Canopytech Resources
Menu

Free · 16 questions · no sign-up

How exposed is your business to a cyber attack?

Answer 16 questions about the controls that decide how bad an IT incident gets, and get a weighted risk score, your weakest areas in priority order, and a concrete next step for each one. Built for Canadian businesses by the Canopytech team in the GTA.

Nothing you enter leaves your browser. There is no form to submit, no email address to hand over, and no server receiving your answers. Close the page and it's gone.

0 of 16 answered

Question 1: How is your business data backed up — and when did someone last restore from it?

1. Backup & Recovery

Weight: 12 of 150

Question 2: Is multi-factor authentication enforced on email and your other critical apps?

2. Multi-Factor Authentication

Weight: 12 of 150

Question 3: What is protecting your computers and servers from malware and ransomware?

3. Endpoint Protection

Weight: 12 of 150

Question 4: How are administrator accounts handled?

4. Admin Accounts & Privilege

Weight: 10 of 150

Question 5: Is anyone watching your network and email for threats outside business hours?

5. Monitoring & Alerting

Weight: 10 of 150

Question 6: How do operating systems and third-party software actually get updated?

6. Patching & Updates

Weight: 10 of 150

Question 7: Is your domain protected against someone sending email as you?

7. Email Authentication (SPF, DKIM, DMARC)

Weight: 10 of 150

Question 8: If you run Microsoft 365, how deliberately are its security settings configured?

8. Microsoft 365 Configuration

Weight: 9 of 150

Question 9: When someone leaves, how quickly does their access genuinely disappear?

9. Staff Offboarding

Weight: 9 of 150

Question 10: Who else can reach your systems remotely — vendors, contractors, support tools?

10. Vendor & Remote Access

Weight: 9 of 150

Question 11: Is the data inside Microsoft 365 or Google Workspace backed up independently?

11. Microsoft 365 & Cloud Data Backup

Weight: 9 of 150

Question 12: Do your people get security awareness and phishing training?

12. Phishing & Staff Awareness

Weight: 8 of 150

Question 13: Do you have a plan for a cyber attack or major outage — and has anyone rehearsed it?

13. Incident Response Plan

Weight: 8 of 150

Question 14: Are laptops, desktops and phones encrypted — and can you wipe one that goes missing?

14. Device Encryption & Mobile Data

Weight: 8 of 150

Question 15: How is day-to-day IT handled today?

15. IT Support Model

Weight: 8 of 150

Question 16: Could you evidence your security controls to an insurer, auditor or client tomorrow?

16. Compliance & Insurance Readiness

Weight: 6 of 150

Answer all 16 questions to see your score

16 still to go.

How the score is calculated

No black box. Every control carries a weight based on how much damage its absence tends to cause. Your answers are added up, divided by 150 — the worst possible total — and expressed as a score out of 100. The weights are published here so you can disagree with them on the evidence rather than on faith.

12 points

Any one of these missing can turn a routine incident into weeks of downtime on its own.

Backup & Recovery · Multi-Factor Authentication · Endpoint Protection

10 points

These decide how far an intruder gets, and how quickly anybody notices.

Admin Accounts & Privilege · Monitoring & Alerting · Patching & Updates · Email Authentication (SPF, DKIM, DMARC)

9 points

Quiet routes in — and the ones businesses most often assume somebody else is covering.

Microsoft 365 Configuration · Staff Offboarding · Vendor & Remote Access · Microsoft 365 & Cloud Data Backup

8 points

These limit the damage rather than prevent the access.

Phishing & Staff Awareness · Incident Response Plan · Device Encryption & Mobile Data · IT Support Model

6 points

Real financial exposure, but it surfaces after an incident rather than causing one.

Compliance & Insurance Readiness

Low Risk · 0–19

Moderate Risk · 20–39

Elevated Risk · 40–64

High Risk · 65–100

What this is

A structured way to find out which gap to close first, using the same control areas we'd walk through in a paid assessment. It's honest about uncertainty: "I'm not sure" is scored as a risk, because not knowing whether a control works is its own exposure. Good for taking to a management meeting, an insurer, or your current IT provider.

What this is not

It is not a security audit, a penetration test, or a compliance certification. It scans nothing and cannot see your network — it reflects exactly what you told it. A real assessment means looking at your actual tenant, devices and configuration, and it will find things a questionnaire never can.

IT Risk Calculator FAQs

How does the IT risk calculator work?

You answer 16 questions covering backups, multi-factor authentication, endpoint protection, admin accounts, monitoring, patching, email authentication, Microsoft 365 configuration, offboarding, vendor and remote access, cloud data backup, staff training, incident response, device encryption, your IT support model, and compliance readiness. Each control carries a weight based on how much damage its absence usually causes. Your answers are added together, divided by 150 — the worst possible total — and expressed as a score out of 100, with your weakest areas listed in priority order.

Is anything I enter sent to Canopytech?

No. Your answers are never transmitted, stored or logged. The calculator runs entirely inside your browser: there is no form to submit, no account to create, no analytics event carrying your answers, and no server receiving them. We keep no record of them on our side and put nothing about them in browser storage. To be precise about what we do count: like most sites we log page visits, using analytics we host ourselves, which records that this page was opened and sets a first-party cookie to avoid counting you twice — it never sees anything you enter here. The one thing outside our control is your own browser — we ask it not to autofill, but if you have it set to restore a previous session it may bring your answers back on that device. "Start over" clears them. If you want us to look at your results you have to send them to us yourself: the "email these results" button opens your own mail app with the summary already written, and nothing leaves your computer until you press send.

Is this a security audit?

No, and it should not be presented as one. It is a structured self-assessment: it reflects what you tell it, it scans nothing, and it cannot see your network. It is genuinely useful for deciding what to look at first and for showing a management team where the gaps are. A real assessment means looking at the actual tenant, devices and configuration.

Why are some questions worth more than others?

Because the consequences are not equal. Missing backups, missing multi-factor authentication and unmanaged endpoint protection carry the heaviest weight at 12 points each, since any one of them alone can turn a routine incident into weeks of downtime. Staff training and incident response planning carry 8, because they limit damage rather than prevent access. Every weight is printed next to its question so you can disagree with our ranking on the evidence.

What should I do with my score?

Work the flagged items from the top down. The list is already ordered by how much each gap contributes to your score, so the first two or three are where the effort pays off most. Each one comes with a plain-English next step. If you would rather walk through it with someone, Canopytech works with businesses across the Greater Toronto Area — call 647.478.8449 or book a free 30-minute consultation.

Who is this for?

Small and mid-sized Canadian businesses that want an honest read on where their IT and security posture is weak — professional services, healthcare, real estate, construction and trades, non-profits, and any business running on Microsoft 365. You do not need to be technical to answer the questions; if you are unsure about one, "I'm not sure" is a real answer and it is scored as a risk, because uncertainty is one.

Ready to close the gaps?

Bring your score to a free 30-minute call and we'll tell you which two things to fix first — whether or not you end up working with us.

Request a Quote