How This Works
Answer 12 questions across four security categories. Each question takes 10–20 seconds. At the end, you'll get a scored risk report with a recommended set of priority actions — tailored to what you answered. The questions point to widely recognised best practices; which ones fit your business is your call.
Category 1 — Identity & Access Management
Two-step login (sometimes called MFA) asks for a second step — like a code or a tap on your phone — in addition to the password. It is widely recognised as one of the most effective steps against automated attacks that use stolen passwords.
The recommended practice is that people have only the access their job needs — no more (sometimes called "least privilege").
Former employees with active accounts are a commonly exploited weak point for small businesses.
Category 2 — Data Classification & Retention
It is hard to protect — or respond to a breach of — data you haven't mapped.
Regulatory non-compliance can carry fines; knowing which rules apply is the starting point. Confirm specifics with legal counsel.
"Delete" does not always mean "erased." Retaining old data you no longer need adds unnecessary risk.
Category 3 — Backup & Disaster Recovery
Ransomware often targets backups stored in the same account as production data.
An untested backup may not work when you need it. Many SMBs discover this only during an actual incident.
This is simply how long it would take to get back up and running after something goes wrong (sometimes called your "recovery time"). An unknown recovery time is hard to plan around.
Category 4 — Vulnerability & Patch Management
It is hard to patch what you don't know you have. Shadow IT and forgotten systems are a common breach vector.
Most small-business breaches that exploit a weakness use known problems that already had a fix available. Speed matters most for the most serious, actively-exploited flaws.
Ad hoc patching is hard to rely on. A monthly review cadence is a widely recommended baseline.
Answer all 12 questions to see your report.
Your Security Risk Assessment Results
Your Recommended Priority Actions
Want the rest of the plan?
This snapshot shows where you stand. The Full Edition turns it into a step-by-step plan you can act on — every priority in order, a plain next step for each area, and the templates to do it (policies, checklists, a risk register, and tabletop exercises). It's the security baseline cyber insurers actually ask for — without a six-figure consulting engagement.
Get the Full Edition — from $49, one-time. Files you own forever.
30-day money-back guarantee: if it's not useful, email us within 30 days for a full refund, no questions asked.
sylvanassurance.com/smb-security-assessment
Found this useful? Send the free assessment to someone who'd benefit — your IT person, your bookkeeper, or your insurance broker. It runs in their browser, takes about five minutes, and we never see their answers either: sylvanassurance.com/free/smb-security/
Your First 5 High-Impact Security Fixes
A short, plain-English guide to the five actions that address the most common SMB attack patterns — in the right order. Enter your email and we'll send it over.
Optional, and separate from your assessment — your answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Ready for the Full Roadmap?
The free assessment shows where you may be exposed. The Full Edition adds a deeper 16-question assessment and a scored, prioritised implementation roadmap — category by category — so you know what to consider, in what order, and why.
From $49, one-time — files you own forever. Backed by a 30-day money-back guarantee.
See the Full Edition + Roadmap →