Security tool

Security Risk Assessment

Answer 14 questions and get a graded (A–F) cybersecurity posture report with tailored remediations for your firm.

1. Is MFA enabled on every account in your organization?
2. Do you have endpoint detection and response (EDR) on every device?
3. Are your backups tested with verified restores at least monthly?
4. Do you have a documented and tested incident response plan?
5. Is your email protected beyond basic spam filtering?
6. Do you conduct security awareness training and phishing simulations?
7. Are your systems patched within 48 hours of critical releases?
8. Do you have network segmentation separating critical systems?
9. Is data encrypted at rest and in transit?
10. Do you have a formal vendor risk assessment process?
11. Is privileged access (admin accounts) separated from daily-use accounts?
12. Do you have an asset inventory with ownership and lifecycle tracking?
13. Are user offboarding procedures executed within 1 business day?
14. Do you have a written cyber insurance policy with current coverage levels?
0/14 answered · need at least 10 to see results

Frequently asked questions

How is my grade calculated?

Each of the 14 questions is weighted by impact — high-leverage controls like MFA, EDR, tested backups, and an incident response plan carry the most points. Your answers are scored against the maximum, converted to a percentage, and mapped to an A-F grade. Nothing you enter leaves your browser; the entire assessment runs locally.

What do the tailored remediations cover?

For every control you answer 'No' to, we surface a specific, prioritized fix — for example, enforcing phishing-resistant MFA via Conditional Access, deploying EDR to 100% of endpoints, or running monthly verified restore drills. The guidance reflects how Elevate hardens regulated Los Angeles firms in legal, healthcare, and financial services.

Want this handled for you?

Elevate manages IT & security for regulated Los Angeles firms.

Book a strategy call