Free Assessment

Free Cyber Risk Assessment

A 10-minute online assessment that gives you an honest picture of your business's current cybersecurity posture. Answer questions across key risk areas, receive an immediate risk score, and get a prioritised list of recommended actions — at no cost and with no obligation.

Quick answer

CyberTest is AMVIA's free, 10-minute online cyber risk assessment. Answer 25 questions across five risk areas, get an immediate risk score with a category-by-category breakdown, and receive a prioritised action plan — at no cost and no obligation. It is the fastest honest read on where your business is exposed, run by a security-first UK provider.

How the Assessment Works

01

Complete the assessment

Answer 25 questions across 5 risk categories: identity and access management, endpoint security, email security, backup and recovery, and network security. Takes approximately 10 minutes.

02

Receive your risk score

Your answers generate an overall risk score and a breakdown by category. You will see immediately where your greatest exposure lies and how you compare to typical businesses of your size.

03

Get your action plan

Each risk area is accompanied by specific, prioritised recommendations. The most impactful actions are listed first — you do not need to address everything at once.

What the Assessment Covers

Identity & Access Management

Multi-factor authentication, password policies, privileged account controls, and user offboarding processes.

Endpoint Security

Endpoint detection and response (EDR), patch management, device encryption, and remote wipe capability.

Email Security

Anti-phishing controls, email filtering, impersonation protection, DMARC/DKIM/SPF configuration, and user awareness.

Backup & Recovery

Backup coverage, frequency, off-site or cloud storage, recovery testing, and ransomware resilience.

Network Security

Firewall configuration, network segmentation, remote access controls, and Wi-Fi security.

Compliance Readiness

Alignment with security compliance requirements, GDPR data security obligations, and sector-specific compliance considerations.

You do not need an account, a sales call, or a credit card. You answer, you score, you leave with a plan. If you act on it with us, good — but the plan is yours either way.

How does the CyberTest assessment work?

CyberTest works in three steps: complete a 25-question online assessment in about 10 minutes, receive an instant overall risk score plus a breakdown by category, then get a prioritised action plan. The most impactful fixes are listed first, so you tackle your biggest exposures before anything else.

  • 01 — Complete the assessment. Answer 25 questions across five risk categories: identity and access management, endpoint security, email security, backup and recovery, and network security. It takes roughly 10 minutes.
  • 02 — Receive your risk score. Your answers generate an overall risk score and a per-category breakdown, so you see immediately where your greatest exposure lies and how you compare to typical businesses of your size.
  • 03 — Get your action plan. Each risk area comes with specific, prioritised recommendations. The highest-impact actions sit at the top — you do not need to fix everything at once.

What does the CyberTest assessment cover?

CyberTest covers the five risk areas that account for most SME breaches — identity, endpoints, email, backup, and network — plus a compliance readiness check. Each category maps directly to a control AMVIA manages day to day, so the recommendations are practical, not theoretical. Below is exactly what each section examines.

Risk categoryWhat CyberTest checksWhy it matters
Identity & access managementMFA, password policy, privileged accounts, user offboardingStolen or weak credentials are the most common way in
Endpoint securityEDR, patch management, device encryption, remote wipeAn unmanaged laptop is an open door to your network
Email securityAnti-phishing, filtering, impersonation protection, DMARC/DKIM/SPFEmail is the primary delivery route for attacks
Backup & recoveryBackup coverage, frequency, off-site/cloud storage, recovery testingUntested backups are the reason ransomware succeeds
Network securityFirewall config, segmentation, remote access, Wi-Fi securityFlat networks let one intrusion become a full breach
Compliance readinessGDPR data-security obligations and sector-specific requirementsRegulators expect demonstrable, not assumed, controls

The identity section reflects the National Cyber Security Centre's long-standing guidance that multi-factor authentication is the single highest-value control most businesses are still missing. If your score flags it, our multi-factor authentication setup is usually the first fix we make.

Why take a cyber risk assessment before a breach forces one?

Most UK businesses learn where their gaps are the expensive way — during an incident. A 10-minute assessment turns guesswork into a ranked list you can act on this week. The government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses identified a breach or attack in the prior 12 months, and the cost falls hardest on those who never checked first.

CyberTest exists to move that check earlier. Map your exposure now and the worst outcomes — credential theft, phishing that lands, ransomware that sticks — become things you planned for rather than things that happened to you. The full Cyber Security Breaches Survey is published on gov.uk if you want the underlying detail.

Who is CyberTest for?

CyberTest is built for MDs and IT directors at UK businesses with roughly 10 to 500 staff who want a straight answer about their security posture without a procurement process. If you own the risk but lack a dedicated security team — or you have one and want a second read — this gives you a defensible baseline in minutes.

It is equally useful before a board meeting, an insurance renewal, or a Cyber Essentials application, where you need evidence of where you stand rather than a hunch.

What happens after you get your CyberTest score?

You keep the score and the action plan — there is no obligation to use AMVIA. If you want help, we can turn the plan into managed controls: identity hardening, endpoint detection and response, email defence, and backup and business continuity, all under one accountable provider.

Where the assessment surfaces deeper questions — exploitable weaknesses or compliance gaps — a hands-on penetration testing engagement or a full managed cybersecurity review takes it further. One provider. Security-first. Microsoft-certified.

Proof you can check

  • Cyber Essentials Plus certified — the UK government-backed scheme, independently verified, not self-assessed.
  • Microsoft Solutions Partner for Modern Work, Security, and Infrastructure.
  • Rated 4.8/5 by the 1,200+ UK businesses AMVIA supports.

Know your risk level before a breach does it for you

The assessment takes 10 minutes. The results are immediate. There is no cost and no obligation to use AMVIA's services.