CloudGrid Africa

Assessments / Cybersecurity Health Check

How easily could someone get into your business systems?

Five areas an attacker tests first: who has access, whether backups would survive, whether anyone is watching, how fast you patch, and what staff do with a suspicious message.

15 questions, about 5 minutes. Free. Result shown immediately.

Your result

0out of 100

Score by area

    Where to start, weakest area first

      This reflects your own answers. It is a guide to where to look, not an audit.

      Have the result checked

      Book a 30-minute review call. Denis goes through your answers with you, tells you which of these matter for a business of your size and sector, and what each would take to close. Your score and weakest areas are sent with this form so the call starts from them.

      What the 15 questions cover

      • Access Control

        Do all administrator and finance-system accounts require multi-factor authentication, with no exceptions for convenience? Are former employees' system access and accounts disabled on their last working day, every time? Do different roles (finance, HR, admin) have access limited to only what their job requires, rather than shared broad access?

      • Backup & Recovery

        Are backups of critical systems and data taken on an automated, documented schedule? Has a full restore from backup actually been tested in the last 12 months — not just confirmed the file exists? Are backups stored somewhere that would survive the same incident that took down the primary system?

      • Monitoring & Detection

        Is there monitoring that would flag an unusual login (new device, location, or off-hours) within hours, not days? Does someone actually review security alerts and logs on a regular schedule, rather than only after an incident? Would you know within 24 hours if a laptop or phone with access to company systems was lost or stolen?

      • Patching & Updates

        Are operating systems and critical software patched within days of a security update, not "eventually"? Is there an inventory of what software and systems the business actually runs? Are internet-facing systems (website, remote access, email) specifically prioritized for patching over internal-only systems?

      • Human Risk

        Has staff received phishing-awareness training or a simulated phishing test in the last 12 months? Is there a clear, known process for staff to report a suspicious email or possible incident? Would a staff member know not to act on an urgent payment or password-reset request that only arrived by email or WhatsApp, without verifying it another way?

      CloudGrid Africa assistantAI assistant. Do not share passwords or card details.