Assessment
SMB cybersecurity assessment: know where you actually stand
A clear picture of your real exposure (access, backups, email, IT vendors, obligations)so you can decide what to fix first instead of buying at random.
Key points
- An assessment establishes your real exposure. It sells nothing and assumes no particular tool.
- The order of treatment matters more than the list: a few targeted actions rule out most scenarios.
- We start with what you already pay for and do not use: usually the most productive ground.
- You leave with a prioritized map you can act on, whether or not you work with us.
Why start with an assessment rather than a tool?
Because a tool bought before understanding your exposure solves a problem you may not have, while leaving the one you do have untouched. The assessment establishes where your data goes, who can reach it, and what would stop you tomorrow. Tooling follows from that, not before it.
The reverse sequence is nonetheless the common one. A business hears that a competitor was hit, buys a premium endpoint product, and stays exposed on what would actually have stopped it: remote access without a second factor, a backup never restored, a vendor holding the keys to everything.
The haste is understandable. The market is organized around products, and a product is easier to order than an analysis. But it produces security in appearance only: real spending, unchanged risk.
An assessment costs attention rather than equipment budget. That is its point: it is reversible, and it commits you to nothing: neither to us nor to a vendor.
What exactly do you look at?
Six areas, taken in the order they give way in real incidents: access, backups, email, your internet-facing surface, the IT supply chain, and regulatory obligations. Each is checked through concrete questions, not a self-declared questionnaire.
The order is not arbitrary. It follows what, in documented incidents, actually serves as the entry point and as the aggravating factor. A weakness in access cancels out effort spent elsewhere; an untested backup turns a manageable incident into a prolonged outage.
- Access and identity. Who can get in, from where, with what second factor. Administrative accounts, remote access, shared accounts, and above all the accounts that should have been closed when someone left.
- Backups. Their existence is not the point: what matters is their isolation from the network and the date of the last restore actually performed. A backup never restored is a hypothesis, not a protection.
- Email. Domain authentication, filtering, automatic forwarding rules installed without your knowledge, and the verification procedure for payment requests.
- Internet-facing surface. What your organization publishes without knowing: services reachable from the internet, admin interfaces, unpatched components, expired certificates.
- The IT supply chain. Who holds standing access to your systems, under what contractual framing, and what happens if that vendor is itself compromised.
- Obligations. What Law 25 expects of you, and what your enterprise customers now require in their supplier questionnaires.
What do you get at the end?
A map of your risk areas, ranked by impact against effort rather than alphabetically or by product family. It states what deserves attention first, what can wait, and what belongs to a trade other than ours.
The document is written to be read by a management team, not by engineers. It names business consequences (downtime, a lost contract, an unmet regulatory obligation)rather than technical vulnerabilities whose significance nobody outside the field can weigh.
It is also built to be reused. What it contains answers a good share of supplier questionnaires and insurer requests, which almost always cover the same ground.
It stays yours. If you decide to handle the work internally, with another provider, or later, the findings keep their value. We do not treat that as a loss; it is the only honest way to offer an assessment.
Assessment or full audit: which one?
The assessment locates exposure and sets priorities; it suits an organization deciding where to start. The full audit measures, tests and documents in depth; it suits an organization that already knows what to examine, often because a third party requires it.
Starting with a full audit and no prior assessment means examining a perimeter nobody chose, in great detail. The output is bulky, expensive to produce, and frequently unusable for lack of hierarchy.
The opposite (stopping at the assessment when a customer, an insurer or a regulator expects evidence)is not enough either. The assessment says where to look; it does not replace measurement.
In practice, most organizations consulting us for the first time need the former. The latter comes next, on a narrow and justified perimeter.
Frequently asked questions
Yes. It involves a conversation with the people who know your systems, followed by a written summary of your principal exposure. That summary stays yours, whether or not the discussion continues. We do not make its delivery conditional on signing anything, and we resell no licences, which makes our recommendations verifiable.
Most of the work rests on a conversation with the people who actually handle the systems: whoever runs payroll, whoever opens accounts, your IT vendor if you have one. It is short but irreplaceable: an assessment run from an org chart misses real usage, and real usage is what creates exposure.
No, and we do not ask for it at this stage. The assessment rests on conversation and on what is observable from outside, with no connection to your systems. If a deeper technical check proves useful afterwards, it is covered by a separate written agreement with an explicit scope and authorization.
We tell you immediately, ahead of everything else, and set out the steps in order. The priority shifts from analysis to response: contain the scope, preserve evidence, and determine whether a confidentiality incident must be notified. The assessment resumes once the situation is stable.
No, and it is one of the situations where an assessment is most useful. Your provider operates your systems; they are poorly placed to evaluate the risk their own access represents, or to arbitrate what you should require of them. We regularly work alongside the incumbent provider, and replacing them is never the objective.
Sources
- Commission d'accès à l'information du Québec · supervisory authority, obligations and incident reporting
- Canadian Centre for Cyber Security · advisories, alerts and recommended baseline controls
- Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1) · official text
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.