Cybersecurity Checklist for Small Businesses
This checklist is designed for owners and operators of small and mid-sized businesses across Greater Sudbury, Lively, Chelmsford, Hanmer, Garson, Azilda, Copper Cliff, Coniston, Parry Sound, North Bay, and Northern Ontario. It's not exhaustive (nothing short of a full audit is), but it covers the controls that make the biggest difference for the least effort. Work through it, mark honestly, and prioritize the gaps.
Identity and access
- MFA enforced on Microsoft 365 for every user, no exceptions
- MFA on VPN, Remote Desktop, and any remote access
- Legacy authentication protocols disabled in Microsoft 365
- Conditional Access configured (block risky sign-ins, require compliant devices)
- Admin accounts separated from daily-use accounts
- Break-glass admin accounts documented and secured with hardware key MFA
- Business password manager deployed to all users
Endpoint protection
- Business-grade EDR on every workstation and server (not consumer AV)
- Central visibility for the IT team
- Local admin rights removed from everyday user accounts
- Disk encryption enabled (BitLocker on Windows)
- Screens lock automatically after 5 to 15 minutes idle
- USB device policy defined and enforced
Email security
- Advanced email filtering with anti-phishing and impersonation detection
- Attachment sandboxing for high-risk file types
- SPF, DKIM, and DMARC configured for your domain
- External sender warnings enabled
- Auto-forwarding to external domains blocked
- Report Phishing button available in Outlook
Not sure where your security gaps are?
Our free cybersecurity risk assessment scores your posture across MFA, backup, endpoint protection, and email security, then hands you a prioritized fix list.
Talk to a Security SpecialistPatching and updates
- Windows updates deployed within 30 days of release
- Third-party software (browsers, Adobe, Java, etc.) patched monthly
- Firewall and network device firmware kept current
- Servers rebooted for updates on a defined schedule
- End-of-life software identified and replaced
Backup and recovery
- Backups for workstations, servers, and Microsoft 365 data
- Backups stored off-network and immutable (ransomware can't reach or delete them)
- Restore tests performed on real workloads at least quarterly
- Documented recovery time and recovery point objectives
- Backup monitoring: failures alert someone who acts on them
Network security
- Business-grade firewall with active security services subscription
- Guest Wi-Fi segregated from business network
- Wi-Fi uses WPA2/WPA3 Enterprise or a strong shared key rotated on staff change
- Remote access via VPN or Zero Trust with MFA, never direct RDP
- Network segmentation between users, servers, and IoT
People and process
- Security awareness training for all staff (short-format, ongoing)
- Periodic phishing simulations
- Documented onboarding and offboarding checklists
- Documented incident response plan: who calls whom
- Written information security policy staff have read
- Third-party vendors reviewed for security posture
Governance and evidence
- Cyber insurance in place with accurate answers on the questionnaire
- Evidence pack for auditors, insurers, and clients (MFA coverage, EDR, training)
- Annual security assessment against a documented baseline
- Quarterly Microsoft 365 tenant review
Frequently asked questions
What if we can't do all of this at once?
Prioritize in this order: MFA everywhere, EDR on every endpoint, tested backups, email filtering, and staff training. Those five items close the biggest gaps for the vast majority of SMBs.
Is there a scoring version of this checklist?
Yes, our free Cybersecurity Risk Assessment scores your posture in about 5 minutes and returns a prioritized action list.
Does this checklist satisfy cyber insurance requirements?
It covers most items current insurers ask about. Specific policies vary, so match the checklist against your insurer's actual questionnaire before renewal.
How long should working through this take?
The honest self-assessment takes an afternoon. Closing every gap takes weeks to months, depending on how much needs to change.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamTurn this checklist into a score
Our free Cybersecurity Risk Assessment scores your posture in 5 minutes and returns a prioritized action list, with no sales pressure.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- OT and IT Convergence Basics for Small Industrial Operations
Small manufacturers and industrial operations increasingly connect PLCs, HMIs, and control systems to the s…
- Reducing ERP and Production Downtime for Small Manufacturers
An ERP outage on a small manufacturing floor doesn't just inconvenience the office; it stops product from s…
- Cybersecurity for Transportation Companies
Transportation companies are realistic targets for freight fraud, business email compromise, and ransomware…
- IT Offboarding Checklist: What to Do When an Employee Leaves
A step-by-step IT offboarding checklist for when an employee leaves: disable sign-in, revoke sessions, reta…
