Most small-business owners have no idea where they actually stand until something goes
wrong. Answer 10 plain-English questions and get an honest 0–100 security & compliance score — plus the gaps worth fixing first. It’s built on the same CIS Controls IG1 baseline behind
a Texas SB 2610 safe-harbor program.
Takes about 2 minutes
10 questions · instant score
No sales call to see your results
Honest self-check, not a formal audit. Nothing is shared until you choose to send yourself
the results.
Question 1 of 100%
CIS Control 6 — Access Management
Does every employee use multi-factor authentication (MFA) on email and critical apps?
Stolen passwords are the #1 way small businesses get breached. MFA stops almost all of it.
CIS Control 11 — Data Recovery
Are your backups automated, kept off-site, and tested by an actual restore at least quarterly?
An untested backup is a guess. Ransomware recovery lives or dies on this one.
CIS Control 10 — Malware Defenses
Is every computer and server running managed, monitored antivirus / EDR?
Unmonitored endpoints are where attackers hide. "Installed" is not the same as "watched."
CIS Control 7 — Continuous Vulnerability Management
Are operating-system and software updates applied automatically across all your devices?
Most breaches exploit a known bug that a patch already fixed. Speed is the whole game.
CIS Control 5 — Account Management
When someone leaves, is all of their access removed the same day?
Orphaned accounts are an open door — for ex-employees and for anyone who steals their login.
CIS Control 14 — Security Awareness
Do employees get phishing / security-awareness training at least once a year?
Your people are the target. Trained staff report the email instead of clicking it.
CIS Control 3 — Data Protection
Do you know what sensitive or regulated data you hold (customer PII, health, cardholder) and where it lives?
You can't protect — or prove you protect — data you haven't mapped.
CIS Control 14 / SB 2610 program
Do you have written security policies your team has actually seen and agreed to?
Auditors, insurers, and safe-harbor laws all ask for the paper — not just the practice.
Insurance attestation / evidence
If your cyber-insurer asked tomorrow, could you prove the security controls your policy requires?
Policies require MFA, backups, and training. Can’t prove them and a claim can be denied.
CIS Control 17 — Incident Response
Do you have a written incident-response plan you could actually follow during a breach?
The worst time to invent a plan is at 2 a.m. during an active breach.
Your result
Here’s where you stand
0out of 100
Your biggest gaps to close first
Email me my full results + a prioritized fix-list
Get your score, every answer, and a short ordered to-do list built from your gaps — the
fastest things to fix, first. We’ll send it to your inbox.
No spam — just your results and a follow-up about your baseline.
Want a real number you can prove?
This score is a gut check. A baseline assessment scores you against all 56 CIS IG1
safeguards, collects the evidence, and hands you a roadmap and an attestation you can put
in front of an insurer. Book a free 30-minute discovery call — no obligation.
Nothing from Google, Microsoft, or Meta loads on this site unless you say yes. We keep
basic, cookieless visit counts on our own server either way. Details in our
Privacy Policy.
Essential site function and first-party, cookieless visit counts run either way and can't be
switched off here.