Free · 2 minutes · No sign-up required

What's Your Security Score?

Answer 9 quick questions and get an instant score across your security environment.

1
💾
PILLAR 1 OF 9

Backup and Disaster Recovery

✓

Can your business recover all data and systems if ransomware encrypted everything today?

Backup and Disaster Recovery: What is it?

A reliable backup is your last line of defence against ransomware. If a backup cannot be restored in a test, it cannot be trusted in a crisis. Offsite and immutable copies are required to survive a full encryption event.
Yes: daily automated backups, tested regularly, stored offsite
Partially: backups exist but have not been tested or are not offsite
No: no formal backup solution in place
I'm not sure
2
🛡️
PILLAR 2 OF 9

Security and Threat Protection

✓

Are your devices and email protected against malware, phishing, and ransomware?

Security and Threat Protection: What is it?

Endpoint protection and email filtering together cover the two most common attack paths. Next-generation antivirus uses behaviour analysis to stop threats that signature-based tools miss. Email filtering blocks phishing before it reaches the inbox.
Yes: next-gen antivirus and advanced email filtering on all devices
Partially: some devices covered or basic protection only
No: default settings only, no dedicated protection
I'm not sure
3
🔍
PILLAR 3 OF 9

Monitoring and Incident Response

✓

Is your environment monitored 24/7 for signs of a breach, with a documented response plan?

Monitoring and Incident Response: What is it?

Continuous monitoring detects attacker activity that automated tools miss. An incident response plan means you know what to do before something goes wrong, cutting recovery time and limiting damage.
Yes: 24/7 SOC monitoring with a tested incident response plan
Partially: some monitoring in place, no dedicated response plan
No: reactive only, no active monitoring
I'm not sure
4
📋
PILLAR 4 OF 9

Centralized Logs and Audit Trail

✓

Do you have a central record of who accessed what, when, and from where?

Centralized Logs and Audit Trail: What is it?

Audit logs are the evidence trail for every security investigation and compliance audit. Without centralised, retained logs, you cannot answer "who changed what, when" after an incident.
Yes: centralised logging collecting and retaining audit events across systems
Partially: some logging in place but not centralised or not retained
No: no structured log collection
I'm not sure
5
📜
PILLAR 5 OF 9

Compliance and Governance

✓

Does your organisation have documented security policies aligned with PIPEDA or relevant regulatory standards?

Compliance and Governance: What is it?

Documented policies demonstrate due diligence under PIPEDA and provide a baseline for any security audit. Without them, you are exposed to regulatory liability and disqualified from many government procurement processes.
Yes: fully documented, reviewed annually, aligned with applicable standards
Partially: some policies exist but not formally documented or maintained
No: no formal policies
I'm not sure
6
🔑
PILLAR 6 OF 9

Identity and Access Management

✓

Is access to your systems controlled with multi-factor authentication and least-privilege principles?

Identity and Access Management: What is it?

Stolen credentials are the leading cause of breaches. MFA makes a stolen password alone insufficient to log in. Conditional access and least-privilege principles limit what an attacker can do even if one account is compromised.
Yes: MFA enforced for all users, conditional access policies, regular access reviews
Partially: MFA enabled for some users only, no conditional access
No: standard passwords only, no MFA
I'm not sure
7
🎓
PILLAR 7 OF 9

Security Awareness Training

✓

Do your employees receive regular security training and phishing simulations?

Security Awareness Training: What is it?

Most breaches involve a human action: a clicked phishing link, a reused password, or a socially engineered request. Phishing simulations and regular training build the habits that technical controls alone cannot create.
Yes: ongoing programme with regular phishing simulations
Partially: occasional training, no phishing simulations
No: no formal security training for employees
I'm not sure
8
☁️
PILLAR 8 OF 9

Licensing and Cloud Management

✓

Do you have a current, accurate record of all software licences, cloud subscriptions, and their security settings?

Licensing and Cloud Management: What is it?

Unused or misconfigured licences are a common source of security gaps. An accurate inventory ensures you are not paying for what you do not use and that security features included in your subscriptions are actually turned on.
Yes: full licence inventory, subscriptions reviewed quarterly, security baselines configured
Partially: most licences tracked but gaps in security configuration
No: no formal licence or cloud management process
I'm not sure
9
⚙️
PILLAR 9 OF 9

Documentation and Asset Management

✓

Does your organisation have up-to-date documentation of all devices, accounts, and configurations?

Documentation and Asset Management: What is it?

Accurate asset documentation is the foundation of every other security control. You cannot protect what you do not know exists. End-of-life systems that slip off the inventory become permanent vulnerabilities.
Yes: all assets documented, refresh cycle defined, documentation reviewed regularly
Partially: mostly documented but some legacy or undocumented systems
No: no formal asset inventory or documentation
I'm not sure

Why This Matters

  • 🎯 Identify gaps before attackers do
  • 🇨🇦 Built for Canadian businesses

Want a Full Picture?

Get a free IT Health Report: a remote read-only review of your Microsoft environment, delivered in writing within two weeks.

Learn About the IT Health Report