top of page
Concept of cyber security in two-step verification, multi-factor authentication, informati

Cybersecurity Self-Assessment for Small Businesses

Take our Cybersecurity Self-Assessment for Small Businesses to evaluate your current security measures and identify areas for improvement. This quick, easy assessment helps you understand your business's cybersecurity needs, so you can take the necessary steps to protect your data and operations.

1. Do you regularly update your software (operating systems, antivirus, apps)?
Yes, I have automatic updates enabled. (3 points)
Yes, but I update manually. (2 points)
No, updates are not a priority. (0 points)
2. Do you use strong, unique passwords for each of your accounts?
Yes, I use a password manager and ensure each password is unique. (3 points)
I use strong passwords, but not all are unique. (2 points)
No, I reuse passwords across multiple ac

What it means: A unique password is one that is distinct for each account or service you use. Avoid reusing passwords across multiple accounts, as this increases the risk if one account is compromised. A strong password should include a mix of upper and lowercase letters, numbers, and special characters, and be long enough to resist common hacking techniques.


3. Have you implemented multi-factor authentication (MFA) for sensitive accounts (e.g., email, bank accounts)?
Yes, for all sensitive accounts. (3 points)
Yes, for some accounts. (2 points)
No, I haven’t enabled MFA. (0 points)

What it means: MFA is a security system that requires more than one form of verification to access an account or system. Typically, this involves something you know (like a password) and something you have (like a smartphone app or a physical token). MFA significantly reduces the chances of unauthorized access, even if someone knows your password.


4. Do you regularly back up your business data?
Yes, I back up data to both cloud and external storage. (3 points)
Yes, I back up data, but only to the cloud or external storage (not both). (2 points)
No, I don’t have a regular backup system. (0 points)

What it means:

Cloud storage refers to storing data on remote servers accessed via the internet. Providers like Google Drive, Dropbox, and iCloud offer cloud services where data is backed up online and can be accessed from anywhere with an internet connection.


External Storage typically refers to physical devices like hard drives or USB drives that you connect to your computer. They are used for local backups but must be physically secured to prevent data loss or theft.


5. Do you have a cybersecurity policy or training in place for your employees (if applicable)?
Yes, all employees are trained and aware of our cybersecurity policy. (3 points)
We have some basic training or guidelines in place. (2 points)
No, there is no formal policy or training. (0 points)

What it means: A cybersecurity policy is a set of rules and guidelines designed to protect your organization's data and network from cyber threats. It covers areas such as password management, data protection, and acceptable usage of technology resources. A strong cybersecurity policy helps reduce the risk of data breaches and ensures employees are aware of best practices.


Learn more: Creating a Cybersecurity Policy


6. Do you use secure or unsecure email accounts/apps for communication between staff and customers/clients?
I use encrypted or secure email services for all communications. (3 points)
I use standard email accounts, but I take steps to ensure privacy (e.g., encryption tools). (2 points)
I use unencrypted or standard email for communication. (0 points)

What it means: Encrypted email uses encryption methods to ensure that the contents of an email are only readable by the intended recipient. This makes it more secure than regular email, which can be intercepted. Secure email services often include features like end-to-end encryption, which protects the message both in transit and at rest.


15-18 points: Strong Cybersecurity Practices – Your business is well-prepared. Keep staying proactive as threats evolve to ensure continued protection.


10-14 points: Moderate Cybersecurity Awareness – You have solid practices in place, but there’s room for improvement. Reach out to us, and we’ll help tighten your security measures.


0-9 points: Weak Cybersecurity Practices – Significant gaps need to be addressed immediately. We’ll reach out to assess your needs and recommend the most urgent next steps for strengthening your security.


Toll Free 1-844-TECH101 (832-4101)

Canada Wide

Call toll free

  • Facebook
  • Instagram
bottom of page