All Resources
Cybersecurity

Cybersecurity Checklist for Small Businesses

This checklist is designed for owners and operators of small and mid-sized businesses across Greater Sudbury, Lively, Chelmsford, Hanmer, Garson, Azilda, Copper Cliff, Coniston, Parry Sound, North Bay, and Northern Ontario. It's not exhaustive — nothing short of a full audit is — but it covers the controls that make the biggest difference for the least effort. Work through it, mark honestly, and prioritize the gaps.

July 8, 2026 8 min read Greater Sudbury & Ontario

Identity and access

  • MFA enforced on Microsoft 365 for every user, no exceptions
  • MFA on VPN, Remote Desktop, and any remote access
  • Legacy authentication protocols disabled in Microsoft 365
  • Conditional Access configured (block risky sign-ins, require compliant devices)
  • Admin accounts separated from daily-use accounts
  • Break-glass admin accounts documented and secured with hardware key MFA
  • Business password manager deployed to all users

Endpoint protection

  • Business-grade EDR on every workstation and server (not consumer AV)
  • Central visibility for the IT team
  • Local admin rights removed from everyday user accounts
  • Disk encryption enabled (BitLocker on Windows)
  • Screens lock automatically after 5–15 minutes idle
  • USB device policy defined and enforced

Email security

  • Advanced email filtering with anti-phishing and impersonation detection
  • Attachment sandboxing for high-risk file types
  • SPF, DKIM, and DMARC configured for your domain
  • External sender warnings enabled
  • Auto-forwarding to external domains blocked
  • Report Phishing button available in Outlook

Patching and updates

  • Windows updates deployed within 30 days of release
  • Third-party software (browsers, Adobe, Java, etc.) patched monthly
  • Firewall and network device firmware kept current
  • Servers rebooted for updates on a defined schedule
  • End-of-life software identified and replaced

Backup and recovery

  • Backups for workstations, servers, and Microsoft 365 data
  • Backups stored off-network and immutable (ransomware can't reach or delete them)
  • Restore tests performed on real workloads at least quarterly
  • Documented recovery time and recovery point objectives
  • Backup monitoring — failures alert someone who acts on them

Network security

  • Business-grade firewall with active security services subscription
  • Guest Wi-Fi segregated from business network
  • Wi-Fi uses WPA2/WPA3 Enterprise or a strong shared key rotated on staff change
  • Remote access via VPN or Zero Trust with MFA — never direct RDP
  • Network segmentation between users, servers, and IoT

People and process

  • Security awareness training for all staff (short-format, ongoing)
  • Periodic phishing simulations
  • Documented onboarding and offboarding checklists
  • Documented incident response plan — who calls whom
  • Written information security policy staff have read
  • Third-party vendors reviewed for security posture

Governance and evidence

  • Cyber insurance in place with accurate answers on the questionnaire
  • Evidence pack for auditors, insurers, and clients (MFA coverage, EDR, training)
  • Annual security assessment against a documented baseline
  • Quarterly Microsoft 365 tenant review

Frequently asked questions

What if we can't do all of this at once?

Prioritize in this order: MFA everywhere, EDR on every endpoint, tested backups, email filtering, and staff training. Those five items close the biggest gaps for the vast majority of SMBs.

Is there a scoring version of this checklist?

Yes — our free Cybersecurity Risk Assessment scores your posture in about 5 minutes and returns a prioritized action list.

Does this checklist satisfy cyber insurance requirements?

It covers most items current insurers ask about. Specific policies vary, so match the checklist against your insurer's actual questionnaire before renewal.

How long should working through this take?

The honest self-assessment takes an afternoon. Closing every gap takes weeks to months, depending on how much needs to change.

Turn this checklist into a score

Our free Cybersecurity Risk Assessment scores your posture in 5 minutes and returns a prioritized action list — no sales pressure.

Keep exploring

Related services, locations, and resources

Related services

Related resources