Skip to main content

Where do you stand?

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

Ten questions about whether you could show it, not whether you feel secure. It takes about five minutes. There is no email gate and nothing you answer leaves your browser.

1 of 10

Is there one named person accountable for cyber security and privacy?

Not a committee, and not “IT”. A person.

2 of 10

If a system had to be taken offline at 9pm on a Friday, is it written down who decides?

Including when that person is on holiday.

3 of 10

Is there a written list of the systems and data whose loss or exposure would materially damage the business?

A short list of the things that would actually hurt, not an asset register of everything.

4 of 10

Do you keep a record of every privacy breach, including the ones you decided were harmless?

PIPEDA requires records of all breaches, kept for two years, whether or not they were reportable.

5 of 10

Are your data retention periods actually enforced, or only published?

If your privacy notice says you delete after a period, does anything make that happen?

6 of 10

Has anyone tested restoring from a backup in the last twelve months?

Not whether backups run. Whether a restore has been done.

7 of 10

Do you know which third parties can reach your systems or personal data, and did anyone check them before you signed?

Including the ones a department bought on a company card.

8 of 10

Do you have a list of the AI tools and features in use, including the ones switched on inside products you already own?

Most organisations are running more AI than they think.

9 of 10

Are any decisions about people made entirely by software, and if so have you told them?

Quebec’s Law 25 has required this since September 2023.

10 of 10

If a customer, insurer or regulator asked today what you do about cyber and privacy, what would you hand them?

Something dated, that someone senior has actually seen.

0 of 10 answered

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.