Bastani Security
Book the Fire Drill
Free self-assessment · Toronto & GTA · 5 minutes

Where would a scam get in? Score your team in five minutes.

Most owners have a gut feeling about where they're exposed, but never a clear picture. This is the picture. Answer 25 plain-English yes-or-no questions about how your team handles email, money, devices and a bad day - tally your score, and see exactly where you'd start. No sign-in wall to read it, no jargon, and nothing here that could appear on a generic cyber-tips blog. Each question maps to a Canadian Centre for Cyber Security baseline control, so a low answer points straight at a real fix.

  • Answer 25 specific yes/no questions and walk away with a real score, not a vague feeling
  • Every weak answer maps to a Canadian Centre for Cyber Security baseline control - so you know the actual fix, not just the gap
  • Covers the five places small businesses actually get hit: people, email, money movement, devices and backups, and the first hour of an incident
  • Plain language a non-technical owner or office manager can score over a coffee - no IT degree required
Email me the editable pack

Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.

01

Your people - the front line, not the weak link

Almost every small-business incident starts with a person making a normal-looking decision under a little pressure. These questions check whether your team has the habits and the cover they need to slow down and verify. Score one point for each honest yes. (Maps to the Cyber Centre baseline: tailored security awareness training.)

Has every person on your team - not just the owner or IT - had real cybersecurity training in the last 12 months, beyond a one-time onboarding video?
Would a new front-desk or junior staffer know it's safe to question or slow down a request that came from you, the boss, without fear of getting in trouble?
Does your team know the specific scams aimed at your line of work (for a brokerage, the closing-day wire switch; for a clinic, the fake intake attachment), not just 'phishing' in the abstract?
Has anyone on your team ever practised spotting a fake message in a safe setting, rather than only being told to 'be careful'?
Do new hires get a clear, plain-English rundown of how your business verifies money requests and handles client data in their first week?
02

Your email - where the attack usually walks in

Email is the front door for business email compromise, fake invoices and credential-harvesting login pages. These checks cover the controls that actually stop those, not 'use a strong password.' Score one point per yes. (Maps to the Cyber Centre baseline: multi-factor authentication; email security; phishing protection.)

Is multi-factor authentication (a code or prompt on top of a password) turned on for every staff email account - no exceptions for the owner or 'the person who's too busy'?
Have you set up the three email-authentication records - SPF, DKIM and DMARC - so scammers can't easily send email that looks like it came from your domain?
Does your email system visibly flag or tag messages that come from outside your organization, so a spoofed 'internal' note stands out?
If a staff member entered their password into a fake login page today, would MFA still stop the attacker from getting in - and would you find out?
Does anyone in your team know how to report a suspicious email to a real person or inbox, instead of just deleting it and moving on?
03

Your money movement - the part a thief is actually after

Wire fraud, fake-invoice fraud and banking-change scams are where small businesses lose six figures in a single afternoon. These questions check for the one habit that defeats nearly all of them: verifying out-of-band before money moves. Score one point per yes. (Maps to the Cyber Centre baseline: secure financial processes and protection against business email compromise.)

Before you change where a payment goes (a vendor's banking details, a client's wire instructions), does someone call a known phone number to confirm - not the number or email in the request itself?
Do payments or wire transfers over a set dollar amount require a second person to approve, so no single inbox can move large money alone?
Does your team treat 'updated banking details' or 'use this new account' emails as a red flag to verify by phone, every single time, even mid-deal?
If a request to move money felt urgent and came 'from the boss,' does your team have an agreed rule to verify it that a fake-urgency message can't talk them out of?
Do you keep a simple written record of who is allowed to approve payments and change payment details, so it isn't decided in the moment?
04

Your devices and backups - so a bad click isn't the end

Ransomware and lost laptops are survivable if your basics hold. These checks cover the controls that turn a disaster into an inconvenience. Score one point per yes. (Maps to the Cyber Centre baseline: backups, patching, device security and malware protection.)

Do you have automatic backups of your critical systems and client data, kept somewhere a ransomware infection can't reach (offline or a separate cloud account)?
Have you actually restored a file from those backups in the last 90 days to confirm they work - rather than assuming they do?
Are your computers, phones and key software set to install security updates automatically, so known holes get patched without anyone remembering to?
Is every laptop and phone that touches business data protected by a screen lock and disk encryption, so a stolen device isn't an open door?
Does reputable, up-to-date malware protection run on the computers your team uses every day, including any personal devices that access work email?
05

Your first hour - knowing what to do when it happens

The difference between a scare and a catastrophe is usually the first hour. Most small businesses have never decided who to call or what to do. These questions check whether you have a plan you could actually follow under pressure. Score one point per yes. (Maps to the Cyber Centre baseline: incident response planning.)

If you discovered a breach or a fraudulent wire right now, do you know the first three things to do and the first three people to call - without having to Google it?
Is there a written, one-page response plan that says who is in charge, who contacts the bank, and who contacts your IT provider when something goes wrong?
Do you know that wire fraud and online scams can be reported to the Canadian Anti-Fraud Centre, and that fast bank contact gives the only real chance of recovering funds?
Would your team know which incidents may trigger a legal duty to notify clients or a regulator (for example a privacy breach under PIPEDA, or PHIPA for a clinic), rather than guessing?
Have you ever walked through a 'what would we do if' scenario as a team, even once, so the plan isn't just a document nobody has read?
How to use this

How to score: give yourself one point for each honest 'yes' across all five sections - 25 questions, 25 possible points. Be honest; this is for you, not a grade. Then read your band. 20–25 (Ready): you're ahead of most GTA small businesses - your job now is to keep the habits sharp and prove it to insurers and clients. 13–19 (Exposed): you have real foundations but clear gaps a scammer could walk through - pick your two lowest-scoring sections and fix those first. 7–12 (At risk): the basics that stop a six-figure loss aren't reliably in place; this is where most unprepared small businesses sit, and a single convincing email could do real damage. 0–6 (Wake-up call): you'd likely not catch a targeted attack or know what to do next - start with multi-factor authentication on email, tested backups, and a money-verification rule this week. Whatever your band, your weakest section is your starting point: people, email, money, devices and backups, or incident-readiness. Each lines up with a Canadian Centre for Cyber Security baseline control, so the gap names its own fix.

A checklist is a start. A drill makes it stick.

The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this self-assessment become muscle memory. Three hours, on-site, with a scored 30-day plan.

Book the Fire Drill See the real estate & mortgage page →
My score was low. What does that actually mean - and what do I do about it?

A low score doesn't mean you've done something wrong; it means the habits that stop the most common attacks - multi-factor authentication, a verify-by-phone rule before money moves, tested backups, and a first-hour plan - aren't reliably in place yet. The good news is these are fixable in weeks, not years. Start with your lowest-scoring section. The catch most owners run into is that the weakest area is almost always people, not machines - and a checklist alone won't change how your team behaves under pressure. That's exactly what The Cyber Fire Drill is for: a live, three-hour, on-site workshop where your real team rehearses the actual scams aimed at your business - safely, no malware, no shaming - and leadership walks out with a scored 30-day plan. If your score landed in the 'At risk' or 'Wake-up call' band, the Fire Drill turns this scorecard from a snapshot into muscle memory.

Is this scorecard enough on its own, or just a starting point?

It's a genuine starting map, and an honest one - but it's a self-assessment, not a guarantee, and no checklist makes anyone 'secure' or 'unhackable.' It tells you where you stand against the Canadian Centre for Cyber Security baseline so you can fix the obvious gaps yourself, today. Where it stops is behaviour: knowing the rule and following it at 4:55 on closing day under pressure are different things. If you want your team to actually catch the real thing - or you need something to show a cyber-insurer or a client security questionnaire - that's the step up from this page to a live drill or a quick Baseline Security Checkup.

We're a small team and we already have an IT provider. Do we still need this?

Yes, and here's why it isn't a knock on your IT company: they harden your machines, but the breach usually walks in through a person making a normal decision - approving a fake invoice, clicking a believable login page, trusting an urgent 'boss' text. Your IT provider can't click 'verify' for your staff. This scorecard checks the people-and-process layer most small businesses never assess, and it's deliberately built so a non-technical owner or office manager can score it without IT in the room. If the people section came back low, that's the gap a live drill closes - and your IT provider is welcome to sit in.

More resources in the resource library · questions? contact@bastani.org