The 14 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
Accounts & access
-
Is multi-factor authentication (MFA) turned on for email, and for every other account that supports it?
Turn on MFA everywhere you can, starting with email and admin logins. It blocks the large majority of account-takeover attacks.
-
Are admin rights limited to the few people who need them, with staff using standard (non-admin) accounts day to day?
Give everyday work standard accounts and keep separate admin logins for when they are actually needed. It contains the damage if one account is compromised.
-
When someone leaves the business, are all their accounts and access removed the same day?
Build a simple leaver checklist so accounts, email and remote access are disabled the moment someone departs.
Devices & patching
-
Are operating systems and key software set to update automatically, and devices replaced before they stop getting security updates?
Enable automatic updates and plan to replace devices before end-of-support (for example Windows 10). Unpatched software is the most common way in.
-
Does every computer run reputable, centrally-managed endpoint protection (not just the built-in default)?
Deploy managed endpoint protection on every device so threats are caught and visible in one place, not left to each user.
-
Are laptops and phones encrypted (BitLocker, FileVault or device encryption) so a lost device does not leak data?
Switch on full-disk encryption everywhere. It turns a lost or stolen laptop from a data breach into just a lost laptop.
Data & backup
-
Is your important data backed up automatically, with at least one copy kept off-site or in the cloud?
Set up automatic backups following the 3-2-1 rule: three copies, two types of media, one off-site. It is your last line of defence against ransomware.
-
Have you actually tested restoring from a backup in the last 12 months?
Schedule a restore test at least once a year. A backup you have never restored is a hope, not a safety net.
Email & web
-
Have you set up SPF, DKIM and DMARC so attackers cannot easily send email pretending to be your domain?
Publish SPF, DKIM and DMARC. Our Email Security Checker shows exactly what is missing for your domain.
-
Do you have email filtering or anti-phishing protection beyond the mailbox default?
Add a layer of email security filtering to catch phishing, spoofing and malicious attachments before they reach inboxes.
People & process
-
Does your team get regular (at least yearly) security-awareness or phishing training?
Run short, regular awareness and phishing training. Your team is the most-targeted control, and the cheapest one to strengthen.
-
Does your team use a password manager with unique passwords (no reuse, no shared spreadsheets)?
Roll out a password manager so everyone uses long, unique passwords without reusing or sharing them.
-
Do you have a written plan for what to do if you are breached or hit by ransomware (who to call, what steps to take)?
Write a simple incident plan now: who to call, how to isolate systems, how to recover. Decide it in calm, not mid-crisis.
-
Do you know which outside vendors can reach your systems or data, and do you carry cyber insurance?
List who can access your systems and review cyber insurance. Both limit how bad it gets when something goes wrong.
A score is a starting point, not a plan
Knowing where you stand is the easy part. Closing the gaps, in the right order, without grinding your team to a halt, is the work. That is exactly what we do for small Canadian businesses: turn a list like the one above into a practical, prioritised roadmap, then run it for you as one team you can actually call.