Question 1 of 11 — Incident Response
Does your organisation have a formal incident response plan?
A documented procedure with clear responsibilities: who calls whom, what gets shut down, who communicates externally.
Question 2 of 11 — Incident Response
How often does your organisation practise responding to a cyber attack?
Think of scenario exercises, simulations or tabletop sessions. Research shows 43% of SMEs have never practised at all.
Question 3 of 11 — NIS2 Readiness
Does your organisation operate in one of the following sectors?
The NIS2 Directive takes effect on 15 August 2026. There is no transition period.
Question 4 of 11 — NIS2 Readiness
Does your organisation have 50 or more employees, or an annual turnover above €10 million?
For many SMEs this is the critical question. A metal fabricator with 15 employees often falls outside NIS2, while a manufacturer with 150 employees may well fall within scope.
Question 5 of 11 — NIS2 Readiness
How far has your organisation progressed with implementing NIS2 requirements?
From 15 August 2026 you must comply in full from day one. There is no grace period.
Question 6 of 11 — NIS2 Readiness
Is cybersecurity on the agenda of your board or senior management as a strategic risk?
NIS2 requires accountability at board level, including personal liability for directors and executives.
Question 7 of 11 — AI Policy
Does your organisation have a formal policy for the use of AI tools such as ChatGPT?
Only 9% of SMEs have this in place. Yet 78% of SMEs already use AI, and 77% of users paste business data into generative AI tools.
Question 8 of 11 — AI Policy
How widely does your organisation use AI tools?
The broader the use, the more important it is to have clear governance in place.
Question 9 of 11 — Supply Chain Risk
Have you made cybersecurity agreements with your IT suppliers and chain partners?
An attack through a supplier hits you just as hard as a direct attack. The ransomware attack on ChipSoft disrupted three-quarters of Dutch hospitals.
Question 10 of 11 — Supply Chain Risk
To what extent do your critical processes depend on American cloud or AI services?
46% of SMEs experience a partial to very high dependency on American tech platforms. Geopolitical and legal factors make this a growing strategic risk.
Question 11 of 11 — Supply Chain Risk
When did your organisation last carry out a cyber risk scan?
Barely a third of SMEs conducted a risk scan in the past year. Without an up-to-date picture, you cannot prioritise effectively.
Your results are ready
Enter your details to receive the results by email and schedule a no-obligation consultation. You can also view your results without leaving your details.