Ten questions about whether you could show it, not whether you feel secure. It takes about five minutes. There is no email gate and nothing you answer leaves your browser.
1 of 10
Is there one named person accountable for cyber security and privacy?
Not a committee, and not “IT”. A person.
2 of 10
If a system had to be taken offline at 9pm on a Friday, is it written down who decides?
Including when that person is on holiday.
3 of 10
Is there a written list of the systems and data whose loss or exposure would materially damage the business?
A short list of the things that would actually hurt, not an asset register of everything.
4 of 10
Do you keep a record of every privacy breach, including the ones you decided were harmless?
PIPEDA requires records of all breaches, kept for two years, whether or not they were reportable.
5 of 10
Are your data retention periods actually enforced, or only published?
If your privacy notice says you delete after a period, does anything make that happen?
6 of 10
Has anyone tested restoring from a backup in the last twelve months?
Not whether backups run. Whether a restore has been done.
7 of 10
Do you know which third parties can reach your systems or personal data, and did anyone check them before you signed?
Including the ones a department bought on a company card.
8 of 10
Do you have a list of the AI tools and features in use, including the ones switched on inside products you already own?
Most organisations are running more AI than they think.
9 of 10
Are any decisions about people made entirely by software, and if so have you told them?
Quebec’s Law 25 has required this since September 2023.
10 of 10
If a customer, insurer or regulator asked today what you do about cyber and privacy, what would you hand them?
Something dated, that someone senior has actually seen.