Most breaches in small and mid-sized firms come through the same few gaps: a mailbox without a second factor, backups ransomware can delete, updates that wait. Eleven questions, from the CIS Controls, show which of yours are open.
Yes, no or not sure. Answer for how things are now, not how the policy says they are.
Reading your answers in your browser
Matching them to the CIS Controls
Grouping the gaps by area
Putting the gaps in order
Security basics report
1 Summary
Where you are weakest
2 The basics
3 What this could not check
Based on the CIS Critical Security Controls v8 (Implementation Group 1, the essential safeguards) and on your own answers, which this check cannot verify. Guidance, not an audit; see the terms.
QUESTIONS
Asked often
The questions people search for before they run the check.
What are the CIS Controls?
A list of security safeguards published by the Center for Internet Security, a non-profit, and used worldwide as a starting point. Version 8 groups them into three Implementation Groups; the first, IG1, is the set it calls essential cyber hygiene for any organisation. This check asks about eleven of the IG1 safeguards that matter most.
What security basics should a small business have?
A second factor on every email account and on remote access, a backup copy ransomware cannot delete and a restore that has been tested, updates installed within a couple of weeks, endpoint protection someone watches, separate admin accounts, access removed when people leave, encrypted laptops, DMARC on the email domain, and staff who know how to report a suspicious message.
Is MFA really that important?
Yes. Most business email compromise starts with one password that was guessed, reused or phished. A second factor from an authenticator app stops almost all of those. The gaps are usually the exceptions: a director who found the codes annoying, or a shared mailbox.
Why does a backup need to be offline or immutable?
Because ransomware operators look for the backups first and delete them before they encrypt anything. A copy that cannot be reached or deleted with ordinary admin access, offline or with object lock, is the one that is still there afterwards.
Is this check an audit?
No. It is guidance based on your own answers, which it cannot verify. Each item names the CIS safeguard it comes from, so an auditor or your IT provider can check it against your systems.
Godwit AI Labs
This report is available as a branded PDF. Use “Download the report” on the page,
or ask us for the detailed report at godwit-tech.com/contact.
Rather we check it on your systems?
A posture review reads the admin consoles, not the policy: who can sign in without a second factor, which backups an attacker could delete, what is behind on updates.