This is a sample with made-up answers.
It shows the results for Harbor Dental Group, a fictional example: a 25-person dental practice where the office manager also looks after IT, with day-to-day technical work handled by an outside IT provider. Your own results will look like this, based on your answers.
What the questions look like
Every question has the same answers, from “No” to “Improving”, plus “Not sure” and “Doesn't apply”. The quick check has 22 questions like this one.
Try it: pick an answer, or press 1 to 7 on your keyboard. Nothing is saved.
What the results look like
Here are Harbor Dental Group's results from the quick check, exactly as they'd see them.
Quick check · Harbor Dental Group (fictional example)
Your result: Developing
30% self-reported security practices score
Some good practices exist, but they're informal or patchy. Writing them down and making them routine is the next step.
This reflects your own answers about your security practices. It isn't a measurement of how protected you are, and it isn't an audit.
22 of 22 answered · 2 not sure
“Not sure” counts as 0 points, because a practice nobody can confirm can't be relied on when something goes wrong. Finding out often raises your score.
How is this worked out?
Each answer is worth 0 to 4 points: No is 0, Sometimes is 1, Written down is 2, Routine is 3, and Improving is 4. “Not sure” counts as 0, and “Doesn't apply” is left out.
Each area's score is the average across its topics, shown as a percentage of the maximum. Your overall result averages the six areas equally, so no single area dominates.
Levels: Just starting (under 20%), Developing (20–39%), Established (40–59%), Strong (60–79%), and Leading (80% and up). The five levels are dollop technology's scoring model for this self-assessment. They aren't NIST's four CSF Tiers, which describe how rigorously an organization governs and manages cybersecurity risk.
Priorities weigh how weak each answer is against how much that topic matters, based on dollop technology's experience of how attacks happen and what organizations struggle to recover from.
Method: questions 2026-09-28, scoring 2026-09-24.
Your top 5 priorities
Ranked by how much each gap matters, not just by your lowest answers: the most common ways attackers get in and the hardest damage to recover from come first, quick wins get a nudge up, and they're spread across your security so you aren't only working on one thing.
Name an owner for cybersecurity, give them the time and budget to do it, and make leadership accountable.
Govern · Who's responsible. You answered “Sometimes” to: Is it clear who is responsible for cybersecurity, do they have the time and budget to do it, and do leaders take ownership?
From your answers, start with:
- Time and budget: Agree how much of the owner's time and budget goes to cybersecurity, and review it every year.
- Leadership ownership: Have leadership formally own cybersecurity risk, with a short update from the owner at least every quarter.
Already in place: a named owner.
High impactQuick win: days, not weeksOwner: Leadership
- Why it matters
- When nobody clearly owns cybersecurity, important work falls between the cracks and nobody has the authority or budget to fix what's found. Most of the other recommendations depend on having an owner.
- Why it ranks here
- Most other improvements need someone accountable for them, so a missing owner holds everything else back.
Your note: Our office manager handles IT alongside everything else.
Official NIST wording (GV.RR)
Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated
Turn on multi-factor authentication, end shared accounts, and review who has access to what every few months.
Protect · Logins and access. You answered “Sometimes” to: Does everyone have their own login, is multi-factor authentication used, and do people only get the access they need?
From your answers, start with:
- Multi-factor authentication: Turn on multi-factor authentication for email, remote access, and admin accounts first, then everything else that supports it.
Not sure: only the access people need. Worth finding out.
Already in place: individual logins.
High impactQuick win: days, not weeksOwner: IT lead or IT provider
- Why it matters
- Stolen and guessed passwords are among the most common ways attackers get in. Multi-factor authentication blocks most of these attacks, and removing shared accounts and old access limits the damage when one account is compromised.
- Why it ranks here
- Weak logins are one of the most common ways attackers get in, and multi-factor authentication is one of the cheapest, most effective fixes.
Your note: Everyone has their own login. Multi-factor authentication is on for email, but not for the practice-management system.
Official NIST wording (PR.AA)
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
Name an incident lead, agree how to rate incident severity, and know who to call for outside help.
Respond · Managing incidents. You answered “No” to: When a security incident happens, is there a plan that says who leads, how serious it is, and when to escalate?
Medium impactQuick win: days, not weeksOwner: Cybersecurity owner, with leadership
- Why it matters
- In the first hours of an incident, confusion about who's in charge and who to call costs time and money. A short plan gets the right people moving fast.
- First step
- Write a one-page plan naming who leads during an incident, who they call (IT provider, insurer, lawyer), and how to reach them out of hours.
- Why it ranks here
- A one-page plan is quick to write and saves critical time when something goes wrong.
Works best after: Who's responsible
Official NIST wording (RS.MA)
Responses to detected cybersecurity incidents are managed
Send security alerts to a named person or provider, and agree clear rules for when an alert becomes an incident.
Detect · Spotting warning signs. You answered “Not sure” to: When something unusual happens on your systems, does someone review it and decide whether it's a real incident?
Medium impactQuick win: days, not weeksOwner: IT lead, IT provider, or security monitoring service
- Why it matters
- Security tools raise alerts, but alerts nobody reads don't stop anything. Attackers often go unnoticed for weeks when warnings aren't reviewed.
- First step
- Find out where security alerts from your email, antivirus, and firewall go today, and make sure a named person or provider reviews them.
- Why it ranks here
- Spotting an attack early greatly reduces the damage it can do.
Works best after: Monitoring
Your note: Our IT provider may watch for alerts. Need to ask them.
Official NIST wording (DE.AE)
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
List who you'd have to notify after a breach, such as customers, partners, and regulators, and the deadline for each.
Respond · Telling people. You answered “Sometimes” to: Do you know who you must notify during an incident, such as customers, partners, regulators, or police, and how?
Medium impactQuick win: days, not weeksOwner: Leadership, with legal or compliance advice
- Why it matters
- Many laws and contracts set strict deadlines for reporting a breach, sometimes within 72 hours. Missing them can bring fines and damage trust more than the breach itself.
- First step
- List everyone you'd have to notify after a data breach (regulators, customers, partners, insurer) with the deadline for each, and keep it with your incident plan.
- Why it ranks here
- Notification deadlines are short and legally binding, and missing them adds cost to an already bad situation.
Works best after: Your mission and obligations
Official NIST wording (RS.CO)
Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
Your score in each area
Govern · Setting the rules17%Show topics
- Your mission and obligations50%
- Your approach to risk25%
- Who's responsible25%
- Security policy0%
- Checking it's working0%
- Suppliers and partners0%
Identify · Knowing what you have25%Show topics
- Knowing what you have50%
- Understanding your risks25%
- Learning and improving0%
Protect · Locks and good habits55%Show topics
- Logins and access25%
- Staff training25%
- Protecting data and backups75%
- Keeping systems up to date75%
- Resilient networks and equipment75%
Detect · Alarms25%Show topics
- Spotting warning signs0%
- Monitoring50%
Respond · When something goes wrong19%Show topics
- Managing incidents0%
- Investigating incidents0%
- Telling people25%
- Containing incidents50%
Recover · Getting back to normal38%Show topics
- Restoring systems50%
- Recovery updates25%
Things to find out (4)
You weren't sure about these. Here's what to ask your IT provider, or whoever manages each area, and what to ask them to show you. Not knowing is worth fixing too, because nobody can manage what nobody is tracking.
Logins and access
You weren't sure: only the access people need
Ask
- Do people only have the access their job needs, checked at least once a year?
Spotting warning signs
You weren't sure: When something unusual happens on your systems, does someone review it and decide whether it's a real incident?
Ask
- Who receives security alerts from our email, antivirus, and firewall?
- How quickly are alerts reviewed, including nights and weekends?
- Who decides when an alert is a real incident, and who do they escalate to?
Ask to see: Where alerts are sent, the agreed response times, and a recent example of an alert being handled.
Suppliers and partners
You weren't sure: Do you know which suppliers could hurt you if they were hacked, and do your contracts set security expectations for them?
Ask
- Which suppliers hold our data or can access our systems?
- Do their contracts say anything about security or telling us about a breach?
Ask to see: A supplier list, and the security or breach-notification clauses in key contracts.
Knowing what you have
You weren't sure: knowing where important data is
Ask
- Do you know where your important or sensitive data is kept?
Everything to improve (19)
Every answer of “Written down” or lower, highest priority first.
Name an owner for cybersecurity, give them the time and budget to do it, and make leadership accountable.
Govern · Who's responsible. You answered “Sometimes” to: Is it clear who is responsible for cybersecurity, do they have the time and budget to do it, and do leaders take ownership?
From your answers, start with:
- Time and budget: Agree how much of the owner's time and budget goes to cybersecurity, and review it every year.
- Leadership ownership: Have leadership formally own cybersecurity risk, with a short update from the owner at least every quarter.
Already in place: a named owner.
High impactQuick win: days, not weeksOwner: Leadership
Your note: Our office manager handles IT alongside everything else.
Official NIST wording (GV.RR)
Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated
Turn on multi-factor authentication, end shared accounts, and review who has access to what every few months.
Protect · Logins and access. You answered “Sometimes” to: Does everyone have their own login, is multi-factor authentication used, and do people only get the access they need?
From your answers, start with:
- Multi-factor authentication: Turn on multi-factor authentication for email, remote access, and admin accounts first, then everything else that supports it.
Not sure: only the access people need. Worth finding out.
Already in place: individual logins.
High impactQuick win: days, not weeksOwner: IT lead or IT provider
Your note: Everyone has their own login. Multi-factor authentication is on for email, but not for the practice-management system.
Official NIST wording (PR.AA)
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
Name an incident lead, agree how to rate incident severity, and know who to call for outside help.
Respond · Managing incidents. You answered “No” to: When a security incident happens, is there a plan that says who leads, how serious it is, and when to escalate?
Medium impactQuick win: days, not weeksOwner: Cybersecurity owner, with leadership
Works best after: Who's responsible
Official NIST wording (RS.MA)
Responses to detected cybersecurity incidents are managed
Send security alerts to a named person or provider, and agree clear rules for when an alert becomes an incident.
Detect · Spotting warning signs. You answered “Not sure” to: When something unusual happens on your systems, does someone review it and decide whether it's a real incident?
Medium impactQuick win: days, not weeksOwner: IT lead, IT provider, or security monitoring service
Works best after: Monitoring
Your note: Our IT provider may watch for alerts. Need to ask them.
Official NIST wording (DE.AE)
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
List who you'd have to notify after a breach, such as customers, partners, and regulators, and the deadline for each.
Respond · Telling people. You answered “Sometimes” to: Do you know who you must notify during an incident, such as customers, partners, regulators, or police, and how?
Medium impactQuick win: days, not weeksOwner: Leadership, with legal or compliance advice
Works best after: Your mission and obligations
Official NIST wording (RS.CO)
Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
List your suppliers, rank them by access and importance, and add security requirements to contracts with the critical ones.
Govern · Suppliers and partners. You answered “Not sure” to: Do you know which suppliers could hurt you if they were hacked, and do your contracts set security expectations for them?
From your answers, start with:
- Checking suppliers' security: Ask critical suppliers for evidence of their security, such as a certification or a completed questionnaire, before signing and at renewal.
Not sure: security terms in contracts. Worth finding out.
Already in place: knowing your critical suppliers.
Medium impactShort project: a few weeksOwner: Operations or whoever manages vendors, with the cybersecurity owner
Works best after: Knowing what you have
Your note: Our practice-management software vendor holds patient records. Not sure what our contract says about security.
Official NIST wording (GV.SC)
Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
Scan regularly for weaknesses, track what you find, and fix the most likely and most damaging first.
Identify · Understanding your risks. You answered “Sometimes” to: Do you regularly look for weaknesses in your systems and work out which ones could cause the most harm?
Medium impactOngoing routine: a regular habit to keep upOwner: IT lead or IT provider
Works best after: Knowing what you have
Official NIST wording (ID.RA)
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
Give all staff short yearly security training, including how to spot and report phishing, plus extra for sensitive roles.
Protect · Staff training. You answered “Sometimes” to: Do all staff get regular security awareness training, with extra training for people in sensitive roles?
Medium impactOngoing routine: a regular habit to keep upOwner: Cybersecurity owner, with HR or office management
Official NIST wording (PR.AT)
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
Write a short security policy, have leadership approve it, share it with staff, and review it every year.
Govern · Security policy. You answered “No” to: Do you have a written security policy that staff know about, and is it kept up to date?
FoundationalShort project: a few weeksOwner: Cybersecurity owner, approved by leadership
Works best after: Who's responsible
Official NIST wording (GV.PO)
Organizational cybersecurity policy is established, communicated, and enforced
Pick a few security measures to report to leadership regularly, and review your approach after any incident.
Govern · Checking it's working. You answered “No” to: Do leaders regularly review whether your security approach is working, and change course when it isn't?
FoundationalOngoing routine: a regular habit to keep upOwner: Leadership
Works best after: Who's responsible
Official NIST wording (GV.OV)
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy
Write an incident response plan, practice it with a tabletop exercise, and update it with what you learn.
Identify · Learning and improving. You answered “No” to: Do you have an incident response plan, and do you learn from tests, reviews, and past problems to improve?
FoundationalOngoing routine: a regular habit to keep upOwner: Cybersecurity owner
Works best after: Managing incidents
Your note: No written plan. If something happened we'd call our IT provider and hope.
Official NIST wording (ID.IM)
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
During incidents, keep a written timeline and preserve logs and evidence, then find and fix the root cause.
Respond · Investigating incidents. You answered “No” to: After an incident, do you work out what happened and why, and keep careful records and evidence?
FoundationalShort project: a few weeksOwner: IT lead or IT provider
Works best after: Managing incidents
Official NIST wording (RS.AN)
Investigations are conducted to ensure effective response and support forensics and recovery activities
Write down your most critical services, what they depend on, and which laws and contracts set security requirements for you.
Govern · Your mission and obligations. You answered “Written down” to: Do you know what your organization depends on most, and which laws, regulations, and contracts set security requirements for you?
Medium impactQuick win: days, not weeksOwner: Leadership, with whoever runs IT
Your note: We have a list of key systems and know HIPAA applies, but the list hasn't been updated in two years.
Official NIST wording (GV.OC)
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood
Make sure someone can quickly isolate infected devices and disable compromised accounts, day or night.
Respond · Containing incidents. You answered “Written down” to: Can you quickly stop an incident from spreading and fully remove the cause?
Medium impactQuick win: days, not weeksOwner: IT lead or IT provider
Works best after: Managing incidents
Official NIST wording (RS.MI)
Activities are performed to prevent expansion of an event and mitigate its effects
Build an inventory of your devices, software, cloud services, and sensitive data, and keep it current.
Identify · Knowing what you have. You answered “Written down” to: Do you keep an up-to-date list of your devices, software, online services, and important data?
From your answers, start with:
- A software and services list: List the software and online services you use, including free ones, and who manages each.
Not sure: knowing where important data is. Worth finding out.
Already in place: a device list.
Medium impactShort project: a few weeksOwner: IT lead or IT provider
Official NIST wording (ID.AM)
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy
Use tools that watch for malware and suspicious logins on your computers, network, and email.
Detect · Monitoring. You answered “Written down” to: Do you monitor your networks, computers, accounts, and buildings for signs of trouble?
Medium impactShort project: a few weeksOwner: IT lead or IT provider
Works best after: Knowing what you have
Official NIST wording (DE.CM)
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
Write down the order to restore critical systems, and check backups are clean before restoring from them.
Recover · Restoring systems. You answered “Written down” to: After an incident, can you restore your most important systems from clean backups, in the right order, and confirm they're safe?
Medium impactShort project: a few weeksOwner: IT lead or IT provider
Official NIST wording (RC.RP)
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
Plan how you'll update leadership and the public during recovery, and decide who approves public statements.
Recover · Recovery updates. You answered “Sometimes” to: During recovery, do you keep leadership, affected partners, and the public informed with approved messages?
FoundationalQuick win: days, not weeksOwner: Leadership
Works best after: Telling people
Official NIST wording (RC.CO)
Restoration activities are coordinated with internal and external parties
Agree security goals with leadership and start a simple risk list that ranks each risk by likelihood and impact.
Govern · Your approach to risk. You answered “Sometimes” to: Have your leaders agreed how much cyber risk the organization is willing to accept, and how risks get compared and prioritized?
FoundationalShort project: a few weeksOwner: Leadership
Works best after: Your mission and obligations
Official NIST wording (GV.RM)
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions
The PDF report
When you finish, you can download your results as a PDF to share with leadership or your IT provider.
Open the full sample reportOr the one-page executive summarySee where your organization stands
The quick check takes about 10 minutes. No account required: you get your results and PDF report straight away.