
Cybersecurity
SME Cybersecurity Self-Assessment Tool
- Year
- 2026
- Category
- Cybersecurity
- Tech stack
- Next.jsPostgreSQLRéférentiel CIS Controls IG1
An interactive questionnaire letting small and medium Congolese enterprises assess their exposure to the most common cyber risks in 15 minutes.
The problem
Large institutions have dedicated cybersecurity budgets and teams; Congolese SMEs typically have neither, even though they are just as exposed to common risks (phishing, weak passwords, missing backups).
Existing security frameworks (ISO 27001, NIST) are designed for large organisations and demand a time and expertise investment out of reach for an SME with a few dozen employees.
Our approach
We looked for a framework rigorous enough to be useful, yet simple enough to be filled in without in-house expertise. The CIS Controls, in their "Implementation Group 1" (IG1) version aimed precisely at small organisations with limited resources, matched that need.
The challenge was translating a technical framework into a questionnaire an SME owner could understand with no specialised vocabulary, while keeping enough rigour for the result to be genuinely actionable.
Technical solution
The concept offers around fifteen plain-language questions, each answer feeding a maturity score per domain (access, backups, endpoints, team awareness).
At the end of the questionnaire, the tool generates a prioritised action plan — the 3 to 5 high-impact, low-cost measures to implement first — rather than a discouraging exhaustive list of every recommendation in the framework.
The score can be tracked over time, letting an SME measure its progress after implementing the first measures, with no need for a paid external audit at every step.
Gallery


This project is a research & development concept (spec work) designed by Novenvera to demonstrate our technical expertise against the realities of Central Africa.
