Skip to content
Signature CZIT experience

Cyber Health & Decision Engine

Answer 12 practical questions. CZITAPP turns your answers into a prioritised security posture summary and points you to the most relevant guidance and security categories.

Browser-only answersNo loginEducational self-assessment
Cyber posture check0/12 answered
01IdentityIs MFA enforced for administrator accounts and internet-accessible business accounts?
02IdentityDo staff use unique work passwords with an approved secure way to store them?
03AccessAre administrator privileges limited to people who genuinely need them and separated from normal day-to-day use?
04UpdatesCan you show that operating systems, applications and devices are kept within supported and required security-update windows?
05ConfigurationAre default accounts, unnecessary services and insecure configurations removed or disabled on in-scope systems?
06EndpointDo in-scope devices have a managed approach to malware protection or equivalent application-control protections?
07ResilienceAre critical business data and systems backed up with restore tests and protection from the same compromise as production?
08EmailDo you have practical controls for phishing, malicious links and suspicious email reporting?
09AssetsCan you identify the laptops, desktops, mobile devices, servers and cloud services that are in business use?
10AccessCan you promptly disable accounts and recover business access when someone leaves or changes role?
11PeopleDo staff receive practical guidance on phishing, password handling and how to report a suspected incident?
12ResponseDoes the organisation know who will make decisions, communicate and restore services during a cyber incident?

Your answers stay in this browser unless you choose to print the result. This does not constitute a certified security audit or guarantee Cyber Essentials certification.

Continue the decision

Use the evidence, then take the next step.

Cyber Essentials readiness→Security buying guides→Compare providers→