AMAX PRACTICAL RESOURCE

IT Risk Assessment

Assess essential controls protecting business information, systems and day-to-day continuity.

About 3 minutes8 questionsInstant summary

HOW TO USE IT

Answer based on what is true today.

Select Yes only where the control is consistently in place and supported by current records. This is an initial guide, not a formal professional opinion.

01Multi-factor authentication is enabled for critical systems.
02Staff access is removed immediately when employment ends.
03Backups are automated, monitored and regularly tested.
04Devices receive security updates and endpoint protection.
05Staff receive practical phishing and cyber-risk awareness training.
06Sensitive data is classified and access is limited.
07The business has an incident-response and recovery plan.
08External IT providers have clear responsibilities and service standards.