Free · No Account Required

How Healthy
Is Your IT?

Rate your practices in five critical areas. We'll generate a maturity scorecard and email a copy — takes about 5 minutes.

Step 1 of 3

Tell us a little about you

Optional — helps us tailor your recommendations.

Company size
Industry
Step 2 of 3

Rate your current practices

Answer every question — select the number that best describes where you are today.

1 — Not in place 2 — Partially started 3 — Partially in place 4 — Mostly complete 5 — Fully automated

Security

EDR/XDR deployed on all endpoints Endpoint detection and response — not just antivirus
MFA enforced for email, remote access, and admin roles Multi-factor authentication across all critical access points
Patch management within defined maintenance windows Servers, endpoints, and network devices patched on a schedule

Cloud & Identity

Single Sign-On for key apps; offboarding closes all access One identity, everywhere — and revoked immediately when someone leaves
Conditional access and least-privilege admin roles Geo/device/risk policies; admins use dedicated accounts
Documented change control for cloud services Approved processes before modifying cloud configs or adding SaaS tools

Backup & Disaster Recovery

Immutable or offline backups with tested restores Ransomware-resistant backups you've actually verified work
Documented RTO/RPO objectives with monitoring You know your recovery time targets and measure against them
Quarterly recovery drills with documented evidence You practice recovery — and can prove it to an auditor

Network

Segmented networks — guest, IoT, and OT separated Firewall rules reviewed; untrusted devices can't reach production
Reliable Wi-Fi with roaming, QoS, and RF coverage No dead spots; voice/video prioritized; AP placement validated
Secure remote access — SSO/MFA, jump hosts, no shared accounts Every remote session is authenticated, logged, and accountable

Support & Monitoring

24/7 monitoring and alerting with documented runbooks Alerts have defined owners and response procedures
Asset inventory and lifecycle management Build standards, MDM enrollment, deprovisioning process
Security awareness training and phishing simulations Regular staff training with simulated phishing to measure improvement
Step 3 of 3

Where should we send your results?

Enter your details to display your scorecard and receive an emailed copy.

Full Name Please enter your name.
Work Email Please enter a valid work email.
Company
Phone (optional)
Your information is only used to send your scorecard. We will never sell or share it.

Your IT Maturity

Processing your assessment…

Priority Recommendations

What We Measure

Each area is rated 1–5 and mapped to four maturity levels. Three questions per category — 15 total.

Security
EDR, MFA, patching
Cloud & Identity
SSO, least-privilege, CA
Backup & DR
Immutability, RTO/RPO, drills
Network
Segmentation, Wi-Fi, access
Support
Monitoring, inventory, training
Initial · 1.0–1.9
Ad-hoc practices, no formal processes, significant gaps.
Basic · 2.0–2.9
Some processes in place but inconsistently applied.
Managed · 3.0–3.9
Documented, repeatable processes with defined ownership.
Optimized · 4.0–5.0
Automated, measured, continuously improving.

Want a Deeper Dive?

We can validate your self-assessment with a short workshop and deliver a 90-day improvement roadmap — no obligation.