend 10 minutes checking that updates actually installed.
Detailed step-by-step instructions: BitLocker and automatic updates on Windows
If you would rather not do it alone: Security Assessment
Backups and restore
- Set up an automatic daily backup for critical data — manual means forgotten.
- Keep one copy outside the company network (separate cloud account or disconnected drive).
- Once a quarter, restore a test file. An untested backup is a hope, not a plan.
Detailed step-by-step instructions: Backups with the 3-2-1 rule
If you would rather not do it alone: Continuity & Incident Response
Network and endpoint protection
- Change the admin password on your router/firewall and close internet access to its management page.
- Put protection (antivirus/EDR) on every computer, not just the "important" ones — attacks come in wherever it is thinnest.
- If anyone works remotely, give them a secure path (VPN) instead of open ports.
Detailed step-by-step instructions: Router, Wi-Fi and remote access, step by step
If you would rather not do it alone: Security Assessment
Incident response plan
- Write one page: the first 5 actions in an incident, who decides, and the phone numbers — then print it.
- Tell every employee, once and clearly: "anything suspicious gets reported to X immediately, no blame".
Detailed step-by-step instructions: A one-page incident response plan
If you would rather not do it alone: Continuity & Incident Response
Employee training
- Start with one hour a year on phishing — it is how most attacks get in.
- After the training, test it: a phishing exercise shows whether the message stuck.
Detailed step-by-step instructions: Stop fake emails sent in your company's name (SPF, DKIM, DMARC)
If you would rather not do it alone: Security Training
Governance and accountability
- Name a security owner — without a "who", everything else belongs to nobody.
- Put security on the leadership agenda once a quarter: what happened, what exposes us, what we do next.
- Write down the policies you already apply and review them yearly — not the other way around.
Detailed step-by-step instructions: The governance minimum for a small company
If you would rather not do it alone: Virtual CISO (vCISO)
Do you fall under NIS2? Then the self-assessment above is just the beginning — the law requires an assessment against the official CyberFundamentals framework, documentation and reporting deadlines. CERTO keeps your whole NIS2 file in one place.