Fusion Computing Limited Logo

Free cybersecurity self-check · Canada

Cybersecurity Assessment

Start with a free 10-question self-check across identity, endpoints, email, backup and detection. Your score reflects your answers, without inspecting your systems. See the score first; email is optional for the detailed self-check report.

Need evidence for an insurer, audit or investment decision? The CISSP-led 168-point assessment is a paid engagement. A free 30-minute discovery call helps us agree the scope before quoting the work.

For Canadian businesses with 10 to 150 employees, run from our Toronto, Hamilton, and Vancouver offices. Typically $2,500 to $6,500; we aim to reply within one business day.

Or go straight to the booking form

Reviewed September 15, 2026 by Mike Pearlstein, CISSP. 500+ Canadian SMBs secured since 2012.

5 steps · quick to finishNo email until you see the number
1 / 5 · Your business

Tell us about your business

Two quick questions to size your report. Not scored.

How many employees?
What brings you here?

The next step

Need a report built for insurer and auditor review?

Only your own answers drive the self-check score. The paid 168-point assessment inspects the environment and delivers a written report with risk scores, evidence, and a 30/60/90-day roadmap. Typically $2,500 to $6,500, with the scope and fee agreed in writing before any work begins.

The 30-minute discovery call is free. We aim to reply within one business day.

Why teams trust the Fusion assessment

  • 50 Best Managed IT

    Named two years running, 2024 and 2025

  • 4.9 on Google

    93% first-contact resolution

  • 500+ Canadian SMBs

    Secured since 2012

  • CISSP-led

    Mapped to CIS Controls v8.1 and CCCS

What it is

What a cybersecurity assessment covers

A cybersecurity assessment is a structured, evidence-based review of how well your controls actually protect the business, scored against CIS Controls v8.1 and the Canadian Centre for Cyber Security (CCCS) baseline. It looks at identity, endpoints, email, network, backup, and compliance together, the way an attacker, an auditor, or an insurer does, rather than one system at a time.

It is not the same as a vulnerability scan. A vulnerability scan points an automated tool at your network and lists missing patches and open ports. A cybersecurity assessment includes that scan, then adds the human review a scanner cannot do. It checks whether your backups are actually immutable and restore-tested, and whether MFA is enforced everywhere it matters. It also finds who owns the dozen stale Microsoft 365 accounts nobody has signed into in a year. The scan tells you what is unpatched; the assessment tells you what is exploitable.

Most teams book a cybersecurity assessment for one of two reasons: an insurer, auditor, or board is asking for documented proof the controls work, or they want an independent baseline before betting the next decision on instinct.

Scope the work

What does a cybersecurity assessment cost?

Tell us how many users and endpoints you run and the deadline behind the request. We confirm the fixed fee in writing before the assessment starts, and the completed report is yours to keep.

What we review

168 checkpoints across six domains

A full evaluation of your security posture, written for decision-makers as well as technicians.

  • Identity & access

    Multi-factor authentication (MFA) coverage, Microsoft Entra ID hygiene, Conditional Access, and the orphaned or over-privileged accounts an attacker enumerates first.

  • Endpoints

    Endpoint detection and response (EDR) coverage, BitLocker, patch lag against CIS v8.1, and unmanaged devices that never report to monitoring.

  • Email & phishing

    Email authentication (DMARC, DKIM and SPF), impersonation protection, and Microsoft Purview sensitivity labels with the sharing and encryption settings behind them.

  • Network & firewall

    Firewall rulesets, segmentation, VPN posture, and the exposed RDP or edge services that show up on an external scan.

  • Backup & recovery

    Immutability, restore testing, and air-gapping, the controls that decide whether ransomware is a bad day or a business-ending one.

  • Compliance & CIS

    A CIS Controls v8.1 and CCCS baseline gap analysis mapped to PIPEDA, PHIPA, SOC 2, and the evidence insurers ask for at renewal.

The deliverable

A board-readable report in about two weeks

You get a written report with risk scores, a vulnerability scan, and a list of fixes ranked by real risk. It is built for decision-makers, and it is yours to act on with any provider.

Every finding is mapped to CIS Controls v8.1 and the CCCS baseline, so the report reads in the language an auditor, an insurer, or an incoming security lead already knows.

Why it matters now

The evidence Canadian SMBs are missing

  • IBM Cost of a Data Breach, 2025

    CA$6.98M average Canadian breach

    Fusion Computing's 168-point assessment documents your controls against CIS Controls v8.1 and the CCCS baseline, then confirms at scoping what your own insurer or regulator asks for.

    Read more
  • CIRA Cybersecurity Survey, 2025

    24% hit by ransomware

    Among surveyed Canadian organizations with at least 50 employees, 24% reported ransomware in the previous 12 months. Bring your insurer’s evidence requirements to the scoping call.

    Read more
  • Statistics Canada, 2023 data

    59% identify cyber risk

    In 2023, 59% of Canadian businesses with at least 10 employees reported activities to identify cybersecurity risks.

    Read more
  • Canadian Centre for Cyber Security

    CCCS baseline controls

    Fusion Computing scores the CCCS baseline line by line, the control set the Cyber Centre recommends for small and medium organizations.

    Read more

Who it is for

You do not need to be in crisis

Most teams that book an assessment share one of these four situations.

  • Post-incident

    You had a breach, ransomware scare, or near-miss and need to know what is still exposed.

  • Compliance-driven

    An auditor, insurer, or board wants documented proof your controls are actually in place.

  • Switching providers

    You are leaving your current MSP and want an independent baseline before onboarding anyone new.

  • Insurance renewal

    Your cyber-insurance renewal requires a current assessment or risk evaluation, on a deadline.

How it works

From free discovery to a paid assessment

The 30-minute discovery call is free. Assessment scope and price are agreed in writing before work begins; the completed report is yours to keep.

  • 1. Free 30-minute discovery

    Tell us about your environment and the decision, insurer or audit requirement behind the request. We confirm the information needed to scope the work.

  • 2. Paid 168-point review

    After you approve the scope and fee, our CISSP-led team reviews endpoints, identity, email, backup, network, and compliance against CIS Controls v8.1.

  • 3. Written report in ~2 weeks

    Findings ranked by risk with a prioritized remediation roadmap. The report is yours to act on with any provider.

What our clients say

  • The assessment found an admin account with domain-level rights that hadn’t been used in four years but was still active. One phishing email away from a full breach. We never would have caught that on our own.

    MS

    Mark S.

    CFO, Professional services firm, Ontario

    168-point cybersecurity assessment client

  • I called Fusion in a panic at 9pm on a Friday. By Monday morning our team walked in and got back to work like nothing happened. Every in-scope file recovered. No ransom paid.

    CC

    Client CEO

    Industrial supply company, Ontario

    Ransomware incident response client

Mike Pearlstein, CISSP, founder and security lead at Fusion Computing

CISSP-led leadership

Mike Pearlstein, CISSP, Founder of Fusion Computing

Mike has led security assessments for Canadian businesses since 2012. “The moment that always lands is the identity-attack-surface map. Most SMBs we assess are running dozens of stale Microsoft 365 accounts with active auto-forward rules and no MFA on a few service accounts. None of it shows on a firewall report, but it is the first thing an attacker, examiner, or insurer asks to see.”

CISSPSince 2012CIS Controls v8.1CCCS baseline

Frequently asked questions

A cybersecurity assessment, also called a security audit or a cyber risk assessment, is a structured, evidence-based review of how well your security controls actually protect the business, scored against CIS Controls v8.1 and the CCCS baseline. It examines identity, endpoints, email, network, backup, and compliance together, then delivers risk scores and a prioritized remediation roadmap an insurer or auditor can act on.

Fusion's 168-point cybersecurity assessment is a paid, fixed-fee engagement, typically $2,500 to $6,500 CAD depending on environment size and scope. The 30-minute scoping consultation is free, pricing is confirmed in writing before any work begins, and there is no obligation to engage Fusion for remediation afterward.

The IT assessment asks whether your technology works and what it would cost to run properly. It covers service management against ITIL 4 practice areas, plus assets, vendors, contracts and spend, with CIS Controls IG1 as a security floor. It starts at $3,000. The cybersecurity assessment asks whether you are safe, going control-by-control against CIS Controls v8.1 and the CCCS baseline with evidence collection, vulnerability scanning, and an insurer-ready report. Commission the IT assessment when the question is operations, cost or sourcing; commission this one when the question is security, insurance or an audit.

The initial session is about two hours, and you receive a written report in about two weeks. For larger environments (100+ endpoints) the timeline can extend a little.

A 168-point evaluation across endpoints, identity, email, backup, network, and compliance, with risk scores, a CIS Controls v8.1 gap analysis, and a prioritized remediation roadmap.

Yes. We need read-level access to review configurations, policies, and logs. It is a structured intake with a signed NDA and a defined scope before anything begins.

Yes. We map findings to PIPEDA, Ontario PHIPA for healthcare, CyberSecure Canada, and, for federally regulated operators, the incident-reporting obligations.

No. The free 10-question self-check produces a score from your answers and does not inspect your systems. The paid 168-point assessment is a separately scoped, CISSP-led review with evidence collection and a written report. A free 30-minute discovery call helps establish the scope and information needed for a quote.

Request scoping

Book your free 30-minute discovery call

Send the size of your environment, the insurance, audit, or board requirement behind the request, and the date you need the report by. A senior consultant aims to reply within one business day.

The 168-point assessment is a paid, fixed-fee engagement, typically $2,500 to $6,500 CAD depending on environment size and scope. Pricing is confirmed in writing before any work begins, and there is no obligation to engage Fusion for the remediation afterward.

  • CISSP-led review against CIS Controls v8.1 and the CCCS baseline
  • Written report in about two weeks, with a 30/60/90-day roadmap
  • A signed NDA and an agreed scope before anything begins
  • No obligation to engage Fusion for the remediation afterward

Prefer to talk it through?(416) 566-2845

Book your free 30-minute discovery call

Tell us about the environment and the deadline. We aim to reply within one business day.

By submitting this form, you consent to Fusion Computing contacting you. We won’t share your information.

Find out where you are exposed

Request a free 30-minute discovery call to discuss your security requirements. The paid assessment begins after you approve its scope and fee; the completed report is yours to keep.