Cyber risk assessments for e-commerce brands

Find the gaps first.

If someone got into your store tonight, how long before you noticed? Most founders answer that and realise they have no idea.

Start free check See the report 2 min · no signup
NIST CSF 2.0The global security standard, translated into plain English.
48 hoursA complete written assessment back within two working days.
22 controlsAccess, payments, apps, devices, backups, breach response.
The free check

How exposed is your store?

Ten questions, two minutes, no signup. You get a risk score and the specific controls that scored worst — drawn from the same checklist we use in paid assessments.

Risk check v2.0 Ready
Step 00 — Start

First, one quick question.

What platform does your store run on? This changes the wording of the questions and the gaps we look for.

0/ 100

Your weakest controls, worst first

This is a self-assessment, not an audit. The full 48-hour assessment verifies every answer against your actual store, scores 22 controls instead of 10, and returns a written report with a prioritised 30-day fix plan.

Nothing you enter is sent anywhere. The score is calculated in your browser and discarded when you close the tab.

Process

Three steps, forty-eight hours.

Step 01

Intake

We walk through the checklist with you — 22 controls covering access, payments, apps, devices, backups and breach response. Nothing installed, no code access required.

Step 02

Assessment

Each control is verified against your live setup and scored: not in place, partially in place, or fully in place. Every gap gets a risk level and a real-world consequence.

Step 03

Report

Within 48 hours you get a written report with your score, the priority risks in order, and a 30-day plan setting out exactly what to fix first.

Deliverable

What lands in your inbox.

Written for the person who signs the cheque, not for an IT department. If a sentence needs you to know what NIST is, it didn't make the cut.

01
Overall risk scoreA single figure out of 100 with a clear risk band — critical, high, medium or low — so you know where you stand.
02
Category breakdownEleven scored areas, from account access to breach response, each with its own percentage and risk level.
03
Top priority risksThe gaps that matter most, ordered by real exposure: identity first, then financial, then customer data.
04
Detailed findingsEvery gap written specifically for your business — what it is, what happens if it's exploited, and the exact steps to close it on your platform.
05
30-day fix planSequenced and realistic. What to do this week, this fortnight, this month, with the quick wins flagged.
06
Current position vs. targetWhere you sit today against where a business your size should be, so you can show progress at the next review.
Assessment summarySample
54/ 100High risk
Account access & identity25%
Payment & financial0%
Third-party apps50%
Business email security67%
Data backups75%
Breach response plan100%
Illustrative figures. Full assessments score 11 categories across 22 controls.
Methodology

Built on NIST CSF 2.0. Written in English.

The Cybersecurity Framework is the standard large enterprises are measured against. We assess against the same six functions, then drop the vocabulary.

Govern

How you manage risk

Whether anyone actually owns security, and whether your contractors are contractually obliged to hand access back.

Identify

What you know about your systems

Every app, integration, device and login that touches your store — including the ones nobody remembers approving.

Protect

How you prevent attacks

The largest section: MFA, shared logins, offboarding, payout settings, API keys, app permissions, device encryption.

Detect

How you spot threats

Whether anything alerts you when an admin does something unusual, or a customer list is exported at three in the morning.

Respond

How you react to incidents

Whether there's a written plan, who gets called, and in what order — decided before the day you need it.

Recover

How you get back to normal

Backups that exist, are isolated, and have actually been restored from — not just assumed to be working.

Questions

Reasonable objections.

Do you need access to my store?

No. The assessment is evidence-based rather than intrusive — we ask you to confirm settings and show us specific screens. We never ask for your admin password, and we install nothing.

Isn't my platform already secure?

Shopify, WooCommerce and the rest secure their own infrastructure. They don't secure how you configure it: who holds admin, which agency still has access from a project two years ago, whether a payout account change requires re-authentication. That layer is yours, and it's where almost every gap we find lives.

We're small. Are we really a target?

Most attacks aren't targeted. They're automated sweeps for known-weak configurations, and a small store with an unused developer account open looks identical to a large one. Recovering from a breach typically runs into five figures in legal fees, lost customers and downtime.

Will I understand the report?

That's the entire design goal. Plain-English finding, plain-English consequence, plain-English fix. The technical framework reference sits in small print at the end of each item, for the day an enterprise customer's procurement team asks.

What happens after the report?

You get a 30-day plan and can implement it yourself — most findings are configuration changes rather than purchases. If you'd rather be walked through it, that's a call.

Next step

Before someone else does.

Start with the free two-minute check. If it turns up anything worth discussing, we'll walk you through a 30-day fix plan on a short call.