Blog

Eight Security Assessments to Help You Review Your Cybersecurity Posture

Choose among eight Network Box USA security assessments, understand what each result can tell you, and turn the findings into practical next steps.

How confident are you in your organization’s security coverage? More importantly, which parts of that confidence can you verify?

Network Box USA’s security assessment hub brings together eight tools to help you ask better questions about your defenses. You can review the overall security program, examine a specific layer of protection, check public domain settings, or practice recognizing phishing.

Use this guide to choose a starting point and turn the findings into something useful: clearer responsibilities, evidence to collect, and improvements to prioritize.

Choose where to start

For a broad review, begin with the cybersecurity posture scorecard. For an immediate technical check, try the domain scanner. If you already have a concern, go directly to email, network-edge protection, web browsing, public applications, detection and response, or phishing awareness.

The tools have different purposes and scoring methods. Their results should be considered separately. A strong result in one area cannot establish that another area is covered.

1. Cybersecurity posture scorecard

Start the cybersecurity posture scorecard

This 18-question assessment reviews five categories: ownership and visibility, accounts and access, everyday protection, monitoring and improvement, and response and recovery. Topics include asset inventories, multi-factor authentication, patching, alert review, incident response, and tested backups.

The backup questions help you review your own recovery arrangements. Network Box USA does not provide backup storage. SIEM log retention supports security investigation and is distinct from backup storage and recovery.

It is a useful starting point for business leaders, IT managers, and teams reviewing responsibilities with an outside provider. Graded answers recognize partial coverage, while “Not sure” identifies an area needing evidence. Unverified answers widen the possible coverage range; they are handled separately from reported gaps.

The full scorecard includes category findings and three practical next steps. An email address is required, and both you and Network Box USA receive the full scorecard, including your answers. Submission does not subscribe you to marketing. An optional PDF download lets you keep a copy for discussion.

Use the result to agree on what needs verification first. The score describes self-reported coverage and cannot establish breach probability, compliance, or certification.

2. Domain security scanner

Run the domain security scanner

The scanner examines publicly available signals associated with a domain, including website security headers, email authentication, DNS controls, TLS, and domain registration health. Its report groups findings into website, email, DNS, and domain-health categories.

This is particularly useful for domain owners, website administrators, and IT teams looking for externally visible configuration issues. Unlike the questionnaires, it gathers technical observations. The checks are non-intrusive and do not access private systems.

Review flagged items with the people responsible for your website, DNS, and email. The report is a point-in-time view of public settings, so a finding needs context before you treat it as a confirmed vulnerability. Submitted domains and scan results may be retained for security analytics and business development. No email address is required.

3. Managed email security scorecard

Review your email attack surface

This eight-question review covers email authentication, attachment analysis, click-time link checks, impersonation protection, phishing reporting, and recurring awareness training. An optional public scan can prefill findings for SPF, DKIM, and DMARC, the mechanisms used to help authenticate outgoing email and set handling policies.

Use it if you manage Microsoft 365, Google Workspace, or another business email environment, especially when phishing and impersonation are recurring concerns. It helps connect domain configuration with protection inside the mailbox and the actions employees take.

Confirm the scan findings against your legitimate sending services and email configuration. Public records alone cannot verify every internal control. Questionnaire answers stay in your browser; the optional scan has the domain-retention disclosure described above. No email address is required.

4. Unified Threat Management scorecard

Review your network-edge protection

The seven-question UTM scorecard examines firewall coverage, intrusion prevention, gateway malware scanning, application controls, secure remote connections, consistent policies across locations, and round-the-clock monitoring.

It suits IT teams responsible for office networks, branches, or multiple security appliances. The questions help establish whether protection is enabled, maintained, and monitored throughout the environment.

Use your answers to review traffic paths, active settings, and the responsibilities of your network provider. Where your architecture uses a different approach, discuss how it delivers the intended protection. A questionnaire cannot validate live traffic handling or device configuration. Results are calculated in your browser, and no email address is required.

5. Secure Web Gateway scorecard

Review your users’ web protection

This seven-question assessment focuses on employee browsing: protected traffic paths, HTTPS inspection, download scanning, acceptable-use controls, remote-user coverage, identity-based policies, and monitoring.

It is especially relevant to hybrid teams and organizations whose employees work across offices, homes, and mobile locations. It can reveal uncertainty about whether the same browsing policies follow people wherever they work.

Check coverage on representative devices and locations, and review exceptions with your IT team. HTTPS inspection requires attention to privacy, certificates, and application compatibility. The scorecard cannot confirm that every connection is actually protected. Your questionnaire answers stay in your browser, and no email address is required.

6. Web Application Firewall scorecard

Review your application protection

The seven-question WAF review covers public websites, portals, administrative interfaces, and APIs. It asks about managed blocking rules, continuous tuning, direct access to application servers, bot defenses, rate limits, and centralized monitoring.

Use it if your organization operates customer-facing applications, online services, or ecommerce systems. It helps application owners and infrastructure teams discuss which systems are covered and whether attackers could bypass the intended protection.

Follow up by checking the application inventory, origin-access restrictions, and evidence that rules are working. The scorecard does not test application code or replace application-security testing. Answers remain in your browser, and no email address is required.

7. NBX detection and response scorecard

Review your detection and response readiness

This seven-question review examines analyst response after hours, device isolation, connected investigation tools, retained logs, visibility across the network, proactive threat hunting, and post-incident remediation.

It is useful for teams with security tools already in place who want to understand the operational coverage behind them. MDR means managed detection and response, EDR addresses endpoints, and XDR connects detection context across supported sources.

Use the findings to confirm who investigates, who can authorize containment, and how escalation works when your usual contact is unavailable. A tabletop exercise can help validate those arrangements. Questionnaire answers cannot demonstrate response performance during an incident. Results stay in your browser, and no email address is required.

8. Security awareness training quiz

Try the phishing awareness quiz

This interactive exercise presents 22 phishing scenarios, including misleading links, lookalike domains, unexpected attachments, urgent requests, credential requests, and repeated MFA prompts. Each scenario reinforces a practical decision about what to do next.

Employees can use it individually, and managers can use the scenarios as discussion starters. Its value is in practicing recognition, verification, and reporting before a real message creates pressure to act.

Revisit unfamiliar scenarios and connect the lessons to your organization’s reporting process. Completing the exercise does not measure how an entire workforce will behave during a real attack or replace recurring training and simulations. No email address is required.

Turn the findings into an action plan

Keep the review manageable:

  • Verify uncertainty. Ask for settings, logs, a service agreement, or a recent test result to support an answer.
  • Prioritize by business impact. Start with gaps affecting important systems, privileged access, detection, or recovery.
  • Assign an owner and a date. Make each follow-up specific enough that someone can complete it.
  • Check again after changes. Confirm the improvement with evidence, then revisit the relevant assessment.

These tools provide starting points for investigation and discussion. They do not certify security or replace a technical assessment.

Explore all eight assessments, or request a Security Stack Review to discuss your findings with Network Box USA and identify appropriate next steps.