Skip to content

Free IT & Security Health Check

How Healthy IsYour IT & Security?

Start with our Basic Health Check — plain-language questions for any business. Then optionally unlock the Advanced Security Assessment for deeper technical analysis. Get an instant score and expert recommendations.

  • Basic18 questions · Any business
  • Advanced36 questions · NIST / ISO 27001

What the health check covers

Eight domains, fifty-four questions

The basic set asks whether the fundamentals exist. The advanced set asks whether they are enforced, monitored and tested — the difference auditors and attackers both notice.

Endpoint and threat protection

Antivirus or EDR coverage, patch latency, USB control, application whitelisting and MDM for the phones and laptops that leave the office.

Identity and access

MFA enforcement, privileged account separation, single sign-on, shared-account hygiene and Conditional Access for cloud and remote users.

Network and perimeter

Firewall generation and tuning, VLAN segmentation, VPN or ZTNA for remote staff, DNS filtering and enterprise Wi-Fi authentication.

Email and phishing defence

Advanced email gateway, SPF/DKIM/DMARC enforcement, phishing simulations and a working route for staff to report suspicious mail.

Data security and DLP

Data classification, encryption at rest and in transit, data loss prevention and controls on external sharing from OneDrive and SharePoint.

Monitoring and incident response

Central logging or SIEM, 24/7 detection cover, a written incident response plan and evidence that it has been exercised.

Backup and resilience

The 3-2-1-1 rule with an immutable copy, monthly full restores, MFA-protected backup credentials and a business continuity plan.

Compliance and vulnerability management

Annual VAPT, patch SLAs, alignment to ISO 27001, NIST CSF, CIS Controls or the UAE IA Regulation, and vendor risk checks.

How scoring works

Weighted by impact, not by question count

Every question carries a weight from 2 to 5 reflecting how often that gap leads to a real incident. MFA enforcement and immutable backups weigh 5; an acceptable-use policy weighs 2.

Each answer scores 0 for No, 1 for Partial and 3 for Yes, multiplied by the weight. Your percentage is the total against the maximum for the questions in scope, so unanswered questions count as gaps rather than being skipped. Any weight-4 or weight-5 control answered No is listed separately as a critical gap.

80–100%

Strong

Core controls are in place and maintained. Focus moves to testing, monitoring depth and formal certification.

60–79%

Moderate

Fundamentals exist but gaps remain in one or two domains. Usually fixable in a single quarter.

35–59%

High risk

Several weighted controls are missing. A structured remediation plan should start within weeks, not months.

0–34%

Critical

The environment is exposed to common ransomware and account-takeover paths. Immediate action is recommended.

What you receive

A score now, a plan within a day

The tool gives you the number. The engineers give you the order in which to fix things.

Instant score and domain breakdown

An overall percentage, a risk band and a per-domain bar chart the moment you click See My Results. Nothing is sent anywhere until you choose to request the report.

Prioritised remediation report

A written plan from a Binary Minds engineer within 24 hours: each critical gap, why it matters in a UAE context, the control that closes it and an indicative effort and cost band in AED.

Optional 30-minute review call

Walk through the findings with a certified engineer, ask what applies to your industry and regulator, and decide whether a full IT infrastructure audit is warranted.

What happens next

From self-assessment to a measured improvement

  1. 01

    Complete the assessment

    Answer the 18 basic questions — about ten minutes — and add the 36 advanced questions if you want a score against NIST CSF and ISO 27001.

  2. 02

    Receive your report

    Request the remediation report with your work email. An engineer reviews the answers and sends a prioritised plan within one working day.

  3. 03

    Validate on site or remotely

    Where the self-assessment shows high or critical risk, we recommend a scoped IT infrastructure audit to verify the answers against the real configuration.

  4. 04

    Fix, then measure again

    Remediation is delivered as a fixed-price project or under a managed agreement. Re-run the health check after 90 days to evidence the improvement to your board or auditor.

FAQ

IT health check — common questions

The assessment and the instant score are free and require no contact details. The remediation report is also free; in return we ask for a work email so an engineer can send it, and we may follow up once to offer a review call. There is no obligation to buy anything.

Prefer an engineer to do it?

Book a full IT infrastructure audit

A hands-on review of your network, endpoints, Microsoft 365, backups and security controls, delivered as a risk-ranked report with a costed fix plan.

  • On site across Dubai and Abu Dhabi
  • Report within 5–10 working days
  • Fixed price in AED