Skip to content

Colour theme

Region

Opens the same page on another regional site.

Search site

Search pages and articles

Ctrl+K · Search site
Menu

Free 3 minute self-check

Score your medical IT risk in 3 minutes

Answer 12 quick questions about continuity, cyber security, Microsoft 365 and identity, clinical systems, vendor access, and governance. Get an instant risk score with plain language priorities. No sign-up required.

Medical IT risk check for healthcare organisations

Pick the answer that best matches your organisation today. If you are not sure, choose the middle option: the result will flag it as something worth confirming.

Each question has three options. Answer all twelve, then select See my result to view your risk score.

When did you last successfully restore clinical or patient data from a backup as a test?
Do you have a written plan for how clinical work continues if IT is down for half a day?
Is multi-factor authentication (MFA) enforced on email, Microsoft 365, and remote access?
Are servers and clinical workstations patched on a known schedule with exceptions tracked?
Are privileged Microsoft 365 and directory admin accounts limited and separately protected?
Are shared mailboxes, forwarding, and guest access reviewed so identity sprawl stays under control?
Are clinical system updates (PACS, RIS, PMS, or EMR) tested before they reach live clinics?
Is uptime of critical clinical systems monitored with alerts someone will act on?
Is vendor remote access time limited, logged, and approved rather than always on?
Do third party vendors who touch clinical systems use MFA and least privilege accounts?
Do you have a current Essential Eight, ISO 27001, or equivalent security maturity assessment?
Can you produce access control, backup, and incident evidence quickly for an audit or regulator?