FREE forever · no login for checks and guides
MSME Cyber-Security Self-Assessment (score + report)
Twenty yes / no questions across accounts, devices, payments, data, people and backups. A score out of 100, the gaps ranked, and a printable report with the fix for each.
Answer honestly — the score is computed on this page and never stored. 0/20 answered.
Accounts
- Is two-factor authentication on for the business e-mail and the owner's e-mail?
- Is two-factor on for WhatsApp, Instagram / Facebook and any marketplace seller accounts?
- Does every system have its own password (no reuse), kept in a password manager?
- Does each employee have their own login (no shared admin / accounts login)?
Devices
- Are automatic updates on for the billing PC, phones and the router?
- Is all software licensed (no cracked Windows / Tally / design tools)?
- Do all devices have a screen lock and find-my-device enabled?
- Have app permissions (SMS, contacts, accessibility) been reviewed in the last three months?
Backups
- Is there a daily automated backup of accounting data with one copy offline or versioned?
- Has a restore been tested in the last month?
Payments
- Is there a written rule that bank-detail changes and urgent payment requests are confirmed by a call to a known number?
- Are daily UPI / card limits set and transaction alerts on for every debit?
- Are business collections on a merchant / current-account UPI separate from personal UPI?
- Are online card payments taken only through a licensed payment gateway (never card numbers by hand)?
People
- Has every employee signed an IT & social-media security policy?
- Has the team done scam-awareness training or the phishing quiz in the last six months?
- Is access removed and shared passwords rotated the same day an employee leaves?
Data
- Is there a privacy notice for customers and a list of what personal data you hold, why and for how long?
- Do vendors who access your data (CA, software, agency) have their own login and written confidentiality terms?
Response
- Is there a one-page incident plan with the bank, 1930, CERT-In and IT contacts, known to at least two people?
Questions people ask
Is the score stored?
No. It is computed and shown in your browser; print or save the report yourself.
Been hit and need a human?
Our team helps you draft, file and follow up with the bank and the cyber cell — leave your number for a free callback.
More on the Cyber Desk
- 🔑 Password meterType a password and see its strength, what weakens it (dictionary words, dates, keyboard runs, reuse patterns) and how long a modern attack would need — computed entirely in your browser; nothing is sent anywhere.
- 🎲 Password generatorRandom passwords and four-word passphrases generated in your browser with the Web Crypto API — length, symbols and readability options, and a copy button.
- 🧠 Phishing quizTwelve real-style messages and screens. Decide scam or genuine, get the tell for each, and a score to share with your team.
- 🟢 2FA — GoogleStep-by-step: passkeys or an authenticator app for the Google account that holds your business mail, Drive and Play Console — plus backup codes and recovery contacts.
- 🟩 2FA — WhatsAppThe six-digit PIN that stops a hijacker registering your number on another phone, the e-mail recovery, and the privacy settings for a business account.
- 🏧 2FA — banking & UPIApp lock, biometric login, transaction limits, alerts on every debit, disabling international / online use when idle, and SIM binding — the settings, app by app.
The Cyber Desk provides educational tools, checklists and self-help drafts — not legal advice. For serious or high-value fraud, also consult the police and a qualified lawyer.