Free • 5 minutes • No email required to start

Security Risk Report

Answer 10 yes/no questions about your current cybersecurity posture. You'll get an instant score showing how you stand against the questions Canadian cyber-insurance carriers are asking in 2026. Honest answers only — "mostly" counts as no, "I think so" counts as no.

1

Is Multi-Factor Authentication (MFA) enforced on every Microsoft 365 or Google Workspace account in your business?

2

Do you have managed EDR (Huntress, SentinelOne, CrowdStrike — not basic antivirus) on every laptop, desktop, and server?

3

Has someone successfully restored a file from your backups in the last 90 days?

4

Is your Microsoft 365 / Google Workspace data backed up by a third-party service (separate from Microsoft's native retention)?

5

Have all staff completed cybersecurity awareness training in the last 12 months, including a phishing simulation?

6

Do you have a written incident response plan that names a responder, an external IR firm, and your insurance broker's hotline?

7

Are all critical software security updates installed within 30 days of release on every machine?

8

Do your IT administrators have separate accounts for daily work versus admin tasks?

9

Do you currently carry standalone cyber-insurance coverage (not a small endorsement on a general business policy)?

10

When an employee leaves, is their access to every system revoked within 24 hours?

0 of 10 answered