Measure Your Cybersecurity Posture
Answer 16 practical questions to see where your organization is strong, where exposure remains, and what to improve first. No account, email, or data submission is required.
Your score is calculated only in your browser. It is a practical baseline, not a certification or a substitute for a security assessment.
Identity & Access
Who can get in, and how tightly that's controlled — the single most attacked layer in every breach.
- 1
MFA enforced on every email account
Multi-factor authentication is required for remote access to all company email accounts — the most targeted entry point for attackers.
- 2
MFA enforced for remote network access
VPN and any other remote access to your network requires multi-factor authentication, not just a password.
- 3
MFA enforced on cloud resources with sensitive data
Every cloud application or storage location holding sensitive or confidential information requires multi-factor authentication to access.
- 4
Local admin rights restricted
Everyday users don't have local administrator rights on their laptops or desktops, and privileged accounts are kept separate from day-to-day use.
Threat & Incident Readiness
What happens the moment something goes wrong — detection, response, and the controls that stop fraud.
- 1
Network monitoring or SOC in place
A monitoring solution or Security Operations Centre alerts your organization to suspicious or malicious activity on the network.
- 2
Incident response plan tested periodically
A formal cyber incident response plan exists and is tested on a regular schedule, not just written and filed away.
- 3
Annual phishing simulation training
Employees are tested with simulated phishing attacks at least once a year to keep awareness sharp.
- 4
Out-of-band verification for fund transfers
Before changing a vendor's bank details or wiring funds, your team verifies the request through a separate channel — the single control insurers check first for crime coverage.
Vulnerability Management
How fast you find weaknesses — and how fast you close them — before attackers do.
- 1
Recurring vulnerability scanning
Your network perimeter is scanned for vulnerabilities on a recurring schedule, not just once a year.
- 2
Regular penetration testing
Independent penetration testing of your network and applications happens at least annually.
- 3
EDR deployed on every endpoint
Endpoint detection and response is deployed and monitored across all endpoints — not just servers or a subset of devices.
- 4
No unmanaged end-of-life software
Systems past end-of-life or end-of-support are identified and either retired or fully segregated from the network.
Foundational Controls
The baseline every cyber insurer expects before they'll even quote you.
- 1
Next-generation firewalls at every ingress point
Next-gen firewalls are deployed at all network ingress and egress points, not just the perimeter edge.
- 2
Email filtering with DMARC enforced
Inbound and outbound email is filtered for spam and malicious content, with DMARC enforced against spoofing.
- 3
Sensitive data encrypted at rest and in transit
Sensitive and confidential data is encrypted both while stored and while moving across your network.
- 4
Backups tested and kept offline from the live environment
Backups are stored disconnected from the live environment and you regularly test full restoration — not just that the backup job completed.
Turn your score into a practical plan
A senior BrainFort consultant can validate your results, prioritize the gaps, and create a roadmap that fits your business and budget.
