This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More
Know what to verify or fix first in your business IT.
Not sure what your IT provider covers, whether backups can be restored, or what to ask before a renewal? Turn what you know into three practical next steps, with clear evidence requests and an owner for each action.
Free visual PDF guide with charts, an example report and practical worksheets. No email signup or sales conversation required. Preview the PDF or get the plain-text instructions. ChatGPT account settings and upload limits apply.
You do not need administrator access or a technical background. Broad context is enough to begin. Leave out passwords, confidential records and raw logs.
Save the visual PDF guide. It includes the questions, evidence labels, sample report, worksheets and source links. The plain-text instructions remain available as an alternative.
Open ChatGPT and upload the guide. Do not upload company evidence to start.
Copy the prompt below. Answer a few questions about critical work, who handles IT and what you know.
This starts a guided conversation. It does not install a plugin or configure future chats. If uploads are unavailable, open the plain-text instructions and paste their contents into the chat. Check ChatGPT’s current upload availability and limits.
The quick route reviews seven selected topics: critical work, IT ownership, access protection, offboarding, devices, backups and recovery. You receive a scoped assessment, three next actions, questions for your current provider and a checkpoint to keep for a later review.
“We’re a 20-person business with outsourced IT. Email and accounting are critical. Our backups say successful, but we don’t know when anything was restored. What should we verify first?”
Synthetic example. This is not a customer testimonial or a completed technical audit.
Recovery readiness: unknown in the described scope
Reported in place: backups are said to run successfully.
Unknown: usable recovery, test date and coverage.
No numeric security score or blanket assurance is inferred.
Keep the checkpoint and bring it back with a sanitized progress summary. The guide can compare supplied results. It does not remember earlier chats or monitor your systems.
A deeper route covers 18 topics when you need a broader review. You can stop at any point and receive a partial result.
The assessment separates reported controls, reported gaps, narrowly supported evidence, unknowns and conflicting claims. Dates and scope stay visible.
The original questions are informed by NIST’s small-business cybersecurity guidance and CISA’s small-business resources. The guide is not a NIST or CISA certification.
Take the result to your existing provider or another qualified professional. Using the guide does not require a Rivell engagement.
No. It is a guided readiness assessment based on the information you provide. It does not connect to accounts, scan systems, certify compliance, verify control effectiveness or guarantee security. A formal audit or technical assessment needs a separately defined scope and qualified human review.
Yes. The result includes draft evidence questions you can send to your existing provider. No message is sent automatically, and you can use the result without contacting Rivell.
Start with broad business activities, who handles IT and sanitized descriptions of what is covered. Do not include passwords, tokens, recovery codes, customer or patient records, confidential contracts, account lists or raw security logs.
This package has no account connection, separate assessment database or automatic report submission. ChatGPT and any tools you independently enable use their own processing and retention policies. Review your organization’s approved use before entering company information. Read the package’s data and privacy explanation.
The public route available here is the downloadable guide. Downloading it is separate from an OpenAI directory installation or approval. Publisher verification and any directory review are controlled by OpenAI. Use the download-and-upload steps above to start now.
Contact your responsible IT or security provider through a known channel. An active compromise or major outage takes priority over a routine questionnaire. This guide does not replace incident response or recovery support.
If your result points to work that needs technical help, you can take it to your provider or ask Rivell about a scoped review. Agree the systems, evidence, deliverables and responsibilities before work begins.
Download assessment guide (PDF)The same workflow is available as a downloadable skill and portable plugin. Installation depends on your supported surface and workspace policy.
Download the Codex skill ZIP
Download the portable plugin ZIP
View file checksums
For standalone Codex use, extract the skill ZIP into your configured skills directory so it contains rivell-it-assessment/SKILL.md. Start a new Codex session to load the skill.
Guide and package version 1.0.1. Existing saved assessments remain compatible. Report defects with synthetic examples through Rivell support.