Cyber Risk Scan — free online scan by CompliAdvice

Question 1 of 11 — Incident Response

Does your organisation have a formal incident response plan?

A documented procedure with clear responsibilities: who calls whom, what gets shut down, who communicates externally.

Question 2 of 11 — Incident Response

How often does your organisation practise responding to a cyber attack?

Think of scenario exercises, simulations or tabletop sessions. Research shows 43% of SMEs have never practised at all.

Question 3 of 11 — NIS2 Readiness

Does your organisation operate in one of the following sectors?

Please note: even if your organisation is not directly subject to NIS2, you may still be required to implement additional cybersecurity measures through contractual obligations. This currently affects more SMEs than the law itself.

The NIS2 Directive takes effect on 15 August 2026. There is no transition period.

Question 4 of 11 — NIS2 Readiness

Does your organisation have 50 or more employees, or an annual turnover above €10 million?

For many SMEs this is the critical question. A metal fabricator with 15 employees often falls outside NIS2, while a manufacturer with 150 employees may well fall within scope.

Question 5 of 11 — NIS2 Readiness

How far has your organisation progressed with implementing NIS2 requirements?

From 15 August 2026 you must comply in full from day one. There is no grace period.

Question 6 of 11 — NIS2 Readiness

Is cybersecurity on the agenda of your board or senior management as a strategic risk?

NIS2 requires accountability at board level, including personal liability for directors and executives.

Question 7 of 11 — AI Policy

Does your organisation have a formal policy for the use of AI tools such as ChatGPT?

Only 9% of SMEs have this in place. Yet 78% of SMEs already use AI, and 77% of users paste business data into generative AI tools.

Question 8 of 11 — AI Policy

How widely does your organisation use AI tools?

The broader the use, the more important it is to have clear governance in place.

Question 9 of 11 — Supply Chain Risk

Have you made cybersecurity agreements with your IT suppliers and chain partners?

An attack through a supplier hits you just as hard as a direct attack. The ransomware attack on ChipSoft disrupted three-quarters of Dutch hospitals.

Question 10 of 11 — Supply Chain Risk

To what extent do your critical processes depend on American cloud or AI services?

46% of SMEs experience a partial to very high dependency on American tech platforms. Geopolitical and legal factors make this a growing strategic risk.

Question 11 of 11 — Supply Chain Risk

When did your organisation last carry out a cyber risk scan?

Barely a third of SMEs conducted a risk scan in the past year. Without an up-to-date picture, you cannot prioritise effectively.

Your results are ready

Enter your details to receive the results by email and schedule a no-obligation consultation. You can also view your results without leaving your details.

Please enter your name
Please enter a valid email address
CompliAdvice
Cyber Risk Scan — Your results
--
Total score (0-100)

How CompliAdvice can help you

Schedule a no-obligation consultation
The figures in this scan are derived from the Cybertrends Report 2026, published by ABN AMRO in collaboration with MWM2 (n=777, March 2026).
CompliAdvice developed this scan independently and is not affiliated with ABN AMRO or MWM2.