Free cybersecurity risk assessment · No signup required
Cybersecurity risk assessment
Answer 15 plain-language questions about how your business protects accounts, devices, email, data, and recovery. Get a Wolferdawg diagnostic score, risk level, category breakdown, and prioritized action plan in about three minutes.
Free cybersecurity self-assessment for small business
This tool scores the answers you provide across eight security areas. You see the result on the page without creating an account. It is designed to help an owner identify questions to verify and improvements to prioritize.
- 15 plain-language questions
- About three minutes
- No signup to see results
- Answers scored in your browser
Question loads here
YOUR RISK LEVEL
Moderate risk
76 out of 100
Summary loads here.
Your risk by category
Get the full report by email
If you request the report, your name, email address, company, and complete assessment results are submitted to Wolferdawg IT Consulting so the report can be sent. This includes every answer, category score, finding, grade, and risk level. Wolferdawg IT Consulting may retain this information for direct follow-up about your results and related services.
Want help verifying the findings?
Wolferdawg IT Consulting can review the answers, identify what needs technical verification, and help you turn the result into a practical improvement plan.
Book a free 30-minute reviewThis is a self-reported diagnostic based on selected safeguards. It is not a vulnerability scan, penetration test, full NIST or CIS assessment, compliance audit, legal opinion, or proof of cyber insurance eligibility.
How the cybersecurity risk score works
Each answer receives zero to three points. The tool calculates coverage in each category, applies the weights below, and produces a score from zero to 100. The percentages describe this diagnostic tool, not an industry certification.
| Security area | Weight | What it reviews |
|---|---|---|
| Identity and access | 20% | Multifactor authentication and administrator access |
| Backup and recovery | 20% | Protected backups and restore testing |
| Email and phishing defense | 15% | Email authentication and link or attachment protection |
| Endpoint protection and patching | 15% | Device protection and managed updates |
| Network and remote access | 10% | Protected remote access, firewalls, and separation |
| Data protection | 10% | Encryption and least-privilege access |
| Awareness and incident response | 6% | Staff training and a written response plan |
| Cyber insurance readiness | 4% | Policy status and control alignment |
Risk bands
| Score | Tool result | Interpretation |
|---|---|---|
| 85 to 100 | Low risk | Most selected safeguards were reported as present. |
| 70 to 84 | Moderate risk | Important improvements remain. |
| 50 to 69 | Elevated risk | Material gaps need attention. |
| Below 50 | High risk | Several selected safeguards are missing or uncertain. |
Important: Missing critical safeguards can raise the risk level above the numerical band. Low risk is also unavailable when identity and access or backup and recovery scores as weak.
Privacy and limitations
Your answers are scored in your browser. When the results appear, the usage record includes the request time, IP address and approximate location, grade, score, risk band, and critical and warning counts. The usage record does not include your individual answers.
If you request an emailed report, the name, email address, and company you provide are submitted with the complete results, including every answer, category score, finding, grade, and risk level. By requesting the report, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list.
This is a self-assessment, so Wolferdawg IT Consulting does not independently verify the answers. It maps 15 questions to selected safeguards and functions from the CIS Controls and NIST Cybersecurity Framework. It is not a complete framework assessment, compliance review, or cyber insurance determination. For deeper planning, review the official NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide and CIS Implementation Group 1.
Reviewed by Dieter Wolf
Founder of Wolferdawg IT Consulting, with more than 27 years of IT experience. Last reviewed August 25, 2026.
What to do after you receive the result
- Verify each critical finding. A “not sure” answer is a prompt to check the system, not proof that the control is missing.
- Assign an owner and date. Turn each confirmed gap into a specific task with someone responsible for it.
- Address critical gaps first. Then work through the warning findings in an order that fits your systems and operations.
- Retake the assessment. Use the same answers after changes to document progress within this tool.
More free security tools
Frequently asked questions
Plain answers about what the cybersecurity risk assessment covers, how the score works, and what to do with your results.
What is a cybersecurity risk assessment?
A cybersecurity risk assessment identifies important security gaps and helps a business decide what to address first. This free tool is a 15-question self-assessment. It scores the answers you provide, so it is useful for prioritization but does not independently verify your systems.
What does this cyber risk assessment cover?
It covers eight areas: identity and access, endpoint protection and patching, email and phishing defense, backup and recovery, data protection, network and remote access, security awareness and incident response, and cyber insurance readiness.
How is the cybersecurity risk score calculated?
Each answer receives zero to three points. The tool calculates coverage in each category, applies category weights, and produces a score from zero to 100. Identity and backup each carry 20 percent; email and endpoint security each carry 15 percent; network and data protection each carry 10 percent; awareness and incident response carries 6 percent; and cyber insurance readiness carries 4 percent. Critical gaps and weak identity or backup coverage can cap the final risk level.
What does my cybersecurity risk score mean?
In this tool, 85 to 100 is the low-risk range, 70 to 84 is moderate, 50 to 69 is elevated, and below 50 is high. Critical gaps can raise the risk level even when the numerical score is higher. This is a Wolferdawg self-assessment score, not an industry certification or a prediction that a breach will or will not occur.
How is a cybersecurity risk assessment different from a security audit?
This self-assessment scores what you report. A formal assessment or audit verifies controls with documentation, configuration evidence, interviews, and technical testing against a defined scope. Use this tool to identify questions and priorities, not as proof of compliance or insurance eligibility.
What information does the cyber risk assessment record?
Your answers are scored in your browser. When results appear, the usage record includes the request time, IP address and approximate location, grade, score, risk band, and critical and warning counts. It does not include your individual answers. If you request an emailed report, the name, email address, and company you provide are submitted with the complete results, including every answer, category score, finding, grade, and risk level. By requesting the emailed report, you agree that Wolferdawg IT Consulting may retain your contact information and assessment results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list.
Can a nontechnical business owner take this assessment?
Yes. The questions are written for business owners and managers. If you do not know an answer, select the not sure option. The result will treat that uncertainty as something to verify rather than assuming the protection is in place.
What should I address first after the assessment?
Start with findings marked critical. Verify the finding, assign an owner, and plan the change. Common priorities include multifactor authentication, protected and tested backups, monitored endpoint protection, timely patching, and correctly configured email authentication. The correct order still depends on your systems, legal obligations, and business operations.
Review your cybersecurity priorities with an experienced partner
Wolferdawg IT Consulting helps small businesses in Southwest Oklahoma and remote clients nationwide verify security gaps and build a practical improvement plan. Founder Dieter Wolf brings more than 27 years of IT experience to managed IT, cybersecurity, and Microsoft 365 work.
Book a free 30-minute reviewOr call (580) 956-8424 or email hello@wolferdawg.io.