- Home
- Cyber Security
Find out where your business actually stands on cyber risk, in four minutes
Twenty short questions about how your business runs. Add your details at the end and you get a score out of 100, colour-coded results across eight areas, and a prioritised list of what to fix first. Written in plain English for owners and managers, not for IT staff.
Free, no card details, and no sales call unless you ask for one. Answer honestly and the score will tell you something useful.
Start the check See what it covers
01
Take the check
Twenty questions, about four minutes. Answer honestly rather than optimistically. If you are not sure, pick the option that says so, because an unknown is a real finding. Your score and full report appear once you have added your details at the end.
Question 1 of 20
All 20 answered
Your results are ready
Add your details below and your score, your colour-coded breakdown across the eight areas and your prioritised action list appear on this page straight away.
We store your answers and your details so we can follow up if you ask us to. We will not share them with anyone else, and you can ask us to delete them at any time by emailing info@remedian.co.uk.
Please add your name, your company and a valid work email address.
Your full report
out of 100
Your eight areas
Talk it through with us
A free thirty minute review with one of our engineers. We prioritise the top three actions for a business your size and answer your questions. No sales pitch.
Book my free review02
Most businesses have no idea whether their security is adequate
Ask a business owner whether their IT is secure and you usually get one of two answers. Either yes, because nothing bad has happened yet, or no idea, because it is somebody else's job. Neither answer is much use when you are trying to decide what to spend money on.
The problem is that security is not one thing. It is roughly thirty separate decisions, most of which get made once and never revisited. Somebody turns on multi-factor authentication for the directors and not for everyone else. Backups get set up properly and then never tested. A member of staff leaves and their account stays live because closing it was nobody's specific job. Each of those is small. Together they are how businesses get breached.
What this check is, and what it is not
It is a structured way of asking yourself the questions an assessor would ask, and getting an honest answer back about where the gaps are. It takes four minutes and it will tell you what to fix first.
It is not an audit. We are not scanning your network or looking at your systems. Everything in the report comes from what you tell us, so the score is only as good as the honesty of the answers. If you are not sure about something, say so. An unknown is a real finding, not a failure to complete the form.
The score matters less than the ranking. A number out of 100 is a useful thing to compare against in six months, but the part worth acting on is the order of the list. It puts the gaps that would cause you the most damage at the top.
03
The eight areas we score, and why each one is on the list
Every question maps to one of eight areas, and each area carries a different weight. Accounts and backups are worth the most, because they are where the damage happens. Here is what each area covers and why it earns its place.
Multi-factor authentication, shared password management, and whether admin accounts are separate from everyday ones. This is the heaviest area on the list. Most break-ins are logins, not hacks.
Whether your domain is protected against spoofing, and whether staff have had training in the last year. Email is where nearly every incident starts.
Automatic security updates, endpoint protection, and disk encryption on laptops and phones. The difference between a lost laptop and a data breach is usually encryption.
Automated, off-site, and actually tested. An untested backup is a hope rather than a plan, and ransomware is the reason this area is weighted as heavily as accounts.
Knowing where customer data lives, who can reach it, when it gets deleted, and whether your site runs on a valid certificate. This is where UK GDPR exposure sits.
Which outside parties can log in to your systems, and how quickly access is closed when someone leaves. Both are routinely forgotten and both are routinely exploited.
Whether guest and staff Wi-Fi are separated, and how card payments are handled. If you have no office or take no cards, you score full marks rather than being penalised.
Whether anyone independent has looked at your setup in the last year, and whether you carry cyber cover. Insurers increasingly expect the rest of this list to be in place first.
The eight areas are scored separately as well as rolled into the total, so a business can come out at 62 overall while still being red in one area. That single red area is usually the thing worth dealing with this month.
04
What your score means, and what it does not
The total lands you in one of three bands. The bands are deliberately broad, because the exact number matters far less than which side of the lines you fall on.
Under 40: high risk
Several of the basics are missing and an attacker would not need to be sophisticated. This is a very common starting point, particularly for businesses under twenty staff who have never had anyone look at this properly. Most of what sits at the top of your action list will be free or close to it.
40 to 69: needs attention
The obvious controls are partly in place, which usually means somebody set things up correctly at some point and nothing has been reviewed since. The gaps here tend to be the unglamorous ones: untested backups, leavers' accounts, no incident plan.
70 and above: in good shape
The main controls are working. What is left is generally maintenance and evidence: testing the restore, writing down what you already do informally, and getting an independent view once a year.
What the score does not do is tell you that you are safe. It covers the controls that account for most incidents at businesses of your size, and it deliberately ignores anything that needs a specialist to assess. A high score means you have closed the common gaps, not that you are immune.
It also cannot see your systems. If you answer that backups are tested when nobody has tried a restore in two years, the score will be wrong and it will be wrong in your favour. That is the one way to waste the four minutes.
05
What to do with the report once you have it
The report gives you three groups: priority actions, things worth improving, and what is already working. Work down from the top of the first group and stop when you run out of appetite. Doing the first three items properly beats doing all fifteen badly.
If you have an IT provider, send them the report and ask which items they consider already covered. That conversation is often more revealing than the report itself. A provider who can explain why something on your list is already handled is doing their job. A provider who has never mentioned any of it is worth a harder look.
If you look after IT yourself, the top items are almost always things you can do without buying anything. Turning on multi-factor authentication, enforcing automatic updates and closing old accounts cost nothing but an afternoon.
- Start at the top of the priority list rather than the easiest item.
- Do the free ones first, because they are usually the highest impact.
- Book the retest for six months from now, so you have something to compare against.
You can take the check again whenever you like. Use the same email address and your score is stored against the same record, so a second run shows the movement rather than just a new number. Businesses that go from the forties to the seventies usually do it in two or three sessions of work, not a project.
06
How this relates to Cyber Essentials
Cyber Essentials is the UK government-backed certification scheme run by the NCSC through IASME. It covers five technical control areas and it is assessed formally, either by self-assessment with verification or, for Cyber Essentials Plus, by hands-on testing.
This check is not that. It is informal, it is self-scored, and nobody verifies your answers. What it does do is cover most of the same ground, which makes it a reasonable way to see how close you are before you commit to an application.
In practice, businesses scoring below 40 here would fail a Cyber Essentials assessment, usually on access control or patching. Businesses above 70 are generally close enough that certification becomes an exercise in evidence rather than remediation. The middle band is where the work is.
If certification is the goal, our cyber security page covers what the process involves and where applications tend to fail. We have taken clients through it and the failures are consistent: default admin roles left in place in Microsoft 365, and patching that relies on individuals remembering.
07
Free cyber risk check: frequently asked questions
Talk your report through with an engineer
A free thirty minute review. We go through your results, tell you which of the priority actions actually matter for a business your size, and answer whatever you want to ask. If some of the list is already covered by your current setup, we will say so.
- A real engineer rather than a salesperson, so you get straight answers about what is worth doing.
- No obligation, no follow-up sequence, and no pitch unless you ask what we charge.
- Useful whether or not you ever become a client. Plenty of people take the actions away and do them themselves.
Our Services
Computer Not Working?
We Can Help You Get Back to Work with Expert Computer Repairs Manchester. Contact Us!
Secure Backup
A Secure Backup Solution from Remedian I.T. keeps your personal and business data secure and encrypted; both on and offsite to get your business back up and running with the minimum of downtime.
Broadband & WiFi
In our interconnected world your business needs to be online 24/7. Our managed broadband and WiFi will provide quick, quality connection to get the job done. Speak to our sales team to get connected.
Connection Monitoring
By monitoring your internet connection, we can detect any problems and respond to them before they become major issues, keeping you connected and working towards your goals.
Phone and CCTV Systems
Digital phone systems provide you with premium features and flexible plans that grow with your business, from single handsets to full office installations. Ask us about an HD CCTV system and access control to monitor your premises and keep your offices as secure as your data.
Hardware
Providing best value is what we are all about. When it comes to advice, supply and installation of new hardware we make sure you get the best options for your business. We can even arrange finance to help you spread the cost and manage your budgets.
Remote Support
Our helpdesk team are on hand, from Monday to Friday 8:30am – 5:00pm, to provide free, friendly remote support to make sure you can get your IT back on track in no time.

.png?width=150&height=64&name=output-onlinepngtools%20(2).png)
.png?width=229&height=97&name=output-onlinepngtools%20(2).png)