Endpoint and threat protection
Antivirus or EDR coverage, patch latency, USB control, application whitelisting and MDM for the phones and laptops that leave the office.
Free IT & Security Health Check
Start with our Basic Health Check — plain-language questions for any business. Then optionally unlock the Advanced Security Assessment for deeper technical analysis. Get an instant score and expert recommendations.
What the health check covers
The basic set asks whether the fundamentals exist. The advanced set asks whether they are enforced, monitored and tested — the difference auditors and attackers both notice.
Antivirus or EDR coverage, patch latency, USB control, application whitelisting and MDM for the phones and laptops that leave the office.
MFA enforcement, privileged account separation, single sign-on, shared-account hygiene and Conditional Access for cloud and remote users.
Firewall generation and tuning, VLAN segmentation, VPN or ZTNA for remote staff, DNS filtering and enterprise Wi-Fi authentication.
Advanced email gateway, SPF/DKIM/DMARC enforcement, phishing simulations and a working route for staff to report suspicious mail.
Data classification, encryption at rest and in transit, data loss prevention and controls on external sharing from OneDrive and SharePoint.
Central logging or SIEM, 24/7 detection cover, a written incident response plan and evidence that it has been exercised.
The 3-2-1-1 rule with an immutable copy, monthly full restores, MFA-protected backup credentials and a business continuity plan.
Annual VAPT, patch SLAs, alignment to ISO 27001, NIST CSF, CIS Controls or the UAE IA Regulation, and vendor risk checks.
How scoring works
Every question carries a weight from 2 to 5 reflecting how often that gap leads to a real incident. MFA enforcement and immutable backups weigh 5; an acceptable-use policy weighs 2.
Each answer scores 0 for No, 1 for Partial and 3 for Yes, multiplied by the weight. Your percentage is the total against the maximum for the questions in scope, so unanswered questions count as gaps rather than being skipped. Any weight-4 or weight-5 control answered No is listed separately as a critical gap.
80–100%
Core controls are in place and maintained. Focus moves to testing, monitoring depth and formal certification.
60–79%
Fundamentals exist but gaps remain in one or two domains. Usually fixable in a single quarter.
35–59%
Several weighted controls are missing. A structured remediation plan should start within weeks, not months.
0–34%
The environment is exposed to common ransomware and account-takeover paths. Immediate action is recommended.
What you receive
The tool gives you the number. The engineers give you the order in which to fix things.
An overall percentage, a risk band and a per-domain bar chart the moment you click See My Results. Nothing is sent anywhere until you choose to request the report.
A written plan from a Binary Minds engineer within 24 hours: each critical gap, why it matters in a UAE context, the control that closes it and an indicative effort and cost band in AED.
Walk through the findings with a certified engineer, ask what applies to your industry and regulator, and decide whether a full IT infrastructure audit is warranted.
What happens next
Answer the 18 basic questions — about ten minutes — and add the 36 advanced questions if you want a score against NIST CSF and ISO 27001.
Request the remediation report with your work email. An engineer reviews the answers and sends a prioritised plan within one working day.
Where the self-assessment shows high or critical risk, we recommend a scoped IT infrastructure audit to verify the answers against the real configuration.
Remediation is delivered as a fixed-price project or under a managed agreement. Re-run the health check after 90 days to evidence the improvement to your board or auditor.
FAQ
The assessment and the instant score are free and require no contact details. The remediation report is also free; in return we ask for a work email so an engineer can send it, and we may follow up once to offer a review call. There is no obligation to buy anything.
It is as accurate as the answers. The questions are written so that a business owner or office manager can answer the basic set honestly, and the advanced set is intended for whoever administers your systems. Where the score matters — for an audit, a tender or a cyber-insurance renewal — we recommend validating it with a hands-on IT infrastructure audit.
The basic set covers the controls every UAE business should have regardless of size. The advanced set maps to NIST CSF functions, ISO 27001 Annex A controls, the CIS Critical Security Controls and the UAE Information Assurance Regulation, so the domain scores translate directly into audit language.
Scores are calculated in your browser. If you request the report, your answers and contact details are stored in our CRM and used only to prepare the report and follow up with you. They are never shared with third parties and can be deleted on request in line with the UAE Personal Data Protection Law.
Prefer an engineer to do it?
A hands-on review of your network, endpoints, Microsoft 365, backups and security controls, delivered as a risk-ranked report with a costed fix plan.
We use cookies to run the site and measure how it is used — cookie policy.