0
          questions covering the controls that account for most small business breaches
          0
          risk areas scored separately so you can see where the weakness sits
          0
          minutes to complete, with no free text and nothing to look up
          0
          cost, with no card details and no obligation to speak to anyone

          01

          Take the check

          Twenty questions, about four minutes. Answer honestly rather than optimistically. If you are not sure, pick the option that says so, because an unknown is a real finding. Your score and full report appear once you have added your details at the end.

          Cyber risk check Free · 4 minutes · No sales call

          Question 1 of 20

          All 20 answered

          Your results are ready

          Add your details below and your score, your colour-coded breakdown across the eight areas and your prioritised action list appear on this page straight away.

          We store your answers and your details so we can follow up if you ask us to. We will not share them with anyone else, and you can ask us to delete them at any time by emailing info@remedian.co.uk.

          Please add your name, your company and a valid work email address.

          Your full report

          out of 100

          Your eight areas

          Talk it through with us

          A free thirty minute review with one of our engineers. We prioritise the top three actions for a business your size and answer your questions. No sales pitch.

          Book my free review

          02

          Most businesses have no idea whether their security is adequate

          Ask a business owner whether their IT is secure and you usually get one of two answers. Either yes, because nothing bad has happened yet, or no idea, because it is somebody else's job. Neither answer is much use when you are trying to decide what to spend money on.

          The problem is that security is not one thing. It is roughly thirty separate decisions, most of which get made once and never revisited. Somebody turns on multi-factor authentication for the directors and not for everyone else. Backups get set up properly and then never tested. A member of staff leaves and their account stays live because closing it was nobody's specific job. Each of those is small. Together they are how businesses get breached.

          What this check is, and what it is not

          It is a structured way of asking yourself the questions an assessor would ask, and getting an honest answer back about where the gaps are. It takes four minutes and it will tell you what to fix first.

          It is not an audit. We are not scanning your network or looking at your systems. Everything in the report comes from what you tell us, so the score is only as good as the honesty of the answers. If you are not sure about something, say so. An unknown is a real finding, not a failure to complete the form.

          The score matters less than the ranking. A number out of 100 is a useful thing to compare against in six months, but the part worth acting on is the order of the list. It puts the gaps that would cause you the most damage at the top.

          03

          The eight areas we score, and why each one is on the list

          Every question maps to one of eight areas, and each area carries a different weight. Accounts and backups are worth the most, because they are where the damage happens. Here is what each area covers and why it earns its place.

          Accounts and passwords

          Multi-factor authentication, shared password management, and whether admin accounts are separate from everyday ones. This is the heaviest area on the list. Most break-ins are logins, not hacks.

          Email and phishing

          Whether your domain is protected against spoofing, and whether staff have had training in the last year. Email is where nearly every incident starts.

          Devices and updates

          Automatic security updates, endpoint protection, and disk encryption on laptops and phones. The difference between a lost laptop and a data breach is usually encryption.

          Backups and recovery

          Automated, off-site, and actually tested. An untested backup is a hope rather than a plan, and ransomware is the reason this area is weighted as heavily as accounts.

          Data and website

          Knowing where customer data lives, who can reach it, when it gets deleted, and whether your site runs on a valid certificate. This is where UK GDPR exposure sits.

          Suppliers and leavers

          Which outside parties can log in to your systems, and how quickly access is closed when someone leaves. Both are routinely forgotten and both are routinely exploited.

          Network and payments

          Whether guest and staff Wi-Fi are separated, and how card payments are handled. If you have no office or take no cards, you score full marks rather than being penalised.

          Governance and insurance

          Whether anyone independent has looked at your setup in the last year, and whether you carry cyber cover. Insurers increasingly expect the rest of this list to be in place first.

          The eight areas are scored separately as well as rolled into the total, so a business can come out at 62 overall while still being red in one area. That single red area is usually the thing worth dealing with this month.

          04

          What your score means, and what it does not

          The total lands you in one of three bands. The bands are deliberately broad, because the exact number matters far less than which side of the lines you fall on.

          Under 40: high risk

          Several of the basics are missing and an attacker would not need to be sophisticated. This is a very common starting point, particularly for businesses under twenty staff who have never had anyone look at this properly. Most of what sits at the top of your action list will be free or close to it.

          40 to 69: needs attention

          The obvious controls are partly in place, which usually means somebody set things up correctly at some point and nothing has been reviewed since. The gaps here tend to be the unglamorous ones: untested backups, leavers' accounts, no incident plan.

          70 and above: in good shape

          The main controls are working. What is left is generally maintenance and evidence: testing the restore, writing down what you already do informally, and getting an independent view once a year.

          What the score does not do is tell you that you are safe. It covers the controls that account for most incidents at businesses of your size, and it deliberately ignores anything that needs a specialist to assess. A high score means you have closed the common gaps, not that you are immune.

          It also cannot see your systems. If you answer that backups are tested when nobody has tried a restore in two years, the score will be wrong and it will be wrong in your favour. That is the one way to waste the four minutes.

          05

          What to do with the report once you have it

          The report gives you three groups: priority actions, things worth improving, and what is already working. Work down from the top of the first group and stop when you run out of appetite. Doing the first three items properly beats doing all fifteen badly.

          If you have an IT provider, send them the report and ask which items they consider already covered. That conversation is often more revealing than the report itself. A provider who can explain why something on your list is already handled is doing their job. A provider who has never mentioned any of it is worth a harder look.

          If you look after IT yourself, the top items are almost always things you can do without buying anything. Turning on multi-factor authentication, enforcing automatic updates and closing old accounts cost nothing but an afternoon.

          • Start at the top of the priority list rather than the easiest item.
          • Do the free ones first, because they are usually the highest impact.
          • Book the retest for six months from now, so you have something to compare against.

          You can take the check again whenever you like. Use the same email address and your score is stored against the same record, so a second run shows the movement rather than just a new number. Businesses that go from the forties to the seventies usually do it in two or three sessions of work, not a project.

          06

          How this relates to Cyber Essentials

          Cyber Essentials is the UK government-backed certification scheme run by the NCSC through IASME. It covers five technical control areas and it is assessed formally, either by self-assessment with verification or, for Cyber Essentials Plus, by hands-on testing.

          This check is not that. It is informal, it is self-scored, and nobody verifies your answers. What it does do is cover most of the same ground, which makes it a reasonable way to see how close you are before you commit to an application.

          In practice, businesses scoring below 40 here would fail a Cyber Essentials assessment, usually on access control or patching. Businesses above 70 are generally close enough that certification becomes an exercise in evidence rather than remediation. The middle band is where the work is.

          If certification is the goal, our cyber security page covers what the process involves and where applications tend to fail. We have taken clients through it and the failures are consistent: default admin roles left in place in Microsoft 365, and patching that relies on individuals remembering.

          07

          Free cyber risk check: frequently asked questions

          Is the cyber risk check really free?+
          Yes. There is no charge, no card details and no obligation. You answer twenty questions, add your details, and your score and action list appear on the page. What you do next is up to you.
          How long does it take?+
          About four minutes. Twenty multiple choice questions, nothing to write and nothing to look up. You can go back and change an answer before you finish.
          What do you do with my answers?+
          We store your score, your risk band and your contact details so we can follow up if you ask us to. We do not share your details with anyone else, and you can ask us to delete them at any time by emailing info@remedian.co.uk.
          Do I need to be technical to answer the questions?+
          No. The questions are written for owners and managers rather than IT staff. Every question has an option for when you are not sure, and picking it is more useful than guessing. An unknown counts as a gap because in practice it usually is one.
          Is this the same as Cyber Essentials?+
          No. Cyber Essentials is a formal certification assessed by a licensed body. This is an informal self assessment covering similar ground, so it is a sensible way to see how close you are before applying.
          What happens after I get my score?+
          Nothing automatic. Your full report appears on this page, so print it or save it as a PDF before you close the tab. You can act on it yourself, hand it to whoever looks after your IT, or book a free thirty minute review with one of our engineers. There is no sales sequence attached.
          Can I take it again later?+
          Yes, and it is worth doing every six months or after any significant change. Use the same email address and your record updates, so you can see the movement rather than just a fresh number.
          Does a good score mean we are safe?+
          It means you have closed the gaps that account for most incidents at businesses your size. It does not mean you are immune, and it cannot see anything we have not asked about. Treat it as a baseline, not a certificate.

          Talk your report through with an engineer

          A free thirty minute review. We go through your results, tell you which of the priority actions actually matter for a business your size, and answer whatever you want to ask. If some of the list is already covered by your current setup, we will say so.

          • A real engineer rather than a salesperson, so you get straight answers about what is worth doing.
          • No obligation, no follow-up sequence, and no pitch unless you ask what we charge.
          • Useful whether or not you ever become a client. Plenty of people take the actions away and do them themselves.

          Book my free review

          Our Services

          Computer Not Working?

          We Can Help You Get Back to Work with Expert Computer Repairs Manchester. Contact Us!

          secure-server

          Secure Backup

          A Secure Backup Solution from Remedian I.T. keeps your personal and business data secure and encrypted; both on and offsite to get your business back up and running with the minimum of downtime.

          wifi-router

          Broadband & WiFi

          In our interconnected world your business needs to be online 24/7. Our managed broadband and WiFi will provide quick, quality connection to get the job done. Speak to our sales team to get connected.

          monitor-screen

          Connection Monitoring

          By monitoring your internet connection, we can detect any problems and respond to them before they become major issues, keeping you connected and working towards your goals.

          cctv-camera (1)

          Phone and CCTV Systems

          Digital phone systems provide you with premium features and flexible plans that grow with your business, from single handsets to full office installations. Ask us about an HD CCTV system and access control to monitor your premises and keep your offices as secure as your data.

          it-department

          Hardware

          Providing best value is what we are all about. When it comes to advice, supply and installation of new hardware we make sure you get the best options for your business. We can even arrange finance to help you spread the cost and manage your budgets.

          online-support

          Remote Support

          Our helpdesk team are on hand, from Monday to Friday 8:30am – 5:00pm, to provide free, friendly remote support to make sure you can get your IT back on track in no time.

          Testimonials

          As a long-term client of Remedian, Ashworth Electrical Services have nothing but the highest praise for their assistance in managing our IT systems.
          The service Remedian provide is professional and efficient. The staff are always helpful and friendly.
          Remedian have been our IT support providers now for almost 6 years. During that time they have demonstrated a high level of customer service and value for money support and IT equipment.
          Remedian have helped us grow into the company we are today. The standard of service and expertise Remedian provide us with is second to none, whether it is remote helpdesk support or onsite maintenance.
          The Remedian team have provided weekly on-site technician services and have also provided strategic direction in relation to the Trust's infrastructure which has been invaluable. When issues arise the Remedian team are fast to respond and are proactive in recommending solutions to mitigate any potential issues.