How this score is calculated

The twelve questions are derived from two public frameworks: the ICT minimum standards of the National Cyber Security Centre (NCSC), which structure security into five functions (identify, protect, detect, respond, recover), and France's ANSSI guide for very small and small businesses.

Not all measures are equal, and a score that treated them equally would be misleading. Three levels of weighting are applied.

LevelWhy this weightExamples
Critical Blocks a common attack on its own Offline backup, two-factor authentication, automatic updates
Important Sharply reduces the attack surface or recovery time Automatic backup, restore test, access removal, e-mail filtering
Useful Strengthens protection without being decisive on its own Password manager, least privilege, awareness training, crisis checklist

A "partly" answer is worth half the points. This is deliberate: an SME's reality is rarely binary, and forcing a yes or a no would distort the diagnosis.

What this check-up does not do

A declarative questionnaire measures the presence of measures, not the quality of their implementation. You can answer yes to the backup question and discover on the day of the incident that the restore fails. That is why the restore-test question is asked separately.

This test therefore replaces neither a technical audit, nor a penetration test, nor an analysis of the risks specific to your business. It answers a different, more modest and often more useful question at the outset: where to begin when you don't know where you stand.

After the test

Deal with the three priorities in the order shown, then retake the test. The rise in the score is a good indicator for management, and the recommended measures also serve your compliance with the data protection law, which requires security measures proportionate to the risk.

To go deeper, the Best practices pillar details every measure, and the article on the 3-2-1 backup rule covers the point that comes up most often among the priorities.