FWSG · Fisher Web Security Gauge · FFSS Suite · Beta

Is your website actually
secure — or just
unnoticed?

Most attacks on small business sites aren't clever — they're bots rattling door handles, looking for one left unlocked. Monte Fisher — retired CPA, CFE, and independent governance advisor — built FWSG to help you score where you stand and fix what's open, in the order that actually matters.

5Security layers
SMBPrimary focus
$0Vendor relationships
fwsg_output_sample.json
// FWSG Report — illustrative sample
access_hardening: 58/100
auto_blocking: 20/100
change_detection: 50/100
awareness: 80/100
ai_surface: flagged
overall_fwsg_score: 52/100
tier: "EXPOSED"
critical_flag: "auto_blocking"
recommendation: "Talk to Monte"
Who this is for

Built for small and medium businesses
who don't have a security team.

You have a website. Maybe a few internal tools. Possibly an AI chatbot you added last year. And no clear way to tell whether any of it is locked down or wide open. The overwhelming majority of attacks on sites your size aren't sophisticated — they're automated bots checking every door for the one left unlocked. FWSG helps you find your own open doors before they do.

Businesses running a website or web app without a dedicated security team
Owners unsure whether their site is hardened or just hasn't been noticed yet
Companies that added an AI chatbot or assistant without governing it
Professional services firms holding client data on their own infrastructure
Anyone who's worried about getting "hacked" but doesn't know where to start
Teams that want a plain-English baseline before hiring a security pro

The order matters: lock the doors before you install the alarm

FWSG scores you the way a professional would actually work: close the obvious entry points first, then add detection for whatever gets past them. There's no point catching an intruder if you left the front door open. The five layers — access hardening, auto-blocking, change detection, awareness, and the AI surface — go worst-first, so your lowest scores are exactly where to start.

Free assessment — start here

FWSG — Fisher
Web Security Gauge

Seven questions. Five layers. Live score. 3 minutes. No signup. Your answers stay in your browser — nothing is sent anywhere. "Not sure" counts as a gap — because in security, not knowing carries the same risk as "no."

FWSG Self-Assessment · Fisher Web Security Gauge
Aligned with CIS Controls · OWASP · NIST CSF
0/7
Five layers

What FWSG checks.
In the order a pro would fix it.

L1 · DOORS

Access hardening

Key-only login, a closed-by-default firewall, automatic updates, real protection on private pages.

L2 · GUARD

Auto-blocking

Something that auto-bans the bots rattling the handles — repeated failed logins and probes.

L3 · ALARM

Change detection

A nightly tripwire that flags any file that changed, appeared, or vanished without you.

L4 · CAMERAS

Awareness

Knowing who's been probing your site and what they're looking for.

L5 · AI

AI surface

The new door most owners haven't governed: chatbots and assistants that take visitor input.

The analyst

Monte Fisher,
CPA (Ret.) · CFE

Monte Fisher
Monte Fisher
CPA · Texas (Retired) CFE · ACFE 25+ Yrs Analytics Forensic Controls No Vendor Agenda

Monte brings a forensic accountant's lens to security and governance — the same controls-focused mindset he applies to AI vendor due diligence and fraud examination. Security gaps are controls gaps: where's the accountability, who can get in, would you know if something changed?

FWSG asks the questions a small business owner can actually answer, then points to the gaps worth fixing first. No product to sell. No vendor kickbacks. Honest analysis of where you actually stand.

Email Monte

Important disclosures & disclaimers

Educational purposes only. The FWSG assessment and all content on this page is for general educational purposes only. It is not legal advice, a penetration test, or a formal security audit.

A high score is not a guarantee. A FWSG score means "no obvious open doors found by these questions" — not that your site is secure. It does not constitute certification or compliance under any framework (CIS, OWASP, NIST).

Consult qualified professionals. For formal security audits, penetration testing, or incident response, always engage qualified security professionals in your jurisdiction.