What's Your Security Score?
Answer 9 quick questions and get an instant score across your security environment.
Backup and Disaster Recovery
Can your business recover all data and systems if ransomware encrypted everything today?
A reliable backup is your last line of defence against ransomware. If a backup cannot be restored in a test, it cannot be trusted in a crisis. Offsite and immutable copies are required to survive a full encryption event.
Security and Threat Protection
Are your devices and email protected against malware, phishing, and ransomware?
Endpoint protection and email filtering together cover the two most common attack paths. Next-generation antivirus uses behaviour analysis to stop threats that signature-based tools miss. Email filtering blocks phishing before it reaches the inbox.
Monitoring and Incident Response
Is your environment monitored 24/7 for signs of a breach, with a documented response plan?
Continuous monitoring detects attacker activity that automated tools miss. An incident response plan means you know what to do before something goes wrong, cutting recovery time and limiting damage.
Centralized Logs and Audit Trail
Do you have a central record of who accessed what, when, and from where?
Audit logs are the evidence trail for every security investigation and compliance audit. Without centralised, retained logs, you cannot answer "who changed what, when" after an incident.
Compliance and Governance
Does your organisation have documented security policies aligned with PIPEDA or relevant regulatory standards?
Documented policies demonstrate due diligence under PIPEDA and provide a baseline for any security audit. Without them, you are exposed to regulatory liability and disqualified from many government procurement processes.
Identity and Access Management
Is access to your systems controlled with multi-factor authentication and least-privilege principles?
Stolen credentials are the leading cause of breaches. MFA makes a stolen password alone insufficient to log in. Conditional access and least-privilege principles limit what an attacker can do even if one account is compromised.
Security Awareness Training
Do your employees receive regular security training and phishing simulations?
Most breaches involve a human action: a clicked phishing link, a reused password, or a socially engineered request. Phishing simulations and regular training build the habits that technical controls alone cannot create.
Licensing and Cloud Management
Do you have a current, accurate record of all software licences, cloud subscriptions, and their security settings?
Unused or misconfigured licences are a common source of security gaps. An accurate inventory ensures you are not paying for what you do not use and that security features included in your subscriptions are actually turned on.
Documentation and Asset Management
Does your organisation have up-to-date documentation of all devices, accounts, and configurations?
Accurate asset documentation is the foundation of every other security control. You cannot protect what you do not know exists. End-of-life systems that slip off the inventory become permanent vulnerabilities.