Cybersecurity Checklist for Small Businesses
This checklist is designed for owners and operators of small and mid-sized businesses across Greater Sudbury, Lively, Chelmsford, Hanmer, Garson, Azilda, Copper Cliff, Coniston, Parry Sound, North Bay, and Northern Ontario. It's not exhaustive — nothing short of a full audit is — but it covers the controls that make the biggest difference for the least effort. Work through it, mark honestly, and prioritize the gaps.
Identity and access
- MFA enforced on Microsoft 365 for every user, no exceptions
- MFA on VPN, Remote Desktop, and any remote access
- Legacy authentication protocols disabled in Microsoft 365
- Conditional Access configured (block risky sign-ins, require compliant devices)
- Admin accounts separated from daily-use accounts
- Break-glass admin accounts documented and secured with hardware key MFA
- Business password manager deployed to all users
Endpoint protection
- Business-grade EDR on every workstation and server (not consumer AV)
- Central visibility for the IT team
- Local admin rights removed from everyday user accounts
- Disk encryption enabled (BitLocker on Windows)
- Screens lock automatically after 5–15 minutes idle
- USB device policy defined and enforced
Email security
- Advanced email filtering with anti-phishing and impersonation detection
- Attachment sandboxing for high-risk file types
- SPF, DKIM, and DMARC configured for your domain
- External sender warnings enabled
- Auto-forwarding to external domains blocked
- Report Phishing button available in Outlook
Patching and updates
- Windows updates deployed within 30 days of release
- Third-party software (browsers, Adobe, Java, etc.) patched monthly
- Firewall and network device firmware kept current
- Servers rebooted for updates on a defined schedule
- End-of-life software identified and replaced
Backup and recovery
- Backups for workstations, servers, and Microsoft 365 data
- Backups stored off-network and immutable (ransomware can't reach or delete them)
- Restore tests performed on real workloads at least quarterly
- Documented recovery time and recovery point objectives
- Backup monitoring — failures alert someone who acts on them
Network security
- Business-grade firewall with active security services subscription
- Guest Wi-Fi segregated from business network
- Wi-Fi uses WPA2/WPA3 Enterprise or a strong shared key rotated on staff change
- Remote access via VPN or Zero Trust with MFA — never direct RDP
- Network segmentation between users, servers, and IoT
People and process
- Security awareness training for all staff (short-format, ongoing)
- Periodic phishing simulations
- Documented onboarding and offboarding checklists
- Documented incident response plan — who calls whom
- Written information security policy staff have read
- Third-party vendors reviewed for security posture
Governance and evidence
- Cyber insurance in place with accurate answers on the questionnaire
- Evidence pack for auditors, insurers, and clients (MFA coverage, EDR, training)
- Annual security assessment against a documented baseline
- Quarterly Microsoft 365 tenant review
Frequently asked questions
What if we can't do all of this at once?
Prioritize in this order: MFA everywhere, EDR on every endpoint, tested backups, email filtering, and staff training. Those five items close the biggest gaps for the vast majority of SMBs.
Is there a scoring version of this checklist?
Yes — our free Cybersecurity Risk Assessment scores your posture in about 5 minutes and returns a prioritized action list.
Does this checklist satisfy cyber insurance requirements?
It covers most items current insurers ask about. Specific policies vary, so match the checklist against your insurer's actual questionnaire before renewal.
How long should working through this take?
The honest self-assessment takes an afternoon. Closing every gap takes weeks to months, depending on how much needs to change.
Turn this checklist into a score
Our free Cybersecurity Risk Assessment scores your posture in 5 minutes and returns a prioritized action list — no sales pressure.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- How to Protect Your Business from Ransomware
Ransomware isn't a Fortune-500 problem. Here's how small and mid-sized businesses in Greater Sudbury and No…
- Small Business Cybersecurity Checklist for Ontario Businesses
A practical, no-jargon cybersecurity checklist Ontario small businesses can work through in an afternoon co…
- The Most Common Cybersecurity Threats Facing Small Businesses
Forget nation-state hackers. Here are the threats actually hitting Northern Ontario SMBs today — and the pr…
- Why Every Business Needs Multi-Factor Authentication
If you do only one security thing this year, do this. MFA blocks the vast majority of account-takeover atta…
