Cybersecurity Readiness Assessment
Would your business recognise a cyber incident — and know what to do next?
Most small businesses have some protection in place. Far fewer know whether it would hold when a convincing request arrives, an account is compromised, or normal operations stop. WorkplaceReady assesses readiness across access, devices, email fraud, backups, incident response, suppliers and staff awareness — in plain business language.
Built for small-business owners, managers and operations leads who need to know whether everyday business controls would hold up during a cyber incident — no specialist cybersecurity knowledge required.
- One-time module purchase
- Self-service — no calls or consultants
- Secure Stripe checkout
- Written for non-technical business owners
Structured assessment, executive report and prioritised actions. Not a certificate, penetration test, or legal advice.
Four questions worth being able to answer
A supplier emails new bank details.
Who independently verifies the change — and using what trusted contact information?
A senior manager appears to call or message with an urgent payment or access request.
Can staff verify it without relying on the same incoming message, voice or video?
A business email account is compromised.
Is it immediately clear who owns containment, communication and recovery?
Your critical business information must be restored tomorrow morning.
Has the business actually tested that recovery works?
If one of those answers is “I'm not sure,” that uncertainty is exactly what a readiness assessment should uncover.
When a request looks real, the process has to be what protects the business.
This short example shows how a convincing request can move through a business unchallenged — and why the useful question is not “would we spot it?” but “what would stop it even if nobody did?”
- Requests can look and sound completely legitimate
- A safe process does not depend on spotting the fake
- Verification, approval and escalation are what hold under pressure
Short example · sound on when you press play
Not completely sure how your business would handle that?
The Cybersecurity Readiness Assessment checks the wider business and shows where readiness is strong, where gaps may exist, and what deserves attention first.
Impersonation is one example. Readiness goes further.
A convincing fraudulent request is only one way a business can be disrupted. Cybersecurity readiness also depends on whether:
Wider cybersecurity readiness
- access is properly controlled
- devices and software are maintained
- phishing and fraud procedures work
- important information can actually be recovered
- incident responsibilities are clear
- suppliers and third parties are considered
- staff know what to do when something feels wrong
The assessment looks across the business rather than treating one scam or one security product as the whole problem.
Where readiness usually breaks down
The email looks normal.The bank details are new.
- From
- Regular supplier
- Subject
- Updated bank details for future invoices
“Please use the new account below for future payments.”
Readiness gap
The payment process depends too heavily on trusting the incoming message.
Stronger control
Changed payment details are independently verified using an established trusted contact route before money is sent.
The voice sounds right.The request is urgent.
Calling
Managing Director
“Need this payment authorised now.”
Readiness gap
The business has no independent verification step for unusual high-impact requests.
Stronger control
The request is confirmed through a known trusted channel and, where appropriate, receives a second approval before action.
The backup exists.Has anyone proved it works?
Daily backup completed
- Last backup
- Today — 02:15
- Last restore test
- Unknown
- Recovery owner
- Not defined
Readiness gap
A backup exists on paper, but recovery readiness is unproven.
Stronger control
Critical recovery is tested periodically so the business knows what can actually be restored, how long it takes and who owns the process.
Also assessed
Everyone knows there is an IT problem. Who actually takes control?
The business has security tools but unclear incident ownership.
Stronger control
Incident responsibilities, escalation paths and first actions are established before the pressure arrives.
WorkplaceReady Cybersecurity Readiness looks for this kind of gap across the wider business — then helps prioritise what deserves attention first.
Would your current process stop this?
Cybersecurity Readiness checks where everyday controls hold up — and where one convincing request, failed recovery or unclear responsibility could pass through them.
Cybersecurity readiness is not only a technology question
Security tools matter. So do the people using them and the processes around important decisions. WorkplaceReady looks at all three together.
Technology
- MFA
- Software updates
- Backups
- Device protection
People
- Staff awareness
- Reporting
- Access responsibilities
Process
- Payment verification
- Supplier changes
- Approval controls
- Incident ownership
- Recovery procedures
What the assessment covers
Seven areas, scored against how your business actually operates.
Identity & access
Can the right people get access without leaving unnecessary access open to the wrong people?
Devices & software
Are everyday systems maintained and protected well enough to support normal operations?
Email, phishing & fraud
Would suspicious requests, payment changes and convincing impersonation attempts meet practical safeguards?
Backups & recovery
Could critical information actually be restored when needed?
Incident response
Does the business know who does what when a cyber incident occurs?
Third-party & supplier security
Could supplier access, changed payment details or third-party dependencies create avoidable exposure?
Staff awareness & security culture
Do people know what to question, how to verify and where to escalate?
This is what you receive
A fictional example of a completed Cybersecurity Readiness Assessment. The findings and actions shown are the real ones the assessment produces.
Example Services Company
Small business · approximately 20–30 staff
Business Readiness Score
61/ 100
Top three priorities
- 1
Verify unusual high-impact requests independently of the message
- 2
Add a proportionate second approval for high-impact actions
- 3
Test a real backup restore this month
Immediate actions
- 1Agree one trusted verification route for unusual payment, access or sensitive-information requests
- 2Confirm supplier bank-detail changes using contact information the business already holds
- 3Define when a named second person must approve a high-impact action
- 4Write down who is called first when a cyber incident happens
Workspace action
Verify unusual high-impact requests independently of the message
AnswerFindingPriorityAction
See sample report detailHide sample report detail
Business context
Cloud email and shared business systems, external IT support, and several staff who can approve payments or account changes.
Several important gaps remain. The priority actions below address the clearest readiness gaps identified in this fictional example.
Category scores
Executive summary
Example Services Company sits at a Business Readiness Score of 61 / 100 for the Cybersecurity module, placing the business in the "Moderate Readiness" band. Multi-factor authentication, endpoint protection and daily backups are already in place, so the business is not starting from zero. The exposure is concentrated in the business processes around important decisions: how unusual requests are verified, when a second person is required, and whether recovery has actually been proved. The priority improvements are practical and can be agreed by a small team without new software.
Key strength. Multi-factor authentication on email and banking, endpoint protection on business devices and daily backups of critical files are already in place.
Priority detail
Priority 1
Verify unusual high-impact requests independently of the message
- Issue
- Unusual requests for payments, access or sensitive information can be acted on without an independent check, so the request itself is the only evidence that it is genuine.
- Why it matters
- Staff should not have to become deepfake experts. A verification step that does not depend on the incoming email, voice or video removes that burden from the individual and puts it on the process.
- Action
- Agree one rule: any unusual or high-impact request is confirmed through a separately known route — never a contact detail supplied in the request itself.
Priority 2
Add a proportionate second approval for high-impact actions
- Issue
- High-impact actions — unusual payments, changed bank details, large transfers, sensitive access changes — can be completed by one person acting alone.
- Why it matters
- Not every business needs the same threshold or procedure. What matters is that the highest-impact actions are not a one-person decision made under pressure.
- Action
- Decide a threshold that fits the size of the business and require a named second person to confirm anything above it.
Priority 3
Test a real backup restore this month
- Issue
- Backups have not been restore-tested, so it is unknown whether they would actually work when needed.
- Why it matters
- A backup that has never been restored is a hope, not a plan. Testing one file today is far cheaper than discovering the problem in the middle of an incident.
- Action
- Restore one real file and one real system from backup this month, then schedule the same test twice a year in the calendar.
Example finding
Unusual high-impact requests
Readiness gap. A convincing email, phone call or video request can be acted on without an independent check.
Action. Confirm the request through a separately known trusted route before it is actioned.
Why it matters. Staff should not have to become deepfake experts. The process should create the safeguard.
Workspace action detail
Agree one rule: any unusual or high-impact request is confirmed through a separately known route — a number from your own supplier record or internal directory, or a direct message in an established internal channel — never a contact detail supplied in the request itself.
Sections in this sample result
- 01 Business Readiness Score
- 02 Executive Summary
- 03 Top Three Priorities
- 04 Immediate Actions
- 05 Example Finding
- 06 Workspace View
Fictional example. Your result is generated from your own answers.
How it works
- 1
Purchase access
Complete the secure one-time Stripe checkout for the Cybersecurity Readiness Assessment.
- 2
Create or open your account
Use the checkout email to sign in or create the WorkplaceReady account that will own the assessment.
- 3
Complete the assessment
Answer practical questions in plain business language about access, devices, email and payment fraud, backups, incident response, suppliers and staff awareness.
- 4
Receive your report and priorities
Your Business Readiness Score, findings and prioritised actions appear inside your Business Readiness Workspace as soon as the assessment is complete.
The threat changes. The readiness principle doesn't.
- Verify unusual requests.
- Protect access.
- Prepare recovery.
- Know who acts.
CISA — United States
CISA recommends verifying suspicious messages through a known contact method rather than replying to the message or using contact details contained in it.
ENISA — European Union
European cybersecurity guidance continues to identify phishing, social engineering, Business Email Compromise and emerging AI- and deepfake-enabled scams as relevant cyber threats.
Government guidance is referenced as the origin of the readiness principle, not as law. WorkplaceReady is decision support for employers. It is not a certificate, inspection, penetration test or legal determination.
Get the Cybersecurity Readiness Assessment
Cybersecurity Readiness Assessment
A one-time purchase that unlocks the Cybersecurity Readiness Assessment for your account.
- Where your existing controls are strong
- Where everyday processes create uncertainty
- What deserves attention first
- What practical improvements should follow
- One-time module purchase
- Self-service — no calls or consultants
- Secure Stripe checkout
- Written for non-technical business owners
Alternative · WorkplaceReady Annual
Every current and future readiness module, including Cybersecurity Readiness, with unlimited reassessments.
Start Annual — €199/yrQuestions before you start
We already have an IT provider or cybersecurity software.
Good — keep them. WorkplaceReady is not trying to replace technical protection, and it does not scan or attack your systems. Technical protection is one layer of readiness. This assessment also looks at the business controls around it: verification, approvals, staff escalation, supplier risk, recovery and incident ownership.
Our staff are careful.
Awareness matters, and careful staff are an advantage. But a strong process should not depend entirely on one employee noticing that a convincing request is fake. The assessment checks whether important decisions have practical safeguards behind them.
We're a small business. Is this really relevant?
Phishing, fraud, ransomware and business impersonation are not concepts limited to large enterprises, and small teams usually have fewer people between a request and an action. WorkplaceReady is written to make readiness understandable without specialist cybersecurity knowledge.
Is this a penetration test?
No. It is a business Cybersecurity Readiness Assessment. It does not attack, scan or connect to your systems.
Does this make us compliant?
No. WorkplaceReady helps a business understand readiness and identify practical improvements. It is not a compliance certificate, inspection or legal determination.
Do I need technical cybersecurity knowledge?
No. The questions use plain business language and focus on everyday operating practices — who approves what, how requests are verified, what happens when something goes wrong.
What happens after I buy?
Secure Stripe checkout, then sign in or create your WorkplaceReady account with the checkout email. The Cybersecurity Readiness Assessment unlocks on that account. When you complete it you receive your Business Readiness Score, an executive report and prioritised actions inside your Business Readiness Workspace.
Do I need WorkplaceReady Annual?
No. The Cybersecurity Readiness Assessment can be bought once on its own as a one-time module purchase. Cybersecurity is also included in WorkplaceReady Annual, which adds every other current and future readiness module and unlimited reassessments across them.
Know where your cyber readiness is strong — and what to improve first.
One structured assessment. One clear readiness baseline. Practical priorities for the business you already run.