92% OF CERTIFIED UK BUSINESSES AVOID BREACHES  •  CYBER ESSENTIALS INCLUDES FREE £25,000 CYBER LIABILITY INSURANCE  •  SERIOUS BREACHES COST UK SMALL BUSINESSES AN AVERAGE OF £7,960 (BT / DSIT, 2025)  •  MFA IS NOW MANDATORY UNDER CE v3.3  •  GOVERNMENT CONTRACTS REQUIRE CYBER ESSENTIALS CERTIFICATION  • 
GET-IT Cyber Division — Free Assessment Tool

How secure is your
business, really?

Most UK SMEs don't know where their cyber security gaps are until something goes wrong. Our free Operational Risk Assessment tells you where you stand against the Cyber Essentials five control areas — in about 10 minutes, with no technical knowledge required.

Free — no obligation ~10 minutes Instant results CE v3.3 framework No technical knowledge needed
£7,960
Average cost of a serious breach for UK micro/small businesses
BT & Be the Business / DSIT, 2025
92%
Certified businesses that avoid breaches
£25k
Free cyber insurance with every CE certificate
10 min
Time to complete the assessment

A straight answer about your cyber posture

The Operational Risk Assessment is a structured questionnaire mapped to the UK Government's Cyber Essentials framework. You answer plain-English questions about how your business operates — no technical jargon, no trick questions. We score your answers against the five CE control areas and give you a clear, prioritised picture of where your risks are.

Not a sales tool

The assessment runs automatically. Nobody reads your answers before you get your results. There's no pressure to engage us — though we're here if you want to.

Based on real standards

Every question maps directly to the Cyber Essentials v3.3 control framework — the same standard used in formal certification. Your score reflects real-world exposure, not a made-up metric.

Actionable output

You don't just get a score. You get a per-pillar RAG rating, prioritised recommendations for each gap, and a PDF report you can share with your board, your insurer, or your IT provider.

A starting point, not a verdict

The ORA is a self-reported assessment — it tells you where to look, not what a formal audit will find. Think of it as a benchmark, not a certificate.

The CE Five Control Areas

Cyber Essentials covers five technical control areas. Your assessment scores each one independently so you know exactly where to focus first.

P1

Firewalls & Network Boundaries

Are your network boundaries properly controlled? Guest Wi-Fi, remote access, and internet-facing services all count.

P2

Secure Configuration

Are your devices set up securely from the start? Default passwords and unlicensed software are the most common failures.

P3

Security Updates

Is your software kept up to date? Unpatched systems are the single biggest preventable vulnerability class.

P4

User Access Control

Who has access to what? MFA, password management, and access privileges are assessed here.

P5

Malware Protection

Are your devices protected against malware? Coverage, management, and licensing all matter.

Four steps, ten minutes

No account required. No software to install.

1

Fill in the form

30 plain-English questions about your business — devices, staff, software, and working practices. No technical knowledge needed.

2

We score your answers

Your responses are automatically scored against the CE five-pillar framework. A RAG rating and risk score is calculated for each control area.

3

Get your results instantly

A link to your full results report is shown immediately. Your confirmation email contains the same link plus a PDF copy of the report.

4

Decide what to do next

Review the recommendations at your own pace. If you want help acting on them, GET-IT is here — but there's no obligation at any point.

Everything included, nothing held back

The full assessment output is free. There's nothing gated behind a sign-up or a sales call.

📊

Five-pillar risk report

An interactive online report showing your RAG rating and score for each CE control area, overall risk tier (Low / Medium / High / Critical), and prioritised recommendations ordered by severity.

📄

PDF report

A branded, printable PDF version of your results — complete with your scores, recommendations, what CE certification unlocks for your business, and the GET-IT five-stage CE journey. Suitable for sharing with your board or insurer.

📧

Results by email

Your results link and PDF are sent to the email address you provide. The link remains active for seven days so you can revisit or share it. No account needed, no login, no password.

Find out where you stand

The assessment takes around 10 minutes. You'll have your results before the kettle's boiled. No technical knowledge needed, no sales call required, no cost.

Start Your Free Assessment →

[ Free — instant results — no obligation ]