The Cyber Arm Security · Cybersecurity for Canadian Businesses

Cybersecurity Blog / Risk Assessment

Cybersecurity Assessment Checklist for Canadian Businesses

A cybersecurity assessment should answer a simple question: where could a realistic attack cause meaningful business damage, and are the current controls strong enough? This checklist gives Canadian small and mid-sized organizations a practical starting point.

1. Identity and access

Confirm that multi-factor authentication is enforced for privileged accounts, remote access and cloud services. Review inactive accounts, shared credentials, administrator privileges, conditional access, password policies and the process for immediately disabling access when an employee leaves.

2. Microsoft 365 and cloud security

Review tenant security settings rather than assuming Microsoft 365 is secure by default. Examine MFA coverage, legacy authentication, risky sign-ins, administrator roles, external sharing, mailbox forwarding rules, audit logging and recovery procedures. Organizations using Azure, AWS or other cloud platforms should also review exposed services, excessive permissions and configuration drift.

3. Endpoint protection

Inventory workstations and servers and verify that supported operating systems, endpoint detection, disk encryption and patching are consistently deployed. Identify devices that have stopped reporting to management tools and establish a process for lost or stolen equipment.

4. Email and phishing protection

Email remains a major entry point for account compromise and fraud. Assess anti-phishing controls, impersonation protection, SPF, DKIM and DMARC, malicious attachment and URL protection, external sender warnings and employee reporting procedures. Security awareness should reinforce technical controls rather than replace them.

5. Vulnerability and patch management

Determine how quickly critical operating-system and third-party software vulnerabilities are identified, prioritized and remediated. Internet-facing systems deserve special attention. Vulnerability scanning should be recurring, with ownership and deadlines assigned to remediation.

6. Backups and ransomware resilience

Confirm what is backed up, how frequently, how long copies are retained and whether attackers who compromise production credentials can also delete backups. Test restoration rather than relying only on successful backup-job notifications. Important systems should have documented recovery priorities and recovery procedures.

7. Network security

Review firewall configuration, remote access, exposed ports, wireless security, segmentation and administrative interfaces. Remove obsolete rules and ensure logging is available for investigation. Sensitive systems should not be unnecessarily reachable from ordinary user networks.

8. Monitoring and detection

Determine who watches security alerts and what happens outside normal business hours. Important signals can include endpoint detections, suspicious authentication, privilege changes, unusual mailbox activity and firewall events. A documented escalation path is essential.

9. Incident response

Your organization should know who makes decisions during a cyber incident, how systems can be isolated, how legal/privacy obligations are evaluated, how leadership is contacted and how evidence is preserved. Tabletop exercises help reveal gaps before a real incident.

10. Privacy and third-party risk

Identify where sensitive personal and business information is stored, who can access it and which vendors process it. Canadian organizations should align cybersecurity controls with applicable privacy and contractual obligations. Vendor access should be limited, reviewed and removed when no longer needed.

How to score the assessment

For every control, record: implemented and verified; partially implemented; missing; or unknown. “Unknown” is itself a finding. Prioritize issues based on business impact, exposure and likelihood rather than trying to fix every technical weakness at once.

What should happen next?

Turn findings into a remediation roadmap with an owner, priority and target date. Start with weaknesses that could enable account takeover, ransomware, data theft or prolonged downtime. Reassess regularly as technology, staff and threats change.

Request The Cyber Arm cybersecurity gap assessment →

Related resources

Vulnerability Assessment · PIPEDA Compliance · Microsoft 365 Security Baseline · MDR vs SIEM vs SOC