FREE CYBER HEALTH CHECK

How Cyber Resilient Is Your Business?

Find out in around 5 minutes with our free Cyber Health Check.

A practical assessment designed to help Australian businesses understand their cyber risks, identify their biggest gaps and know what to do next.

GET MY FREE CYBER SCORE
35 practical questions   •   Around 5 minutes   •   Personalised PDF report
WHY TAKE THE CHECK?

Know where you stand. Know what to fix.

Cybersecurity doesn’t have to be complicated. The Cyber Health Check gives you a simple, practical view of the areas that matter most.

🔎

Identify Your Gaps

Understand where your business could be exposed and which areas deserve attention.

📊

Get Your Score

Receive your Cyber Resilience Score™ out of 100, giving you a simple view of your overall position.

📋

Know What To Do Next

Get practical recommendations showing what to fix first, why it matters and what to do next.

WHAT WE CHECK

The things that matter to your business

The assessment looks at practical cybersecurity controls across the areas most likely to affect your business.

🔐 Accounts & MFA
Passwords, multi-factor authentication and account security.
💾 Backup & Recovery
Whether your important information can actually be recovered.
💻 Devices & Patching
Keeping computers and business systems protected and up to date.
📧 Email & Phishing
Reducing the risk of phishing, fraud and compromised email accounts.
🛡️ Endpoint Protection
Protection and visibility across business devices.
🌐 Network & Remote Access
Network security and how remote connections are controlled.
👥 People & Awareness
Helping your people recognise and avoid common cyber threats.
🚨 Incident Response
Knowing what happens when something goes wrong.
🔑 Privileged Access
Controlling access to important systems and information.
🏢 Suppliers & Data
Understanding risks involving suppliers, information and business dependencies.

Ready to find out where you stand?

Complete the free Cyber Health Check below. It takes around 5 minutes and requires no technical knowledge.

Your answers are used to generate your Cyber Resilience Score™ and personalised recommendations.
Important: This Cyber Health Check is a practical self-assessment. It is not a penetration test, security audit, certification or guarantee that your business cannot be compromised.
Enter your business's official name.
This field is required.
Employee Count
Select the number of employees in your business.
Enter your business's industry sector.
This field is required.
1. Is MFA enabled or all business email accounts?
2. Is MFA enabled on other critical systems (accounting, banking, CRM, cloud storage)?
4. Are strong, unique passwords/passphrases used for important business accounts?
5. Is important business data backed up automatically?
6. Are backups protected from deletion or encryption by attackers?
7. Have you successfully tested restoring data from backups?
8. Are important cloud services included in your backup/recovery strategy?
9. Are operating systems automatically or regularly updated?
10. Are important applications patched regularly?
11. Are all operating systems and software you use currently supported and regularly updated?
12. Do you know what computers, phones and other business devices you have?
13. Does your email have effective spam and phishing protection?
14. Do employees receive regular cybersecurity/phishing awareness training?
15. Is there a process for independently verifying unusual payment or bank-detail change requests?
16. Does every business computer have active endpoint protection?
17. Is endpoint protection centrally managed or monitored?
18. Are company mobile devices protected with appropriate security controls?
19. Is guest Wi-Fi separated from business systems?
20. Are remote-access methods known and controlled?
21. Is remote access protected with MFA?
22. Do you know which external providers or people have remote access?
23. Do staff know how to identify and report suspicious messages?
24. Do staff know who to contact after a suspected cyber incident?
25. Is cybersecurity included in new-employee onboarding?
26. Is access removed promptly when employees leave?
27. Do ordinary users avoid using administrator accounts for everyday work?
28. Are administrator accounts separated from normal user accounts?
29. Do you know who has administrator access to important systems?
30. Is administrator access reviewed periodically?
31. Do you have a documented cyber incident response plan?
32. Do employees know what to do if a cyber attack is suspected?
33. Do you know who to contact for technical/business assistance after a serious cyber incident?
34. Do you know what sensitive or valuable information you hold and where it is stored?
35. Do you consider cybersecurity when selecting or reviewing important suppliers and IT providers?

YOUR CYBER RESILIENCE SCORE: / 100