Where do you stand?

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

Ten questions about whether you could show it, not whether you feel secure. It takes about five minutes. There is no email gate and nothing you answer leaves your browser.

1 of 10

Is there one named person accountable for cyber security and privacy?

Not a committee, and not “IT”. A person.

2 of 10

If a system had to be taken offline at 9pm on a Friday, is it written down who decides?

Including when that person is on holiday.

3 of 10

Is there a written list of the systems and data whose loss or exposure would materially damage the business?

A short list of the things that would actually hurt, not an asset register of everything.

4 of 10

Do you keep a record of every privacy breach, including the ones you decided were harmless?

PIPEDA requires records of all breaches, kept for two years, whether or not they were reportable.

5 of 10

Are your data retention periods actually enforced, or only published?

If your privacy notice says you delete after a period, does anything make that happen?

6 of 10

Has anyone tested restoring from a backup in the last twelve months?

Not whether backups run. Whether a restore has been done.

7 of 10

Do you know which third parties can reach your systems or personal data, and did anyone check them before you signed?

Including the ones a department bought on a company card.

8 of 10

Do you have a list of the AI tools and features in use, including the ones switched on inside products you already own?

Most organisations are running more AI than they think.

9 of 10

Are any decisions about people made entirely by software, and if so have you told them?

Quebec’s Law 25 has required this since September 2023.

10 of 10

If a customer, insurer or regulator asked today what you do about cyber and privacy, what would you hand them?

Something dated, that someone senior has actually seen.

0 of 10 answered
French Version »