Skip to Main Content

Take Charge of Your Cybersecurity

Here is how the assessment works, in plain English.

No security background needed. Answers, a grade, and a plan you can act on.

Veteran OwnedBuilt by a 30-year practitionerPlain English, start to finish

What the assessment is

A cyber risk assessment is a structured look at how your firm handles cybersecurity today. We go through a set of practical controls, you tell us where you stand on each one, and at the end you get a letter grade from A to F and a prioritized plan for what to fix first.

It is not a penetration test. It is not a compliance checklist written for a 50-person company. It is the basics, prioritized, explained in the language of a small business owner who has real things to do besides become a security expert.

The grade and the report you get are real: a regulator can read them, an insurer can read them, and a client can read them.

The 56 controls, grouped the way an owner thinks

The assessment covers 56 controls. We do not hand you a spreadsheet. We group them into owner-friendly Pillars, so at any point you know which part of your cybersecurity you are looking at.

The 10 Pillars are:

The 10 owner-friendly Pillars and what each one covers
PillarWhat it covers
Access ControlWho can get into your systems and how
Backup and RecoveryWhether your data is backed up and whether you can actually restore it
Continuous MonitoringWhether you have visibility into what is happening on your network
Device SecurityLaptops, desktops, phones, and how you manage them
Email SecuritySpam filters, impersonation protection, the basics of your inbox
Incident HandlingWhat you do if something goes wrong
Network SecurityYour internet connection, firewall, and how traffic flows
OversightPolicies, accountability, and who is responsible for what
Physical SecurityWho can walk into your office and touch your equipment
Security AwarenessWhether the people at your firm know what to watch for

Behind each Pillar, the controls map to the NIST Cybersecurity Framework 2.0. That means if a regulator or an insurer wants to see a NIST-aligned assessment, your report covers it. We just do not make you learn NIST to take the assessment.

What each control asks

For each control, you rate where your firm stands. It is not a pass or fail. Your options are:

Implemented
(you have this covered)
Partially Implemented
For Partially Implemented, enter a whole-number percentage from 60% through 100%. Scoring groups that input into the 60%, 70%, or 80% band.
In Progress
(you have started, but are not done yet)
Not Implemented
Then choose Accepted with risk and explain why, Planned, or Unplanned.
Not Applicable
(this control genuinely does not apply to your firm)

Each answer feeds into your grade. An honest answer is always better than an optimistic one, because the report is most useful when it reflects where you actually are.

Notes stay in the in-app control activity with author and date. They are not printed in the shared or downloaded PDF.

Your grade: A to F, backed by a percentage

When you finish, every Pillar gets a score. Those scores roll up into your overall grade.

The grade runs A to F, backed by a percentage (so "B, 83%" tells you more than just the letter). The grade is the headline. The percentage is the evidence behind it.

Level 1 is 70% or better (a C-), Level 2 is 80% or better (a B-), and Level 3 is 90% or better (an A-).

Each level earns an embeddable seal. More on that at Levels and Seal.

The arithmetic before geometry framing

Think of it this way. You would not try to learn calculus before you know basic arithmetic. Most small firms are in the same position with cybersecurity: they do not need an enterprise security program. They need the fundamentals, in the right order.

The big frameworks, NIST CSF 2.0, ISO 27002, and others like them, are built for larger organizations. They are geometry and algebra. They are a natural progression as your firm grows, and your H2Cyber report gives you the NIST mapping when you get there.

We are the arithmetic: 56 practical controls, the ones that matter most for a small financial firm, in plain English, in the order that reduces the most risk first.

What gets validated, and how

Technical controls: A Validated seal requires H2Cyber review of the framework-designated subset of critical technical controls and explicit approval for the current report. Completing the full-service sessions alone does not automatically confer it.

Docs and procedures: you self-evidence these. For controls like written policies, training records, and procedure documents, you tell us what you have. Your dated notes remain in the in-app control activity, not the shared or downloaded PDF.

This is why the full-service option includes a practitioner's time: not to do the assessment for you, but to walk through it with you so the technical answers are accurate and the report holds up if someone ever looks closely at it.

Two ways to take the assessment

Self-service (guided wizard)

You work through the 56 controls at your own pace, privately, using our step-by-step wizard. Each control comes with a plain-English description and guidance on what to look for. You can start and stop whenever you want, pick up where you left off, and finish on your schedule. No one is watching.

Self-service customers can earn the same Level and plain seal, without the Validated band; the report remains a self-assessment.

Start free. No credit card required to get your grade.

Full-service (with a cyber expert)

Prefer a hand to hold? A cybersecurity practitioner at H2Cyber walks you through the assessment over two roughly one-hour calls. We score the controls as we go, based on what we see and what you tell us. Most firms finish the assessment in those two sessions. If you need a little longer, that is fine: no upcharge, no pressure.

Full-service sessions help establish accurate answers, but a Validated seal still requires the designated review and explicit approval for that report.

What you get at the end

  • Your letter grade and your overall percentage.

    The headline your firm earned, backed by the math.

  • A score for each Pillar.

    So you know which areas are strong and which need the most work.

  • A prioritized action plan.

    The controls in the order that moves your grade the fastest, starting with the ones most likely to reduce real risk for your firm.

  • A report you can hand to someone.

    The cover identifies your firm without displaying its grade or Level. The grade, percentage, earned Level, and recorded responsible party appear on the Pillar scores page.

    Only finalized incidents captured for reporting enter the report. Draft incidents do not.

  • A record that updates over time.

    Take another assessment later and you will see your grade, how it changed, and whether you are on track. The report is a point-in-time snapshot. The trend is the story.

Tracking your grade over time

Every report is saved in your account. You can look back at past reports and see exactly where your grade was then versus where it is now.

We run a fresh report on your account's reporting schedule, so you always have a current snapshot for a regulator or an insurer who asks. Need one sooner? Ask H2Cyber and we will run it for you.

Is this required?

If you are a financial advisor under SEC, FINRA, or state regulatory oversight, yes: most regulators expect a current cyber risk assessment on file. Having one means you are ready before an exam asks for it, and before an insurance application requires it.

Even if it is not required at your firm today, it is becoming more common. Getting your grade now puts you ahead of the question.

Earn your Level seal

Finish your assessment, hit a qualifying score, and you earn an embeddable Level 1, 2, or 3 seal. You can put it on your website, your email signature, or your client portal.

A plain seal records the Level earned by a self-assessment without the Validated band. A Validated seal additionally records H2Cyber review and explicit approval for that report.

Level 1 is 70% or better, Level 2 is 80% or better, and Level 3 is 90% or better.

Ready to see where your firm stands?

Take the free assessment yourself, or talk to a real person and we will walk you through it together.

Or call us: 469-715-5255