2026 Cybersecurity Baseline

Practical SMB-focused assessment covering identity, endpoints, email, backup, AI security, and monitoring — aligned to modern cyber insurance expectations.

Your Information

Your information is kept private and used only to send your results.
0 of 45 answered 0%

Identity and Access

Is multi-factor authentication required for every user account?
High impact
Is MFA enforced for email
Are administrator accounts separate from day-to-day accounts?
High impact
Are shared accounts eliminated or tightly restricted?
High impact
Is a password manager deployed to all staff?
High impact
Are stale user accounts disabled within 24 hours of departure?
High impact

Endpoint Security

Is an EDR solution deployed on every workstation?
High impact
Is an EDR solution deployed on every server?
High impact
Is EDR monitored 24x7 by a SOC or MDR provider?
High impact
Are full-disk encryption (BitLocker / FileVault) enabled on all devices?
High impact
Are USB ports controlled or restricted by policy?
Are local administrator rights restricted on user workstations?
High impact

Network Security

Is a next-generation firewall in place with active threat feeds?
High impact
Is guest Wi-Fi isolated from the internal network?
High impact
Is DNS filtering deployed (DNSFilter Cisco Umbrella or similar)?
High impact
Are IoT devices on a separate network segment?
Is remote access via VPN or ZTNA with MFA enforced?
High impact

Email Security

Is advanced email security deployed beyond built-in filtering?
High impact
Is DMARC configured with p=reject or p=quarantine?
High impact
Are SPF and DKIM configured for all sending domains?
High impact
Is external sender banner enabled on inbound email?
Are users trained to report phishing with one-click reporting?
High impact

Patch and Vulnerability

Are OS patches applied within 14 days of release?
High impact
Are third-party application patches applied within 30 days?
High impact
Are vulnerability scans run at least quarterly?
High impact
Are critical vulnerabilities remediated within 15 days?
High impact

Backup and Recovery

Are backups performed daily for all critical systems?
High impact
Are backups stored immutable or air-gapped against ransomware?
High impact
Is a cloud backup copy maintained offsite?
High impact
Are SaaS applications (Google Workspace or Microsoft 365) backed up separately?
High impact
Are restore tests performed at least quarterly?
High impact

Security Awareness

Is annual security awareness training mandatory for all staff?
High impact
Are phishing simulations run monthly?
High impact
Are training completion and simulation results tracked?

AI and Data Security

Is an approved list of AI tools defined for business use?
High impact
Are staff trained on what data cannot be shared with public AI tools?
High impact
Is shadow SaaS discovery performed to find unauthorized cloud apps?
High impact
Is DLP deployed on email and key document repositories?
High impact

Monitoring and Response

Is there a 24x7 security monitoring service (MDR or SOC-as-a-Service)?
High impact
Are security logs retained for at least 12 months?
High impact
Is there a documented incident response plan?
High impact
Is the IR plan tested via tabletop at least annually?
High impact

Compliance and Documentation

Are written cybersecurity policies approved and reviewed annually?
High impact
Are cyber insurance requirements reviewed before renewal?
Is a vendor risk list maintained with BAAs / DPAs on file?
High impact
Please answer all questions. remaining.
Results will be emailed to you immediately after submission.
Powered by Blackhawk MSP