We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

The Cyber Hygiene Test · 3 minutes · 12 questions

How much of the attack actually gets through? Find out in three minutes.

Twelve plain-English questions on the controls that stop most attacks, scored against the CIS baseline that the UAE IA Standard, ADHICS and your regulators build on. Your score and your three biggest gaps appear the moment you finish, with the number that matters: how much of the common attack techniques you are covered against today.

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

Step 1 of 3 · About your business

What kind of business are you?

How many people work there?

What is in your environment? Pick all that apply.

Your score and your three biggest gaps appear the moment you finish. The full report and the fix plan come by email.

Questions about the test

What the score measures, and what a good one looks like.

What does the Cyber Hygiene Test measure?
Twelve controls from the CIS Controls v8.1 Implementation Group 1 baseline: multi-factor login, least privilege, patching, endpoint protection, backups, email protection, training, inventory, logging, encryption, vendor risk and incident response. It is the same baseline the UAE IA Standard v2 and ADHICS build on, so the score speaks the regulators’ language.
Where do the coverage percentages come from?
The CIS Community Defense Model v2.0 found that the IG1 baseline defends against 77% of the attack techniques used across the top five attack types and 78% of ransomware techniques. Your coverage is a proportional estimate from how many of those controls you have in place.
What is a cyber hygiene checklist?
The routine habits that stop most attacks: multi-factor login on every account, automatic software updates, tested backups kept offline, a list of every device and account you own, removing access when people leave, and basic staff training. The recognised checklist for small firms is CIS Controls Implementation Group 1, which the Center for Internet Security calls essential cyber hygiene.
What is a security score, and what is a good one?
A number that summarises how many recommended safeguards you have in place, usually out of 100 or as a letter grade. Scores differ by tool (Microsoft Secure Score, insurer scans and CIS-based assessments measure different things), so compare your score against the same tool over time rather than against another company. A useful score tells you which gap to fix next.
What are the CIS Controls IG1?
CIS Controls version 8.1 has 18 controls and 153 safeguards. Implementation Group 1 is the starter subset of 56 safeguards for organisations with limited IT staff: asset and software inventory, data protection, secure settings, account and access management, vulnerability management, logging, email and browser protection, malware defences, recovery, network basics and awareness training.
How often should a business check its security?
A hygiene self-check quarterly and a professional assessment at least once a year, or after any big change: a new office, a new cloud system, a merger, major staff turnover. Regulated businesses often have a required cadence, and DoH, DHA and the financial regulators ask for evidence at renewal. The read-only compliance agent keeps the picture current between checks.

Bring your score. Leave with a plan and a fixed fee.

Thirty minutes with an engineer who has closed these gaps inside banks and hospitals. We go through your twelve controls, agree the order, and scope the first three.