ITensure Security Assessment

Are you vulnerable to threats?

These quick 15 security assessment questions will give you an overall idea of how
well you’re securing yourself.

Please use the option "More Information" to share your business specific needs and concerns.

You will receive an Email for the result and get more insight into how your business doing.

1. Do you have a way to determine how many electronic devices and cloud services are in your environment? *

Why we ask:

Unaccounted for systems are a key vector for attackers. In 2017, manufacturing companies were hit hard by the WannaCry ransomware attack because many of them used unsupported legacy systems.}

2. Do you have the tools to ensure an inventory of sensitive data? *

Why we ask:

Sensitive data is often stored in places no one intended, causing it to be forgotten and potentially made accessible to users without proper permissions.

3. Do you know who actually has accounts in your environment? *

Why we ask:

An often-overlooked aspect of security is that end users may have too many account privileges, or may not be authorized to have accounts in the first place.

4. Do you automatically and regularly patch your systems? *

Why we ask:

60% of companies that have experienced security breaches say they could have occurred because a patch was not applied (Ponemon, 2019). Regular patching is necessary.

5. Do you block unnecessary or harmful files from reaching you via email? *

Why we ask:

Email is the biggest vector for attacks. Despite transition to fileless attacks and phishing, attachments are nevertheless a common way to be breached.

6. Do you scan removable media or block auto-running of content in your environment? *

Why we ask:

In 2016, University of Illinois researchers left 300 unmarked USB flash drives around the campus, and nearly half of them were plugged into a computer within six minutes.

7. Do you keep track of how admin privileges are assigned among end-users? *

Why we ask:

The admin role has powerful permissions but its assignment is often unchecked, making it far too easy to miss hackers with illegitimate high-level access.

8. Do you look for patterns of malware events in your environment? *

Why we ask:

Malware events can occur as singular incidents, but hackers often launch large coordinated attacks with a barrage of malware.

9. Do you monitor login behaviors in your environment? *

Why we ask:

A popular way for hackers to breach systems is try logging directly into a targeted environment.

10. Do you regularly and automatically disable inactive accounts? *

Why we ask:

Half of all user accounts are dormant, and are favored targets for cyber criminals.

11. Do you regularly compare consecutive vulnerability scans? *

Why we ask:

Studying snapshots of vulnerabilities is a good short-term practice, but is insufficient long term.

12. Do you enforce policies for removing unauthorized hardware and software? *

Why we ask:

Hard drives can fail, risking data breaches or permanent loss of critical information.

13. Do you automatically and regularly back up your most important systems and data? *

Why we ask:

Half of all user accounts are dormant, and are favored targets for cyber criminals.

14. Do you have three copies of your data: two stored on different media, and at least one stored off-premises? *

Why we ask:

Backups kept in the same place as your original data are as at-risk as what you’re trying to protect.

15. Are you able to restore critical systems after a breach or disaster within 90 minutes? *

Why we ask:

Restoring your data as quickly as possible can be the difference between your business closing its doors or keeping them open. The average cost of a data breachis $3.92 million (Ponemon, 2019).