Know how exposed your business is, and what to fix first.
Answer 32 plain-language questions built on the NIST Cybersecurity Framework 2.0 and the CIS Controls. You get a score you can explain, a ranked list of gaps weighted to how your business works, and reports your leadership and insurer can read.
SecureScore is opening to TW Universe clients first. Tell us about your business and we’ll set you up.
70/ 100
Moderate risk · up 12 points since last quarter
- Protect84
- Detect50
- Recover25
Fix first
- Backup restores have not been testedCritical
- Admin rights used on everyday accountsCritical
- Risky sign-ins are not monitoredHigh
How it works
-
Describe your business
Size, industry, and what you handle: card payments, patient records, remote staff, Microsoft 365. This decides which gaps matter most to you.
-
Answer the assessment
About 20 minutes, written for owners and office managers rather than IT specialists. “Not sure” is a fine answer. Progress saves as you go.
-
Fix, track, and reassess
Turn findings into tasks with owners and due dates, download reports, and watch your score move each time you reassess.
What you get
A score you can explain
Every point traces back to a weighted control, and the method is published. The same answers always produce the same score.
Findings ranked for your business
Missing MFA matters more when you hold patient or card data. Each gap gets a severity and a business-impact rating.
Remediation tracking
Assign fixes, set due dates, and keep a history of who changed what. Closing the last task on a finding marks it resolved.
Executive and technical reports
A two-page summary for leadership and a detailed PDF for your IT provider, with framework references for every finding.
Microsoft 365 verification
Optionally connect Microsoft 365 with read-only access to confirm MFA, admin and device settings. Verified answers are marked as verified.
Plain-language guidance
Step-by-step fixes for each open finding, based only on your results. Your names, notes and documents are never sent.
Plans
Monthly, cancel any time.
Basic
$49 per month
- Full assessment and risk score
- Ranked findings
- Executive PDF report
- Remediation tracking
- 3 team members
Professional
$149 per month
- Everything in Basic
- Technical PDF report
- Plain-language remediation guidance
- Microsoft 365 verification
- 10 team members
MSP
$499 per month
- Everything in Professional
- Up to 25 client organizations
- 50 team members
- Priority support
Questions
Is this a penetration test or a compliance audit?
No. SecureScore is a guided self-assessment. It is not a penetration test, vulnerability scan, security audit, or a certification of compliance with any law or standard. The framework references show which recognized principles each question is based on.
Does SecureScore scan my network or install anything?
No. It never scans, probes, or tests your systems, and there is nothing to install. The optional Microsoft 365 connection only reads configuration settings, with your explicit authorization, and can be disconnected any time.
How is this different from the free Risk Calculator?
The Risk Calculator gives a 90-second estimate. SecureScore is the full assessment: 32 controls, findings with fix steps, task tracking, reports, and trends over time.
Who can see my answers?
Only the people you add to your organization. Each business’s data is isolated from every other customer’s, and every change is recorded in an activity log you can review.
