FREE forever · no login for checks and guides

MSME Cyber-Security Self-Assessment (score + report)

Twenty yes / no questions across accounts, devices, payments, data, people and backups. A score out of 100, the gaps ranked, and a printable report with the fix for each.

Answer honestly — the score is computed on this page and never stored. 0/20 answered.

Accounts

  • Is two-factor authentication on for the business e-mail and the owner's e-mail?
  • Is two-factor on for WhatsApp, Instagram / Facebook and any marketplace seller accounts?
  • Does every system have its own password (no reuse), kept in a password manager?
  • Does each employee have their own login (no shared admin / accounts login)?

Devices

  • Are automatic updates on for the billing PC, phones and the router?
  • Is all software licensed (no cracked Windows / Tally / design tools)?
  • Do all devices have a screen lock and find-my-device enabled?
  • Have app permissions (SMS, contacts, accessibility) been reviewed in the last three months?

Backups

  • Is there a daily automated backup of accounting data with one copy offline or versioned?
  • Has a restore been tested in the last month?

Payments

  • Is there a written rule that bank-detail changes and urgent payment requests are confirmed by a call to a known number?
  • Are daily UPI / card limits set and transaction alerts on for every debit?
  • Are business collections on a merchant / current-account UPI separate from personal UPI?
  • Are online card payments taken only through a licensed payment gateway (never card numbers by hand)?

People

  • Has every employee signed an IT & social-media security policy?
  • Has the team done scam-awareness training or the phishing quiz in the last six months?
  • Is access removed and shared passwords rotated the same day an employee leaves?

Data

  • Is there a privacy notice for customers and a list of what personal data you hold, why and for how long?
  • Do vendors who access your data (CA, software, agency) have their own login and written confidentiality terms?

Response

  • Is there a one-page incident plan with the bank, 1930, CERT-In and IT contacts, known to at least two people?

Questions people ask

Is the score stored?

No. It is computed and shown in your browser; print or save the report yourself.

Been hit and need a human?

Our team helps you draft, file and follow up with the bank and the cyber cell — leave your number for a free callback.

The Cyber Desk provides educational tools, checklists and self-help drafts — not legal advice. For serious or high-value fraud, also consult the police and a qualified lawyer.