AccuSights
PartnersBlogAbout
Book my 30-minute demo

The Cyber Hygiene Test · 3 minutes · 12 questions

How much of the attack actually gets through? Find out in three minutes.

Twelve plain-English questions on the controls that stop most attacks, scored against the CIS baseline the insurers and regulators use. Your score and your three biggest gaps appear the moment you finish, with the number that matters: how much of the common attack techniques you are covered against today.

Start the test →
12 questions, one tap eachScore shown immediatelyCIS v8.1 IG1 baseline, DBIR 2026 evidence

Step 1 of 3 · About your business

What kind of business are you?

How many people work there?

What is in your environment? Pick all that apply.

Your score and your three biggest gaps appear the moment you finish. The full report and the fix plan come by email.

Questions about the test

What the score measures, and what a good one looks like.

What does the Cyber Hygiene Test measure?
Twelve controls from the CIS Controls v8.1 Implementation Group 1 baseline: multi-factor login, least privilege, patching, endpoint protection, backups, email protection, training, inventory, logging, encryption, vendor risk and incident response. One tap each, plain English, three minutes.
Where do the coverage percentages come from?
The CIS Community Defense Model v2.0 found that the IG1 baseline defends against 77% of the attack techniques used across the top five attack types and 78% of ransomware techniques. Your coverage is a proportional estimate from how many of those controls you have in place.
What is a cyber hygiene checklist?
The routine habits that stop most attacks: multi-factor login on every account, automatic software updates, tested backups kept offline, a list of every device and account you own, removing access when people leave, and basic staff training. The recognized checklist for small firms is CIS Controls Implementation Group 1, which the Center for Internet Security calls essential cyber hygiene. Tick every IG1 item and you are ahead of most small businesses.
What is a security score, and what is a good one?
A number that summarizes how many recommended safeguards you have in place, usually out of 100 or as a letter grade. Scores differ by tool (Microsoft Secure Score, insurer scans and CIS-based assessments all measure different things), so compare your score against the same tool over time rather than against another company. A useful score tells you which gap to fix next, not just a grade.
What are the CIS Controls IG1?
CIS Controls version 8.1 has 18 controls and 153 safeguards. Implementation Group 1 is the starter subset of 56 safeguards designed for small businesses with limited IT staff: asset and software inventory, data protection, secure settings, account and access management, vulnerability management, logging, email and browser protection, malware defenses, recovery, network basics and awareness training. It is the baseline most cyber insurers and frameworks now expect.
Is a free self-assessment worth it?
It is if it is built on a recognized standard like CIS IG1 and gives you a specific fix list instead of a sales pitch. It will not replace a professional assessment with vulnerability scanning and control testing, but it tells you whether you need one and what to prioritize. Treat it as the first step. Your score and top three gaps show immediately; the full twelve-control report comes by email and a 30-minute call with an engineer is offered, never required.
How often should a small business check its security?
Run a hygiene self-check quarterly and a professional assessment at least once a year, or after any big change: a new office, a new cloud system, a merger, major staff turnover. Regulated businesses often have a required cadence; HIPAA expects an ongoing risk analysis, and insurers increasingly ask for annual evidence. Continuous monitoring closes the gap between checks.