Cyber Security Assessment Form Aegis IT partners with the Small Business Development Centers in Southwest VA to help companies assess and mitigate cyber-security problems. In order to help us best help your company, please fill out this assessment questionnaire. Thank you. Step 1 of 5 20% Company InformationFirst Name* Last Name* Business Name* Email Address* Phone Number* How many Employees do you have?* 1-10 11-20 21-50 51-100 100+ Start of Assessment1. How many computers do you have? This includes desktops and laptops. 1-10 11-20 21-50 51-100 100+ 2. Does your company pay for cell phones for employees? Yes No No, but employees get reimbursement Mixture of yes and no 3. Do you currently work remotely? Yes No I do not know or I am not sure 4. Do any of your employees work remotely? Yes No I do not know or I am not sure 4a. If yes to 4, do they use personal computers or company provided computers to work remotely? Personal computers Company provided computers I do not know or I am not sure 5. Do any of your vendors or sub-contractors work remotely? Yes No I do not know or I am not sure 5a. If yes to either 4 or 5, do you know what software is used for remote connections? Yes No I do not know or I am not sure 5b. If yes to 5a, what software is used? Logmein Remote Desktop Teamview GoToMyPc Splashtop 6. Do you have anti-virus software on your computers? Yes No I do not know or I am not sure 6a. If yes to 6, what software is used? Symantec McAffee BitDefender Kaspersky AVG Avast ESET-NOD Microsoft Windows Defender 7. Do you run regular scans with your anti-virus software? Yes No I do not know or I am not sure 8. Does anyone check or monitor your anti-virus scans and results? Yes No I do not know or I am not sure 9. Do you have anti-ransomware software? Yes No I do not know or I am not sure 10. Do you have backups of your systems? Yes No I do not know or I am not sure 10a. If yes to 10, how often are your backups running? Daily Weekly Monthly 10b. Do you check your backups to ensure they have completed? Yes No I do not know or I am not sure 10c. If yes to 10, do you take on-site backups, off-site backups, or both? Check all that apply. On-site (external drive or NAS) Off-site Both I am not sure or do not know 11. Do you have a list of all the access employees have to company systems, such as usernames and passwords for websites and vendors? Yes No I do not know or I am not sure 12. Do you have procedures for removing old equipment from use, such as destroying or wiping hard drives from replaced computers? Yes No I do not know or I am not sure 13. Do you have a list of administrative passwords for key devices and systems on the network? Yes No I do not know or I am not sure 14. When was the last time your admin passwords were changed? Within the past month? 6 months or less 1 to 2 years ago 2+ years Change your passwords? 15. Do you reuse your passwords? Yes No I do not know or I am not sure 16. Do you use 2 Factor Authentication for secure login to any of your systems? Yes No I do not know or I am not sure 17. Can employees or staff install whatever software they want on their computers? Yes No I do not know or I am not sure 18. Do you have any website content filtering on company equipment? Yes No I do not know or I am not sure 19. Do you have wireless access in your office? Yes No I do not know or I am not sure 19a. If yes to 19, do you have a separate guest network that cannot see your main network? Yes No I do not know or I am not sure 19b. If no to 19a, do you give your wireless password out to visitors and guests? Yes No I do not know or I am not sure 20. Do you take credit cards? Yes No I do not know or I am not sure 21. Do you have a physical device that clients or customers swipe or dip? Yes No I do not know or I am not sure 21a. If yes to 21, does this device connect on your main network by ethernet? Yes No I do not know or I am not sure 21b. If yes to 21, do you know if you are PCI compliant with your processor? Yes No I do not know or I am not sure 21c. If yes to 21, who do you use for credit card processing? Paypal Square Elavon First Data Banqcard Clover Whoever my bank suggested 22. Do you have a website? Yes No I do not know or I am not sure 22a. If yes to 21 and 22, do you take credit cards on your website? Yes No I do not know or I am not sure 22b. If yes to 22a, do you actively monitor your website for updates to software and plugins? Yes No I do not know or I am not sure 23. If yes to 20, do you know who in your organization has access to the credit card information either as it is being processed or after it has been processed? Yes No I do not know or I am not sure 24. Do you have cyber liability insurance or data breach insurance? Yes No I do not know or I am not sure 24a. If yes to 24, who is your insurance carrier for cyber liability? Erie Farmers Farm Bureau Chubb Progressive 25. Have you had to file a data breach claim before? Yes No I do not know or I am not sure 26. Do you have an acceptable use policy for employees for company equipment? Yes No I do not know or I am not sure 27. Which geographic region are you located in?* Blue Ridge Crossroads SBDC (City of Galax, Carroll, Grayson, Bland, and Wythe Counties) Mountain Empire Community College SBDC (City of Norton, Lee, Scott, and Wise Counties) - a part of Dickenson County Southwest Virginia Community College SBDC (Buchanan, Dickenson, Russell, Tazewell Counties) - a part of Dickenson County Virginia Highlands Community College SBDC (City of Bristol, Smyth and Washington Counties) I do not know or I am not sure CAPTCHA Δ