The Cyber Arm Security · Cybersecurity for Canadian Businesses

Cybersecurity Blog / Risk Assessment

Cybersecurity Assessment Checklist for Canadian Businesses

A cybersecurity assessment should answer a practical question: where could a realistic attack cause meaningful business damage, and are the current controls strong enough? The result should be evidence, prioritized findings and a remediation roadmap, not simply a long vulnerability list.

Assessment outcome: identify critical assets and exposures, verify whether important controls actually work, assign risk based on business impact and produce a prioritized plan with owners and target dates.

1. Identity and access

Confirm that multi-factor authentication is enforced for privileged accounts, remote access and cloud services. Review inactive accounts, shared credentials, administrator privileges, Conditional Access, password policies and the process for immediately disabling access when an employee leaves.

2. Microsoft 365 and cloud security

Review tenant security settings rather than assuming Microsoft 365 is secure by default. Examine MFA coverage, legacy authentication, risky sign-ins, administrator roles, external sharing, mailbox forwarding rules, audit logging and recovery procedures. Azure, AWS and other cloud environments should also be reviewed for exposed services, excessive permissions and configuration drift.

3. Endpoint protection

Inventory workstations and servers and verify supported operating systems, endpoint detection, disk encryption and patching. Identify devices that have stopped reporting to management or security tools and establish a process for lost or stolen equipment.

4. Email and phishing protection

Assess anti-phishing controls, impersonation protection, SPF, DKIM and DMARC, malicious attachment and URL protection, external sender warnings and employee reporting procedures. Security awareness should reinforce technical controls rather than replace them.

5. Vulnerability and patch management

Determine how critical operating-system and third-party vulnerabilities are identified, prioritized and remediated. Internet-facing systems deserve special attention. Recurring vulnerability scanning should produce accountable remediation work, not just recurring reports.

6. Backups and ransomware resilience

Confirm what is backed up, frequency, retention and whether attackers who compromise production credentials can also delete backup copies. Test restoration instead of relying only on successful job notifications. Important systems should have documented recovery priorities.

7. Network security

Review firewall configuration, remote access, exposed ports, wireless security, segmentation and administrative interfaces. Remove obsolete rules and ensure useful logging is available for investigation. Sensitive systems should not be unnecessarily reachable from ordinary user networks.

8. Monitoring and detection

Determine who reviews security alerts, what happens outside normal business hours and how incidents are escalated. Important signals can include endpoint detections, suspicious authentication, privilege changes, unusual mailbox activity and firewall events.

9. Incident response

Verify who makes decisions during a cyber incident, how systems can be isolated, how legal and privacy obligations are evaluated, how leadership is contacted and how evidence is preserved. A tabletop exercise can reveal gaps that written policies do not.

10. Privacy and third-party risk

Identify where sensitive personal and business information is stored, who can access it and which vendors process it. Canadian organizations should align cybersecurity controls with applicable privacy and contractual obligations. Vendor access should be limited, reviewed and removed when no longer needed.

11. Security ownership and documentation

For each major control, identify who owns configuration, monitoring, remediation and escalation. Document important systems, vendors and security dependencies. Controls that exist without an accountable owner often degrade over time.

How to score the assessment

For each control, record verified, partially implemented, missing or unknown. Unknown should be treated as a finding until evidence is available. Then prioritize issues using exposure, likelihood, business impact and the effort required to reduce the risk.

What evidence should an assessment collect?

What should the final report contain?

A useful cybersecurity assessment should give leadership an executive summary, prioritized findings, supporting evidence, business impact, recommended remediation, an accountable owner and a target timeline. Separate urgent exposure from longer-term maturity improvements so the organization knows what to address first.

Assessment vs vulnerability scan

A vulnerability scan is one input. A broader cybersecurity assessment also examines identity, cloud configuration, backups, email, monitoring, response capability, governance and operational ownership. See our vulnerability assessment vs penetration testing guide for another useful distinction.

Need an independent view of your security gaps?

The Cyber Arm can review your current controls and turn findings into a prioritized remediation roadmap.

Book a Cybersecurity Gap Assessment

Related resources

Vulnerability Assessment · PIPEDA Compliance · Microsoft 365 Security Baseline · EDR vs MDR