Cybersecurity Blog / Risk Assessment
Cybersecurity Assessment Checklist for Canadian Businesses
A cybersecurity assessment should answer a practical question: where could a realistic attack cause meaningful business damage, and are the current controls strong enough? The result should be evidence, prioritized findings and a remediation roadmap, not simply a long vulnerability list.
1. Identity and access
Confirm that multi-factor authentication is enforced for privileged accounts, remote access and cloud services. Review inactive accounts, shared credentials, administrator privileges, Conditional Access, password policies and the process for immediately disabling access when an employee leaves.
2. Microsoft 365 and cloud security
Review tenant security settings rather than assuming Microsoft 365 is secure by default. Examine MFA coverage, legacy authentication, risky sign-ins, administrator roles, external sharing, mailbox forwarding rules, audit logging and recovery procedures. Azure, AWS and other cloud environments should also be reviewed for exposed services, excessive permissions and configuration drift.
3. Endpoint protection
Inventory workstations and servers and verify supported operating systems, endpoint detection, disk encryption and patching. Identify devices that have stopped reporting to management or security tools and establish a process for lost or stolen equipment.
4. Email and phishing protection
Assess anti-phishing controls, impersonation protection, SPF, DKIM and DMARC, malicious attachment and URL protection, external sender warnings and employee reporting procedures. Security awareness should reinforce technical controls rather than replace them.
5. Vulnerability and patch management
Determine how critical operating-system and third-party vulnerabilities are identified, prioritized and remediated. Internet-facing systems deserve special attention. Recurring vulnerability scanning should produce accountable remediation work, not just recurring reports.
6. Backups and ransomware resilience
Confirm what is backed up, frequency, retention and whether attackers who compromise production credentials can also delete backup copies. Test restoration instead of relying only on successful job notifications. Important systems should have documented recovery priorities.
7. Network security
Review firewall configuration, remote access, exposed ports, wireless security, segmentation and administrative interfaces. Remove obsolete rules and ensure useful logging is available for investigation. Sensitive systems should not be unnecessarily reachable from ordinary user networks.
8. Monitoring and detection
Determine who reviews security alerts, what happens outside normal business hours and how incidents are escalated. Important signals can include endpoint detections, suspicious authentication, privilege changes, unusual mailbox activity and firewall events.
9. Incident response
Verify who makes decisions during a cyber incident, how systems can be isolated, how legal and privacy obligations are evaluated, how leadership is contacted and how evidence is preserved. A tabletop exercise can reveal gaps that written policies do not.
10. Privacy and third-party risk
Identify where sensitive personal and business information is stored, who can access it and which vendors process it. Canadian organizations should align cybersecurity controls with applicable privacy and contractual obligations. Vendor access should be limited, reviewed and removed when no longer needed.
11. Security ownership and documentation
For each major control, identify who owns configuration, monitoring, remediation and escalation. Document important systems, vendors and security dependencies. Controls that exist without an accountable owner often degrade over time.
How to score the assessment
For each control, record verified, partially implemented, missing or unknown. Unknown should be treated as a finding until evidence is available. Then prioritize issues using exposure, likelihood, business impact and the effort required to reduce the risk.
What evidence should an assessment collect?
- Identity and administrator-role configuration
- MFA and access-control coverage
- Endpoint and security-agent inventory
- Patch and vulnerability status
- Backup configuration and restore-test evidence
- Email security and domain-authentication settings
- Firewall, remote-access and exposed-service review
- Monitoring and escalation responsibilities
- Incident-response procedures
- Critical vendor and third-party access
What should the final report contain?
A useful cybersecurity assessment should give leadership an executive summary, prioritized findings, supporting evidence, business impact, recommended remediation, an accountable owner and a target timeline. Separate urgent exposure from longer-term maturity improvements so the organization knows what to address first.
Assessment vs vulnerability scan
A vulnerability scan is one input. A broader cybersecurity assessment also examines identity, cloud configuration, backups, email, monitoring, response capability, governance and operational ownership. See our vulnerability assessment vs penetration testing guide for another useful distinction.
Need an independent view of your security gaps?
The Cyber Arm can review your current controls and turn findings into a prioritized remediation roadmap.
Related resources
Vulnerability Assessment · PIPEDA Compliance · Microsoft 365 Security Baseline · EDR vs MDR