Most business owners, if you asked them how protected their business is from a cyberattack, would give some version of "I think we're okay?" with a question mark hanging on the end. And that uncertainty is exactly the problem. You cannot really act on "I think so." You can act on knowing. So let us turn that vague feeling into something concrete.
What follows is a simple, honest self-assessment you can do in about five minutes, right now, wherever you are. It is a set of plain-yes-or-no questions about the protections that matter most. Answer each one truthfully, and by the end you will have a genuinely useful picture of where your business stands, what is solid, and what needs attention. There is no grade and no judgment here, just clarity. And clarity is the thing that lets you take a real next step instead of continuing to wonder. Grab a pen or just keep a running count in your head, and let us begin.
Section 1: Your accounts and passwords
Answer yes only if it is honestly and fully true.
- Is multi-factor authentication turned on for your email and your important business accounts? This is the single most important protection, so be honest here.
- Does everyone in your business use strong, unique passwords, rather than reusing the same ones across accounts?
- Do you use a password manager to keep those passwords straight?
- If someone got the password to one of your accounts tonight, are you confident that a second layer, like a phone code, would still stop them from getting in?
Count your yeses for this section. These questions cover the most common way businesses get breached, through stolen or weak passwords, so this section matters a great deal.
Section 2: Your devices and data
- Are all your business devices, computers and phones, protected and set to update automatically?
- Do your phones have strong locks, and could you remotely wipe one if it were lost or stolen?
- Is your important business data backed up automatically?
- Here is the crucial follow-up: have you actually tested that you could restore from that backup? Answer yes only if you have genuinely confirmed it works, not just assumed it does.
Count your yeses. This section is about resilience, whether you could keep going and recover if a device failed or an attack struck.
Section 3: Your people and habits
- If you have a team, do they know how to spot a suspicious email, and do they feel comfortable pausing to check when something seems off?
- Do you have a firm rule that any payment or banking change is verified by phone, through a known number, before anyone acts on it?
- Would a team member feel safe telling you immediately if they clicked something they should not have, without fear of blame?
- If an urgent request came in that looked like it was from you, asking to send money or buy gift cards, are you confident your team would verify it rather than just act?
Count your yeses. This section covers the human side, which is where a huge share of attacks actually succeed or fail.
Section 4: Your access and readiness
- Do you know exactly who has access to your systems and data right now?
- When someone leaves your business, is their access reliably and promptly removed?
- If your business were hit by a cyberattack tomorrow, do you have any kind of plan, even a simple one, for what you would do and who you would call?
- Is someone, whether you, a team member, or a service, actually watching your systems for signs of trouble, rather than everyone just assuming things are fine?
Count your yeses. This section is about knowing your exposure and being ready for the bad day.
What your answers mean
Now add up your yeses across all four sections. There are sixteen questions. Here is how to read where you land, honestly and without drama.
If you answered yes to almost all of them, genuinely, then you are in strong shape, well ahead of most small businesses. Your job now is maintenance: keeping these protections current, testing your backups periodically, and keeping awareness fresh, because security is a posture you keep, not a project you finish. Consider whether the one piece most businesses lack, someone actively watching, is fully covered.
If you answered yes to many but had a handful of nos, you have a solid foundation with specific, fixable gaps, which is a good and common place to be. The nos are your roadmap. Look at which ones they were, because some matter more than others, and start with the highest-impact ones. If any of your nos were in Section 1, multi-factor authentication or unique passwords, or the backup-testing question in Section 2, start there this week, because those are the highest-value gaps to close.
If you answered no to many of them, please do not feel discouraged. This is where a great many small businesses genuinely are, and the fact that you just took an honest look already puts you ahead of those still avoiding the question. You have real exposure, but you also have a clear picture now, and closing these gaps is very achievable, especially if you start with the fundamentals and work through them a step at a time.
Whatever your number, the point is not the score. It is that you now know, specifically, where you stand, which is exactly what you needed to take a real next step.
Turning your answers into a next step
Here is what to actually do with this. Look at your nos, and pick the most important one to address first, ideally something from Section 1 or your backups, because those deliver the most protection for the least effort. Do that one thing this week. Then take the next. You do not have to fix everything at once, and trying to often leads to doing nothing. One meaningful step, then another, is how real protection gets built.
If your assessment turned up more gaps than you feel equipped to handle on your own, that is not a failure, it is useful information, and it points to the natural next step: getting help. This is exactly why a professional Business Security Assessment exists. Think of this self-check as the quick version you can do yourself, and a full assessment as the thorough version, where someone who knows what to look for examines your specific situation, finds the gaps you could not see, and gives you a clear plan. Either way, the movement from "I think we're okay?" to a concrete list of next steps is the whole point.
How we think about it
Helping business owners move from uncertainty to clarity to action is the entire reason we do what we do at Red Door Shield, organized around a simple framework we call KIT: Keep, Inspect, Trust. Notice that this self-assessment mirrors it. Sections one and two are largely Keep, are your valuable things secured. Sections three and four bring in Inspect and Trust, are you watching, verifying, and ready. We built our protection to take whatever your assessment reveals and turn it into a handled, watched, and maintained reality, so that "I think we're okay" becomes "I know we're protected," and stays that way without becoming another job on your plate.
What ready looks like
Picture doing this self-check again a few months from now, after you have worked through your nos, and answering yes with confidence down the list. Your accounts locked, your data backed up and tested, your team sharp, your access tidy, and someone watching your back. The uncertainty that hung on the end of "I think we're okay?" is simply gone, replaced by a calm, specific knowledge of exactly how protected you are.
That is what ready feels like. Not a vague hope that you are probably fine, but a clear, earned confidence that you know where you stand and you have handled what matters.
You just did something most business owners never do: you took an honest, specific look at where your business stands. That clarity is worth a lot, and the only thing that makes it truly valuable is what you do next. Pick your most important gap and close it this week. And if you would like the thorough version, a clear, no-pressure professional look at exactly where your business stands and what to do about it, that is precisely what our free Business Security Assessment offers, and it is the natural next step from here.
Learn about a 30-day plan to secure your business, read about why we avoid cybersecurity, or see our guide on building a security culture.
Know Where Your Business Stands
Our free Business Security Assessment gives you a clear, professional picture of your current security posture in less than 10 minutes. No technical knowledge required.
Not sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

