The 12 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
Identity & access
-
Is MFA turned on for email and your most important accounts?
Turn on MFA everywhere you can, starting with email and admin accounts. It is the single highest-value control for a young business.
-
Do you use a password manager instead of reused or shared passwords?
Roll out a password manager so the team uses strong, unique passwords instead of reusing or sharing them.
-
When someone joins or leaves, is there a clear way to grant and remove their access?
Decide now how access is granted and removed as people join and leave, before it becomes a tangle of leftover logins.
Devices
-
Are work laptops and phones encrypted and kept up to date?
Enable disk encryption (BitLocker or FileVault) and automatic updates on every device, so a lost laptop is not a data breach.
-
Does every device run reputable, centrally visible security software?
Put reputable endpoint protection on all devices and make sure someone can see its status, not just the built-in defaults.
Data & backup
-
Is your important data backed up automatically, with a copy you could recover after a disaster?
Automate backups of anything you cannot afford to lose, keep a copy off-site or in the cloud, and test that you can restore it.
-
Do you know where your company data actually lives, across apps and accounts?
List where your data lives, the SaaS apps and accounts, so it is controlled and recoverable, not scattered and forgotten.
Email & web
-
Have you set up basic email security so others cannot easily spoof your domain?
Set up SPF, DKIM and DMARC for your domain. The SPF and DMARC generator builds the records for you.
-
Has the team had a quick primer on phishing and what not to click?
Give the team a short phishing primer; most attacks on small businesses start with one convincing email.
Foundations & ownership
-
Is it clear who owns IT decisions, internally or a provider, so they do not fall through the cracks?
Decide who owns IT, an internal lead or a provider, so decisions get made and nothing critical is left to chance.
-
Do you have a couple of basic written policies (acceptable use, passwords) that staff have seen?
Write a couple of simple policies (acceptable use, passwords) so expectations are clear as you hire.
-
Are you choosing tools and setup with growth in mind, not just the cheapest quick fix?
Pick core tools (identity, email, devices) with where you are going in mind; foundations are cheap to set right early and costly to redo.
Build the foundations once, scale on them for years
The IT and security choices you make early either compound in your favour or become expensive to unwind. We help founders and early-stage Canadian businesses set up identity, devices, backup and email security the right way from day one, so you get a foundation that scales with you instead of a mess to clean up later.