Cyber Health Check — score your organization (NIST CSF based)
1. Is MFA enabled on all business email and admin accounts?
2. Do you have written payment-verification procedures (callback on changed bank details)?
3. Backups: how are they kept?
4. Software licensing on business machines?
5. Staff security training in the last 6 months?
6. Is there an incident response plan with contact list?
7. Endpoint protection (AV/EDR) coverage?
8. Customer/employee data inventory and access control?
