Cybersecurity Posture Assessment

Evaluate your organization’s cybersecurity readiness.

This assessment calculates a company cybersecurity score and sends detailed results to Synapse Cyber for consultation review.

What you will receive

  • Overall company cybersecurity score
  • Risk level summary
  • Category-by-category score
  • Detailed answer report sent to Synapse Cyber
Step 1

Company Information

Security Domain

Asset Management

1. Do you maintain an inventory of company-owned devices?

2. Do you maintain an inventory of software and applications?

3. Do you remove or replace unsupported operating systems?

4. Do you know where sensitive business data is stored?

Security Domain

Identity & Access Management

5. Is multi-factor authentication required for email and cloud accounts?

6. Is MFA required for administrator accounts?

7. Are user accounts disabled quickly when employees leave?

8. Are privileged accounts separated from normal user accounts?

Security Domain

Endpoint Security

9. Do company computers have antivirus or EDR protection?

10. Are laptops encrypted with BitLocker or similar technology?

11. Are security patches installed regularly?

12. Are USB storage devices controlled or restricted?

Security Domain

Network Security

13. Is your firewall actively managed and reviewed?

14. Is the network segmented with VLANs or similar controls?

15. Is guest Wi-Fi separated from business systems?

16. Do remote users connect through VPN or Zero Trust access?

Security Domain

Email & Phishing Protection

17. Do you use email filtering or advanced threat protection?

18. Are SPF, DKIM, and DMARC configured for your domain?

19. Do employees receive phishing awareness training?

20. Do you run phishing simulation tests?

Security Domain

Backup & Disaster Recovery

21. Are critical systems backed up regularly?

22. Are backups tested for recovery?

23. Do you keep offline or immutable backups?

24. Do you have documented RTO and RPO goals?

Security Domain

Policies & Governance

25. Do you have written cybersecurity policies?

26. Do you have an incident response plan?

27. Do you have a business continuity or disaster recovery plan?

28. Do you review cybersecurity risks with leadership?

Security Domain

Monitoring & Incident Response

29. Are security logs collected and reviewed?

30. Do you have alerts for suspicious activity?

31. Do you have a process for responding to ransomware?

32. Have you performed an incident response tabletop exercise?

Security Domain

Compliance & Risk Management

33. Do you know which compliance requirements apply to your organization?

34. Do you maintain a cybersecurity risk register?

35. Do you review vendor or third-party cybersecurity risk?

36. Do you carry cyber insurance?

Final Step

Additional Notes