IT Security Health Check

Comprehensive IT Infrastructure & Cybersecurity Assessment – 10 sections, ~15–20 minutes

Section 1 of 10 0%

1 · Company Profile

Basic information about your company to help us understand your needs and scale.

Company name Your organisation's legal or trading name.
Your name The person completing this assessment.
Email address We'll use this to follow up on your assessment.
1.1 Number of employees Helps determine the scale of IT infrastructure needed.
1.2 Growth plans for the next 12–24 months? Helps make your IT infrastructure scalable.
1.3 Internal IT staff Determines the level of external support needed.
1.4 Is there a clearly defined responsibility for IT security? E.g. a dedicated security officer or an assigned person.
1.5 Are IT roles and responsibilities documented? Clear documentation of who is responsible for what in your IT environment.

2 · Regulatory Requirements

Understanding your regulatory environment helps ensure your IT infrastructure is compliant.

2.1 Regulatory bodies Select all regulatory bodies that oversee your operations.
2.2 Data privacy regulations Select all data privacy regulations that apply to your business.

3 · Collaboration & Digitalization

Your digital workplace needs, collaboration requirements, and cloud configuration.

3.1 Office productivity tools Your choice of productivity suite affects your IT infrastructure.
3.2 Is remote work important for your team? Affects VPN and remote access solutions.
3.3 Should your IT infrastructure support AI tools? Microsoft Copilot, ChatGPT, or similar.
3.4 Document management: automated workflows? Document routing, approvals, notifications.
3.5 Document management: compliant archiving? Long-term retention, legal holds.
3.6 Should your document management support version control? Track document changes and maintain revision history.
3.7 Business applications Determines if you need server hosting for your applications.
3.8 Are cloud services used consciously and in a controlled manner? Shadow IT prevention, approved cloud service catalog, usage policies.

4 · Workplace Devices & Patching

Your approach to workplace devices, operating system updates, and patch management.

4.1 Which device strategy do you use or plan to implement? Affects security policies, device management, and compliance requirements.
4.2 Is there a clear separation between corporate IT and private devices? Network segmentation, separate profiles, or containerization for BYOD.
4.3 Are operating systems and applications regularly updated (patching)? Timely installation of security patches and software updates across all systems.
4.4 Are technical protection measures (firewall, endpoint security) in place? Firewalls, antivirus, EDR, or similar endpoint protection on all devices.

5 · Security Governance & Compliance

Assess your security policies, access controls, and governance maturity.

5.1 Data sensitivity level Determines the level of security controls needed.
5.2 Do basic IT/security policies exist (e.g. password policy, remote work policy)? Written policies that define acceptable use, password requirements, and security expectations.
5.3 Is there a defined process for handling IT security incidents? Documented incident response plan with escalation procedures and communication channels.
5.4 Is there a central user and role management model? Centralized identity management (e.g. Active Directory, Entra ID).
5.5 Are administrator privileges granted restrictively? Principle of least privilege for admin access.
5.6 Is MFA activated for critical access? Multi-factor authentication for admin portals, VPN, email.
5.7 Are user accounts regularly reviewed and cleaned up? Offboarding process, removing stale accounts.
5.8 Concerned about cyber threats? Ransomware, phishing, data breaches.
5.9 Are employees regularly trained on security awareness? Phishing simulations, password best practices, security workshops.

6 · IT Documentation

Good documentation is the backbone of reliable IT operations and a fast incident response.

6.1 Are the following IT documents available and up-to-date? Select all that apply.
6.2 Are changes to the IT environment documented? Change management log, configuration changes.
6.3 Are external IT service providers contractually regulated? SLAs, defined roles and responsibilities, data processing agreements.

7 · Microsoft 365 / Cloud Security

If you use Microsoft 365 or similar cloud platforms, these questions assess your security configuration.

7.1 Are basic security defaults or comparable measures activated? E.g. M365 Security Defaults, Conditional Access policies.
7.2 Are administrator accounts specially protected? Dedicated admin accounts, PIM, break-glass accounts.
7.3 Are there policies for external sharing of data? SharePoint/OneDrive sharing settings, guest access rules.
7.4 Are sign-in and security events actively monitored? Audit logs, suspicious login alerts, SIEM integration.

8 · Data Backup & Recovery

Backup strategy, disaster recovery readiness, and external risk awareness.

8.1 Are regular backups performed? Automated, scheduled backups of critical data and systems.
8.2 Are backups protected against ransomware or manipulation? Immutable backups, air-gapped storage, encryption.
8.3 Has backup restoration been tested? Regular restore drills to verify backup integrity.
8.4 Is a procedure for IT emergencies clearly defined? Emergency contacts, escalation paths, recovery priorities.
8.5 Do you know which systems are publicly accessible from the internet? Web servers, email gateways, VPN endpoints, exposed APIs.
8.6 Are external security risks (e.g. compromised accounts, data leaks) monitored? Dark web monitoring, breach notification services.
8.7 Are there clear rules for external partner access to your systems? Vendor access policies, third-party risk management.

9 · Budget & Operation Model

Understanding your budget constraints and preferred operational model.

9.1 Annual IT budget range Helps us tailor recommendations to your budget.
9.2 Preferred payment model Affects how costs are structured.
9.3 IT infrastructure approach How you prefer your IT to be managed.
9.4 How do you rate your current overall IT security level? Your honest self-assessment helps us calibrate recommendations.
9.5 Where do you currently see the greatest need for action? Free-text — describe your biggest IT security concern or gap.

10 · Recommended Solutions

Based on your answers, select the IT solutions that best fit your needs.

10.1 Infrastructure & Hosting Select the infrastructure solutions that match your needs.
10.2 Security Solutions
10.3 Data Protection & Compliance Select data protection and compliance tools.
10.4 Professional Services Select additional services.

Your data will be securely stored in a swiss datacenter.

Thank you for your submission!

Your IT Security Health Check has been successfully received. Our team will review your responses and contact you shortly.