Free security assessment · a Defyn service
What's your Security Score?
Answer 27 plain-English questions about how your business handles passwords, backups, devices and data. Get a free, personalised PDF report showing exactly what to fix first, mapped to ISO 27001, SOC 2 and the ACSC Essential Eight.
Takes 5-10 minutes · No credit card · Instant PDF report
How it works
-
1
Answer 27 quick questions
Plain-English questions about passwords, patching, backups, devices, email and data. No jargon, no wrong answers.
-
2
Get your Security Score
We score every answer against recognised security frameworks and weight the controls attackers exploit most.
-
3
Fix what matters first
Your PDF report lands in your inbox with a prioritised action plan. Critical first, with clear why-it-matters and what-to-do steps.
Built on the standards that matter
Every question maps to recognised security frameworks, so your report speaks the same language as auditors, insurers and enterprise customers.
-
ACSC Essential Eight
The Australian Government's baseline for stopping the most common attacks.
-
ISO 27001
The international standard for information security management.
-
SOC 2
The trust framework enterprise customers ask about.
-
Australian Privacy Act
Including the Notifiable Data Breaches scheme.
Start your free assessment
"*" indicates required fields
Frequently asked questions
Is it really free?
Yes. The assessment and your personalised PDF report are completely free. If you want help fixing what it finds, the Defyn team is a reply away, but there's no obligation.
How long does it take?
Most people finish in 5-10 minutes. The questions are multiple-choice and written in plain English. If you're not sure, "Not sure" is a valid answer.
Is my information safe?
Your answers are used only to generate your report and are treated as confidential. We don't share them, and the report goes only to the email address you provide.
Is this a formal audit or certification?
No. It's a point-in-time self-assessment that shows where you stand and what to fix first. It's an ideal first step before pursuing formal ISO 27001 or SOC 2 work.
Who should fill it out?
Whoever knows your IT setup best: a founder, office manager or your IT provider. You can also fill it out together with your Defyn consultant.