# Free Cyber Security Self-Check for Small Business

![Patch, the TERESEC mascot, pointing at a shrink-wrapped security product whose switch is set to OFF while holding a tablet with a three-colour coverage bar; a stack of brochures marked NEW and an empty shopping trolley sit behind](coverage-check-launch.jpg)

The most common reaction to our free security coverage check so far is a short one: "wait, we already pay for that?" A small business buys a licence for the features it needs on day one, never switches on the security features that came with it, and later buys a second product that does the same job. The check exists to make all of that visible in about three minutes, before the next purchase order goes out.

## What Is the Free Security Coverage Check?

It is a self-check you run yourself at [check.teresec.com.au](https://check.teresec.com.au/?utm_source=teresec.com.au&utm_medium=blog&utm_campaign=coverage-check-launch). No sign-up is needed to start, and it takes about three minutes.

Step one asks **which of these do you pay for?** You pick the security products you already own - the everyday stack: Microsoft 365, a backup product, whatever protects your laptops - and the licence tier you are on. Tier matters, because tier is what decides whether a capability is actually included in what you pay for.

Step two asks **a few questions about how you use them**. Each is answered Yes, No or Not sure, and the questions are chosen for the products you selected. Owning a licence is not the same as having the capability switched on, and switched on is not the same as watched. "Not sure" is a useful answer; it is often the finding.

Step three shows **what your licences already cover**. The check reads your selection against the Australian Information Security Manual (ISM), the cyber security framework published by the Australian Signals Directorate (ASD), and shows your Essential Eight coverage alongside it, using ASD's own maturity markings. You see coverage by framework and by ISM chapter, and a list of findings tagged *Already paid for*, *Worth checking*, *Overlap* or *Gap*. Each finding links to the vendor's own public documentation and shows the date we checked it.

## What Is the Information Security Manual, and Why Would a Private Business Care?

The ISM is ASD's cyber security framework: in ASD's words, one "that an organisation can apply, using their risk management framework, to protect their information technology and operational technology systems from cyber threats". It is written with government systems in mind, freely published, and the most complete public description of what "secure" means in Australia. The Essential Eight is drawn from it: eight mitigation strategies ASD recommends as a baseline because they make it "much harder for adversaries to compromise systems".

No law requires a private small business to follow the ISM. It is useful for a different reason: it is a long, specific, free list of things a secure system does, and the licences you already pay for can be checked against it one control at a time.

## How Is This Different From a Self-Assessment Questionnaire?

Most free self-assessment questionnaires ask you to rate your own practices from one to five. The result is a maturity chart of your own opinion. ASD's free [Cyber health check tool](https://www.cyber.gov.au/cyberhealthcheck) is the best of that kind: under five minutes, anonymous, and a sensible first step if you are not sure where to begin.

Our check starts from a different place. Instead of asking how you feel about your security, it asks what you pay for, and reads what those licence tiers appear to entitle you to against the vendor's own public documentation. Your answers about how you use the products then turn entitlement into findings. The two approaches complement each other; only one of them tells you what is already sitting in your licences unused.

## Does Microsoft 365 Business Premium Cover the Essential Eight?

It depends on the tier and on what is switched on, which is exactly why the check asks for both. The same product name can carry quite different security entitlements at different licence levels, and an entitlement nobody has turned on covers nothing.

Rather than answer for one product here, we publish a [sample report](/sample-report.html) generated from our live catalogue for a typical small-business stack - Microsoft Entra ID P1, Microsoft Intune Plan 1 and NinjaOne Backup - so you can see exactly what the output looks like before you run your own. This is how it opens:

![The opening of the sample report: three products selected, the at-a-glance tiles, and coverage bars for the Australian ISM and the three Essential Eight maturity levels](sample-report-overview.png)

## What Does "Owned but Switched Off" Mean?

![Patch, the TERESEC mascot, shining a torch along a shelf of security products beside a wall switch labelled OFF](coverage-check-launch-torch.jpg)

The full report is emailed to you, free, and is yours to keep: print it or save it as a PDF, and the link expires after seven days. It continues the same analysis chapter by chapter in ASD's own words, rolls coverage up by cyber security principle (govern, identify, protect, detect, respond and recover), and sorts what it found into five groups:

- **Entitled but switched off.** Your licences include these, and you told us they are not in use. Turning them on costs nothing further.
- **Worth confirming.** You were not sure these are in use. Check before buying anything that would duplicate them.
- **Running, but unattended.** Switched on, but your answers suggest nobody runs them or would notice them failing. Usually fixed with a process, not a purchase.
- **Provided by more than one of your products.** You are paying more than once for the same evidence.
- **Not reached by your selection.** The gaps, split three ways: closed by a written policy or plan, closed by a named owner, or the kind a tool can close.

Nothing in it is a sales list. The report never names a product to buy. In the sample report, four of the five groups look like this, each finding citing the vendor's own documentation and the date we checked it:

![Four of the five finding groups from the sample report: entitled but switched off, worth confirming, running but unattended, and provided by more than one of your products, each with the vendor documentation link and the date checked](sample-report-findings.png)

## Do I Need Two Products That Do the Same Thing?

Sometimes. Overlap is not automatically waste, but it should be a decision rather than an accident. IBM's Institute for Business Value puts the average enterprise at 83 security tools from 29 vendors. A small business runs far fewer, but the pattern is the same at any size: each purchase solved one problem on one day, and nobody went back to check what the last one already did. The overlap findings show where two of your products provide the same thing, so the owners can decide which one stays.

## Before You Buy Anything

This is where the check earns its keep. Before a new purchase, you know three things you did not know before: what you already own that is switched off, where two of your products overlap, and which of the remaining gaps could be closed by a product at all. Many cannot. They need a written policy or a named owner, and no purchase order fixes those.

The report also counts how many remaining gaps could be reached with capabilities already in our catalogue, provided by products outside your selection. Which products, whether they fit your environment, and what we have not yet mapped are what we work through with you in a consultation. Your shortlist starts from evidence, not from whichever brochure arrived last.

![The gap section of the sample report: controls not reached by the selected products, split into those closed by a written policy, by a named owner, or by a tool, with a count of how many the wider catalogue could reach](sample-report-gaps.png)

## What Essential Eight Maturity Level Should a Small Business Aim For?

ASD's own small business guide is direct about it: "we recommend small businesses implement Maturity Level One of the Essential Eight". The check shows your coverage at Maturity Levels One, Two and Three, so you can see how far your existing licences take you towards that baseline before spending anything.

## The Rules We Hold Ourselves To

Every claim in our catalogue cites the vendor's own public documentation with the date we checked it. If we cannot find it there, we do not claim it. Our claims are about our catalogue, never about a vendor's product: a gap means we have not mapped a capability that satisfies that control for the products you selected, and it is not a statement about what the product can do. Any vendor may ask us to review a claim about their product, and we will.

The output is not an audit, a certification, or advice on which products to buy. It reflects what your licence tiers appear to entitle you to, not whether those capabilities are deployed, configured or effective in your environment. The tool stores nothing about you in a database, your details are never passed to any vendor, and there is no Google analytics on it.

## Never Finished

The part we are most proud of is the least glamorous. We add products and recheck vendor documentation every week, and adjust claims as things change. More frameworks will follow as the research progresses, and ASD itself is consulting on how the Essential Eight evolves into a broader "Essentials" series grounded in the ISM. The check will move with it. The check you run next month is sharper than the one you run today, and it will still be free.

If you would rather read about threats first, our weekly [Plain English Security Briefing](/briefing) covers what happened, whether it affects you, and the one thing to do about it. Last month we wrote that [our recommendations start from what you already own](/blog/2026-08-14-procured-not-operated-vulnerability-lifecycle) and that we were building something to make that less manual. This is it.

## Sources

- Australian Signals Directorate, [*Essential Eight*](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight) - the baseline and the "much harder for adversaries" wording
- Australian Signals Directorate, [*Information security manual*](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism) - the framework description quoted above
- Australian Signals Directorate, [*Essential Eight maturity model and ISM mapping*](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model-and-ism-mapping)
- Australian Signals Directorate, [*Small business cyber security guide* (January 2025, PDF)](https://www.cyber.gov.au/sites/default/files/2025-03/Small%20business%20cybersecurity%20guide%20%28January%202025%29.pdf) - the Maturity Level One recommendation
- Australian Signals Directorate, [*Cyber health check tool*](https://www.cyber.gov.au/cyberhealthcheck)
- Australian Signals Directorate, [*Consultation on evolution of Essential Eight*](https://www.cyber.gov.au/about-us/view-all-content/news/consultation-on-evolution-of-essential-eight) - the "Essentials" series
- IBM Institute for Business Value, [*Unified cybersecurity platform*](https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/unified-cybersecurity-platform) - average of 83 security solutions from 29 vendors

## Engaging Us

Run the free check at [check.teresec.com.au](https://check.teresec.com.au/?utm_source=teresec.com.au&utm_medium=blog&utm_campaign=coverage-check-launch) in about three minutes. If you would like someone to walk through the result with you and turn it into a prioritised plan, our fixed-price [IT Security Review](/security-review) is $399 inc GST: a structured questionnaire, a one-hour consultation and a plain-English report.

[Contact us](/contact) to discuss your requirements.
