Is your IT actually handled?
Ten questions about the things that put organizations out of business for a week or longer. Answer honestly and you get a scored snapshot, the red flags that outrank your score, and a short list of what to fix first. Built for organizations of any size, and written for the realities of small and mid-sized businesses.
Honest answers beat optimistic ones
Point values are hidden while you answer, on purpose. Pick what is actually true today, not what you intend to have in place by the end of the quarter. Hover or tap the on any question to see why it matters.
Here is where you stand
Where your score sits
Four zones, 0 to 100The ten areas, weakest first
Bar length is the share of available points you earned. Color, glyph and the words all say the same thing, so nothing depends on seeing color.
| Area | Your answer | Status | Points | Max |
|---|---|---|---|---|
| Total | 0 | 100 | ||
What each answer means, and what to do next
Open any area for the gap, the fix, the podcast episodes that cover it, and the published guidance behind the question.
Three questions to ask on Monday
Whatever you scored. Ask them exactly like this, and listen to how long the pause is.
Show me the last successful test restore.
Not the backup log, which only proves a copy was made. Ask to see the day someone pulled data back and confirmed it worked. If they describe the backup instead of the restore, you have your answer.
What is on our network that the manufacturer no longer supports?
Firewalls, VPN appliances, switches, servers: gear that still works but no longer gets security updates. End-of-life equipment never gets a patch, no matter how fast your patching process is.
Walk me through the first hour if this happens at 2am on a Saturday.
Who gets paged, who can unplug things, who calls the insurer, who calls customers. If the plan is "someone notices Monday," the weekend belongs to the attacker.
One question for the leadership team
"For each of the ten areas above, who is accountable, and who is watching when our one IT person is asleep?"
Free email security assessment
See what your Microsoft 365 or Google Workspace email security is actually missing. Fourteen days, two 30 minute sessions, and real findings from your own environment rather than a generic checklist.
- 14 days
- Two 30 minute sessions
- Findings from your tenant
Where these questions came from
Every question maps to published guidance and to episodes of the two IT Audit Labs podcasts. The Audit goes deep with practitioners. SipCyber explains the same risks without the jargon, which is usually the better place to start if IT is not your job.
Standards and published guidance
The frameworks and advisories these ten questions are drawn from.
The Audit podcast
The technical show, for when you want the practitioner view. New episodes at theaudit.itauditlabs.com.
SipCyber
Plain language, no jargon, hosted by Jen Lotze. Start here if you do not work in IT. Full show at itauditlabs.com.