TorontoBiztech
Search

Resources

Cybersecurity Readiness Checklist

A working checklist for Toronto businesses covering identity, backup, access review, vendor offboarding, incident response, and privacy obligations.

By Biztech Editors Reviewed TorontoCybersecurityCompliancePrivacy

Quick answer: readiness is mostly procedural instead of technical. Identity, backup, access review, and offboarding cover most realistic risk, and all four are cheap. Tools help after those are in place.

Identity

  • Multi-factor authentication on email, remote access, and administrator accounts
  • No shared logins, and no shared administrator password
  • Administrator rights held only by people who need them, on separate accounts from daily use
  • Departures trigger same-day disablement, ahead of any month-end cleanup

Backup and Recovery

  • Backups isolated from the systems they protect, so an intruder in one cannot reach the other
  • A restore tested on a schedule, with the test date written down
  • Recovery time and data loss tolerance stated, and the backup design matched to them
  • Cloud application data backed up as well, since a hosted system is not automatically a backed-up one

Access and Vendors

  • A written list of every third party with access, what they can reach, and why. See vendor access
  • Access scoped to the role and time-limited where the work is
  • A quarterly review, plus removal on the day a relationship ends
  • Contracts stating what a vendor may access and what they must do in a breach

People and Process

  • An incident plan naming who decides, who communicates, and who to call, printed and stored offline
  • Cyber insurance reviewed for what it actually covers and what it requires you to have in place
  • Phishing awareness training, repeated through the year instead of annually
  • A finance control requiring verbal verification of payment instruction changes, which stops most invoice fraud

Privacy and Ontario-Specific Obligations

Breach reporting. Under PIPEDA, breaches of security safeguards must be reported to the Office of the Privacy Commissioner of Canada and affected individuals notified where there is a real risk of significant harm, with records kept of all breaches. Details at priv.gc.ca.

Electronic monitoring policy. Ontario employers with 25 or more employees must maintain a written policy disclosing whether and how they electronically monitor employees. The dates, required contents, and employee-copy rule are tabulated in our Toronto software planning guide, and a great deal of ordinary security tooling triggers it. Provincial guidance is at ontario.ca.

Supplier questionnaires. If you sell into financial services, government, or large enterprise, expect to evidence the items above. Having the list ready is the difference between a two-day response and a three-week one.

Nothing here is legal advice. Confirm your obligations with qualified counsel.

Further Reading

Frequently Asked Questions

What is the single highest-value item on this list?
Multi-factor authentication on email and remote access. Most incidents at small and mid-sized businesses begin with a working credential, and MFA breaks that chain for close to no cost. If only one thing gets done, it should be this.
Do we have to report a breach?
Under PIPEDA, organisations must report breaches of security safeguards to the Privacy Commissioner of Canada and notify affected individuals where the breach creates a real risk of significant harm, and must maintain records of all breaches. Confirm how the obligation applies to you with counsel, because the assessment is fact-specific.
How often should access be reviewed?
Quarterly is a reasonable default, and the trigger matters more than the interval. Every departure, every ended vendor relationship, and every role change should prompt a removal on the day it happens instead of waiting for a scheduled review.