Free assessment

How exposed is your business to cyber threats?

Answer 11 quick questions and get your IT security readiness score out of 100, a breakdown across five control categories, and a prioritized list of what to fix first. It takes about two minutes and costs nothing.

What this IT security scorecard measures

The scorecard measures five control areas that decide whether a security incident stays an inconvenience or becomes a shutdown. Each area carries 20 points, split across two questions, so no single tool can carry the whole score. The questions describe outcomes rather than product names, because the same control can be delivered by several vendors.

Identity and access

Identity is the control area attackers reach for first, because a working password needs no malware. Strong answers here look like multi-factor authentication on email, remote access, and every administrator account, staff running as standard users rather than local administrators, and accounts disabled the day somebody leaves. Weak answers look like multi-factor authentication on email only, shared administrator logins, and dormant accounts nobody has removed.

Endpoint and email security

Endpoint and email defenses decide whether a click turns into an intrusion. Strong answers describe managed detection and response with a person reviewing alerts around the clock, plus inbound filtering backed by SPF, DKIM, and DMARC set to enforce so nobody can spoof your domain. Consumer antivirus and default mail filtering sit at the weak end, and unmonitored detection software sits in the middle because alerts nobody reads catch nothing.

Backup and recovery

Backup is the control that turns ransomware from a crisis into a bad afternoon, and only a tested restore proves it. Strong answers describe automated daily backups covering servers, workstations, and cloud mailboxes, one copy that ransomware cannot alter, a full restore tested within the last year, and documented recovery time and recovery point targets. Untested backups score low here on purpose, because a backup nobody has restored is a hypothesis.

Patching, network, and monitoring

Patching and network hygiene close the doors that need no phishing email at all. Strong answers describe centrally managed updates applied within 30 days and reported on, nothing running past end of support, a business firewall with active security subscriptions, guest Wi-Fi separated from company data, and remote access through VPN or a zero-trust service. Remote desktop published straight to the internet scores zero, because it is scanned constantly.

People, policy, and response

People and process decide how much damage the first ten minutes of an incident cause. Strong answers describe security awareness training at least quarterly with simulated phishing, a written incident response plan that names who calls whom, at least one rehearsal, and insurer requirements mapped to the controls that satisfy them. Annual training and an untested plan score partial credit, because both exist on paper more than in practice.

How the score is calculated

The score is the share of available control points your answers earn. Ten of the 11 questions carry a maximum of 10 points each, for 100 points in total, and the opening question about company size carries none because it provides context rather than risk. Answers are graded on outcome, so a control that exists but is unverified earns partial credit and a control that is missing earns none. Choosing I am not sure earns 2 points, since uncertainty about a control is itself a finding worth surfacing. Scores of 85 and above read as a strong posture, 70 to 84 as solid with real gaps, 50 to 69 as exposed in several areas, and below 50 as high exposure.

Who should take the scorecard

The scorecard fits owners, operations leads, and office managers at businesses of roughly 10 to 200 staff across the Midwest, especially in the situations listed below.

What happens after you get your score

Your results appear on screen the moment you answer the last question. You see the score out of 100, a band that explains what it means, a breakdown showing which of the five categories carried you and which dragged you down, and up to three prioritized fixes written as actions rather than product recommendations. Print the page or save it as a PDF to share internally. If you want the findings verified, Zenetrix reviews your environment and confirms what is actually configured, with no obligation to buy anything. Cybersecurity services, managed IT services, IT support and helpdesk.

Related reading covers how multi-factor authentication works, setting recovery time and recovery point targets, security awareness training, and the threats aimed at smaller businesses.

The control areas above follow the same logic as widely used public frameworks, including the CIS Critical Security Controls and the NIST Cybersecurity Framework, which both put identity, data recovery, and incident response near the front of the queue.

Frequently asked questions

How long does the IT security scorecard take?

The scorecard takes about two minutes. You answer 11 multiple choice questions, and the score, the category breakdown, and the recommendations appear on screen as soon as you finish.

Is the scorecard really free?

Yes, the scorecard is free and carries no obligation. Zenetrix asks for your name, business email, and company so the results can be tied to a real environment if you want to talk them through afterwards.

What does the score out of 100 actually mean?

The score is the percentage of available control points your answers earned across five categories. Ten questions carry 10 points each, so 100 points represents every control in place and verified. The first question captures company size and carries no points.

Is this an audit or a penetration test?

The scorecard is a self-assessment, not an audit. It reflects what you believe is configured. A technical review of your tenant, endpoints, and firewall confirms what is actually running, and that is the usual next step.

Will the results help with cyber insurance or compliance questionnaires?

The five categories map to the control areas insurers and auditors ask about most, including multi-factor authentication, endpoint detection, tested backups, patching, and incident response. Frameworks such as HIPAA, PCI DSS, and SOC 2 go further, so treat the scorecard as a starting point rather than a certificate.

Prefer a person to a questionnaire?

Book a free IT strategy session and we will walk the same five control areas with you, then tell you plainly where Zenetrix fits and where it does not.

Book a free IT strategy session