SAMPLE REPORT — fictional company, illustrative resultsThis is a sample report for a fictional company, prepared to show the format and depth of what you receive. The figures are illustrative.
Your readiness score by area, the gaps that carry the most risk today, what closes each one, and the next step we would recommend.
Sunco
Sunco Communication and Installation Ltd.
Connectivity & Network Readiness Assessment
Prepared for
Kestrel Fabrication Ltd.
 

Hello Ray Delacroix,

Thank you for completing the Sunco Connectivity & Network Readiness Assessment. Your personalized results are below.

Assessment completed: August 24, 2026

Your Score
43%
aligned · grade D
FRAGILE
Connectivity Signal
Fragile
One connection, no monitoring, and recovery measured in hours you cannot shorten
HOW THIS SCORE WAS CALCULATED
Your Connectivity Readiness Score is the share of the capabilities assessed here that your organization has in place. Each of the 24 questions scores 0 to 3, where 0 means the capability is fully in place and 3 means it is not, so your score is the share of the 72 available points you did not lose. Connectivity has no single controlling framework — no body publishes a numbered control set for whether a business internet connection is good enough. So this assessment cites something published and checkable on 19 of its 24 questions, and says so on the other five. Where a regulator or a standards body publishes on the subject, it is named: Telecom Regulatory Policy CRTC 2016-496 of the Canadian Radio-television and Telecommunications Commission (CRTC), which sets 50 Mbps download and 10 Mbps upload as the objective for business as well as residential subscribers; Recommendation G.114 of the International Telecommunication Union (ITU), which puts essentially transparent speech below 150 milliseconds of one-way delay; Controls 12 and 13 of the Critical Security Controls version 8.1 published by the Center for Internet Security (CIS), with the Implementation Group tier shown so a baseline expectation can be told from a target; and ISO 22301:2019 — ISO being the International Organization for Standardization — on determining the period the organization can tolerate being without an activity. Where nothing is published, an industry measurement takes its place and is labelled as one, and a measurement is never presented as a requirement. On the remaining five questions nothing published applies at all — your own outage history, application-level bandwidth visibility, how sites are linked, how quickly a location can be added, and whether there is one management view. Those are engineering and business judgement, the assessment says so on the page, and the recommendation on them is attributed to Sunco. Four questions were re-cast during this migration because they scored something other than readiness. Three of them scored a purchasing preference — who you buy support from, whether you lease or capitalise hardware, whether monitoring is internal or contracted — and one counted how many locations you operate and treated four as worse than one. Four more had a zero rung written as the specific product architecture our technology partner sells, so full marks required having already bought it; those now describe the capability, which more than one design can deliver. Answer options are shuffled so the scoring key cannot be inferred from position, except that a genuine “we are not sure” is always shown last. Band boundaries — above 85% and above 50% — are the Fully achieved and Largely achieved thresholds of the ISO/IEC 33020:2019 process achievement scale, jointly with the International Electrotechnical Commission (IEC); the letter grades within them are Sunco’s own subdivision and are not part of that standard. Six areas of four questions each means one answer moves a quarter of that area’s score, so read a single area percentage as direction rather than precision. The requirements panel is a checklist rather than a second score, deliberately. This assessment surfaces readiness gaps — it does not certify compliance with any standard, and it is not legal advice.
Section Breakdown
SectionAlignedRisk Level
Internet Reliability & Redundancy25%FRAGILE
Cloud Application Performance42%FRAGILE
Network Security & Business Protection58%Gaps to close
Multi-Location & Remote Work Readiness50%FRAGILE
Business Continuity & Operational Resilience17%FRAGILE
Scalability & Future Readiness67%Gaps to close
 
 
AT A GLANCE
1
in place
19
need work
4
high risk

Every answer you gave, sorted into three groups. Areas appear worst-first within each.

IN PLACE · 1
What you’re doing well
These capabilities are already in place. They are what makes the gaps below worth closing rather than starting over — and several of them are things most businesses this size do not have.
Scalability & Future Readiness1 of 4 · 67% aligned
Do you know what your next network hardware refresh will cost, and when it is due?
Yes — we know what is due, roughly what it costs, and it is in a plan.
NEEDS WORK · 19
What needs work
Partly in place, manual, or never tested. None of these are emergencies — but each one is something an outage, a new site or a busy Monday morning eventually exposes.
Business Continuity & Operational Resilience2 of 4 · 17% aligned
Does your business have a documented plan for maintaining operations during an internet outage?Partly in place
Your answer: We have an informal understanding of what we would do, but nothing documented or tested
A continuity plan that does not mention the internet is a plan that omits the most common disruption a modern business actually experiences. ISO 22301 asks for a response that is documented and exercised, in that order, and both halves are cheap here: the document is a page, and the exercise is unplugging something during a quiet hour. What makes this question worth asking is that most of the businesses that answer it badly already have a continuity plan — it just stops at fire and flood.
How Sunco closes this
An informal understanding works while the person holding it is available and the incident is the one they imagined. Writing it down is an hour, and the value is less the document than the argument it forces about which activities genuinely cannot wait.
ISO 22301:2019 — Business continuity management systems · Documented and exercised response procedures
The standard’s requirement is documented and exercised, in that order. An informal understanding held by whoever is in the office satisfies neither, and a general continuity plan that does not mention connectivity does not cover the failure that stops most of the work.
Source: ISO (2019)
If your primary internet connection failed right now, how quickly could you be back online?Partly in place
Your answer: Within a few hours — we would need to call our internet service provider (ISP) and wait for resolution or manual intervention
Recovery time is the operational measure of resilience, and the honest version of it includes the human steps: noticing, deciding, reaching somebody, waiting. The number that matters is not how fast recovery is in the abstract but whether it is inside the period the organization decided it could tolerate — which means a business that has never set that period cannot tell whether its recovery time is adequate.
How Sunco closes this
A few hours becomes a full day often enough that it should be planned for as a full day, because the clock is the carrier’s rather than yours. Maintaining a second path means the carrier’s response time stops being the business’s problem — it becomes a repair happening in the background.
ISO 22301:2019 — Business continuity management systems · Recovery within the period the organization has determined it can tolerate
The measure is not how fast recovery is in the abstract but whether it meets the period you set. Which means a business that has never set the period cannot tell whether its recovery time is adequate — it can only compare it with other businesses.
Source: ISO (2019)
Business Continuity & Operational Resilience: Resilience is a number before it is a design: how long you can operate without internet, decided and then built to.
Internet Reliability & Redundancy3 of 4 · 25% aligned
What happens to your business operations when your internet goes down?Partly in place
Your answer: Most operations stop — we cannot access cloud apps, email, or phone systems
This is the question that turns connectivity from a technical subject into a business one. The answer is a list — what stops, and for whom — and it is almost always longer than expected, because the connection now carries the phone system, the card terminal and the file everybody is working from as well as email. ISO 22301 asks an organization to determine the period it can tolerate being without an activity; this is where you find out which activities are on the list.
How Sunco closes this
When applications, email and phones all depend on one connection, they all have the same single point of failure — which means an outage is not an inconvenience in one system but a stop in all of them at once. A second path keeps them reachable while the first is repaired.
ISO 22301:2019 — Business continuity management systems · Determining the tolerable period of disruption before choosing controls for it
The standard asks for the period the organization can be without an activity, set deliberately, and then for a response built to meet it. What stops when the internet stops is how you find out which activities those are — and most businesses discover the list is longer than they expected.
Source: ISO (2019)
Have you experienced an internet outage in the last 12 months, and how long did it last?Partly in place
Your answer: Multiple outages, some lasting several hours
Past outages are the clearest predictor of future ones. This question moves the conversation from theoretical risk to real experienced pain — and begins the process of quantifying what that pain actually cost the business.
How Sunco closes this
Several multi-hour outages in a year is a pattern rather than bad luck, and the carrier or the local infrastructure causing it is unlikely to change on its own. The useful record is dates and durations — with three or four logged, the conversation with the carrier changes, and so does the case for a second path.
No published standard governs this question · Observed reliability — no standard governs what your carrier has actually delivered
No published standard sets how many outages is too many. This question exists because the record is the most persuasive input to any carrier conversation and almost nobody keeps it. The reading is Sunco’s: a pattern of multi-hour outages is a pattern, not luck.
When your internet fails, how long does it take to get working again — and who absorbs that time?Partly in place
Your answer: Hours, and it usually pulls in someone whose time is expensive.
The old version of this question scored who you buy from: an answer naming a managed provider was optimal and handling it yourself was a gap. That is a purchasing state, not a capability. What matters is the clock and who is on it — an internal team with a tested failover beats an outsourced one without, and a business owner personally chasing a carrier is expensive however the contract reads.
How Sunco closes this
The cost here is rarely the outage — it is a senior person spending an afternoon on hold instead of on their own work, repeatedly, with nothing recorded about how often. Worth counting the last three occurrences and who handled them before deciding what to change.
ISO 22301:2019 — Business continuity management systems · Recovery within the tolerable period, and by whom
ISO 22301 asks for a response that is documented, resourced and exercised. Who performs it is the organization’s choice and the standard is indifferent to it — an internal team with a tested failover satisfies the requirement as fully as an outsourced one, which is why this question asks about the clock rather than about the contract.
Source: ISO (2019)
Internet Reliability & Redundancy: A single connection is a single point of failure for everything the business does online, and it is the cheapest one to remove.
Cloud Application Performance3 of 4 · 42% aligned
How would you describe the performance of your cloud applications (Microsoft 365, Teams, Salesforce, your accounting or resource-planning system) during peak hours?Mostly in place
Your answer: Generally good, but we notice occasional slowdowns during busy periods
Cloud application performance during peak hours is the clearest signal of whether a network is optimized for cloud workloads or simply connected to the internet. Degradation at peak times indicates a lack of traffic prioritization — a gap that standard internet connections cannot address on their own.
How Sunco closes this
Occasional peak-hour slowdowns are what a connection does when nothing decides priority: a large file transfer and a voice call are treated identically. Quality-of-service configuration on a managed connection changes which one gives way, and it is a setting rather than a purchase.
Statistics Canada — Survey of Digital Technology and Internet Use, 2023 (industry measurement) · How much of the working day now depends on the connection
No standard governs application responsiveness. The measurement that frames it: cloud computing was the most commonly used information and communications technology among Canadian businesses in 2023, at 48% and rising — which means connection quality and application quality have become the same question. A measurement of what businesses have adopted, not a requirement.
Do your voice or video calls experience drops, delays, or quality issues?Mostly in place
Your answer: Occasionally — some calls are choppy or drop, but it is not a regular issue
Voice and video calls are the most sensitive applications on any network — they require consistent, low-latency bandwidth in both directions simultaneously. Standard internet connections have no mechanism to guarantee this. Dropped calls and poor quality are often the first visible symptom of a network that is not optimized for real-time traffic.
How Sunco closes this
Occasional call quality problems are easy to dismiss one at a time, and they are also the easiest thing here to measure properly: G.114 puts the delay budget for transparent speech below 150 milliseconds one way, and that is testable rather than a matter of opinion. Measure it during the busy hour rather than at nine in the morning, because the busy hour is when the calls that matter happen.
International Telecommunication Union — Recommendation ITU-T G.114 · One-way mouth-to-ear delay below 150 ms; 400 ms the general planning limit
G.114 puts essentially transparent interactivity for speech below 150 milliseconds one way, and 400 milliseconds as the upper limit for general network planning. This is the one question in the assessment with a published numeric threshold behind it, and it is testable rather than a matter of opinion.
Have you noticed your internet slowing down when multiple people are working simultaneously?Partly in place
Your answer: Yes — it is a known issue, especially at the start of the day or after lunch
Bandwidth contention — where multiple users compete for the same limited pipe — is the most common cause of cloud performance degradation in growing businesses. It is a symptom that the network is treating all traffic equally, with no mechanism to protect the most important applications during periods of high demand.
How Sunco closes this
Predictable congestion at the start of the day or after lunch is a capacity and prioritisation problem rather than a fact of business life. Because it is predictable, it is also measurable — which means the fix can be verified rather than hoped for.
Canadian Radio-television and Telecommunications Commission — Telecom Regulatory Policy CRTC 2016-496 · The universal service objective: at least 50 Mbps down and 10 Mbps up, business as well as residential
The Commission set 50 Mbps download and 10 Mbps upload with the option of an unlimited data allowance as the objective for Canadian fixed broadband subscribers, and said explicitly that it applies to business as well as residential subscribers. A connection that degrades when the office is full is either below that floor or unmanaged against it. Note the Commission did NOT set latency, jitter or packet loss thresholds in this decision — it referred those to its industry working group — so speed is the published part and quality is not.
Cloud Application Performance: Cloud applications and voice share the connection with everything else; whether anything decides the priority is a configuration choice somebody has either made or not.
Multi-Location & Remote Work Readiness4 of 4 · 50% aligned
How reliable is the connectivity between your locations — and would you know if one site was degraded right now?Mostly in place
Your answer: Consistent across sites, but we find out about a problem when somebody at that site tells us.
The old version of this question counted sites and scored the count, so a four-location business came out less ready than a one-location business for the crime of having four locations. What matters is whether the connection at each site performs the same way and whether a degraded site announces itself or waits for somebody there to complain. A single-site business answers this too: the site is either monitored or it is not.
How Sunco closes this
Performance is good and detection is manual, which means the measure of how well this works is how quickly somebody complains. That is fine until the affected site is the one with two people in it, or until the degradation is gradual enough that nobody attributes it to the network.
CIS Controls v8.1 · Control 12 · Safeguard 12.2 secure network architecture, including availability monitoring across network segments (Implementation Group 2)
The safeguard covers availability monitoring across segments, which is the requirement behind the second half of this question: whether a degraded site is visible to you or waits to be reported. Implementation Group 2, so above the CIS baseline.
How are your locations connected to each other — and do you know what changing or adding a site involves?Partly in place
Your answer: Sites are linked with tunnels over ordinary internet connections, and reliability varies.
The old version of this question scored the technology: software-defined connectivity was the right answer and dedicated circuits were a gap, even though the option describing them called them reliable. A reliable inter-site network is not a gap because of how it was built. What survives as a readiness axis is consistency plus a known path to change — because the cost that hurts when a site is added is almost never the equipment, it is the lead time nobody established in advance.
How Sunco closes this
Tunnels between every pair of sites multiply as sites are added, and each one is a separate thing to configure, monitor and fix. Connecting every site to a managed core instead means adding a location does not touch the others — which is the difference between growth being a project and being a task.
No published standard governs this question · How sites are linked is an engineering choice with no governing standard
No published standard prescribes dedicated circuits, tunnels or software-defined connectivity between locations. The recommendation is Sunco’s and it depends on what actually runs between the sites — which is worth measuring before choosing, because the right answer differs by workload.
What tools do remote workers use to access business applications and files?Mostly in place
Your answer: A corporate virtual private network (VPN) that most remote workers use, though some access cloud apps directly
The number of different ways remote staff reach business systems is a fair proxy for how deliberately that access was designed. When each person connects differently, security policy applies unevenly and the record of who reached what is partial in exactly the places it matters — which is usually discovered when somebody leaves and nobody can say with confidence what they can still open.
How Sunco closes this
Partial adoption is partial coverage. Staff going straight to cloud applications are outside whatever policy the network path applies, which means the audit trail has holes exactly where the sensitive work happens. Consistent access — applied per user rather than per network — closes the gap without making people work harder.
CIS Controls v8.1 · Control 12 · Safeguard 12.7 remote devices on a virtual private network, connected to enterprise authentication (Implementation Group 2)
The same safeguard as the remote access question in the previous layer, asked about consistency rather than existence: a standard that most people follow leaves the exceptions unmonitored, and the exceptions are where the sensitive work tends to happen.
Have remote connectivity issues affected staff productivity or customer service in the past year?Partly in place
Your answer: Yes — remote connectivity issues are a regular frustration that we work around
Remote connectivity problems that affect productivity or customer service represent real, quantifiable business costs — in staff frustration, delayed work, and customer experience. This question moves the conversation from hypothetical to experienced impact.
How Sunco closes this
A regular workaround is a cost that has been normalised — the business is paying for it in output and nobody is counting. Managed remote access with the same prioritisation as the office is the usual answer, and the improvement is measurable against the same complaints that prompted it.
Statistics Canada — Survey of Digital Technology and Internet Use, 2023 (industry measurement) · How many organizations now have staff working away from the office
28% of Canadian businesses offered staff the option to telework in 2023 — 23% of small businesses, 45% of medium-sized, 64% of large. A measurement of what businesses do, not a requirement: it says the population affected by remote connectivity quality is large and growing, not that any particular arrangement is correct.
Multi-Location & Remote Work Readiness: Multiple sites and remote workers are only as consistent as the least-managed connection among them.
Network Security & Business Protection4 of 4 · 58% aligned
Whatever protects the edge of your network — is it current, still supported by its vendor, and does somebody check?Mostly in place
Your answer: It is actively managed and updated on a regular schedule, but we have not checked whether the model is still supported.
The old version of this question asked whether you had a physical appliance and treated having one as the gap. An appliance patched on a schedule and still under vendor support meets the requirement completely; a cloud-managed service nobody reviews does not. So the question is about currency and support, not about hardware. The half most often missed is the second one: not whether the firmware is current, but whether the vendor still issues firmware for that model at all. Equipment past end of support does not get fixes, however diligently you apply them.
How Sunco closes this
An actively managed appliance is a reasonable position, and the ongoing cost is real: somebody has to track firmware, watch for end-of-support, and schedule the work. Cloud-managed security moves that maintenance off your team rather than removing the need for it, which is worth comparing against what the current arrangement costs in attention.
CIS Controls v8.1 · Control 12 · Safeguard 12.1 ensure network infrastructure is up to date (Implementation Group 1)
CIS places this at its Implementation Group 1 baseline — the tier it expects of the smallest organizations — and asks for software versions to be reviewed monthly or more frequently to verify the software is still supported. That second half is the part usually missed: the question is not only whether the firmware is current but whether the vendor still issues firmware for that model.
Is anything of yours reachable from the public internet that you did not intend to publish?Partly in place
Your answer: Yes — our office has a public address and we rely on the firewall to block what should not get through.
Most business connections are assigned a public address, which means automated scanners find them continuously — not because anybody targeted you, but because everything gets scanned. The measurable question is what those scans can reach: only the services you meant to publish, or the network behind them. Reducing what is reachable at all is the cheaper half of network security, because what cannot be reached does not have to be defended. There is more than one way to get there, which is why this question asks about the exposure rather than about the equipment.
How Sunco closes this
A public address is scanned continuously by automated tools, which means the firewall is the only thing between the business and whatever those scans find. Connecting sites through a private gateway instead reduces what is reachable at all, which is a smaller thing to defend than an exposed address behind a good rule set.
CIS Controls v8.1 · Control 12 · Safeguard 12.2 establish and maintain a secure network architecture (Implementation Group 2)
The safeguard asks for an architecture addressing segmentation, least privilege and availability. CIS places it above its Implementation Group 1 baseline, so reducing what is reachable from the public internet is a target rather than a minimum expectation — but it is the cheaper half of security, because what cannot be reached does not have to be defended.
How do remote employees connect securely to your business network and applications?Mostly in place
Your answer: Through a corporate virtual private network (VPN) — it works, though performance can be slow for remote users
Remote access is where security policy either applies or quietly stops applying. The measurable question is not whether there is a tunnel but whether access is granted centrally — because access that cannot be granted in one place cannot be withdrawn in one place either, and the day that matters is the day somebody leaves. The Center for Internet Security asks for remote devices to connect through a virtual private network into the organization’s own authentication, which is the second half rather than the first.
How Sunco closes this
A corporate virtual private network is genuine security and it often costs remote staff performance, because cloud traffic is pulled back through the office before going out again. Access that routes to cloud applications directly, with policy applied on the way, usually removes the performance penalty without loosening the control.
CIS Controls v8.1 · Control 12 · Safeguard 12.7 remote devices on a virtual private network, connected to enterprise authentication (Implementation Group 2)
CIS asks that remote devices connect through a virtual private network into the enterprise’s authentication and authorization infrastructure, at Implementation Group 2. The point is the authentication rather than the tunnel: access that cannot be centrally granted also cannot be centrally withdrawn.
Does your current network solution include active protection against distributed denial of service (DDoS) attacks, intrusion attempts, and unauthorized access?Mostly in place
Your answer: We have a firewall that provides some protection, but advanced threat detection is not in place
Network perimeter protection goes beyond a firewall. Modern threats include volumetric distributed denial of service (DDoS) attacks that can overwhelm a standard internet connection, intrusion attempts that probe for misconfigurations, and lateral movement attacks that exploit network access once a foothold is established. This question assesses the depth of the business's network security posture.
How Sunco closes this
Perimeter filtering blocks what it recognises. It does not detect an intrusion already inside or movement between systems, which is what the more serious incidents look like. Adding inspection and monitoring is a layer rather than a replacement — and note that CIS publishes no Implementation Group 1 safeguard in Control 13 at all, so this is a target above the baseline rather than part of it.
CIS Controls v8.1 · Control 13 · Network Monitoring and Defense — Safeguard 13.1 centralize security event alerting (Implementation Group 2)
Worth stating plainly: Control 13 publishes NO Implementation Group 1 safeguard at all. Everything in network monitoring and defence sits above the baseline CIS expects of the smallest organizations — 13.1 at Implementation Group 2, host-based intrusion prevention at Implementation Group 3. So this is a target, and an organization without it is not below a minimum.
Network Security & Business Protection: The perimeter is now wherever your people are, which changes what a firewall is for and how much of your network the public internet can see.
Scalability & Future Readiness3 of 4 · 67% aligned
How easily can your current network infrastructure support adding a new location or onboarding a significant number of new remote workers?Mostly in place
Your answer: With some effort — it requires information technology (IT) involvement and takes days to weeks to complete
Scalability is a forward-looking measure of network maturity. Businesses that can answer this question confidently have infrastructure designed for growth. Those that cannot have infrastructure that will eventually become a constraint on it.
How Sunco closes this
Days or weeks to bring a location or a group of people online is a real constraint, and it is usually two constraints wearing one coat: the configuration work, which is within your control, and the carrier lead time, which is not. Establishing the second one now — ask what notice a new circuit actually needs at the kind of address you would open — is what stops it becoming the reason a decision slips.
No published standard governs this question · How quickly you can add a location is a design outcome, not a controlled one
No standard governs provisioning time. The recommendation is Sunco’s: the constraint is usually the carrier lead time rather than anything in your control, which is worth establishing before a growth decision depends on it.
Is somebody watching your network — and do they find out about a problem before your staff do?Partly in place
Your answer: Somebody looks when there is a reason to, but nothing watches continuously.
The old version scored a third-party provider with a service level agreement as optimal and an internal team as a gap. Whether the watching is done in-house or bought changes nothing about whether it happens. The measurable thing is detection: monitoring that alerts somebody, versus finding out when the complaints start.
How Sunco closes this
Checking on demand tells you about the outage and nothing about the slow decline that precedes it. The gap between those two is where the "it has felt slow for months" conversations come from, and continuous monitoring is the cheapest layer in this assessment.
CIS Controls v8.1 · Control 13 · Safeguard 13.1 centralize security event alerting (Implementation Group 2)
CIS asks for alerting to be centralized so that events reach somebody. Whether the somebody is internal or contracted is outside the safeguard — which is why this question asks about detection rather than about who you buy from. Control 13 has no Implementation Group 1 safeguard, so this is a target above the baseline.
Does your current solution give you a single dashboard view of all your network connections, performance, and status?Mostly in place
Your answer: Partial visibility — we can see some metrics but not a unified view across all connections
Visibility and management simplicity are critical factors in network scalability. Businesses managing multiple connections, locations, and users across different tools and portals lose time, miss issues, and make slower decisions than those with a unified management view.
How Sunco closes this
Partial visibility means the connection you cannot see is usually the one with the problem. A single view across every site and connection is what turns a support call into a diagnosis, and it is also what lets you hold a carrier to what it sold you.
No published standard governs this question · A single management view is a preference with no standard behind it
No published standard requires one dashboard. The recommendation is Sunco’s, and the argument is practical: the connection you cannot see is reliably the one with the problem.
Scalability & Future Readiness: What it costs to add the next location, and when the current hardware runs out, are both knowable today.
HIGH RISK · 4
Your biggest risks
These are the answers we would address first. Most of them stop the business rather than slow it down, and the rest are the ones that make everything else harder to diagnose.
Business Continuity & Operational Resilience2 of 4 · 17% aligned
If a connection fails, does traffic move on its own — and has that been tested since it was set up?
Your answer: No automatic failover — if the connection goes down, we are down until it is fixed.
Automatic failover is what separates a link failure from an outage: something notices and moves the traffic before anybody is told. What performs it does not matter. What does matter, and what the old version of this question never asked, is whether it has been exercised since the day it was configured. ISO 22301 asks for a response that is documented AND exercised, in that order, and an untested failover is a plan wearing the clothes of a capability. Testing one is an afternoon.
How Sunco closes this
With no automatic failover, every link failure is an outage with a human recovery process attached, and the recovery takes about as long every time. Automatic failover across two carriers turns almost all of those events into a few seconds of degradation nobody reports — that is a real and measurable increase in uptime, and the mechanism is arithmetic: two paths that share no carrier and no cable do not usually fail together. What it does not cover is both paths failing at once, which is the reason the second one is chosen for its independence rather than its price.
ISO 22301:2019 — Business continuity management systems · Response procedures that are exercised, not only planned
ISO 22301 asks for the response to be exercised. Automatic failover that has never been tested since it was configured is a plan; the test is what makes it a capability, and it is cheap enough to do on a schedule.
Source: ISO (2019)
Have you calculated the actual hourly cost of internet downtime to your business?
Your answer: We have not thought about it in those terms
A business that has worked out what an hour of downtime costs it makes different connectivity decisions from one that has not — not braver ones, just decidable ones. ISO 22301 asks an organization to determine the period of disruption it can tolerate, and that determination needs a figure behind it. This is the question that asks whether one exists, and it is the only figure in this assessment nobody else can supply for you: the published per-hour downtime costs in circulation measure mid-size and large enterprises, and there is no equivalent for a business of thirty people.
How Sunco closes this
Without this figure there is no way to tell whether your current arrangement is prudent or reckless, and no way to size what should replace it. It is one calculation: people idle multiplied by their hourly cost, plus the revenue you could not take, for one hour. Then multiply by the length of your last outage. Nobody else can produce this number for you, which is exactly why it is worth producing.
ISO 22301:2019 — Business continuity management systems · Determining the tolerable period — which requires knowing the cost
The standard asks the organization to determine what it can tolerate. That determination needs a figure behind it, and this is the question that asks whether one exists. Without it, every resilience decision is preference rather than analysis.
Source: ISO (2019)
Business Continuity & Operational Resilience: Resilience is a number before it is a design: how long you can operate without internet, decided and then built to.
Internet Reliability & Redundancy1 of 4 · 25% aligned
How many separate internet connections does your business currently rely on?
Your answer: One connection — if it goes down, we are offline until it comes back
Businesses running on a single internet connection have zero redundancy. When that one connection fails — due to a carrier outage, a cut cable, or equipment failure — the entire business stops. This question surfaces whether a single point of failure exists before it becomes a real incident.
How Sunco closes this
One connection with nothing behind it means every online thing the business does shares a single failure. Two connections from different carriers, over different physical paths, turn most outages into a slowdown instead of a stop — and the reason to insist on different carriers is that the events which take one down usually do not take the other with it.
ISO 22301:2019 — Business continuity management systems · Redundancy for a single point of failure the organization has identified as critical
ISO 22301 does not mandate a second circuit. It asks the organization to determine whether it can operate without the first — and a single connection makes voice, email, applications and payments share one failure, which is the definition of the single point of failure the standard asks you to find. ISO records the standard as under systematic review.
Source: ISO (2019)
Internet Reliability & Redundancy: A single connection is a single point of failure for everything the business does online, and it is the cheapest one to remove.
Cloud Application Performance1 of 4 · 42% aligned
Do you have any visibility into which applications are consuming the most bandwidth on your network?
Your answer: None — we have no visibility into how our network bandwidth is being used
Visibility is the foundation of network management. Businesses without application-level visibility cannot prioritize their most important traffic, cannot identify what is causing congestion, and cannot make informed decisions about bandwidth investment. This question surfaces whether the network is managed or simply running on its own.
How Sunco closes this
With no visibility, every network problem is diagnosed from scratch and no dispute with a carrier can be supported with evidence. A dashboard showing which applications consume the bandwidth also settles the recurring argument about whether the connection is too small or simply unmanaged.
No published standard governs this question · What you choose to measure is a management decision
No standard requires application-level bandwidth visibility. The recommendation is Sunco’s, and it rests on a practical point rather than a compliance one: without it, the argument about whether the connection is too small or merely unmanaged cannot be settled with evidence.
Cloud Application Performance: Cloud applications and voice share the connection with everything else; whether anything decides the priority is a configuration choice somebody has either made or not.
⚡ Quick Wins — Act On These Now
 
Unplug the primary connection during a quiet hour and watch what happens. Write down how long traffic took to move and what did not come back on its own.
This is the difference between a configured failover and a tested one, and it is the cheapest test in this assessment. Typically an hour.
 
Work out one number: people idle multiplied by their hourly cost, plus the revenue you could not take, for one hour. Then multiply it by the length of your last outage.
Every resilience decision downstream is a preference until this figure exists. Typically half an hour.
 
Ask your carrier for the outage history on your circuit for the last twelve months, and start a one-line log from now on: date, how long, what stopped working.
The record is the most persuasive input to any carrier conversation and almost nobody keeps one. Typically under an hour.
 
Assessment Framework & Standards Alignment
 

Your answers have been read against what is actually published on business connectivity — one Canadian regulatory objective, one international technical standard, one security control set, one continuity standard, and one national measurement of what businesses have adopted.

CRTC 2016-496
Telecom Regulatory Policy — Modern telecommunications services
The Canadian universal service objective: at least 50 Mbps download and 10 Mbps upload with the option of an unlimited data allowance, stated to apply to business as well as residential subscribers. It sets no latency, jitter or packet loss threshold — those were referred to an industry working group — so speed is the published part and quality is not.
ITU-T G.114
One-way transmission time, International Telecommunication Union
The delay budget speech has to fit inside: below 150 milliseconds one way for essentially transparent interactivity, with 400 milliseconds the upper limit for general network planning. The one numeric threshold in this assessment that is testable rather than a matter of opinion.
CIS CONTROLS v8.1
Controls 12 and 13, from the Center for Internet Security
Network infrastructure management and network monitoring and defence. Each safeguard carries an Implementation Group tier, which this assessment shows: Control 12’s currency safeguard is a baseline expectation of the smallest organizations, while Control 13 publishes no baseline safeguard at all, so everything in monitoring is a target rather than a minimum.
ISO 22301:2019
Business continuity management systems
Asks the organization to determine the period it can tolerate being without an activity, then to build, document and exercise a response that meets it. Applied to connectivity that is a short and answerable question most businesses have never answered.
Source: ISO (2019)
STATISTICS CANADA
Survey of Digital Technology and Internet Use, 2023
What Canadian businesses have actually adopted — cloud computing at 48%, telework offered by 28% — used here as a measurement of the population this affects, never as a requirement. A measurement of what is, not of what should be.

This assessment surfaces readiness gaps and does not certify compliance with any standard. Five of its twenty-four questions have no published standard behind them at all, and say so where they are asked — the recommendation on those is Sunco’s.

Indicative Connectivity Spend Snapshot
See how you stand against published figures
Everything here is either a published figure with its reference period, or one of your own. No prices, nothing estimated, and no arithmetic across two unsourced numbers — which is what the previous version of this calculator did, multiplying a downtime-hours figure that no publication carries by a per-minute cost that no publication carries.
The figures below use typical values for a business of about this size, because the snapshot was left unfilled. Re-run it with your own numbers for a comparison that reflects your organization.
What the alternatives cost
Your spend across 50 users$125 per user / month
 
One computer network technician in Alberta, fully loaded$105,000
That one hire, expressed the way you buy connectivity$175 per user / month
You spend about $125 per user per month on internet and network. One fully loaded computer network technician in Alberta is about $105,000 a year — $175 per user per month across your 50 people, for one person’s salary, and a person cannot be a second carrier. The figure worth putting beside both is what your last outage actually cost you, which is a question this assessment asks and no publication can answer for you.
How that compares with what is published
Canadians who can get internet at the universal service objective — 50 Mbps down, 10 Mbps up, unlimited dataover 96%
Data year 2024. A site that cannot reach 50/10 is in a shrinking minority, which makes it worth checking rather than assuming. A population figure — the regulator reports business and home fixed internet together.
Subscribers on plans faster than 50 Mbpsover 85%
And nearly 90% of households can reach gigabit speeds. Data year 2024, residential-weighted.
Canadian businesses using cloud computing48%
The most commonly used technology measured, up from 45% in 2021 — which is why connection quality and application quality have become the same question. Reference year 2023.
Canadian businesses offering staff the option to telework28%
23% of small businesses, 45% of medium-sized, 64% of large. Every one of those arrangements runs part of the working day over a connection the business does not control.
What an hour of downtime costs a business this sizenot published
The widely quoted figures — above $300,000 an hour for more than 90% of firms — come from a survey of over 1,000 mid-size and large enterprises worldwide. No equivalent exists for a thirty-person Alberta business, so this snapshot does not invent one. What your last outage cost you is the number worth bringing to the conversation.

Indicative comparison based on published figures and your own. Numbers are rounded and intended to frame a conversation, not to predict your costs. What the right network costs for your environment depends on your sites and your carriers.

Sunco’s Recommendation
Fragile: One connection, no monitoring, and recovery measured in hours you cannot shorten.
Book Your Connectivity Review

A Sunco advisor will walk through your results and identify the highest-impact next steps for your organization.

Book Your Review →
30 minutes • Free • No obligation
Research Sources and Methodology

Every figure and framework reference in this report is listed below with a link to the original source, so you can verify any of it yourself.

Canadian Radio-television and Telecommunications Commission — Telecom Regulatory Policy CRTC 2016-496 — Modern telecommunications services
The universal service objective: Canadian residential AND BUSINESS fixed broadband subscribers can access speeds of at least 50 Mbps download and 10 Mbps upload, with the option of an unlimited data allowance. The Commission did not set latency, jitter or packet loss thresholds in this decision, referring those metrics to its industry working group.
Tier 1 source · Canada · verified 2026-08-24
International Telecommunication Union — Recommendation ITU-T G.114 (05/2003) — One-way transmission time
One-way mouth-to-ear delay below 150 ms gives essentially transparent interactivity for speech; 400 ms is the recommended upper limit for general network planning.
Tier 1 source · International · verified 2026-08-24
Center for Internet Security — CIS Critical Security Controls v8.1 — Control 12, Network Infrastructure Management
Safeguard 12.1, ensure network infrastructure is up to date, sits at Implementation Group 1 and asks for software versions to be reviewed monthly or more frequently to verify support. 12.2 secure network architecture, 12.5 centralized network authentication and 12.7 remote devices on a virtual private network connected to enterprise authentication all sit at Implementation Group 2.
Tier 1 source · International · verified 2026-08-24
Center for Internet Security — CIS Critical Security Controls v8.1 — Control 13, Network Monitoring and Defense
Control 13, Network Monitoring and Defense, publishes no Implementation Group 1 safeguard at all; 13.1 centralize security event alerting is Implementation Group 2 and 13.7 host-based intrusion prevention is Implementation Group 3.
Tier 1 source · International · verified 2026-08-24
ISO — ISO 22301:2019 — Security and resilience, Business continuity management systems, Requirements
Requirements for a business continuity management system — determining the tolerable period of disruption for an activity, then planning, exercising and maintaining a response to it. ISO records the standard as under systematic review.
Tier 1 source · International · verified 2026-08-24
Statistics Canada — Survey of Digital Technology and Internet Use, 2023
Cloud computing was the most commonly used information and communications technology among Canadian businesses in 2023, at 48%, up from 45% in 2021. 28% of businesses offered employees the option to telework — 23% of small businesses, 45% of medium-sized and 64% of large.
Tier 1 source · Canada · verified 2026-08-24
IBM / Ponemon Institute — Cost of a Data Breach Report 2026 (Canada release)
The average cost of a data breach in Canada reached CA$7.11 million, taking an average of 205 days to detect and contain. The sample is enterprise-weighted, so the direction is more informative than the figure for a small business.
Tier 2 source · Canada · verified 2026-08-24
ISO/IEC — ISO/IEC 33020:2019 — Process measurement framework for assessment of process capability
Achievement scale: Not achieved ≤15%, Partially achieved >15–50%, Largely achieved >50–85%, Fully achieved >85%. Source of this assessment’s band thresholds.
Tier 1 source · International · verified 2026-08-24
Canadian Radio-television and Telecommunications Commission — Canadian Telecommunications Market Report 2026
More than 96% of Canadians have access to Internet at the universal service objective level; over 85% subscribe to speeds over 50 Mbps; nearly 90% of households have access to gigabit speeds. Data year 2024. The report tracks retail business and home fixed Internet together and its detail is residential, so these are population and subscriber figures rather than business ones.
Tier 1 source · Canada · verified 2026-08-24
Information Technology Intelligence Consulting — ITIC 2024 Hourly Cost of Downtime Report, Part 1
The average cost of a single hour of downtime exceeds $300,000 for over 90% of mid-size and large enterprises, and 41% put it between $1 million and over $5 million. Over 1,000 firms surveyed globally between November 2023 and mid-March 2024. Measures mid-size and large enterprises — not small business.
Tier 2 source · International · verified 2026-08-24
Employment and Social Development Canada / Statistics Canada — Job Bank — Wages, Computer network technician (NOC 22220), Alberta
Computer network technician, National Occupational Classification 22220, Alberta: median wage $38.67 an hour, low $21.00, high $55.00. Reference period 2023–2024, Labour Force Survey.
Tier 1 source · Alberta · verified 2026-08-24

Statistics are reproduced as published by the sources above and were verified on the dates shown. Regulatory positions reflect the law in force at the time of verification and may change. This assessment surfaces readiness gaps and does not certify compliance with any standard; consult qualified counsel regarding your specific obligations.

Sunco
Sunco Communication and Installation Ltd.
18961 111 Ave NW, Edmonton, AB T5S X4
1-866-310-7007  |  marketingteam@sunco.ca  |  sunco.ca

© 2026 Sunco Communication & Installation Ltd. All rights reserved.