Who can get in
How well you control who can log in to your accounts and systems.
Answer as things really are — there are no wrong answers, and your result is only as useful as it is honest.
When you or your staff log in to important accounts (like email, banking or your main business systems), do you have to enter a second code — for example from a phone app or text — as well as a password?
Does everyone use a different password for each important account, rather than reusing the same one in several places?
Do you use a password manager (an app that creates and remembers strong passwords for you)?
When someone leaves the business, do you reliably remove their access to all systems and accounts?
Do only the people who genuinely need it have 'administrator' or full-control access to your systems?
Is there a firewall or built-in security on your internet connection that controls what can reach your business network?
Do you know which outside companies and online services can access your business data (like your IT provider, accountant or cloud apps)?
Are you confident those providers take security seriously — for example they're reputable, use two-step login, and would tell you quickly if they were breached?