Free to use · Provided by dollop technology
Find your organization's security gaps, and what to fix first
Answer plain-English questions about how your organization handles security. You'll get a clear practices score, your top priorities ranked by what matters most, and a report to share. No security expertise needed, and if you don't know an answer, you can say so.
About 10 minutes. No account required: includes your results and PDF report. For small and mid-sized businesses, nonprofits, schools, and IT teams.
Developing · 30% practices score
- Govern17%
- Identify25%
- Protect55%
- Detect25%
- Respond19%
- Recover38%
Priority 1 of 5
Name an owner for cybersecurity, give them the time and budget to do it, and make leadership accountable.
Choose how deep to go
Quick check
About 10 minutes · 22 questions · no account required
One question per topic. Includes your results and PDF report, with no sign-up.
Start the quick checkFull assessment
About 45 minutes · 106 questions · free account
Every practice in the framework, one topic at a time. It adds:
- Pinpoints which practices are missing within each topic, where the quick check asks one question per topic.
- Priorities and first steps for specific practices, such as reviewing admin access, not just broad topics.
- A report covering all 106 NIST CSF 2.0 practices by code: useful for insurers, auditors, and customer security questionnaires.
- Saves as you go, and can be retaken later with your answers filled in, to track progress.
Best when you need to show your security to an insurer, auditor, or client, or plan the year's security work.
Create a free accountWho should answer?
Ideally an owner or manager who knows how the organization runs, with input from whoever manages your IT, whether that's a staff member or an outside provider. You can start on your own: answer what you know, choose “Not sure” for the rest, and you'll get a checklist to send your IT provider to fill the gaps.
What you get
- A clear result
- One of five levels, from “Just starting” to “Leading”, with what it means for you.
- Your top 5 priorities
- Ranked by what matters most, each with why it matters, a first step, and who should own it.
- A checklist for your IT provider
- Not sure about something? You get the questions to ask and the evidence to request, ready to send.
- A shareable report
- A one-page summary for leadership, and a full report for whoever does the work.
See a sample assessment for a fictional dental practice, including the questions, results, and PDF report.
More free tools
Two quicker checks for specific questions. Also free, with no account.
Cyber insurance readiness check
About 5 minutes · 22 questions · no account required
Would you qualify for cyber insurance? See which security controls carriers expect, which you're missing, and what to fix before you apply or renew.
Check your insurance readinessDomain security scan
About 30 seconds · just your domain · no account required
See what attackers and insurers see from the outside: whether criminals can send email pretending to be you, your HTTPS certificate, and your website's security settings.
Scan your domainThe six areas we'll cover
Think of your organization like a building. Good security means having house rules, knowing what's inside, locking the doors, having alarms, knowing what to do when one goes off, and being able to repair the damage.
1
Govern · Setting the rules
Like agreeing on house rules before anything else: who's in charge of security, what matters most to protect, which laws and contracts you have to follow, and how you keep suppliers in line. Leadership is usually best placed to answer this section.
2
Identify · Knowing what you have
You can't protect what you don't know you own. This section covers keeping track of your devices, software, data, and suppliers, and understanding what could go wrong and how badly.
3
Protect · Locks and good habits
The locks, keys, and good habits that keep problems out: who can log in to what, staff training, protecting data, keeping software up to date, and backups.
4
Detect · Alarms
Even good locks get picked. This section is about the alarms: noticing unusual activity on your systems quickly and working out whether it's a real problem.
5
Respond · When something goes wrong
What happens when the alarm goes off: who takes charge, how you work out what happened, how you stop it spreading, and who you need to tell.
6
Recover · Getting back to normal
Repairs after an incident: restoring systems safely from clean backups, in the right order, and keeping everyone informed along the way.
Who's behind this
This self-assessment is built and provided free by dollop technology, a fractional CISO and IT leadership firm. Engagements are led by Robert Burns, CISSP, CISM, a security and technology executive with more than 20 years of experience building and running IT and security programs. We work with healthcare organizations, nonprofits, digital agencies, and companies going through M&A.
Common questions
Is it really free?
Yes. dollop technology provides it free, with no payment details and no obligation. If you'd like help with your results you can get in touch, but you never have to.
Do I need an account?
Not for the quick check. You'll see your full results and top priorities straight away, and can download the PDF report. A free account lets you save your results, retake the check later to see your progress, and take the full assessment.
Do I need to be a security expert?
No. The questions are in plain English with examples, and “Not sure” is always an option. Anything you're not sure about goes on a checklist for your IT provider, with the questions to ask and the evidence to request, so even an assessment full of “Not sure” gives you something to do next.
Who can see my answers?
Without an account, your answers stay in your browser. They're only sent to us to create your PDF, or to write a results summary if you choose to include one when you contact us. Either way they're used once and not kept, and your notes are only sent if you add them to a full report. Once you save your answers to an account, they're shown only to you when you're logged in. dollop technology runs the site and can access its database, as with any hosted service. Your answers are never sold or used for marketing. See how your data is handled.
How are the priorities chosen?
Each recommendation weighs how weak your answer was against how much that topic matters: the most common ways attackers get in and the hardest damage to recover from come first, and quick wins get a nudge up. The ranking reflects dollop technology's experience running security programs.
What does the score mean?
It's a self-reported security practices score: how consistently you say your organization follows good practices, from “No” to “Improving”. It isn't a measurement of how protected you are. The five levels are dollop technology's own model, not NIST's four CSF Tiers.
Is this an audit or a certification?
No. It's a self-assessment based on your own answers: a starting point, not proof of compliance. It's based on the NIST Cybersecurity Framework 2.0 but isn't endorsed by NIST.
What happens afterward?
Share the report with leadership or your IT provider and work through your next steps. Retake the check later to see your progress. If you'd like help along the way, get in touch.
Can I delete my data?
Yes, anytime. Delete any assessment from your dashboard, or your whole account and everything in it from account settings.
Built on a trusted standard
The questions are based on the NIST Cybersecurity Framework 2.0, a widely used framework from the U.S. National Institute of Standards and Technology. Every question shows NIST's official wording if you want it.