Topshelf Technology / Cyber Risk Assessment
Cyber Risk Assessment.
Find the gaps worth addressing first.
Answer 25 questions about your business’s security and technology practices. Get a score based on your answers, priorities to review and a downloadable PDF summary.
Free / 25 questions / About 5 to 7 minutes
Contact and business details are required to view results. This is a self-assessment, not a technical scan.
01 / Four areas. One view.
What does the cyber risk assessment cover?
Look at the controls that protect your business and the everyday practices that help you recover and plan ahead.
PROTECT
Security controls
Review identity protection, backups, endpoint security, remote access, email threats and incident readiness.
RUN
Operational resilience
Review who owns IT, downtime, device age, documentation and the process for removing former employees’ access.
BUILD
Managed systems
Review password management, relevant compliance responsibilities and device encryption and management.
GROW
Planning and AI use
Review how employees use AI with company data and whether technology priorities have a roadmap and budget.
02 / Your security practices
Start with what you know.
Choose the closest answer based on how your business operates today. Use an unsure or not-applicable option where available. After the questions, business and contact details personalize your on-screen results and PDF.
Answer 25 questions, then add contact and business details to personalize your on-screen results and downloadable PDF. This assessment does not email a report or submit these details to TST.
Your risk profile is ready.
Add your details to personalize the report in this browser. Your company size sets the assumptions for the illustrative cost scenario. You can view your results and download a PDF on the next screen. This tool does not email or submit your assessment.
Your entries and answers are used locally to personalize this report. They are not sent to TST by this assessment. Closing or refreshing the page clears your progress. Read our privacy policy.
Higher readiness scores indicate stronger reported controls. The risk label summarizes your answers, not the probability of an incident.
Explore one disruption scenario
Discuss Your Security Priorities
Talk through the controls to verify first and practical next steps for your business.
This assessment is a self-reported diagnostic tool, not a technical audit or penetration test. Scores summarize self-reported controls and help prioritize a review. They do not predict incidents, measure verified security, determine insurance eligibility, or certify compliance.
03 / Understand the result
Read the score. Review the gaps.
Your readiness score combines weighted answers across four areas. Higher scores reflect stronger reported practices. Your answers also trigger findings, so a high score does not cancel out a critical control gap.
The risk label is a questionnaire category. It is not a probability of an incident, and the assessment does not verify whether a control is effective. Confirm important answers with your team or provider.
Treat the cost estimate as a scenario.
The financial illustration uses company size and fixed assumptions for revenue, downtime, productivity, response and recovery. Those assumptions appear with the results and in the PDF. Use the estimate to frame a discussion, not to predict a specific loss.
04 / Make the results useful
Choose the next action with confidence.
Download your summary and review critical gaps first. Confirm the findings, choose one or two practical priorities, and assign an owner and a next step.
Share the report with your internal team or technology provider. If you want help interpreting the findings, talk with Topshelf about a deeper review.
05 / Before you start
A few useful answers.
Does this cyber risk assessment scan our systems?
No. The assessment uses the answers you provide about your security and technology practices. It does not scan your network, test passwords or verify how controls are configured.
How should I read the score and risk level?
The readiness score combines weighted answers across Protect, Run, Build and Grow. A higher score reflects stronger reported practices. Review the findings as well as the score: critical control gaps are highlighted even when the overall score is high. The risk level is a questionnaire category, not a measured probability of an attack.
Is the financial estimate a prediction of our losses?
No. It is an illustrative disruption scenario based on company size and fixed assumptions about revenue, downtime, productivity, response and recovery. The results explain those assumptions. Actual costs can differ substantially.
When are contact details required, and what will I receive?
You can answer the 25 questions first. Before results, enter your name, company, phone number, work email and company size to personalize the report. Results appear on screen, and you can download a PDF summary of scores, findings, the illustrative cost scenario and next steps. The tool does not automatically email the report.
Can we use the report as proof of security, compliance or insurability?
No. Use it to identify practices to investigate with your team or provider. It is not a technical audit, penetration test, compliance certification or insurance determination. Confirm the underlying controls before relying on the findings.
Turn the findings into a practical plan.
Explore more tools and guides, learn about Cybersecurity, or read our Privacy Policy.