Skip to content

What is your risk of a Cyber attack?

Take our 3 minute quiz to find out. 20 questions across access, devices, data protection and governance, scored instantly.

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6

1. Access and User Security

Is MFA required for all users? *

Employees should provide a second form of authentication, like a code sent to their phone, when accessing Cloud services such as Microsoft 365. Without MFA, accounts are at higher risk of being compromised.

Are employee accounts regularly reviewed to remove unnecessary privileges and leavers? *

Employees should only have the access they need, and accounts for those who have left the company must be removed. Keeping outdated or excessive permissions increases security risks.

Are there separate Administrator and Standard User accounts? *

Employees with administrative privileges should have a dedicated admin account instead of using their everyday login. Using a separate account for admin tasks reduces the risk of privilege misuse and credential theft.

Is there monitoring and alerting in place to detect potential threats? *

The organisation should have security measures in place to identify logins from unusual locations or anonymous VPN's and take action, such as alerting admins or disabling the account. Without this attackers could access systems unnoticed and escalate an attack.

Are emails scanned for malicious links and attachments? *

Emails should be automatically scanned for malicious content like phishing links, malware, or spam without purely relying on the email vendor security (such as 365 only). Without email security measures, employees are more vulnerable to cyber threats.

Cyber Risk Level

Complete Assessment

Answer all questions to see your risk level

How the score works

Each question carries a weight reflecting how much difference the control makes, and the twenty questions total 81 points. Answering “yes” earns the points; “no” and “don’t know” earn none, so an unanswered control counts as one you cannot rely on.

The result is shown as a risk percentage, so lower is better. It is the inverse of the score you achieved, banded on the same scale SCG Solutions uses across the group. This is a self-assessment and reflects what you told it, so treat it as a way to find the obvious gaps rather than an audit.

What do you need?

It's easy to talk to us