Follow Us On:
The 0$ CyberSecurity Test Starting Image

The $0 Cybersecurity Test: How Many of Your Answers Start With “I Think So”?

Picture this.

It’s a normal workday and someone on your team sends you a message:

“Hey, I clicked something in an email and now it’s asking me to log in again. Is that bad?”

What happens next?

Maybe you immediately know who to call.

Maybe someone on your team handles it.

Maybe your IT provider gets involved.

Or maybe there’s a short silence while everyone tries to figure out who actually owns the problem.

That little moment is what gave us the idea for this test.

Because most businesses are not sitting around with zero security. They have passwords. They have backups. They probably have MFA somewhere. Someone manages the website. Someone manages Microsoft 365. Somebody knows how the CRM works.

The problem is that a lot of those things live in the category of:

“Yeah, I think we have that covered.”

And cybersecurity gets much more interesting when you replace “I think so” with “show me.”

That’s what we’re going to do. Not with a vulnerability scanner or by trying to hack anything.

Just by asking six questions that a business should ideally be able to answer without a lot of guessing.

Here’s the only rule

As you go through the questions, score your business like this:
0: We don’t know.
1: We think so.
2: We can actually show it.

That’s it.

And try to be a little strict with yourself.

If someone says:
“Yeah, I’m pretty sure John handles that.”
That’s a 1.

If John can show you exactly where it is, who has access, and what happens if something goes wrong? That’s a 2.

The Rule is Simple, Scoring list for cybersecurity 0$ Test

The score itself isn’t the important part.

The interesting part is finding the question where everyone suddenly realizes they missed an important part of their cybersecurity procedures.

1. Something goes wrong tonight. Who owns it?

Let’s start with something simple.

It’s 8:30 PM. One of your employees notices strange activity on their business email. Who do they contact?

And please don’t say:

“IT.”

Who specifically? Who has the authority to disable the account? Who contacts your provider?

Who checks whether anything else is affected?

Who tells the employee what to do next?

Who follows up tomorrow?

This sounds obvious until you ask three people in the same company and get three different answers.

One person says the office manager handles it. Another says the owner. Someone else says, “I think we just call Microsoft.”

That confusion matters because you don’t need a giant incident-response binder sitting on a shelf but people should know where the problem goes when something unusual happens.

If the answer is clear, great.

If the answer is:

“Let me ask around…”

You just found your first useful result.

2. What would hurt the most if you lost access tomorrow?

Now imagine you walk into the office tomorrow morning and five systems are unavailable, which five would make everyone panic first?

Maybe:

  • Email
  • Shared files
  • Accounting
  • CRM
  • Website

For another company it might be scheduling, payroll, phones, cloud software, project management, or a point-of-sale system.

Pick your five.

Now here’s where the test gets more interesting.

For each one, ask:

Who owns the account? Who has admin access? What email address controls it?

Is there a second authorized person who can get in?

What happens if the current admin leaves the company?

Worksheet for identifying the owners and administrators of five critical business systems including email, files, CRM, accounting and website

This is where businesses sometimes discover things they haven’t thought about in years.

Maybe the domain was registered by an old employee.

Maybe the website account belongs to a freelancer who no longer works with you.

Maybe there is one person in the company who knows how to access everything.

That person might be fantastic.

They’re also now a single point of failure.

So the real question here isn’t just:

“What software do we use?”

It’s:

“Does the business actually control the systems it depends on?”

3. You have MFA. Great. Where?

Most businesses have heard this advice a hundred times:

Turn on MFA.

And that’s good advice.

But I’d ask a slightly different question.

Pick the account that would cause the biggest headache if someone stole the password.

Maybe it’s:

Your Microsoft 365 admin account.

Your Google Workspace admin.

Your domain registrar.

Your accounting platform.

Your CRM.

Your cloud environment.

Now check that account.

Is MFA actually required?

Not:

“I think we turned it on.”

Not:

“Employees can enable it.”

Not:

“Our email has it.”

Go look.

This is the pattern behind the whole article.

A security control existing somewhere is not quite the same thing as knowing your important accounts are actually protected by it.

And if you check one account today and discover MFA isn’t on?

That’s already a useful outcome.

4. If something strange happened, who would notice first?

Now let’s assume somebody does get into an account.

Would anyone notice? Imagine an employee normally logs in from Jacksonville during working hours. Then later that night, the account starts behaving differently.

Maybe there is a strange sign-in.

Maybe settings change.

Maybe new forwarding rules appear.

Maybe something just looks wrong.

Who sees that?

Does an alert go to someone?

Does your provider monitor it?

Does your internal IT person review it?

Or do several security systems quietly generate notifications that nobody really looks at?

This is one of those uncomfortable business questions because it’s completely possible to pay for security tools and still not have a clear answer.

There’s a difference between:

having alerts

and

having someone responsible for the alerts.

So ask the question literally:

“If something weird happens tonight, who sees it tomorrow morning?”

If the answer is a person’s name and a clear process, that’s good.

If the answer is:

“I assume somebody gets notified…”

Put a 1.

5. Now try this on someone from your team

You don’t need to send them a fake phishing email.

Just ask them this:

“You get an email that looks like it came from me. It says we need to change a supplier’s banking details today and it’s urgent. What would you do?”

Then stop talking.

Let them answer.

That answer tells you a lot.

Maybe they say:

“I’d reply and ask if it’s real.”

Better than immediately sending money, but they’re still talking to the same potentially fake sender.

Maybe they say:

“I’d call you.”

Good.

Maybe they say:

“I’d report the email to IT and verify the request another way.”

Even better.

Example phishing email highlighting unusual urgency, a suspicious sender address, sensitive requests and an unexpected link

The important thing here isn’t turning every employee into a cybersecurity analyst.

You don’t want people afraid to open their inbox.

You want one normal habit:

When a request is unusual, urgent, or sensitive, verify it through another channel.

Call.

Message the person directly.

Open the service yourself instead of using the email link.

Ask someone.

And equally important:

Make sure employees know where suspicious messages should be reported.

Because “this looks weird” is only useful if they know what to do next.

6. Let’s stop talking about backups for a minute

Ask almost any business:

“Do you have backups?”

You’ll usually get:

“Yes.”

Okay.

Let’s test that answer.

Choose one file that doesn’t matter.

Delete nothing important.

Break nothing.

Just take a harmless file and try to restore an older copy from whatever backup system your business uses.

Then open it.

Did it work?

That one small exercise tells you more than a long conversation about backup policies.

Because these are two very different sentences:

“We have backups.”

and

“We restored a file from backup today.”

One is confidence.

The other is evidence.

If the restore works, fantastic.

If nobody knows how to restore something?

Also useful.

You found something before you actually needed it.

Before we total the score, try one more thing

This one is a little different.

Open an incognito or private browser window.

Now pretend you don’t work at your company.

Search for the business.

Business cybersecurity exercise showing how to review public website information, employees, old pages, PDFs, contacts and search results

Don’t try logging into anything.

Don’t test accounts.

Don’t probe systems.

Just look at what is already public.

What can you find?

Your website.

Employees.

Old pages.

Old PDFs.

Public email addresses.

LinkedIn profiles.

Former employees.

Job titles.

Technology vendors mentioned in old content.

Contact details.

Maybe everything looks exactly as expected.

Maybe you find a PDF from 2021 with people who left years ago.

Maybe an old employee is still listed as responsible for something.

Maybe there are old website pages you forgot existed.

Here’s why that’s interesting.

None of those things is automatically a security problem by itself.

But imagine someone wants to send a convincing fake email.

Knowing:

who your finance manager is

plus

who your CEO is

plus

which vendor you use

plus

what your email format looks like

can make a fake message sound a lot more believable.

So this little exercise is less about “finding vulnerabilities” and more about understanding what story the public internet tells about your company. That’s worth knowing.

Okay. Now let’s see where you landed.

Go back through the six questions.

Score each one:

0 = We don’t know

1 = We think so

2 = We can prove it

Six-question small business cybersecurity scorecard covering ownership, critical systems, MFA, monitoring, phishing response and backups

Add them up.

Maximum score: 12.

And before you look at the next section, remember:

This isn’t a grade.

Nobody is handing out certificates.

A 12 doesn’t mean nothing can happen to you.

And a 4 doesn’t mean disaster is coming tomorrow.

We’re measuring something simpler:

How many important security questions can your business answer without guessing?

So what does the score tell you?

If you scored 10–12

You have answers, and you can back up most of them.

Good.

Now keep checking them.

People leave.

New employees join.

New software appears.

Vendors change.

Accounts get forgotten.

Security isn’t something you finish once.

If you scored 7–9

Look for every answer where somebody said:

“I think…”

Those are your next questions.

You probably don’t need to rebuild your entire environment.

You just need to turn a few assumptions into answers.

If you scored 4–6

There may be too much living in people’s heads.

Who owns this?

Who has access?

Who sees the alerts?

Can we restore?

Start there.

One issue at a time.

If you scored 0–3

You actually got something valuable out of this.

You found out that several important questions don’t have clear answers yet.

That’s much better than discovering the same thing in the middle of an incident.

And if you got 12/12?

Don’t frame the article.

You’re not finished.

Cybersecurity isn’t a checklist where you reach the bottom and become “secure.”

A business changes too quickly for that.

A new employee starts.

Someone leaves.

A cloud service gets added.

A laptop gets replaced.

A vendor gets access.

An email account becomes more important.

That’s why we like looking at cybersecurity as an ongoing business process instead of a collection of scary products.

The NIST Cybersecurity Framework takes a similar approach by organizing security around six broad ideas:

Govern. Identify. Protect. Detect. Respond. Recover.

You don’t need to memorize those words.

But the logic is useful.

Know what you have.

Know who owns it.

Protect the important parts.

Notice when something goes wrong.

Know how to respond.

And make sure you can recover afterward.

That is a much more realistic picture of cybersecurity than:

“We installed security software, so we’re done.”

The best answer in this whole test might be “I don’t know.”

Seriously.

Because now you know what to ask next.

Maybe you discovered nobody is sure who owns your domain.

Maybe an important admin account doesn’t have MFA.

Maybe nobody knows who receives security alerts.

Maybe your team understands phishing but doesn’t know how to report it.

Maybe backups exist, but nobody has tested recovery.

Those are all solvable problems.

What’s harder to solve is a problem nobody knows exists.

Start with the question that made you hesitate

If you went through this test and one question made everyone pause, start there.

You don’t need to turn this into a huge cybersecurity project overnight.

Figure out the answer.

Document it.

Fix what needs fixing.

Then move to the next question.

And if you want another set of eyes on it, that’s where IT Pro Services can help.

We work with businesses across managed IT, cybersecurity, cloud and backup, Microsoft 365, employee support, and technology planning.

Our approach is pretty simple: understand what is actually slowing the business down or creating risk, then figure out the practical next step instead of forcing a solution before the problem is understood. That approach is also reflected in ITPS’s own client-service philosophy.

If you need a free 15 minute consultation contact us:

← Back

Thank you for your response. ✨

LIMITED-TIME NEW CLIENT OFFER

— PROTECT • AUTOMATE • GROW —

25% OFF
YOUR FIRST MONTH

Save 25% on your first month of eligible IT Pro Services solutions. — up to $250.

We use cookies

We use cookies to improve your experience on this website. You may choose which types of cookies to allow and change your preferences at any time. Disabling cookies may impact your experience on this website. You can learn more by viewing our Cookie Policy.