Page 1 of 1

CIS IG1 — SMB Cyber Hygiene Assessment

20 quick questions on your security maturity. Rate each on a 0–4 scale: 0 = Not in place · 1 = Ad hoc · 2 = Partial · 3 = Mostly · 4 = Fully / optimized.

About you & your organization

First name

Last name

Company name

Business email

Phone

Website

Company size

Organization type

Primary pain point

Compliance need

Asset Inventory & Configuration

Hardware asset inventory accuracy (laptops/servers/mobile/cloud)

Not in placeFully / optimized

Software/application inventory documentation

Not in placeFully / optimized

Secure baseline configuration documentation for new OS/software

Not in placeFully / optimized

Centralized enforcement/verification of secure configurations

Not in placeFully / optimized

Review/update frequency for network device software (firewalls/routers/switches)

Not in placeFully / optimized

Identity & Access Control

MFA implementation for user/admin accounts (cloud/critical systems/VPN)

Not in placeFully / optimized

Least privilege enforcement for user accounts

Not in placeFully / optimized

Speed of disabling terminated/inactive accounts (including credentials)

Not in placeFully / optimized

Need-to-know access control for sensitive data (PII/financial)

Not in placeFully / optimized

Security awareness education standardization

Not in placeFully / optimized

Vulnerability & Endpoint Defense

Endpoint protection/anti-malware coverage across assets

Not in placeFully / optimized

Anti-malware signature/software update reliability

Not in placeFully / optimized

Vulnerability assessment/tracking process formalization

Not in placeFully / optimized

OS patching effectiveness (routine/automated/timely)

Not in placeFully / optimized

Third-party app patching effectiveness (routine/automated/timely)

Not in placeFully / optimized

Recovery & Monitoring

Backup automation/consistency for critical data & configurations

Not in placeFully / optimized

Offline/isolated/segmented backup copy protections (ransomware/breach)

Not in placeFully / optimized

Backup recovery testing frequency (sample restores)

Not in placeFully / optimized

Security log collection/retention from key assets

Not in placeFully / optimized

Incident triage/communication/response procedure definition

Not in placeFully / optimized