Answer 14 questions and get a readiness score, prioritized fixes, and an insurance-readiness check — all in your browser.
Answer the 4 core questions to get your score
MFA, backups, patching, and staff training drive most of your risk — start there.
Sets the maturity bar. Sole-operators can mark the solo options below to skip controls they don't need.
If yes, we run a pass/fail check on the 6 controls 2025–2026 underwriters treat as near-mandatory.
Enter your last audit's score to see how much you've improved.
Highest-weight control and an insurer hard gate. Microsoft reports MFA blocks >99.2% of automated account-compromise attacks.
The core ransomware survival control. An untested backup is effectively no backup.
Unpatched software is a top initial-access vector and an insurer requirement.
The human layer is the most common breach entry point for small businesses.
Underwriters require MFA on remote access and critical SaaS specifically — not just email.
Shared logins defeat MFA and break audit trails. A password manager is the cheapest fix.
Orphaned accounts are a quiet breach path. Auto-passes for true solo operators.
Insurers want next-gen endpoint protection (EDR) on workstations and servers — second-most-cited reason for denial.
A named insurer requirement; counters business email compromise.
Insurers want a documented IR plan with a contact tree. A plan "in your head" doesn't count.
Out-of-box router settings are trivially exploited.
Drives most compliance-framework and breach-notification obligations.
This is a vCISO-style baseline self-assessment for small businesses with no dedicated IT staff. You answer 14 questions about the controls that matter most, and the tool returns a 0–100 readiness score, a risk tier, a prioritized fix list (ordered by how much risk each fix removes), a per-domain breakdown, a framework coverage map, and — if you have or are applying for cyber insurance — an insurance-readiness pass/fail. It's the dated, printable "proof" artifact you can hand a client, insurer, or auditor instead of panicking when they ask.
Each of the 14 items maps to a control score (100% / 50% / 0%), multiplied by a weight reflecting framework and insurer priority, then re-normalized to a 0–100 score. The highest weights go to MFA on email/admin (18), tested + immutable backups (14), patching (11), and endpoint/EDR (11) — the controls CISA names as core and insurers gate on. "Not applicable" answers (no remote access, solo operator) are excluded from the math, so a perfect solo setup still scores 100.
A 5-person firm answers: MFA on email = Some accounts (50%), MFA remote/SaaS = No (0%), backups = exist, never tested (50%), patching = manual (50%), endpoint = basic antivirus (50%), training = never (0%), email = filtering only (50%), written IR plan = none (0%), and passwords/firewall/offboarding/data at the middle option (50%). The tool returns "Cybersecurity Readiness: 39/100 — Critical exposure," flags that MFA-everywhere, training, and the written IR plan are the high-impact gaps (the two quick wins it counts are MFA remote and training, both 0% with weight ≥ 8), and — because they're applying for insurance — shows a FAIL naming MFA, backups, EDR, email/DMARC, patching, and the missing written IR plan. The fix list puts turn on MFA everywhere and enable auto-patching near the top because they recover the most risk for the least cost.
<iframe src="https://snaptoolsuite.com/small-business-cybersecurity-checklist/?embed=1"
style="width:100%;max-width:640px;height:1100px;border:0;"
title="Small Business Cybersecurity Audit Checklist" loading="lazy"></iframe>
<p>Free <a href="https://snaptoolsuite.com/small-business-cybersecurity-checklist/">Small Business Cybersecurity Audit Checklist</a> by Snap Tool Suite</p>
See it live: view a real embed example →
This tool scores 0–100. 70–89 is "Baseline-ready" (you cover the core CISA practices and most insurer requirements) and 90–100 is "Audit-ready." Below 70 means at least one high-impact control — MFA, tested backups, patching, or EDR — is missing or partial and should be fixed first.
No. It is a self-assessment that reflects only what you report. It is calibrated to free public frameworks (CISA Cyber Essentials, CIS Controls v8.1 IG1, NIST CSF 2.0) but is not an official CIS/NIST score, a certification, or a penetration test.
An untested backup is effectively no backup — you only find out it failed when you try to restore during a ransomware incident. Insurers specifically require immutable or isolated backups with documented test-restores, so only tested + immutable backups score 100%.
No. The gate mirrors common 2025–2026 underwriting requirements (MFA, EDR, immutable tested backups, email security/DMARC, patching, written incident response plan) but is not a quote, binding indication, or coverage guarantee. Only your insurer or broker can confirm eligibility. Passing reduces denial risk; it does not eliminate it.
No. The audit runs 100% in your browser. None of your answers are transmitted or stored on a server — which matters for a tool that asks about your security weaknesses.
No. Regulated industries (healthcare/HIPAA, payment cards/PCI DSS, defense/CMMC, finance) have mandatory controls beyond this baseline. Passing here is a strong hygiene signal but does not satisfy those frameworks.
This is a self-assessment, not a penetration test, audit, or certification. Output reflects only what you report — accuracy depends on honest, informed answers. The readiness score is a relative prioritization aid calibrated to free public frameworks (CISA Cyber Essentials four core practices, CIS Controls v8.1 IG1, NISTIR 7621r2 / NIST CSF 2.0); it is not an official CIS/NIST score and does not equal CIS IG1 "compliance," which requires verifying all 56 safeguards. The insurance-readiness gate mirrors common 2025–2026 underwriting requirements but is not a quote, binding indication, or guarantee of coverage — carriers differ; only your insurer or broker can confirm eligibility. The "MFA blocks >99.2% of automated attacks" figure is Microsoft's published statistic for automated account-compromise attacks; it does not cover MFA-bypass (adversary-in-the-middle) phishing, so MFA is necessary but not sufficient. Weights are expert judgment about impact-vs-effort for a typical small business, not a published industry constant; your real risk depends on your data, sector, and threat exposure. Regulated industries (HIPAA, PCI DSS, CMMC, finance) have mandatory controls beyond this baseline. This tool is 100% client-side — nothing is transmitted or stored on a server.
🔒 This audit runs entirely in your browser. We don't store, transmit, or sell your answers.