The Canadian Centre for Cyber Security publishes baseline controls for small and medium organizations. They are short on purpose. The goal is to cover the basics that stop most attacks, not to build a full security program on day one.
This hub turns that list into a 90-day sequence. Do the first 30 days even if nothing else gets done.
A 90-day plan
- Days 1 to 30: stop the common attacksThese controls address the way most small organizations are actually breached.
- Turn on multi-factor authentication for email, remote access, and every administrator account.
- Enable automatic updates for operating systems, browsers, and business applications.
- Back up important data to a copy that an attacker on your network cannot reach, and test a restore.
- Make sure every device has current anti-malware and a firewall turned on.
- List your systems, devices, and the data they hold. You cannot protect what you have not listed.
- Days 31 to 60: close the gapsMove from basics to configuration and access.
- Configure devices securely, removing default accounts and unneeded software.
- Give people the least access they need, and remove access when roles change.
- Secure mobile devices and the connections people use outside the office.
- Check that your cloud providers meet your security expectations, and review their certifications.
- Review your website security, including updates, administrator accounts, and forms.
- Days 61 to 90: build the habitsControls decay without routines.
- Write a one-page incident response plan with names, phone numbers, and the first steps.
- Run security awareness training, and repeat it each year.
- Protect portable storage media, or ban it.
- Name an owner for security, even if it is a part of someone’s job, and set a quarterly review.
- Know your threat and your harmThe baseline asks you to understand what matters most.
- Decide which systems would hurt most if they were unavailable, altered, or exposed.
- Name the main threat you face, such as ransomware, fraud, or data theft.
- Let leadership commit time and budget to the plan, because a baseline without sponsorship stalls.
General information, not legal or professional advice. Official documents change, so confirm details with the linked sources before you act.
// firms
Canadian firms that work on this
Firms whose own websites name CCCS baseline, CIS Controls or list closely related services. A listing is not an endorsement.
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Canadian Cyber
Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.
- GRC advisory
- Audit and certification
- ISO 27001
- SOC 2
- CIS Controls
CyberHunter Solutions
Penetration testing (web, network, cloud, mobile), threat hunting, protection and monitoring, vulnerability scanning and framework-based security assessments.
- Pen testing
- Vulnerability mgmt
- GRC advisory
- Cloud security
- NIST CSF
- CIS Controls
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Arista Cyber
Industrial cybersecurity firm for OT and ICS: risk assessments, gap analysis, IEC 62443 zone and conduit design, vulnerability assessments and incident response planning for energy and industrial operators.
- OT and ICS
- GRC advisory
- Vulnerability mgmt
- IR and forensics
- IEC 62443
- NERC CIP
- NIST CSF
Castellan Information Security Services Inc.
Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.
- GRC advisory
- Audit and certification
- Pen testing
- IAM
- CPCSC
- CMMC
- PCI DSS
// faq
Common questions
Is the baseline enough?
It is a floor. It stops the most common attacks and gives you a defensible starting point, but organizations holding sensitive data or facing specific regulations need more.
What should we do first?
Multi-factor authentication on email and administrator accounts, then tested backups. Those two remove the most risk for the least cost.
Do we need to hire someone?
Not necessarily. Many small organizations use a managed service provider or a part-time adviser for the technical work and keep ownership inside the business.
// more hubs
Keep going
Windows hardening
An ordered path to harden Windows clients and servers, with the official baselines and documentation to build from.
CPCSC: Canadian Program for Cyber Security Certification
What the program is, how its three levels work, the 13 Level 1 controls, and how to prepare, drawn from the official government pages.
Privacy breach response in Canada
A practical sequence for handling a breach involving personal information, covering PIPEDA and Quebec Law 25 duties.