0 of 30 answered
GET-IT Cyber Division — Free Assessment

Operational
Risk Assessment

A structured review of your business's cyber security posture — covering the controls that matter most. Takes around 10 minutes. We'll send a summary to your inbox. No sales call scheduled without your say-so.

~10 minutes No account needed Summary emailed to you Free, no obligation
01

About Your Business

Basic details so we can route your summary correctly and give it meaningful context.

Please enter your company name.
Please enter your name.

We'll send your summary here. If you return to update your answers, we'll match on this address.

Please enter a valid email address.

Optional — helps us identify any publicly visible risks on your domain.

Please select your industry.

Include full-time, part-time, and regular contractors.

Please select a headcount band.

Banded — no exact figure needed. Helps us give financial risk exposure context.

02

People & Awareness

How your team handles security day to day.

Please select an option.

This includes anything from a brief induction session to formal annual training.

MFA — also called two-step verification or 2FA — means staff need a second check (like a code on their phone) in addition to their password to log in.

Please select an option.

A password manager is an app (like Bitwarden, 1Password, or the one built into your browser) that stores and fills your passwords securely.

For example: calling a supplier on a known number to confirm a change of bank details before making a payment. This type of fraud — Business Email Compromise — is among the most costly attacks on UK SMEs.

03

Devices & Software

What your team uses to work, and how it's protected.

Include all PCs, laptops, and Macs used for work — including personal devices used to access business email or systems.

Please enter a device count.

For example: smart TVs, IP cameras, door access systems, printers, smart speakers, or industrial control equipment connected to the internet or your network.

This includes Windows or macOS updates, and updates to apps like Office, browsers, and any software your business relies on.

Please select an option.

This includes standard antivirus (like Windows Defender, Norton, or McAfee) and more advanced tools sometimes called EDR — endpoint detection and response.

Please select an option.

Unlicensed software is often a source of malware and doesn't receive security updates — making it a common entry point for attackers.

Routers, printers, cameras, and other devices often ship with a default admin password like "admin" or "1234". These should be changed before use and are a Cyber Essentials requirement.

A guest Wi-Fi gives visitors internet access without letting them reach your internal files, servers, or connected devices. Mixing the two on a single network is a common and easily exploited gap.

This includes accessing email, files, internal systems, or any business application from outside the office.

Public Wi-Fi is frequently unencrypted and can be monitored by others on the same network. A VPN or mobile data connection provides significantly better protection when working outside the office.

04

Resilience

Your ability to recover if something goes wrong.

Please select an option.

Backups stored only on the same device or network as your main data won't protect you from ransomware. Offsite or cloud copies are important. Select all that apply.

This doesn't need to be formal — even a short document covering who to call and what steps to take counts.

05

Cloud & Business Systems

The platforms and services your business depends on.

Cloud means the software runs over the internet rather than on your own computers. Select all that apply.

06

Data & Client Information

What you handle, and the obligations that come with it.

Personal data includes names, email addresses, phone numbers, financial details, health information, or anything else that could identify a living person. Most businesses handle at least some.

07

Incident History & IT Support

Brief context on your current position.

This includes phishing attacks, ransomware, data breaches, fraud, or any security event — even if it was caught early or didn't cause significant disruption.

For example: a local IT support company, an MSP, or a freelance IT consultant you use regularly.

Ready to submit?

We'll email a summary of your responses to the address you provided. A member of the GET-IT team may follow up if we spot anything worth flagging — but there's no pressure and no obligation.

[ Your data is handled in accordance with our privacy notice. ]

Assessment submitted

Thank you. A summary of your responses is on its way to your inbox. If you don't see it within a few minutes, check your spam folder.

← Return to get-it.uk