How This Works
Answer 12 questions across four security categories. Each question takes 10–20 seconds. At the end, you'll get a scored risk report with a recommended set of priority actions, tailored to what you answered. The questions point to widely recognised best practices; which ones fit your business is your call.
Category 1: Identity & Access Management
Two-step login (sometimes called MFA) asks for a second step (like a code or a tap on your phone) in addition to the password. It is widely recognised as one of the most effective steps against automated attacks that use stolen passwords.
The recommended practice is that people have only the access their job needs, no more (sometimes called "least privilege").
Former employees with active accounts are a commonly exploited weak point for small businesses.
Category 2: Data Classification & Retention
It is hard to protect, or respond to a breach of, data you haven't mapped.
Regulatory non-compliance can carry fines; knowing which rules apply is the starting point. Confirm specifics with legal counsel.
"Delete" does not always mean "erased." Retaining old data you no longer need adds unnecessary risk.
Category 3: Backup & Disaster Recovery
Ransomware often targets backups stored in the same account as production data.
An untested backup may not work when you need it. Many SMBs discover this only during an actual incident.
This is simply how long it would take to get back up and running after something goes wrong (sometimes called your "recovery time"). An unknown recovery time is hard to plan around.
Category 4: Vulnerability & Patch Management
It is hard to patch what you don't know you have. Shadow IT and forgotten systems are a common breach vector.
Most small-business breaches that exploit a weakness use known problems that already had a fix available. Speed matters most for the most serious, actively-exploited flaws.
Ad hoc patching is hard to rely on. A monthly review cadence is a widely recommended baseline.
Answer all 12 questions to see your report.
Your Security Risk Assessment Results
Your Recommended Priority Actions
Want the rest of the plan?
This snapshot shows where you stand. The Team edition turns it into a step-by-step plan you can act on: every priority in order, a plain next step for each area, and the templates to do it (policies, checklists, a risk register, and tabletop exercises). It covers the controls cyber-insurance applications commonly ask about. If it is just you, the Solo edition is sized for a one-person business, with priority advice and seventeen toolkit documents, from $49.
Team from $99, Solo from $49, one-time. Files you own forever.
30-day money-back guarantee: if it's not useful, email us within 30 days for a full refund, no questions asked.
sylvanassurance.com/smb-security-assessment
The framework is also a book: The Small Business Security Playbook, in paperback, hardcover and Kindle. Details and a free first chapter at sylvanassurance.com/book-smb-security-playbook
Found this useful? Send the free assessment to someone who'd benefit: your IT person, your bookkeeper, or your insurance broker. It runs in their browser, takes about five minutes, and we never see their answers either: sylvanassurance.com/free/smb-security/
Your First 5 High-Impact Security Fixes
A short, plain-English guide to the five actions that address the most common SMB attack patterns, in the right order. Enter your email and we'll send it over.
Optional, and separate from your assessment: your answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
The Small Business Security Playbook
These twelve questions are the short form of a four-category framework. The book works it all the way through for the owner who does not have an IT team: what to do, in what order, and how to tell it is working. The back of the book is a sixteen-question version of this assessment, ten policy templates, six tabletop exercises and a vendor security questionnaire, all written to be edited and used.
See the book and read chapter one free → Paperback, hardcover and Kindle.
Choose Solo or Team
The free assessment shows where you may be exposed. The Solo edition turns your answers into a priority order sized for one person, with seventeen toolkit documents to work from. The Team edition goes deeper: sixteen questions across four domains, a maturity band, and a prioritised roadmap that covers every gap, not just the top five.
Solo $49, Team $99, one-time. Files you own forever. Backed by a 30-day money-back guarantee.
Compare Solo and Team →