Skip to main content
Techx4u Pvt Ltd

Free tool

Ransomware readiness quiz

Fifteen questions, about three minutes. Get a ransomware readiness score and an action plan ordered by what makes the biggest difference. Your answers never leave your browser.

0 of 15 answeredAbout 3 minutes
  1. 1.Is multi-factor authentication (MFA) required for every user on email and Microsoft 365 / Google Workspace?
  2. 2.Is remote access (VPN, Remote Desktop, firewall admin) protected by MFA, with no Remote Desktop open directly to the internet?
  3. 3.Are critical security updates installed within 14 days on computers, servers and firewalls/VPN devices?
  4. 4.Do all computers and servers run endpoint detection and response (EDR), not just traditional antivirus?
  5. 5.Is someone watching security alerts 24/7, including nights and weekends?
  6. 6.Do staff use standard accounts day to day, with admin rights kept to a few separate admin accounts?
  7. 7.Is email filtered for malicious links and attachments, with SPF, DKIM and DMARC set up for your domain?
  8. 8.Do staff get security awareness training and phishing simulations at least once a year?
  9. 9.Are all important systems and data (including Microsoft 365 / Google Workspace) backed up every day?
  10. 10.Is at least one backup copy offline or immutable, so it cannot be deleted or encrypted with an admin password?
  11. 11.Have you test-restored a full server or system from backup in the last 6 months?
  12. 12.Do you have a written incident response plan that says who decides what in the first hours of an attack?
  13. 13.Are your systems scanned for vulnerabilities at least monthly, or penetration tested in the last year?
  14. 14.Is your network segmented so one infected laptop cannot reach every server and backup?
  15. 15.Do you have cyber insurance, and do you meet the security controls your insurer asks about?

Answer every question to see your score.

What we check

Four areas that decide how a ransomware attack ends

Prevent
MFA everywhere, no exposed Remote Desktop, fast patching, least-privilege accounts, email filtering, trained staff and a segmented network.
Detect
EDR on every device, alerts watched 24/7, and regular vulnerability scanning so you find gaps before attackers do.
Recover
Daily backups of every system and SaaS app, at least one immutable or offline copy, and restores you have actually tested.
Prepare
A written incident response plan that says who decides what, and cyber insurance whose control requirements you genuinely meet.

FAQ

Common questions

How is the ransomware readiness score calculated?

Each question is weighted by how much it changes the outcome of a real attack. MFA, protected remote access and an immutable or offline backup carry the most weight; written policies and insurance carry the least. 'Partly' earns half the points, and 'Not sure' earns none — if you are not sure, an attacker may find out first.

Do you see or store my answers?

No. The quiz runs entirely in your browser. Your answers are never sent to Techx4u or anyone else, and they are gone when you close the page.

What is the single most important ransomware control?

A backup that ransomware cannot reach — offline or immutable — that you have actually restored from. Prevention controls like MFA and EDR reduce the chance of an attack; a tested, untouchable backup is what lets you recover without paying.

How long does it take to fix the gaps?

Many of the highest-impact fixes — MFA, closing exposed Remote Desktop, turning on EDR — can be done in days. Immutable backups and network segmentation take longer to design properly. Our ransomware readiness assessment turns your results into a costed, prioritised plan.

How is this different from a ransomware readiness assessment?

This quiz is a self-assessment based on what you know. Our ransomware readiness assessment has engineers verify each control in your environment, test a restore, review your attack paths and give you a written report and remediation plan.

More free tools

Want it verified, not self-assessed?

Our engineers check each control in your environment, test a restore and give you a written ransomware readiness report with a costed plan.