Cybersecurity Readiness Assessment

Would your business recognise a cyber incident — and know what to do next?

Most small businesses have some protection in place. Far fewer know whether it would hold when a convincing request arrives, an account is compromised, or normal operations stop. WorkplaceReady assesses readiness across access, devices, email fraud, backups, incident response, suppliers and staff awareness — in plain business language.

Built for small-business owners, managers and operations leads who need to know whether everyday business controls would hold up during a cyber incident — no specialist cybersecurity knowledge required.

  • One-time module purchase
  • Self-service — no calls or consultants
  • Secure Stripe checkout
  • Written for non-technical business owners

Structured assessment, executive report and prioritised actions. Not a certificate, penetration test, or legal advice.

Everyday situations

Four questions worth being able to answer

A supplier emails new bank details.

Who independently verifies the change — and using what trusted contact information?

A senior manager appears to call or message with an urgent payment or access request.

Can staff verify it without relying on the same incoming message, voice or video?

A business email account is compromised.

Is it immediately clear who owns containment, communication and recovery?

Your critical business information must be restored tomorrow morning.

Has the business actually tested that recovery works?

If one of those answers is “I'm not sure,” that uncertainty is exactly what a readiness assessment should uncover.

A familiar situation

When a request looks real, the process has to be what protects the business.

This short example shows how a convincing request can move through a business unchallenged — and why the useful question is not “would we spot it?” but “what would stop it even if nobody did?”

  • Requests can look and sound completely legitimate
  • A safe process does not depend on spotting the fake
  • Verification, approval and escalation are what hold under pressure

Short example · sound on when you press play

Not completely sure how your business would handle that?

The Cybersecurity Readiness Assessment checks the wider business and shows where readiness is strong, where gaps may exist, and what deserves attention first.

Transition

Impersonation is one example. Readiness goes further.

A convincing fraudulent request is only one way a business can be disrupted. Cybersecurity readiness also depends on whether:

Wider cybersecurity readiness

  • access is properly controlled
  • devices and software are maintained
  • phishing and fraud procedures work
  • important information can actually be recovered
  • incident responsibilities are clear
  • suppliers and third parties are considered
  • staff know what to do when something feels wrong

The assessment looks across the business rather than treating one scam or one security product as the whole problem.

Illustrative examples — not customer stories

Where readiness usually breaks down

Scenario 01

The email looks normal.The bank details are new.

Incoming email
From
Regular supplier
Subject
Updated bank details for future invoices

“Please use the new account below for future payments.”

Bank details changedChange not verified
Incoming emailTrust messageChange payment details
Incoming emailVerify using existing supplier contactChange payment details
Email looks legitimatePayment change verified

Readiness gap

The payment process depends too heavily on trusting the incoming message.

Stronger control

Changed payment details are independently verified using an established trusted contact route before money is sent.

Scenario 02

The voice sounds right.The request is urgent.

Incoming call

Calling

Managing Director

“Need this payment authorised now.”

Unusual requestIdentity unverified
CallCallback to known numberApprovalAction
Voice sounds rightIdentity verified

Readiness gap

The business has no independent verification step for unusual high-impact requests.

Stronger control

The request is confirmed through a known trusted channel and, where appropriate, receives a second approval before action.

Scenario 03

The backup exists.Has anyone proved it works?

Backup status

Daily backup completed

Last backup
Today — 02:15
Last restore test
Unknown
Recovery owner
Not defined
BackupRestore testKnown recovery process
Backup existsRecovery proven

Readiness gap

A backup exists on paper, but recovery readiness is unproven.

Stronger control

Critical recovery is tested periodically so the business knows what can actually be restored, how long it takes and who owns the process.

Also assessed

Everyone knows there is an IT problem. Who actually takes control?

The business has security tools but unclear incident ownership.

Stronger control

Incident responsibilities, escalation paths and first actions are established before the pressure arrives.

WorkplaceReady Cybersecurity Readiness looks for this kind of gap across the wider business — then helps prioritise what deserves attention first.

Would your current process stop this?

Cybersecurity Readiness checks where everyday controls hold up — and where one convincing request, failed recovery or unclear responsibility could pass through them.

Cybersecurity readiness is not only a technology question

Security tools matter. So do the people using them and the processes around important decisions. WorkplaceReady looks at all three together.

Technology

  • MFA
  • Software updates
  • Backups
  • Device protection

People

  • Staff awareness
  • Reporting
  • Access responsibilities

Process

  • Payment verification
  • Supplier changes
  • Approval controls
  • Incident ownership
  • Recovery procedures
Scope

What the assessment covers

Seven areas, scored against how your business actually operates.

Identity & access

Can the right people get access without leaving unnecessary access open to the wrong people?

Devices & software

Are everyday systems maintained and protected well enough to support normal operations?

Email, phishing & fraud

Would suspicious requests, payment changes and convincing impersonation attempts meet practical safeguards?

Backups & recovery

Could critical information actually be restored when needed?

Incident response

Does the business know who does what when a cyber incident occurs?

Third-party & supplier security

Could supplier access, changed payment details or third-party dependencies create avoidable exposure?

Staff awareness & security culture

Do people know what to question, how to verify and where to escalate?

Sample result — example only

This is what you receive

A fictional example of a completed Cybersecurity Readiness Assessment. The findings and actions shown are the real ones the assessment produces.

Sample result — example only

Example Services Company

Small business · approximately 20–30 staff

Business Readiness Score

61/ 100

Moderate Readiness

Top three priorities

  1. 1

    Verify unusual high-impact requests independently of the message

  2. 2

    Add a proportionate second approval for high-impact actions

  3. 3

    Test a real backup restore this month

Immediate actions

  1. 1Agree one trusted verification route for unusual payment, access or sensitive-information requests
  2. 2Confirm supplier bank-detail changes using contact information the business already holds
  3. 3Define when a named second person must approve a high-impact action
  4. 4Write down who is called first when a cyber incident happens
See sample report detail

Business context

Cloud email and shared business systems, external IT support, and several staff who can approve payments or account changes.

Several important gaps remain. The priority actions below address the clearest readiness gaps identified in this fictional example.

Category scores

Identity & Access68
Devices & Software72
Email, Phishing & Fraud44
Backups & Recovery52
Incident Response47
Third-Party & Supplier Security58
Staff Awareness & Security Culture66

Executive summary

Example Services Company sits at a Business Readiness Score of 61 / 100 for the Cybersecurity module, placing the business in the "Moderate Readiness" band. Multi-factor authentication, endpoint protection and daily backups are already in place, so the business is not starting from zero. The exposure is concentrated in the business processes around important decisions: how unusual requests are verified, when a second person is required, and whether recovery has actually been proved. The priority improvements are practical and can be agreed by a small team without new software.

Key strength. Multi-factor authentication on email and banking, endpoint protection on business devices and daily backups of critical files are already in place.

Priority detail

Priority 1

Verify unusual high-impact requests independently of the message

Issue
Unusual requests for payments, access or sensitive information can be acted on without an independent check, so the request itself is the only evidence that it is genuine.
Why it matters
Staff should not have to become deepfake experts. A verification step that does not depend on the incoming email, voice or video removes that burden from the individual and puts it on the process.
Action
Agree one rule: any unusual or high-impact request is confirmed through a separately known route — never a contact detail supplied in the request itself.

Priority 2

Add a proportionate second approval for high-impact actions

Issue
High-impact actions — unusual payments, changed bank details, large transfers, sensitive access changes — can be completed by one person acting alone.
Why it matters
Not every business needs the same threshold or procedure. What matters is that the highest-impact actions are not a one-person decision made under pressure.
Action
Decide a threshold that fits the size of the business and require a named second person to confirm anything above it.

Priority 3

Test a real backup restore this month

Issue
Backups have not been restore-tested, so it is unknown whether they would actually work when needed.
Why it matters
A backup that has never been restored is a hope, not a plan. Testing one file today is far cheaper than discovering the problem in the middle of an incident.
Action
Restore one real file and one real system from backup this month, then schedule the same test twice a year in the calendar.

Example finding

Unusual high-impact requests

Readiness gap. A convincing email, phone call or video request can be acted on without an independent check.

Action. Confirm the request through a separately known trusted route before it is actioned.

Why it matters. Staff should not have to become deepfake experts. The process should create the safeguard.

Workspace action detail

Agree one rule: any unusual or high-impact request is confirmed through a separately known route — a number from your own supplier record or internal directory, or a direct message in an established internal channel — never a contact detail supplied in the request itself.

Sections in this sample result

  • 01 Business Readiness Score
  • 02 Executive Summary
  • 03 Top Three Priorities
  • 04 Immediate Actions
  • 05 Example Finding
  • 06 Workspace View

Fictional example. Your result is generated from your own answers.

How it works

  1. 1

    Purchase access

    Complete the secure one-time Stripe checkout for the Cybersecurity Readiness Assessment.

  2. 2

    Create or open your account

    Use the checkout email to sign in or create the WorkplaceReady account that will own the assessment.

  3. 3

    Complete the assessment

    Answer practical questions in plain business language about access, devices, email and payment fraud, backups, incident response, suppliers and staff awareness.

  4. 4

    Receive your report and priorities

    Your Business Readiness Score, findings and prioritised actions appear inside your Business Readiness Workspace as soon as the assessment is complete.

Official guidance

The threat changes. The readiness principle doesn't.

  • Verify unusual requests.
  • Protect access.
  • Prepare recovery.
  • Know who acts.

CISA — United States

CISA recommends verifying suspicious messages through a known contact method rather than replying to the message or using contact details contained in it.

ENISA — European Union

European cybersecurity guidance continues to identify phishing, social engineering, Business Email Compromise and emerging AI- and deepfake-enabled scams as relevant cyber threats.

Government guidance is referenced as the origin of the readiness principle, not as law. WorkplaceReady is decision support for employers. It is not a certificate, inspection, penetration test or legal determination.

Purchase

Get the Cybersecurity Readiness Assessment

Alternative · WorkplaceReady Annual

€199per year

Every current and future readiness module, including Cybersecurity Readiness, with unlimited reassessments.

Start Annual — €199/yr

Have a question before purchasing?

Questions before you start

We already have an IT provider or cybersecurity software.

Good — keep them. WorkplaceReady is not trying to replace technical protection, and it does not scan or attack your systems. Technical protection is one layer of readiness. This assessment also looks at the business controls around it: verification, approvals, staff escalation, supplier risk, recovery and incident ownership.

Our staff are careful.

Awareness matters, and careful staff are an advantage. But a strong process should not depend entirely on one employee noticing that a convincing request is fake. The assessment checks whether important decisions have practical safeguards behind them.

We're a small business. Is this really relevant?

Phishing, fraud, ransomware and business impersonation are not concepts limited to large enterprises, and small teams usually have fewer people between a request and an action. WorkplaceReady is written to make readiness understandable without specialist cybersecurity knowledge.

Is this a penetration test?

No. It is a business Cybersecurity Readiness Assessment. It does not attack, scan or connect to your systems.

Does this make us compliant?

No. WorkplaceReady helps a business understand readiness and identify practical improvements. It is not a compliance certificate, inspection or legal determination.

Do I need technical cybersecurity knowledge?

No. The questions use plain business language and focus on everyday operating practices — who approves what, how requests are verified, what happens when something goes wrong.

What happens after I buy?

Secure Stripe checkout, then sign in or create your WorkplaceReady account with the checkout email. The Cybersecurity Readiness Assessment unlocks on that account. When you complete it you receive your Business Readiness Score, an executive report and prioritised actions inside your Business Readiness Workspace.

Do I need WorkplaceReady Annual?

No. The Cybersecurity Readiness Assessment can be bought once on its own as a one-time module purchase. Cybersecurity is also included in WorkplaceReady Annual, which adds every other current and future readiness module and unlimited reassessments across them.

Know where your cyber readiness is strong — and what to improve first.

One structured assessment. One clear readiness baseline. Practical priorities for the business you already run.