home / hubs / small-business-security-baseline

// resource hub

Small business security baseline

A 90-day plan built on the Canadian Centre for Cyber Security baseline controls for small and medium organizations.

For: Owners, office managers, and IT leads at organizations with fewer than 500 employees and no dedicated security staff. · Reviewed October 2026

The Canadian Centre for Cyber Security publishes baseline controls for small and medium organizations. They are short on purpose. The goal is to cover the basics that stop most attacks, not to build a full security program on day one.

This hub turns that list into a 90-day sequence. Do the first 30 days even if nothing else gets done.

A 90-day plan

  1. Days 1 to 30: stop the common attacksThese controls address the way most small organizations are actually breached.
    • Turn on multi-factor authentication for email, remote access, and every administrator account.
    • Enable automatic updates for operating systems, browsers, and business applications.
    • Back up important data to a copy that an attacker on your network cannot reach, and test a restore.
    • Make sure every device has current anti-malware and a firewall turned on.
    • List your systems, devices, and the data they hold. You cannot protect what you have not listed.
  2. Days 31 to 60: close the gapsMove from basics to configuration and access.
    • Configure devices securely, removing default accounts and unneeded software.
    • Give people the least access they need, and remove access when roles change.
    • Secure mobile devices and the connections people use outside the office.
    • Check that your cloud providers meet your security expectations, and review their certifications.
    • Review your website security, including updates, administrator accounts, and forms.
  3. Days 61 to 90: build the habitsControls decay without routines.
    • Write a one-page incident response plan with names, phone numbers, and the first steps.
    • Run security awareness training, and repeat it each year.
    • Protect portable storage media, or ban it.
    • Name an owner for security, even if it is a part of someone’s job, and set a quarterly review.
  4. Know your threat and your harmThe baseline asks you to understand what matters most.
    • Decide which systems would hurt most if they were unavailable, altered, or exposed.
    • Name the main threat you face, such as ransomware, fraud, or data theft.
    • Let leadership commit time and budget to the plan, because a baseline without sponsorship stalls.

// firms

Canadian firms that work on this

Firms whose own websites name CCCS baseline, CIS Controls or list closely related services. A listing is not an endorsement.

Full service · Greater Toronto Area, Ontario

3Tenets Consulting

Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.

  • Pen testing
  • AppSec
  • GRC advisory
  • IR and forensics
  • Privacy
  • NIST CSF
  • CIS Controls
  • ISO 27001
  • MITRE ATT&CK
  • OWASP
Specialist · Toronto, Ontario

Canadian Cyber

Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.

  • GRC advisory
  • Audit and certification
  • ISO 27001
  • SOC 2
  • CIS Controls
Focused · Ottawa, Ontario

CyberHunter Solutions

Penetration testing (web, network, cloud, mobile), threat hunting, protection and monitoring, vulnerability scanning and framework-based security assessments.

  • Pen testing
  • Vulnerability mgmt
  • GRC advisory
  • Cloud security
  • NIST CSF
  • CIS Controls
Full service · Toronto, Ontario

IRM Consulting & Advisory

Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.

  • GRC advisory
  • Audit and certification
  • Privacy
  • Pen testing
  • AppSec
  • +3
  • SOC 2
  • ISO 27001
  • CMMC
  • CIS Controls
  • GDPR
  • +3
Focused · Calgary, Alberta

Arista Cyber

Industrial cybersecurity firm for OT and ICS: risk assessments, gap analysis, IEC 62443 zone and conduit design, vulnerability assessments and incident response planning for energy and industrial operators.

  • OT and ICS
  • GRC advisory
  • Vulnerability mgmt
  • IR and forensics
  • IEC 62443
  • NERC CIP
  • NIST CSF
Focused · Winnipeg, Manitoba

Castellan Information Security Services Inc.

Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.

  • GRC advisory
  • Audit and certification
  • Pen testing
  • IAM
  • CPCSC
  • CMMC
  • PCI DSS

See all matching firms · How the directory works

// faq

Common questions

Is the baseline enough?

It is a floor. It stops the most common attacks and gives you a defensible starting point, but organizations holding sensitive data or facing specific regulations need more.

What should we do first?

Multi-factor authentication on email and administrator accounts, then tested backups. Those two remove the most risk for the least cost.

Do we need to hire someone?

Not necessarily. Many small organizations use a managed service provider or a part-time adviser for the technical work and keep ownership inside the business.