Skip to main content
+968 2284 4777 Head officeTalk to usMyIT Portal

Free Cyber Health Check

Fifteen straight questions, mapped to the NIST Cybersecurity Framework and the data-protection rules where you operate. You get a score, a breakdown by area, and the gaps worth fixing first. Nothing leaves your browser.

0 of 15 answered

Sets which data-protection and incident-reporting rules we ask about.

Regulated sectors get an extra question.

Do you have a written information-security policy that your staff know about?

Is one person or team clearly responsible for cybersecurity in your organisation?

Do you keep an up-to-date list of your important IT assets (devices, systems, data, cloud apps)?

Have you reviewed your main cyber risks in the last 12 months?

Is multi-factor authentication (MFA) turned on for email and your key systems?

Do your staff get regular security-awareness or phishing training?

Is sensitive data access limited to those who need it (and encrypted where appropriate)?

Are your systems and software kept patched and up to date?

Do all your computers and servers have active endpoint/antivirus protection?

Would you actually notice if an account or device were hacked?

Do you have a plan for what to do during a cyber attack or data breach?

Do staff know how and where to report something suspicious?

Are your critical systems and data backed up regularly?

Have you successfully tested restoring from a backup in the last 12 months?

Are you handling personal data in line with Oman PDPL (consent, breach notification, data-subject rights)?

Could you report a serious cyber incident to the national authorities (CDC / OCERT) within required timelines?

Are you meeting the Central Bank of Oman / FSA cyber requirements?

Are you handling personal data in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021)?

Are you aligned with the UAE Information Assurance Regulation (NESA/SIA) or your emirate standards (e.g. Dubai ISR)?

Are you meeting Central Bank of the UAE (CBUAE) cybersecurity requirements?

Are you handling personal data in line with the DPDP Act 2023 (consent, data-principal rights, breach notification)?

Could you report a serious cyber incident to CERT-In within the required 6-hour window?

Are you meeting your financial regulator cyber requirements (RBI / SEBI / IRDAI)?

An indicative self-assessment for guidance, not a certification or an audit — it reflects what you tell us about your own controls. The full engineer-validated gap assessment is a paid engagement.

Free portal access

Keep your results, and see what changes.

This tool is free and needs no account. Create free access to the MyIT Portal and you also get the Cyber Health Scorecard — every run saved, so you can come back in six months and see whether anything actually improved.

Work email, no password to set, no sales call unless you ask for one.