Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly identify cybersecurity risks in your small business.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe supplied tool data does not price a specialist cybersecurity assessment.
If this goes wrong: a serious weakness is missed or incorrectly prioritised, leaving your business exposed while giving you false confidence.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open a blank document and record your business name, staff count, locations, devices, cloud services, website, suppliers, remote access methods and business-critical processes.
- Gather your current asset list, backup information, MFA and access settings, patching records, security policies, supplier information, recent alerts and incident records, removing passwords, private keys and unnecessary personal data.
- Paste the business description, data description, controls and redacted evidence into the prompt, keeping each item under its matching heading.
- Ask the chatbot to produce the risk register, and copy its separate lists of assumptions, missing evidence, urgent actions and questions for a professional into the same document.
- Compare every stated asset and control against your actual device list, cloud administrator screens, backup records and policies, marking unsupported findings as unknown rather than confirmed.
- Send the risk register and the evidence gaps to a qualified UK cybersecurity professional, and record which risks, severity ratings and remediation actions they confirm or change.
Prompt
Act as a cybersecurity risk analyst for a small UK business. Use only the evidence I provide and clearly label every assumption, uncertainty and missing piece of evidence. Do not invent systems, vulnerabilities, compliance duties, supplier details or technical findings, and do not claim that a control is present unless the evidence shows it. Assess the information below and produce: 1. A plain-English risk register with one row per risk. 2. For each risk: the affected asset or process, evidence, threat, likely consequence, severity, likelihood, confidence, and why you assigned those ratings. 3. A separate list of information you need before confirming each uncertain risk. 4. Prioritised actions for the next 24 hours, next 30 days and later, with the owner and evidence needed to confirm completion. 5. A list of controls that appear present, absent or unknown. 6. A short set of questions for a UK cybersecurity professional to validate the assessment. Do not provide exploit instructions, passwords, attack code or advice to bypass security. Do not treat compliance with Cyber Essentials, UK GDPR or any other framework as established unless the supplied evidence supports it. Flag anything that needs a qualified security professional or urgent incident-response help. Business and systems: [describe the business, staff, locations, devices, operating systems, cloud services, websites, software, suppliers and remote access] Data and important processes: [describe personal data, financial data, confidential information, backups and business-critical processes] Existing controls: [paste policies, MFA status, patching process, backups, antivirus or endpoint protection, access reviews, training and supplier checks] Evidence: [paste a redacted asset inventory, security reports, audit findings, alerts, incident records or relevant configuration summaries] Do not paste passwords, private keys, recovery codes, customer records or other unnecessary personal data.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover every device, account, exposed service or supplier connection from a short description.
- AI cannot prove that a backup can be restored, that a patch is effective or that an account is securely configured.
- AI cannot reliably judge the business impact of an unknown weakness without understanding your operations, contracts and dependencies.
- AI cannot take responsibility for deciding whether a serious risk is acceptable or for responding to an active attack.
What caps this at PARTLY: context depth, judgement under ambiguity and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 1 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI do a cybersecurity risk assessment for my small business?
- Partly. It can organise the evidence you provide into a risk register and suggest questions and priorities, but it cannot reliably find unknown systems or validate technical controls on its own. A qualified cybersecurity professional should confirm serious or uncertain findings.
- Can ChatGPT scan my business for cyber risks?
- No, not by itself. A chatbot can analyse pasted inventories, reports and configuration summaries, but it does not automatically see your network, cloud accounts or devices. Do not paste passwords, private keys, recovery codes or unnecessary personal data.
- What information does AI need to identify cybersecurity risks?
- Give it an accurate list of devices, software, cloud services, users, suppliers, remote access, important data, backups, MFA, patching and existing security controls. Redacted alerts, audit findings and incident records make the result more useful, while secrets and customer records should be left out.
- Is an AI cybersecurity risk assessment enough for Cyber Essentials?
- No. AI can help organise evidence and identify questions, but it cannot certify that your business meets the requirements or replace the required assessment route. Use the current official Cyber Essentials guidance and ask a qualified security professional to resolve uncertain technical points.
Nearby answers
- Can AI check whether my business passwords have been leaked?PARTLY
- Can AI check my business cybersecurity compliance with UK GDPR?NO
- Can AI check whether an email is a phishing attempt?PARTLY
- Can AI choose a password manager for my business?YES
- Can AI choose cybersecurity software for my business?PARTLY
- Can AI compare business antivirus software in the UK?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.