Cybersecurity Assessment Checklist for Canadian SMBs

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

A cybersecurity assessment checklist for a Canadian SMB is a control-by-control review that proves protections are enforced, owned and recoverable. The point is not a binder. The point is producing evidence that the basics hold before a cyber insurer, a procurement reviewer, or a ransomware operator finds the gap first.

Book Your Free IT Business Consultation

What is a cybersecurity assessment, and why every Canadian SMB needs one

According to Statistics Canada (2024), 16% of Canadian businesses were impacted by cyber security incidents in 2023, and large businesses were hit hardest at 30%. A cybersecurity assessment checklist is how a smaller organization proves its own controls hold before an insurer or a procurement reviewer asks.

Copilot section of the checklist: if your tenant is licensing Copilot, add the Pre-Copilot SharePoint Audit to the assessment scope before deployment.

A cybersecurity assessment maps each control to evidence that proves it is live, current and assigned. It scales for Canadian businesses between 10 and 200 users, and aligns with the Canadian Centre for Cyber Security baseline controls, CIS Controls v8.1 IG1, and NIST CSF 2.0.

The Verizon 2026 Data Breach Investigations Report puts vulnerability exploitation at 31% of breaches, ahead of stolen credentials at 13%, reversing the order the 2025 edition reported. In our practice, Canadian cyber insurers now ask for documented MFA, endpoint detection and tested backups at quote and at renewal.

The deliverable is a working tool rather than a policy artifact. Each of the 8 category rows asks one question: can this control be proven right now. If the answer requires a meeting, the control is weaker than the policy claims. See our cybersecurity services for the managed version.

The 8 categories of the FC assessment checklist

According to the Canadian Centre for Cyber Security (2022), its Baseline Cyber Security Controls set 13 controls scoped by OC.1 to organizations under 499 employees, spanning incident response, patching, authentication, backup and access control. The 8 FC categories below group those 13 controls into the order a Canadian SMB can evidence them.

The FC checklist organizes controls into 8 categories. Each pairs a category goal with the pass criteria a Canadian SMB should be able to evidence on demand.

Category Control Focus Pass Criteria Primary Tool
1. Identity and access MFA, PAM, conditional access, offboarding 100% MFA, named admins, conditional access enforced Microsoft Entra ID
2. Endpoint and EDR EDR coverage, patch state, disk encryption 100% device coverage, 14-day patch SLA, BitLocker on Microsoft Defender XDR
3. Email security Phishing defence, DMARC, banner rules, training DMARC enforced, quarterly simulation under 10% click Microsoft Defender for Office 365
4. Backup and DR Immutable backup, restore tests, RTO and RPO Immutable copy, 90-day restore test, RTO documented Immutable backup platform with object lock
5. Data protection Classification, DLP, encryption at rest and in transit Sensitive data labelled, DLP active, TLS enforced Microsoft Purview
6. Detection and response SIEM, alert routing, dwell-time monitoring 90-day log retention, 24×7 alert routing Microsoft Sentinel
7. Policies and IR plan Acceptable use, IR runbook, tabletop exercise IR plan signed, tabletop run inside 12 months Managed policy and patch platform
8. Compliance posture PIPEDA, Bill C-8, OSFI E-21, vendor risk Breach playbook current, vendor register live Microsoft Purview Compliance Manager

The 8 categories are scored independently, then summed into a composite. Identity, endpoint and backup carry the heaviest risk weight, since a failure in any one usually decides whether an incident is a recoverable inconvenience or a board-level event.

Identity and access (MFA, PAM, conditional access)

According to Microsoft Research (2023), multifactor authentication reduced the risk of account compromise by 99.22% across the full population studied, and by 98.56% among accounts whose credentials had already leaked. Identity is the first category on the FC checklist for that reason, and the pass bar is coverage you can prove rather than coverage you assume.

Coverage is where most first assessments fail. An SMB that cannot produce a report showing 100% MFA coverage with conditional access enforced has a control that exists on paper. We measured this across recent scoping engagements: the gap is almost always service accounts and legacy authentication rather than user accounts.

Pass criteria are concrete. Every account, including service accounts and break-glass admins, needs MFA with no legacy bypass. Privileged access uses named admin identities in Microsoft Entra ID with just-in-time elevation. Conditional access blocks risky sign-ins. Offboarding revokes access on day one, verified with a sampled three-user audit.

Endpoint and EDR coverage

According to CIS Controls v8.1 (2024), Control 10 requires anti-malware software to be centrally managed and automatically updated on every enterprise asset. Every active device, including BYOD laptops holding corporate data and any on-prem server, must run an EDR agent reporting into a managed console. A spreadsheet of installed agents is not coverage.

A live console at 100% of inventoried assets with current signatures is coverage. Fusion Computing deploys Microsoft Defender XDR for Microsoft-aligned tenants and a third-party endpoint detection platform where Linux density argues for it. Patch state flows through a managed remote monitoring platform with a 14-day SLA on critical CVEs and 30 days on high severity.

BitLocker stays enforced on every Windows endpoint, FileVault on Mac, with recovery keys escrowed in Entra ID. If a key cannot be produced during the assessment, the control scores Fail.

Email security and phishing defence

According to the Canadian Centre for Cyber Security (2024), ransomware is the top cybercrime threat facing Canada’s critical infrastructure. Smaller Canadian organizations sit inside the same criminal supply chain. The pass bar for this category starts at DMARC enforcement on every sending domain, with SPF and DKIM aligned and external sender banners on.

Microsoft Defender for Office 365 handles attachment detonation, URL rewriting and impersonation protection, with quarantine reviewed weekly. Awareness training sits in the same category: quarterly phishing simulations on a published cadence, with completion tracked and a rolling click rate trending under 10% inside 12 months.

A program that lives only in the policy folder fails this control. Ask for the last Defender simulation report before scoring above Partial.

Backup and disaster recovery

According to the CCCS baseline controls (2022), an organization should back up and encrypt its data and then test the restore. Backups are graded here on three things: immutability, recovery testing and documented objectives. Immutable copies, ideally air-gapped or object-locked, defeat the operator playbook of encrypting the backup tier first.

Fusion Computing runs an immutable backup platform paired with object-lock storage and a retention policy that survives an admin compromise. Restore tests happen at least every 90 days on the workloads that matter most, with the recovery time observed and recorded.

RTO and RPO must be written down for the top 5 workloads, tied to specific systems and signed off by the business owner. A backup job report alone is no evidence of recoverability.

Documented policies and IR plan

According to CIS Controls v8.1 (2024), Control 17 requires designated personnel and a documented incident-handling process. Policies and the IR plan are scored together because they share one failure mode: the document exists, nobody has rehearsed it, and the named owner left two roles ago.

The pass bar is 3 documents: a current acceptable use policy, a data-handling policy, and an IR runbook naming primary and secondary responders, the insurer contact and legal counsel.

A tabletop exercise inside the last 12 months is non-negotiable, and it does not need to be elaborate. A 90-minute walk-through of a ransomware scenario with the IR plan open is enough to surface stale phone numbers, missing approvals and unclear authority.

Run the FC Consultation on Your Stack

Compliance posture (PIPEDA / Bill C-8 / OSFI E-21)

According to PIPEDA (2000) section 10.1, a breach report goes to the Privacy Commissioner as soon as feasible, and the statute sets no 72-hour clock. Compliance is the eighth category because compliance follows controls. Once identity, endpoint, backup and IR are evidenced, mapping into PIPEDA and OSFI E-21 becomes bookkeeping.

The pass bar is a current breach playbook with PIPEDA notification timelines, a live vendor register recording time-bound third-party access, and a written record of how each statutory obligation maps to a tested control.

For federally regulated entities, OSFI Guideline E-21 expects documented operational resilience, third-party risk management and tested recovery. For most other Canadian SMBs, PIPEDA breach-of-security-safeguards reporting and the Bill C-8 obligations on critical cyber systems set the floor. See PIPEDA compliance for small business in Canada for the reporting workflow.

The 6-step assessment workflow FC runs

Fusion Computing runs every assessment through the same 6-step workflow, two weeks from kickoff to remediation roadmap, with a CISSP leading scoping and report sign-off. In our experience the slow step is evidence collection, so the scope memo names an owner per category before anything else starts.

Step What Happens Output
1. Scope Confirm entities, sites, regulated data, and evidence owners Signed scope memo, named owner per category
2. Evidence pull Collect Entra ID, Defender, endpoint management, backup and Purview exports Evidence folder timestamped at intake
3. Control test Validate each control against pass criteria, sample three users per identity row Per-control test notes with screenshots
4. Scoring Score Pass, Partial, Fail per control; weight by category risk Composite score with category heatmap
5. Report CISSP review, executive summary, mapped findings to PIPEDA, Bill C-8, OSFI E-21 Signed assessment report
6. Roadmap Remediation grouped 30-day, 90-day, 6-to-12-month with named owners Sequenced roadmap, insurer-ready evidence pack

Common assessment mistakes, and how to choose what to fix first

Treating policies as evidence is the largest. A signed acceptable use policy is no proof that MFA is enforced on 100% of accounts, that backups restore, or that EDR sits on every device. Reviewers want the live console.

Skipping the restore test is the second. A green job report shows the job ran and says nothing about recoverability. The third is mistaking compliance mapping for control work, where teams colour-code PIPEDA clauses without testing whether a privileged session opens without MFA.

Choose what to fix first by category weight. Anything scoring Fail in identity, endpoint or backup goes in the 30-day tier, because those three decide the blast radius. Everything else can wait for the 90-day tier. Ask us to sanity-check your first roadmap if the ordering is contested internally.

FAQ

According to the CCCS baseline controls (2022), the 13 baseline controls are aimed at organizations under 499 employees. These are the questions Canadian SMBs in that band ask us most often before booking an assessment.

What is a cybersecurity assessment checklist for Canadian SMBs?

It is a structured review that pairs each control with collected evidence and a named owner, scaled for organizations between 10 and 200 users. The 2026 FC checklist covers 8 categories and maps directly to Canadian Centre for Cyber Security baseline controls, CIS Controls v8.1 IG1, and NIST CSF 2.0.

How often should a Canadian SMB run the assessment?

Run a lightweight pass each quarter and a full assessment every 12 months, plus a fresh review after any infrastructure change, insurance renewal, M&A event, or security incident. Annual cadence is the floor most insurers and procurement reviewers expect.

Which framework should the checklist map to?

Use NIST CSF 2.0 for the function-level structure, CIS Controls v8.1 IG1 for the technical control set, and Canadian Centre for Cyber Security baseline controls for Canada-specific obligations. The three overlap by design and align with PIPEDA, Bill C-8, and OSFI E-21.

What evidence proves a control is real?

A recent dashboard export, configuration screenshot, log sample, signed policy, restore test result, or training completion report. A control without recent evidence scores Partial at best, whatever the policy claims, and Fail if the evidence cannot be produced inside 10 minutes.

How does the FC checklist handle PIPEDA and Bill C-8?

Compliance is the eighth category. Once identity, endpoint, backup and IR controls are evidenced, the FC report maps each finding back to PIPEDA breach-of-security-safeguards obligations, Bill C-8 critical cyber system requirements where applicable, and OSFI E-21 for federally regulated entities.

Does PIPEDA give me 72 hours to report a breach?

No. PIPEDA section 10.1 requires a report to the Privacy Commissioner as soon as feasible after the organization determines a breach creating a real risk of significant harm has occurred, with no fixed 72-hour clock in the statute. Records of every breach must be kept for 24 months. Contractual and insurer deadlines are often tighter than the law.

Who should run the assessment internally?

An IT lead, operations manager, or owner with administrative access can complete the first pass. If the business is regulated, multi-site, preparing for cyber insurance renewal, or unable to produce evidence in a working day, a CISSP-led external assessor is the better path.

What tools support the controls in the FC checklist?

The stack pairs Microsoft Entra ID for identity, Microsoft Defender XDR for endpoint, Microsoft Purview for data protection and DLP, and Microsoft Sentinel for SIEM and detection. Patch hygiene and immutable backup run on managed platforms selected per tenant. The checklist scores the control, not the brand, so an equivalent product passes on equivalent evidence.

What is the difference between a checklist and a full assessment?

A checklist is a control-by-control proof exercise an internal team can complete. A full assessment adds independent testing, control-design review and a sequenced remediation roadmap, with a CISSP signing the report. The 2-week FC workflow above describes that deeper version.

What does a good remediation roadmap look like?

A short list with three columns: finding, named owner, target date. Group items into 30-day, 90-day, and 6-to-12-month tiers by composite score and category weight. Anything Fail in identity, endpoint, or backup goes in the 30-day tier with weekly status reporting.

How long does an assessment take, and what does it cost?

Two weeks from kickoff to remediation roadmap for a 10 to 200 user Canadian business, assuming evidence owners respond inside 48 hours. Pricing is quoted per engagement after scoping. Ongoing managed cybersecurity that keeps the controls live runs CA$130 to CA$180 per user per month depending on regulatory scope.

Will the report satisfy our cyber insurance renewal questionnaire?

That is what the evidence pack is for. The report maps each scored control to the questions Canadian cyber insurers ask at renewal: MFA enforcement, endpoint detection coverage, immutable backup, privileged access and the written IR plan. Brokers submit the pack directly instead of chasing screenshots.

Related Resources

The pages below cover the packages, the pillar service and the privacy workflow that sit around this checklist.

A checklist tells you what to look at. If you need the scored artefact an underwriter reads, work through how to conduct a cybersecurity risk assessment and build the register instead.

Ready for your cybersecurity assessment?

Tell us about your environment and compliance pressure. Mike Pearlstein, CISSP, or a senior engineer responds within one business day with a scoping call and a fixed-price quote.

Start the Conversation

Most clients are 10 to 150 employees. Tell us about your situation.

  • Reply in 1 business day
  • Senior engineer, not sales
  • No obligation
Or
Schedule a free call →
Senior team follows up within 1 business day

By submitting this form, you consent to Fusion Computing contacting you. We do not sell your information. We use service providers to operate the form and our communications. See our Privacy Policy.

Or call us directly: (416) 566-2845

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 10 to 150 employees across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611