Where would a scam get in? Score your team in five minutes.
Most owners have a gut feeling about where they're exposed, but never a clear picture. This is the picture. Answer 25 plain-English yes-or-no questions about how your team handles email, money, devices and a bad day - tally your score, and see exactly where you'd start. No sign-in wall to read it, no jargon, and nothing here that could appear on a generic cyber-tips blog. Each question maps to a Canadian Centre for Cyber Security baseline control, so a low answer points straight at a real fix.
- Answer 25 specific yes/no questions and walk away with a real score, not a vague feeling
- Every weak answer maps to a Canadian Centre for Cyber Security baseline control - so you know the actual fix, not just the gap
- Covers the five places small businesses actually get hit: people, email, money movement, devices and backups, and the first hour of an incident
- Plain language a non-technical owner or office manager can score over a coffee - no IT degree required
Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.
Your people - the front line, not the weak link
Almost every small-business incident starts with a person making a normal-looking decision under a little pressure. These questions check whether your team has the habits and the cover they need to slow down and verify. Score one point for each honest yes. (Maps to the Cyber Centre baseline: tailored security awareness training.)
Your email - where the attack usually walks in
Email is the front door for business email compromise, fake invoices and credential-harvesting login pages. These checks cover the controls that actually stop those, not 'use a strong password.' Score one point per yes. (Maps to the Cyber Centre baseline: multi-factor authentication; email security; phishing protection.)
Your money movement - the part a thief is actually after
Wire fraud, fake-invoice fraud and banking-change scams are where small businesses lose six figures in a single afternoon. These questions check for the one habit that defeats nearly all of them: verifying out-of-band before money moves. Score one point per yes. (Maps to the Cyber Centre baseline: secure financial processes and protection against business email compromise.)
Your devices and backups - so a bad click isn't the end
Ransomware and lost laptops are survivable if your basics hold. These checks cover the controls that turn a disaster into an inconvenience. Score one point per yes. (Maps to the Cyber Centre baseline: backups, patching, device security and malware protection.)
Your first hour - knowing what to do when it happens
The difference between a scare and a catastrophe is usually the first hour. Most small businesses have never decided who to call or what to do. These questions check whether you have a plan you could actually follow under pressure. Score one point per yes. (Maps to the Cyber Centre baseline: incident response planning.)
How to score: give yourself one point for each honest 'yes' across all five sections - 25 questions, 25 possible points. Be honest; this is for you, not a grade. Then read your band. 20–25 (Ready): you're ahead of most GTA small businesses - your job now is to keep the habits sharp and prove it to insurers and clients. 13–19 (Exposed): you have real foundations but clear gaps a scammer could walk through - pick your two lowest-scoring sections and fix those first. 7–12 (At risk): the basics that stop a six-figure loss aren't reliably in place; this is where most unprepared small businesses sit, and a single convincing email could do real damage. 0–6 (Wake-up call): you'd likely not catch a targeted attack or know what to do next - start with multi-factor authentication on email, tested backups, and a money-verification rule this week. Whatever your band, your weakest section is your starting point: people, email, money, devices and backups, or incident-readiness. Each lines up with a Canadian Centre for Cyber Security baseline control, so the gap names its own fix.
A checklist is a start. A drill makes it stick.
The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this self-assessment become muscle memory. Three hours, on-site, with a scored 30-day plan.
My score was low. What does that actually mean - and what do I do about it?
A low score doesn't mean you've done something wrong; it means the habits that stop the most common attacks - multi-factor authentication, a verify-by-phone rule before money moves, tested backups, and a first-hour plan - aren't reliably in place yet. The good news is these are fixable in weeks, not years. Start with your lowest-scoring section. The catch most owners run into is that the weakest area is almost always people, not machines - and a checklist alone won't change how your team behaves under pressure. That's exactly what The Cyber Fire Drill is for: a live, three-hour, on-site workshop where your real team rehearses the actual scams aimed at your business - safely, no malware, no shaming - and leadership walks out with a scored 30-day plan. If your score landed in the 'At risk' or 'Wake-up call' band, the Fire Drill turns this scorecard from a snapshot into muscle memory.
Is this scorecard enough on its own, or just a starting point?
It's a genuine starting map, and an honest one - but it's a self-assessment, not a guarantee, and no checklist makes anyone 'secure' or 'unhackable.' It tells you where you stand against the Canadian Centre for Cyber Security baseline so you can fix the obvious gaps yourself, today. Where it stops is behaviour: knowing the rule and following it at 4:55 on closing day under pressure are different things. If you want your team to actually catch the real thing - or you need something to show a cyber-insurer or a client security questionnaire - that's the step up from this page to a live drill or a quick Baseline Security Checkup.
We're a small team and we already have an IT provider. Do we still need this?
Yes, and here's why it isn't a knock on your IT company: they harden your machines, but the breach usually walks in through a person making a normal decision - approving a fake invoice, clicking a believable login page, trusting an urgent 'boss' text. Your IT provider can't click 'verify' for your staff. This scorecard checks the people-and-process layer most small businesses never assess, and it's deliberately built so a non-technical owner or office manager can score it without IT in the room. If the people section came back low, that's the gap a live drill closes - and your IT provider is welcome to sit in.
More resources in the resource library · questions? contact@bastani.org