Cyber Health Check
In 5 minutes, see which client information, payment-change, access, and recovery risks your firm should look at first.
10 practical questions
Can your business or practice quickly confirm who can access sensitive client files, matter records, tax documents, or patient records?
*
Yes, reviewed recently
Partly
Not sure
Is there a documented phone or in-person verification step before changed payment instructions are accepted?
*
Documented and followed
Informal process
No clear process
If a mailbox looks compromised, can someone check forwarding rules, sign-ins, sent items, and suspicious apps quickly?
*
Yes, clear owner
Some checks
Not sure
Are MFA and administrator accounts enforced, limited, and reviewed across Microsoft 365?
*
Enforced and reviewed
Partly
Not sure
Does offboarding reliably remove access from Microsoft 365, devices, cloud apps, and practice systems?
*
Documented
Mostly manual
No clear checklist
Has your business or practice tested restore for email, files, or key systems recently enough to trust it under deadline pressure?
*
Tested recently
Backups exist
Not confident
Could your team keep working if file access, the client portal, internet, or a core app failed during a deadline?
*
Plan tested
Some workarounds
Not sure
Are laptops and workstations covered by managed protection, updates, encryption, and lost-device controls?
*
Managed
Mixed coverage
Unsure
Do staff know which AI tools are approved and what client, patient, or business information must not be entered into public tools?
*
Clear guidance
Informal guidance
No guidance
When something looks wrong, is it clear who acts first, who escalates, and who contacts the IT provider?
*
Clear owner
Informal
No clear owner
MFA and sign-in protections for all Microsoft 365 users, especially admins
*
Yes, enforced
Partly
Not sure
Administrator accounts named, limited, reviewed regularly
*
Reviewed recently
Some checks
Not sure
Ability to quickly check forwarding rules, sign-ins, and message risk after suspicious email or changed payment instruction
*
Yes, documented
Informal process
No clear owner
Email security controls such as filtering, impersonation protection, and domain authentication actively reviewed
*
Reviewed
Partly
Not sure
Workstations covered by managed endpoint protection, patching, and update checks
*
Managed
Mixed coverage
Unsure
Lost, retired, or unmanaged devices can be identified and blocked from business or practice data
*
Yes
Partly
Not sure
Email, files, and critical cloud data backed up outside normal recycle-bin retention
*
Yes
Some data only
Not confident
Successful restore test for email, files, or key systems in the last 90 days
*
Yes, tested
Not recently
Never/not sure
Repeatable process for granting and removing user access across Microsoft 365, devices, and core systems
*
Documented
Informal
No clear process
Known ownership for core systems, vendors, passwords, renewals, and escalation paths
*
Documented
Partly
Not sure
Clear response owner for lockouts, mailbox compromise, or device alert
*
Clear owner
Informal
No clear owner
Staff guidance on approved AI tools and prohibited client, patient, business, or practice data use in public tools
*
Clear policy/guidance
Informal guidance
No guidance/not sure
Lead Capture
Your details are used to send the checklist and respond to the next step you choose.
First name
*
Last name
Business email
*
example@example.com
Business or practice name
*
Team size
*
Please Select
1-10
11-25
26-50
51-100
100+
Phone
Please enter a valid phone number.
Format: (000) 000-0000.
Biggest IT or cybersecurity concern
How would you like to use the checklist?
*
Send me the checklist
Talk through the priority gaps
Not sure yet
Hidden Metadata
source_page
source_url
campaign
funnel_type
offer
industry
assessment_slug
result_band
route
submit_source
page_variant
Contact me about this result.
Contact me about this result.
Send my cyber risk checklist
Should be Empty: