Skip to content
Cyber Security Health Check

How protected is your business, really?

A 20-question assessment built around the ACSC Essential Eight. You'll get a clear security score, your Essential Eight maturity level, and a prioritised list of the fixes that reduce your risk the most.

~5 minutes · 20 questions · No login to start

Multi-factor authentication

Patching & updates

Backups & recovery

Admin privileges

Application control

Staff awareness

About this tool

Cyber Security Health Check

Most Australian small businesses know cyber security matters, but few can say clearly how protected they actually are. The risks — ransomware, email account takeover, phishing, data theft — rarely announce themselves until something breaks, and "we've got antivirus" is no longer a real answer. The Cyber Security Health Check turns that vague worry into a clear picture. It's a short, structured self-assessment built around the Australian Cyber Security Centre's Essential Eight, giving you a security score, a maturity level, and a ranked list of the fixes that reduce your risk the most.

How it works

The tool walks you through a set of plain-English questions covering the Essential Eight mitigation strategies — multi-factor authentication, patching and updates, backups, restricting admin privileges, application control, Office macro settings, application hardening, and operating-system currency — plus supporting controls like staff training, email authentication (SPF/DKIM/DMARC), incident response planning, device/BYOD management, remote-access security, access monitoring, and cyber insurance. For each area you pick the answer that best matches how your business operates today. It then scores your responses to produce an overall security posture, maps your Essential Eight controls to the ACSC's maturity scale (which runs from ad-hoc through to monitored and continuously improving), breaks down your score control-by-control, and orders your gaps as prioritised "quick wins" — weakest and highest-impact first, with a rough effort estimate for each. It's a directional self-assessment to show you where to focus, not a formal audit.

Who it’s for

Owners and managers of Australian small and medium businesses who want a clear, jargon-free read on how exposed they are and where to fix things first.

  • Structured around the ACSC Essential Eight — the Australian Government's baseline set of mitigation strategies — plus supporting controls like staff awareness, email authentication, incident response and cyber insurance.
  • Returns a maturity level on the ACSC's 0-to-3 scale and a control-by-control breakdown, so you can see exactly which mitigations are strong and which are missing.
  • Ranks your gaps as prioritised quick wins ordered by impact-for-effort, so the fastest way to lift your posture is simply to work top-down.

Frequently asked questions

What is the Essential Eight and why does this tool use it?

The Essential Eight is a set of baseline cyber security mitigation strategies published by the Australian Cyber Security Centre (ACSC). It covers the controls that block the most common attacks — things like multi-factor authentication, prompt patching, application control, restricting admin rights, and regular tested backups. It's the closest thing Australia has to a common security yardstick for smaller organisations, which is why the check is built around it and reports your progress against the ACSC's maturity scale rather than an arbitrary vendor checklist.

Is this a formal audit or certification?

No. It's a self-assessment based on the answers you provide, designed to be directional — to show you where your biggest gaps are and what to tackle first. It doesn't inspect your systems or verify your configuration. For a formal audit, certification, or anything you need to attest to an insurer, regulator or client, you should engage a qualified cyber security professional. Think of this as the map that helps you have a much sharper conversation when you do.

Why does my result mention cyber insurance and compliance?

Because they're increasingly linked to the same controls. Many SME cyber insurance policies now require basics like multi-factor authentication and a written incident response plan as a condition of cover, and some client contracts require email authentication (SPF/DKIM/DMARC). If you handle customer payments or personal data, weak controls can also touch PCI and Privacy Act obligations. The check flags where a gap might affect your cover or compliance so you can confirm you still qualify — it doesn't provide legal or financial advice.