OC Security Audit free cybersecurity assessment tools

Free Cybersecurity Self-Assessment Tools

Use a professional library of free cybersecurity, compliance, cloud, Microsoft 365, firewall, vulnerability, internal audit, external exposure, CISO governance, and incident response tools to organize what needs attention first.

87Current tools and tool hubs
8Professional review categories
No loginPublic tools start in the browser
ReportUse results as a discussion guide
A practical starting point

Choose the right tool for the risk conversation in front of you.

This library helps business owners, IT managers, CISOs, CIOs, administrators, MSP owners, and Southern California organizations review common security control areas before a deeper professional audit or remediation project. Use it to organize questions, not to certify that systems are secure or compliant.

Use the tools to prepare for:

Cybersecurity audits, Microsoft 365 and Azure reviews, firewall audits, vulnerability management, HIPAA or PCI DSS readiness, cyber insurance questionnaires, incident response planning, internal control reviews, external exposure checks, and vCISO leadership conversations.

Ali Hassani, CISO and cybersecurity consultant, in a professional data center
Created by Ali Hassani, CISO

25+ years of IT, cybersecurity, compliance, cloud, and infrastructure experience.

Ali Hassani is the cybersecurity and IT professional behind OC Security Audit. These tools reflect practical experience with security audits, Microsoft infrastructure, Office 365 and Microsoft 365 security, Azure, firewalls, vulnerability management, network security, healthcare IT, and executive cybersecurity leadership.

Tool library

Browse the full OC Security Audit free tool library.

The tools are grouped by the way organizations usually work through security questions: first the broad business risk, then identity and cloud, infrastructure, compliance, CISO governance, external exposure, and internal control review.

Tool category

Start With Guided Executive Tools

Use these higher-level tools when leadership needs a practical view of risk, ownership, priorities, and the daily operating rhythm for cybersecurity work.

Guided tool

Business Technology Risk Navigator

A guided advisory tool for cybersecurity, compliance, Microsoft 365, cloud, backup, network, and managed IT risk conversations.

Open tool
CISO planner

CISO Daily Operations Checklist and Leadership Planner

Build a practical CISO daily briefing with risk signals, ownership, vulnerability priorities, executive reporting, and vCISO coaching.

Open tool
Tool hub

Free CISO Tools

A dedicated CISO leadership tool library for governance, risk, policies, vendor risk, incident readiness, and executive reporting.

Open tool
Tool category

Business Risk, Ransomware, Incident Response, And Insurance

Start here when the organization needs a broad readiness snapshot, a ransomware conversation, incident-response planning, or cyber insurance preparation.

Start here

General Cybersecurity Risk Snapshot

Start with a broad review across identities, endpoints, servers, cloud, networks, backups, and response planning.

Open tool
Wizard

Free Cybersecurity and IT Readiness Assessment Wizard

Review overall cybersecurity and IT readiness before deeper technical or compliance work.

Open tool
Executive

Executive Cyber Risk Questionnaire

Help owners, executives, and board-level stakeholders identify governance, accountability, and resilience priorities.

Open tool
Resilience

Ransomware Resilience Assessment

Check preparedness for ransomware prevention, containment, backup protection, recovery testing, and continuity.

Open tool
Response

Cyber Incident Response Readiness Assessment

Review escalation paths, logging, communication planning, containment readiness, and evidence preservation.

Open tool
Insurance

Cyber Insurance Readiness Tool

Organize common cyber insurance control topics such as MFA, EDR, backups, vulnerability management, and response readiness.

Open tool
Exercise

Incident Response Tabletop Generator

Prepare practical tabletop scenarios for ransomware, business email compromise, vendor incidents, and response coordination.

Open tool
Tool category

Microsoft 365, Azure, Cloud, Identity, And Email

Review the account, cloud, collaboration, email, and administrative access controls that commonly drive breach and compliance risk.

Cloud

Cloud Security Readiness Assessment Wizard

Review Azure, AWS, Google Workspace, SaaS, identity, storage, public exposure, and cloud governance topics.

Open tool
Microsoft 365

Microsoft 365 Security Risk Check

Evaluate Microsoft 365 security settings, Entra ID, Exchange Online, SharePoint, OneDrive, Teams, and audit logs.

Open tool
Azure

Azure Cloud Security Readiness Check

Review Azure identity, subscriptions, virtual networks, workloads, storage, monitoring, backup, and governance controls.

Open tool
AWS

AWS Security Readiness Assessment

Review AWS account security, identity, network exposure, logging, storage, workloads, and governance practices.

Open tool
Workspace

Google Workspace Security Assessment

Review Google Workspace identity, email, sharing, admin roles, logging, mobile access, and data protection controls.

Open tool
IAM

Identity and Access Management Assessment

Review MFA, lifecycle controls, sign-in risk, conditional access, guest access, and identity governance.

Open tool
PAM

Privileged Account Security Assessment

Check administrator roles, emergency access, monitoring, separation of duties, and privileged access hygiene.

Open tool
Email

Email Security and Business Email Compromise Assessment

Review phishing defenses, mailbox rules, authentication, filtering, spoofing controls, and compromise response.

Open tool
AD

Active Directory Security Assessment

Assess privileged groups, stale objects, domain controller hardening, service accounts, auditing, and recovery readiness.

Open tool
Tool category

Network, Endpoint, Server, Backup, And Remote Access

Review practical infrastructure controls across firewalls, wireless, servers, endpoints, virtualization, vulnerability management, recovery, and remote access.

Report generator

Network Asset Discovery and Vulnerability Report Generator

Turn network discovery and vulnerability review data into a practical executive and technical report.

Open tool
Wireless

Wi-Fi and Guest Network Security Assessment

Review wireless segmentation, guest access, encryption, admin controls, rogue access points, and monitoring practices.

Open tool
Firewall

Firewall Configuration Risk Check

Review firewall rules, VPN exposure, segmentation, logging, remote access, and risky exceptions.

Open tool
Server

Server Security Hardening Assessment

Check server patching, local admin rights, logging, backup, remote access, and baseline hardening.

Open tool
Virtualization

Virtualization Security Readiness Assessment

Review VMware, Hyper-V, Azure VM, hypervisor, virtual-network, privileged-access, backup, and monitoring readiness.

Open tool
Vulnerability

Vulnerability Management Assessment

Evaluate scanning, prioritization, remediation tracking, asset coverage, exception handling, and validation practices.

Open tool
Endpoint

Endpoint Security and EDR Readiness Assessment

Review endpoint protection, EDR coverage, local privilege, patching, device inventory, isolation, and response visibility.

Open tool
Recovery

Backup and Disaster Recovery Readiness Assessment

Check backup coverage, restore testing, ransomware resilience, cloud backup, and business recovery objectives.

Open tool
Remote access

Remote Workforce Security Check

Review remote access, MFA, device controls, VPN, endpoint security, data access, monitoring, and user awareness.

Open tool
Zero Trust

Zero Trust Readiness Assessment

Evaluate identity, device, access, segmentation, monitoring, cloud, and least-privilege foundations.

Open tool
Tool category

Compliance, Privacy, Vendor, And Data Protection Readiness

Use these tools to prepare for compliance conversations, privacy concerns, vendor review, cyber insurance requirements, and data-protection decisions.

Wizard

Compliance Readiness Assessment Wizard

Identify readiness gaps for HIPAA, PCI DSS, SOC 2, NIST CSF, ISO 27001, CMMC, cyber insurance, and related frameworks.

Open tool
HIPAA

HIPAA Security Readiness Assessment

Review administrative, physical, and technical safeguard readiness for healthcare and PHI-focused environments.

Open tool
PCI DSS

PCI DSS Scope and Readiness Check

Review cardholder data scope, segmentation, access control, vulnerability management, logging, and policy readiness.

Open tool
IRS WISP

IRS WISP Compliance Readiness Assessment

Review written information security program readiness for tax, accounting, and financial-information protection.

Open tool
Privacy

Website Security and Privacy Risk Check

Review public website security, privacy exposure, forms, TLS, cookies, CMS risk, and visitor-data concerns.

Open tool
Vendor

Vendor Risk Assessment Tool

Review third-party access, data handling, contracts, SOC 2 evidence, breach notice, and outsourced-service risk.

Open tool
Tool category

CISO Leadership, Governance, Policy, And Program Tools

Use these CISO-focused tools to review governance, risk ownership, policies, vendor risk, incident readiness, executive scorecards, and security priorities.

CISO

Cybersecurity Governance Readiness Assessment

Assess cybersecurity governance, security ownership, leadership reporting, policies, and CISO-level oversight with this free OC Security Audit tool.

Open tool
CISO

Cyber Risk Management Assessment

Use this free cyber risk management assessment to review risk identification, scoring, ownership, remediation priorities, and executive risk visibility.

Open tool
CISO

Security Policy and Standards Gap Assessment

Review cybersecurity policy gaps including MFA, incident response, backups, vendor access, remote work, acceptable use, and data protection.

Open tool
CISO

Vendor and Third-Party Risk Assessment

Assess vendor and third-party cybersecurity risk, external access, data handling, contracts, breach notification, SOC 2 evidence, and security controls.

Open tool
CISO

Incident Response Tabletop Readiness Assessment

Review incident response planning, ransomware readiness, business email compromise response, escalation, communication, and tabletop exercise maturity.

Open tool
CISO

Executive Cyber Risk Scorecard Assessment

Generate an executive cyber risk scorecard to review cybersecurity visibility, compliance risk, business impact, recovery readiness, and leadership reporting.

Open tool
CISO

Compliance Readiness Selector Assessment

Identify which cybersecurity compliance frameworks may apply to your business, including HIPAA, PCI DSS, CMMC, IRS WISP, SOC 2, NIST CSF, and ISO 27001.

Open tool
CISO

Security Awareness Program Assessment

Assess employee cybersecurity awareness, phishing training, new hire training, executive training, remote work awareness, and reporting procedures.

Open tool
CISO

Data Protection and Sensitive Information Security Assessment

Review sensitive data protection, encryption, access control, backups, file shares, cloud data security, email protection, and DLP readiness.

Open tool
CISO

Cybersecurity Roadmap and Priorities Assessment

Build a practical cybersecurity roadmap by reviewing security gaps, compliance drivers, current tools, staffing, priorities, and remediation planning.

Open tool
Tool category

External Audit And Internet Exposure Tools

Review public-facing systems, DNS, email security, cloud exposure, remote access, vendor portals, and external evidence readiness.

External hub

Free External Audit Tools

Use free External Audit Tools from OC Security Audit to assess public IP exposure, website security, DNS, email security, cloud exposure, remote access, external vulnerabilities, vendor portals, and incident readiness.

Open tool
External

External Security Audit Readiness Scorecard

Review your organization’s overall external security posture across public-facing systems, internet exposure, website security, DNS, email security, cloud exposure, vulnerabilities, and incident readiness.

Open tool
External

Public IP, Open Port, and Network Exposure Assessment

Assess public IP inventory, open ports, exposed RDP, SSH, VPN, admin portals, firewall rules, unnecessary services, and internet-facing network device risks.

Open tool
External

Website and Web Application Security Assessment

Review website CMS security, WordPress and plugin exposure, login protection, web forms, security headers, TLS, client portals, privacy risks, and exposed software versions.

Open tool
External

DNS, Domain, SSL, and Email Security Assessment

Assess DNS records, registrar security, DNS hosting, SSL/TLS certificates, SPF, DKIM, DMARC, MX records, phishing exposure, brand impersonation, and lookalike domains.

Open tool
External

Cloud and SaaS External Exposure Assessment

Assess Microsoft 365 exposure, Azure, AWS, Google Cloud public resources, public storage, SaaS admin access, external sharing, exposed cloud apps, MFA, conditional access, and guest access.

Open tool
External

Remote Access, VPN, and External Authentication Assessment

Review VPN security, remote desktop exposure, external admin portals, MFA enforcement, conditional access, vendor access, privileged remote access, failed login monitoring, brute-force protection, and risk-based access.

Open tool
External

External Vulnerability and Attack Surface Management Assessment

Assess external vulnerability scanning, attack surface management, internet-facing servers, exposed databases, software version exposure, SSL/TLS weaknesses, known exploitable vulnerabilities, remediation tracking, and review cadence.

Open tool
External

Third-Party, Vendor Portal, and Hosted Service Exposure Assessment

Assess vendor-hosted portals, customer portals, outsourced IT platforms, third-party access, hosted applications, access control, vendor security evidence, SOC 2 or ISO 27001 review, and breach notification readiness.

Open tool
External

External Backup, Recovery, and Incident Readiness Assessment

Assess externally accessible backups, cloud backup access, ransomware recovery readiness, incident response contacts, cyber insurance contacts, breach notification workflow, external attack escalation, evidence preservation, and recovery testing.

Open tool
External

External Compliance and Evidence Readiness Assessment

Assess external audit documentation, compliance evidence, vulnerability scan records, penetration test records, cyber insurance evidence, customer security questionnaires, policy evidence, remediation records, and executive reporting.

Open tool
Tool category

Internal Security Audit Tools

Review the internal control environment across physical security, networks, servers, databases, Active Directory, Wi-Fi, patching, EDR, backups, documentation, and process ownership.

Internal hub

Free Internal Audit Tools

Use free Internal Audit Tools from OC Security Audit to assess physical, technical, administrative, network, server, endpoint, Active Directory, Wi-Fi, backup, monitoring, and incident response controls.

Open tool
Internal

Physical Security Controls Assessment

Review how well your organization protects facilities, work areas, network closets, sensitive media, and visitor access as part of an internal security audit.

Open tool
Internal

Server Room and Data Center Security Assessment

Assess physical, environmental, and operational safeguards around server rooms, network racks, and controlled IT infrastructure spaces.

Open tool
Internal

Internal Network Security Assessment

Evaluate internal segmentation, east-west visibility, access control, documentation, and internal traffic protection for business networks.

Open tool
Internal

Server Operating System Security Assessment

Review hardening, patching, privileged access, logging, and remote administration controls for Windows and Linux servers.

Open tool
Internal

Database Security Assessment

Assess database access control, encryption, patching, logging, backup protection, and sensitive-data safeguards across internal business systems.

Open tool
Internal

Internal Web Server Security Assessment

Review patching, authentication, file permissions, TLS, logging, and internal application exposure risks for internal-facing web servers.

Open tool
Internal

Internal Router, Switch, and Firewall Assessment

Assess the hardening, configuration control, access security, logging, and segmentation discipline of internal network devices and firewall infrastructure.

Open tool
Internal

Monitoring, Logging, and SIEM Readiness Assessment

Evaluate how well your organization collects, reviews, correlates, and escalates logs from endpoints, servers, network devices, and cloud services.

Open tool
Internal

Backup and Disaster Recovery Internal Audit Assessment

Assess backup coverage, restore testing, resilience, access control, and documented recovery planning for internal systems and critical business services.

Open tool
Internal

Administrative Security Controls Assessment

Review policies, reviews, ownership, vendor oversight, onboarding controls, and management reporting that support internal security governance.

Open tool
Internal

Incident Response and Internal Security Process Assessment

Assess how prepared your organization is to identify, escalate, contain, investigate, and document internal cybersecurity incidents.

Open tool
Internal

Internal Security Audit Readiness Scorecard

Use a scorecard-style assessment to review major internal audit categories and quickly identify top internal cybersecurity control gaps and remediation priorities.

Open tool
Internal

Wi-Fi Security Internal Audit Assessment

Review enterprise wireless security, guest segmentation, admin access, rogue access point detection, and monitoring for internal wireless networks.

Open tool
Internal

User Security Awareness Program Assessment

Assess employee cybersecurity awareness, phishing readiness, policy acknowledgement, and recurring education across office and remote work environments.

Open tool
Internal

Client Computer Security Assessment

Review endpoint patching, encryption, EDR, browser security, removable media controls, and inventory discipline for desktops and laptops.

Open tool
Internal

Mobile Phone and Handheld Device Security Assessment

Assess mobile device management, encryption, BYOD controls, app risk, update discipline, and secure access requirements for smartphones and handheld devices.

Open tool
Internal

Active Directory Security Assessment

Assess privileged groups, stale objects, domain controller hardening, service accounts, auditing, and recovery readiness for Microsoft Active Directory environments.

Open tool
Internal

Group Policy Security Assessment

Review whether security baselines, password policies, firewall settings, restrictions, and GPO change control are consistently enforced through Group Policy.

Open tool
Internal

DNS and DHCP Security Assessment

Review core DNS and DHCP security, redundancy, access control, logging, and documentation that support internal network reliability and control.

Open tool
Internal

Network Services Security Assessment

Assess the security, monitoring, administration, and resilience of core internal network services such as NTP, RADIUS, LDAP, VPN, file sharing, and certificate services.

Open tool
Internal

Redundancy and Failover Readiness Assessment

Evaluate whether critical infrastructure has meaningful redundancy, documented failover procedures, and tested recovery paths for internal operations.

Open tool
Internal

File Server and Shared Folder Security Assessment

Assess shared-folder permissions, ransomware resilience, file auditing, sensitive-data exposure, and access review discipline across internal file servers.

Open tool
Internal

Privileged Access and Administrator Account Assessment

Review privileged account segregation, MFA, shared-admin risk, monitoring, vaulting, and access-review discipline for administrative identities.

Open tool
Internal

Patch Management Internal Audit Assessment

Assess patch coverage, ownership, testing, reporting, exceptions, and vulnerability-based prioritization across servers, endpoints, browsers, and network devices.

Open tool
Internal

Endpoint Detection and Response Readiness Assessment

Review EDR deployment coverage, isolation capability, behavioral monitoring, alert handling, retention, and response workflows for endpoints and servers.

Open tool
Internal

Change Management Security Assessment

Assess whether security-relevant technology changes are documented, approved, tested, validated, and reviewed across infrastructure and production systems.

Open tool
Internal

IT Asset Inventory Security Assessment

Assess whether hardware, software, servers, network devices, endpoints, and cloud assets are inventoried, owned, classified, and tracked through lifecycle changes.

Open tool
Internal

Internal Vulnerability Management Assessment

Review internal scanning coverage, remediation ownership, exception handling, reporting, and prioritization across servers, endpoints, and network devices.

Open tool
Internal

Secure Remote Access Internal Audit Assessment

Assess VPN security, MFA, zero-trust-style restrictions, vendor access, session logging, and device-compliance checks for remote connectivity.

Open tool
Internal

Internal Audit Documentation and Evidence Assessment

Review whether key policies, diagrams, logs, reports, test results, and evidence records are organized well enough to support an internal security audit.

Open tool
Important limitation

Use the results as initial guidance, then validate important findings.

These free tools are educational starting points based on self-reported selections. They do not replace a professional cybersecurity audit, compliance assessment, penetration test, vulnerability scan, legal review, cyber insurance review, or technical configuration validation. Do not make production changes solely because of an automated result.

What the tools help with

Turn scattered security concerns into a clearer action conversation.

Executive summary

Use the output to explain the business risk, likely impact, and why the topic deserves leadership attention.

Technical review

Use the questions to identify evidence to collect, systems to inspect, and controls that may need validation.

Remediation planning

Use the findings to prioritize owners, dates, dependencies, change windows, and follow-up verification.

Trusted references

Use authoritative resources alongside the free tools.

NIST

NIST Cybersecurity Framework 2.0

Use NIST CSF 2.0 to organize cybersecurity outcomes, governance, risk, and improvement priorities.

Open tool
NIST

NIST Small Business Quick-Start Guide

Use NIST SP 1300 as a practical cybersecurity risk-management starting point for smaller organizations.

Open tool
CISA

CISA Cyber Guidance For Small Businesses

Use CISA guidance to frame practical cybersecurity actions for owners, IT managers, and business leaders.

Open tool
CISA

CISA No-Cost Cybersecurity Tools

Review additional no-cost resources and services that can support security improvement efforts.

Open tool
Microsoft

Microsoft Security Documentation

Review Microsoft guidance for identity, endpoint, email, Microsoft 365, Azure, and security operations.

Open tool
Microsoft

Azure Security Documentation

Use Azure security documentation for cloud governance, workload protection, identity, and network controls.

Open tool
Professional validation

Move from a checklist to a professional cybersecurity review.

When a tool highlights risk, OC Security Audit can help validate evidence, review configurations, prioritize remediation, and communicate the business impact clearly.

Implementation support

From findings to practical IT follow-through.

OC Security Audit focuses on cybersecurity assessment, audit, compliance, risk, and vCISO guidance. When findings require hands-on implementation, project work, troubleshooting, managed IT, Microsoft 365, Azure, server, backup, endpoint, or network support, IT Perfection can support the operational work as a separate managed IT company.

FAQ

Frequently asked questions.

Which free cybersecurity tool should I start with?

If you are unsure, start with the Business Technology Risk Navigator or General Cybersecurity Risk Snapshot. If you already know the topic, choose a specific tool such as Microsoft 365, Azure, firewall, ransomware, HIPAA, PCI DSS, vulnerability management, or internal audit.

Are these tools a replacement for a professional audit?

No. The tools help organize initial guidance. Important findings should be reviewed through a professional cybersecurity audit, compliance assessment, penetration test, vulnerability scan, or technical configuration review.

Do the tools collect sensitive company information?

The public self-assessment tools are intended for browser-based guidance and should not be used to submit passwords, secrets, private keys, sensitive client data, or confidential system details.

Can OC Security Audit help after a tool is completed?

Yes. OC Security Audit can review results, validate evidence, prioritize remediation, and help leadership understand the business and technical impact.

Start with a free tool, then validate the important risks.

Use the library to organize the first conversation. Contact OC Security Audit when you need professional review, evidence validation, compliance readiness, vulnerability management, firewall review, Microsoft 365 or Azure security guidance, cyber insurance readiness, or vCISO support.