 Sunco Communication and Installation Ltd. IT Support & Cyber Insurance Readiness Assessment Prepared for Northgate Millwork Ltd. |
Hello Dana Whitfield, Thank you for completing the Sunco IT Support & Cyber Insurance Readiness Assessment. Your personalized results are below. Assessment completed: August 24, 2026 |
Your Score 54% aligned · grade C | | Insurability Signal Coverage at Risk Gaps an insurer would question or exclude |
|
HOW THIS SCORE WAS CALCULATED Your Cyber Readiness Score is the share of the practices assessed here that your organization has in place. Most map to the Critical Security Controls v8.1 published by the Center for Internet Security (CIS) — to a named Safeguard where one fits and to the control itself where none does, with the reference shown beside the question. One maps to statute rather than to a framework and cites it directly. The remainder cover IT service capacity, planning and insurance context, which no security framework publishes a control for, and those carry no reference rather than an invented one. Where CIS places a safeguard above its Implementation Group 1 baseline — the tier it expects of the smallest organizations — the question says so, because a target and a minimum are different things. Each of the 34 questions scores 0 to 3, where 0 means the practice is fully in place and 3 means it is not, so your score is the share of the 102 available points you did not lose. Answer options are shuffled so the scoring key cannot be inferred from position, except that an “I’m not sure” option is always shown last. Band boundaries — Low Exposure above 85%, Moderate Gaps above 50% — are the Fully achieved and Largely achieved thresholds of the ISO/IEC 33020:2019 process achievement scale — ISO/IEC being the joint International Organization for Standardization and International Electrotechnical Commission — ISO/IEC being the joint International Organization for Standardization and International Electrotechnical Commission; the letter grades within them are Sunco’s own subdivision and are not part of that standard. The control alignment panel is a checklist rather than a second score, deliberately: two competing numbers on one page tell a reader less than one number and a clear list. This assessment surfaces readiness gaps — it does not certify compliance with any standard and is not a substitute for an insurance application. |
Section Breakdown | Section | Aligned | Risk Level | | IT Team Capacity & Service Coverage | 58% | Moderate Gaps | | Cybersecurity & Threat Protection | 45% | CRITICAL GAPS | | Backup, Recovery & Business Continuity | 50% | CRITICAL GAPS | | IT Documentation & Institutional Knowledge | 73% | Moderate Gaps | | Incident Response & Security Awareness | 61% | Moderate Gaps | | Strategic IT Planning & Long-Term Capacity | 42% | CRITICAL GAPS |
|
AT A GLANCE 5 in place | 26 need work | 3 high risk |
Every answer you gave, sorted into three groups. Domains appear worst-first within each. |
IN PLACE · 5 What you’re doing well These controls are already in place. They are what an underwriter wants to see, and they are the reason the gaps below are worth closing rather than starting over. |
| Cybersecurity & Threat Protection | 1 of 11 · 45% aligned |
How does your organization segment its internal network — separating guest Wi-Fi, operational systems, and corporate systems from one another? Our network is segmented with separate VLANs (Virtual Local Area Networks) or zones for guest, corporate, and operational systems — monitored and enforced by our MSP or IT provider |
| IT Team Capacity & Service Coverage | 1 of 4 · 58% aligned |
Does your business have a documented, tested IT ticketing and escalation process with defined response time targets? Yes — we use a professional ticketing platform with defined SLAs (Service Level Agreements) and regular reporting |
| Incident Response & Security Awareness | 1 of 6 · 61% aligned |
Does your organization currently carry cyber liability insurance, and do you know your coverage limits, exclusions, and renewal date? Yes — we carry a current cyber liability policy and know our coverage limits, key exclusions, and renewal date |
| IT Documentation & Institutional Knowledge | 2 of 5 · 73% aligned |
Where are your organization's administrative credentials stored — for Microsoft 365, network devices, servers, and line-of-business applications? All credentials are stored in a shared, audited, organization-owned password vault with access controls |
How does your organization manage software licenses, vendor agreements, and IT service contracts — and who owns that knowledge? All vendor agreements and licenses are documented in a central system with ownership, renewal dates, and contacts |
|
NEEDS WORK · 26 What needs work Partly in place, informal, or not documented. None of these are emergencies — but each one is something an insurer, an auditor, or an incident would eventually expose. |
| Strategic IT Planning & Long-Term Capacity | 3 of 4 · 42% aligned |
| Does your organization have a documented technology roadmap connecting IT investment to business objectives over the next 1–3 years? | Mostly in place |
Your answer: We have informal plans but nothing documented or systematically reviewed A roadmap is what makes technology decisions comparable to one another. Without one, each decision is made in isolation and against whatever budget happens to be available that quarter — reasonable individually, and collectively producing duplicated tools, deferred replacements and a fragmented environment. How Sunco closes this Informal IT planning works in the short term and fails in the medium term. Without documentation, plans aren't held to account, priorities shift without visibility, and IT investment decisions get made without the context of what was decided previously. |
|
| Does your organization keep track of which outside providers have access to your systems or data — and who inside the business owns each relationship? | Mostly in place |
Your answer: We know who our providers are, but there is no list and nobody formally owns reviewing it Third-party involvement reached 48% of breaches in Verizon’s 2026 Data Breach Investigations Report, up 60% in a single year — the largest movement in that report. Worth being precise about the bar, though: CIS asks at its Implementation Group 1 baseline for an inventory of your service providers, classified by the access they hold, with a named internal contact for each and an annual review. Putting security requirements into their contracts is one tier up, and formally assessing them with questionnaires or third-party audit reports is two tiers up. So the baseline really is just knowing who they are and who owns them — which is worth saying plainly, because most businesses assume the bar is higher and answer as though they have already failed. How Sunco closes this Knowing them informally covers you until somebody leaves or a contract lapses unnoticed. Writing the list down with an owner against each one is the whole of the Implementation Group 1 ask, and it is the thing an insurer's supply-chain question is actually looking for. |
CIS Controls v8.1 · Control 15 · Service Provider Management (Safeguard 15.1, Implementation Group 1) Is there an inventory of service providers, classified, with a designated enterprise contact for each, reviewed annually? |
|
| How does your organization track and plan for hardware, operating systems and software reaching end of support — the point at which the vendor stops issuing security updates? | Partly in place |
Your answer: We replace hardware and software when it fails or when a vendor forces the issue Windows 10 mainstream support ended on 14 October 2025. A machine not enrolled in Microsoft’s Extended Security Updates programme receives no security fixes at all, and every vulnerability found after the end-of-support date stays open on it permanently. Extended Security Updates are a time-limited bridge rather than a substitute for replacement: the consumer programme runs to 12 October 2027, and commercial coverage is paid and renewable yearly to a maximum of 10 October 2028. Unsupported software is among the exclusions named on cyber liability policies, so what matters for an application is knowing which of your machines are enrolled, which are replaced, and which are neither. How Sunco closes this Replacing on failure means the decision is made during an outage, at whatever price is available that week. It also means you are running unsupported software for some period every cycle, which is the period an application question about end-of-life software is reaching for. |
CIS Controls v8.1 · Control 2 · Inventory and Control of Software Assets (Safeguard 2.2 — ensure authorised software is currently supported, Implementation Group 1) Does the organization maintain an inventory of authorised software, and remove or document unsupported software? |
|
| Strategic IT Planning & Long-Term Capacity: Sunco provides Strategic Planning services — a documented one-to-three-year technology roadmap, annual budget planning, vendor governance and alignment of IT investment to operational priorities — so that technology spending serves the business plan rather than reacting to whatever broke most recently. |
| Cybersecurity & Threat Protection | 8 of 11 · 45% aligned |
| How does your organization monitor its IT systems for security threats outside of business hours? | Partly in place |
Your answer: Our IT team monitors during business hours — we accept the after-hours gap Ransomware appeared in 48% of breaches in Verizon’s 2026 Data Breach Investigations Report, and it is the costliest claim type an insurer sees — averaging a US$269,000 loss across Coalition’s global claims book in 2025. Worth disclosing the bar: CIS places network monitoring entirely at Implementation Groups 2 and 3, with no Implementation Group 1 safeguard, so a 24/7 monitored service is a step beyond the small-business baseline rather than part of it. A team monitoring only during business hours has no visibility into the nights and weekends when attackers move laterally, escalate privileges and stage data for exfiltration. Detection time is what decides the size of an incident: IBM puts the average breach lifecycle at 247 days in 2026, and breaches that run long cost materially more than those contained early. How Sunco closes this Accepting an after-hours monitoring gap means accepting that anything starting after the team logs off has until morning before anyone looks. For most businesses, the cost of that gap is not something they've consciously decided to accept. |
CIS Controls v8.1 · Control 13 · Network Monitoring and Defense Is security event activity monitored and alerted on across the enterprise, including outside working hours? |
|
| How are your endpoint security tools — EDR (Endpoint Detection and Response) and antivirus — managed, and are they set to block threats rather than only record them? | Mostly in place |
Your answer: Our IT team manages EDR alongside their other responsibilities — we check in periodically EDR is commonly deployed in detect-only mode during rollout so that it cannot break anything, and then never switched over to blocking — logging threats without blocking them. This is one of the most common gaps in organizations where IT teams are stretched: the tool exists, it appears to be working, but it's not actually protecting. CIS places centrally managed anti-malware (Safeguard 10.6) at Implementation Group 2 rather than at its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations. How Sunco closes this Periodic management of EDR means threats detected between check-ins go unresponded. EDR requires continuous oversight — alert triage, policy updates, and incident response. A stretched IT team will always have something more urgent than EDR maintenance. |
CIS Controls v8.1 · Control 10 · Malware Defenses Is anti-malware software centrally managed, kept updated, and configured to act rather than only to log? |
|
| How do employees and IT staff access company systems remotely — and is Remote Desktop Protocol (RDP) exposed directly to the internet? | Partly in place |
Your answer: We use RDP for remote access — it may be accessible from the internet without specific restrictions in place Coalition’s Cyber Threat Index 2025 found that 58% of ransomware claims in 2024 began with a compromised perimeter security appliance — a virtual private network (VPN) or firewall — with remote desktop products second at 18%. Stolen credentials (47%) and software exploits (29%) were the most common initial access vectors overall. These are global claims figures rather than Canadian ones, but the control they point at is the same: an organization with multi-factor authentication (MFA) enforced and Remote Desktop Protocol (RDP) still reachable from the internet has left open a door that bypasses it. CIS places remote access over a virtual private network (Safeguard 12.7) at Implementation Group 2 rather than at its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations. How Sunco closes this Exposed RDP was the second most common ransomware entry point in Coalition’s 2024 claims at 18%, behind compromised perimeter appliances — and it is the easier of the two to close. Attackers scan the internet for exposed RDP ports continuously; a single unprotected session is enough. This is a critical gap and one of the fastest to shut. |
CIS Controls v8.1 · Control 12 · Network Infrastructure Management (Safeguard 12.7) Do remote devices connect over a virtual private network into managed authentication, rather than exposing a service directly to the internet? |
|
| How does your organization enforce and maintain Multi-Factor Authentication (MFA) across all users and systems? | Mostly in place |
Your answer: MFA is in place for most systems — we address gaps when we find them Microsoft Research measured multi-factor authentication reducing the risk of account compromise by 99.22% across the accounts it studied, and 98.56% where the credentials had already leaked. It is the highest-value single control most organizations can deploy. But coverage erodes without oversight — new accounts, onboarding exceptions and system changes create gaps that accumulate quietly — and an insurer asks about your coverage, not about whether MFA exists somewhere. How Sunco closes this Reactive MFA management means gaps exist between discoveries. A credential that bypasses MFA — even temporarily — is an open door. Active MFA governance means no exceptions go unreviewed and every new system or user is covered from day one. |
CIS Controls v8.1 · Control 6 · Access Control Management Is multi-factor authentication required for externally-exposed applications, remote access, and all administrative access? |
|
| How does your organization manage, control, and audit privileged access — administrator accounts with elevated permissions across your systems and infrastructure? | Partly in place |
Your answer: Admin accounts are shared or not formally managed — access is rarely reviewed or revoked when no longer needed Privileged accounts are the keys to your entire IT environment. Domain admin credentials, server administrator accounts, and cloud service root access are the primary targets in advanced attacks — and the entry point for the most damaging breaches. Worth disclosing the bar here too: CIS asks at its baseline tier only that administrative privileges are restricted to dedicated administrator accounts (Safeguard 5.4). Just-in-time provisioning and session recording sit above that baseline, so the top answer below is a target rather than the minimum. PAM (Privileged Access Management) is distinct from MFA: MFA verifies identity, but PAM controls what privileged identities can access, for how long, and under what conditions. How Sunco closes this Unmanaged privileged access is one of the most exploited gaps in small and medium-sized business environments. Shared admin credentials mean any compromise exposes your entire environment. Credentials not revoked when staff leave create persistent insider-threat exposure. Privileged access is an area cyber applications have begun to ask about specifically. |
CIS Controls v8.1 · Control 5 · Account Management (Safeguard 5.4) Are administrative privileges restricted to dedicated accounts, and is their use reviewed? |
|
| How does your organization manage software patching and security vulnerability remediation across all systems and devices? | Mostly in place |
Your answer: We patch regularly but have no defined timelines — critical patches are applied when the team gets to them Exploitation of a known vulnerability became the leading initial access vector in Verizon’s 2026 Data Breach Investigations Report, appearing in 31% of breaches — the first time in nineteen editions that it has passed stolen credentials. CIS asks for automated patching of operating systems and applications on a monthly cycle at its baseline tier (Safeguards 7.3 and 7.4), so anything faster is above the baseline rather than part of it. A team patching alongside a full support workload will always have systems further behind than it realises, and attackers scan continuously for exactly those. How Sunco closes this Without defined patch timelines, critical vulnerabilities stay open days or weeks longer than they should. Exploitation of a known vulnerability is now the leading route into a breach, which tells you how fast that window closes. A managed patch process with defined service levels closes this window without adding to your team's workload. |
CIS Controls v8.1 · Control 7 · Continuous Vulnerability Management (Safeguards 7.3 and 7.4) Is automated patch management applied to operating systems and applications on at least a monthly cycle? |
|
| How does your organization protect against email spoofing, phishing, and Business Email Compromise (BEC) attacks? | Mostly in place |
Your answer: SPF, DKIM and DMARC are configured, but DMARC is in monitor mode only — or we have not verified that the records are correct for our domain Business Email Compromise (BEC) accounted for US$3.05 billion in reported losses in 2025 — on our reading of its category list, the largest business-targeted fraud category the FBI’s Internet Crime Complaint Center (IC3) tracks, second overall only to investment fraud, and far above the US$32 million reported for ransomware. IC3’s ransomware figure counts reported extortion payments only, not downtime or recovery, so read it as a floor rather than a total cost. The three foundational email authentication standards — SPF, DKIM and DMARC, which together let a receiving mail server verify that a message really came from your domain — are consistently misconfigured or absent in smaller environments, leaving organizations exposed to impersonation that bypasses security awareness training entirely. A distinction most businesses miss: DMARC set to ‘monitor’ collects reports but blocks nothing. Only ‘quarantine’ or ‘reject’ enforcement actually prevents impersonation, and some insurers now ask which mode you are in. CIS places implementing DMARC (Safeguard 9.5) at Implementation Group 2 rather than at its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations. How Sunco closes this This is the most common position, and the one that feels finished without being finished. DMARC in monitor mode collects reports and blocks nothing: only quarantine or reject actually stops a message that fails authentication. Moving from monitor to enforcement is a staged change — you watch the reports, fix the legitimate senders they surface, then tighten — and it is the step that turns three configured records into a control. |
CIS Controls v8.1 · Control 9 · Email and Web Browser Protections (Safeguard 9.5, Implementation Group 2) Is DMARC implemented? CIS asks for DMARC but does not specify a policy mode — moving from monitor to quarantine or reject is Sunco’s recommendation, and is what some insurers now ask about. |
|
| Are the laptops, desktops and mobile devices your staff use encrypted, so that a lost or stolen device does not expose the data on it? | Partly in place |
Your answer: Some devices are encrypted — it depends who set them up and when CIS puts encryption of end-user devices at Implementation Group 1 — the baseline it expects of the smallest organizations, not an advanced control. It also matters directly under Canadian privacy law: when the Office of the Privacy Commissioner sets out how to assess whether a breach creates a real risk of significant harm, one of the questions it asks is whether the personal information was “adequately encrypted, anonymized or otherwise not easily accessible”. Encryption is not a safe harbour. You still have to make and defend that assessment, and where PIPEDA (the Personal Information Protection and Electronic Documents Act) applies to you it requires a record of every breach whether or not it turns out to be notifiable — Alberta’s own Personal Information Protection Act (PIPA) requires notice to the provincial Commissioner where the real-risk threshold is met. But on a laptop left in a taxi, encryption is often the difference between an incident and a notification. How Sunco closes this This usually means devices issued before a certain date, or set up by a different person, are unprotected — and nobody knows which. Enforcing encryption by policy rather than at setup time is what closes it for the devices you have not thought about — including the ones bought before anyone was checking. |
CIS Controls v8.1 · Control 3 · Data Protection (Safeguard 3.6, Implementation Group 1) Is data on end-user devices containing sensitive data encrypted? |
|
| Cybersecurity & Threat Protection: Sunco's managed security stack provides round-the-clock monitoring from a Security Operations Centre, active endpoint threat blocking, dark web credential scanning and enforced multi-factor authentication — running continuously alongside your internal team so your staff can focus on the business while Sunco maintains vigilance. |
| Backup, Recovery & Business Continuity | 4 of 4 · 50% aligned |
| How does your organization verify that backups are actually restorable — not just that backup jobs are completing successfully? | Partly in place |
Your answer: We manage backups internally — we check logs regularly but haven't tested actual restores A backup job that reports success is not a restore that works. Veeam’s 2026 resilience report found organizations recovered an average of 72% of their affected data after a ransomware attack, with 44% recovering less than three quarters of it — while 90% had been confident beforehand. Backup jobs fail quietly, particularly after a system change or a migration, and the distance between those two numbers is exactly what a restore test closes. CIS places restore testing (Safeguard 11.5) at Implementation Group 2 rather than at its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations. How Sunco closes this A successful backup log confirms the job ran — not that the data is recoverable. Silent backup failures are extremely common, particularly after system changes or configuration drift. Without restore testing, you don't know your backups work until you need them. |
CIS Controls v8.1 · Control 11 · Data Recovery (Safeguard 11.5) Is data recovery tested on a defined schedule, with the result recorded? |
|
| How is your organization's Microsoft 365 data — emails, Teams, SharePoint, and OneDrive — backed up and protected? | Partly in place |
Your answer: We rely on Microsoft's native retention features for M365 data protection Microsoft’s shared responsibility model places protection of customer data with the customer, and Microsoft recommends that customers keep their own backups. Native retention is not a backup: deleted Exchange Online items are held 14 days by default and 30 at most, and SharePoint and OneDrive recycle bins hold deleted items for 93 days in total. After that the data is gone. Microsoft does sell a first-party backup add-on, but it is billed separately and is not enabled by default. How Sunco closes this Retention is not backup, and the window is shorter than most people assume: deleted Exchange Online items are kept 14 days by default and 30 at most, while SharePoint and OneDrive recycle bins hold deleted items 93 days in total. After that the data is gone. Microsoft’s own shared responsibility model places protection of your data with you, and Microsoft recommends you keep your own backups. |
CIS Controls v8.1 · Control 11 · Data Recovery Is data held in cloud services backed up independently of the provider’s own retention? |
|
| Does your organization have a documented Business Continuity and Disaster Recovery plan, and is it tested regularly? | Mostly in place |
Your answer: We have a BC/DR plan but it hasn't been tested or updated recently Business continuity and disaster recovery planning is a distinct capability rather than something bundled with routine IT support, which is why it is one of the most common gaps an insurer finds. A plan that has never been exercised is a document, not a capability. How Sunco closes this An untested BC/DR (Business Continuity and Disaster Recovery) plan that doesn't reflect current systems is a false sense of security. Plans become stale quickly — particularly after technology changes, staff turnover, or business growth. An untested plan is likely to fail at the worst possible moment. |
CIS Controls v8.1 · Controls 11 and 17 · Data Recovery and Incident Response Management Is there a documented recovery plan, and has it been exercised rather than only written? |
|
| Does your organization have defined Recovery Time Objectives (RTOs) — and does your IT setup support meeting them? | Mostly in place |
Your answer: We have informal recovery expectations but no formally defined or tested RTOs Recovery Time Objectives define how long the business can tolerate being down after an incident. Without defined RTOs, recovery becomes an open-ended event — and the business has no way to evaluate whether its backup and recovery infrastructure is adequate. How Sunco closes this Informal recovery expectations provide no accountability and no basis for infrastructure planning. The business should know its RTO before it needs it — not discover it during an active incident when every hour of downtime has a direct cost. |
CIS Controls v8.1 · Control 11 · Data Recovery Are recovery objectives defined for critical systems, and does the infrastructure demonstrably meet them? CIS does not publish a safeguard defining recovery time objectives; Control 11 is the nearest applicable control and is shown as such. |
|
| Backup, Recovery & Business Continuity: Sunco provides managed backup with scheduled restore testing, full Microsoft 365 (M365) data protection with point-in-time recovery, and defined Recovery Time Objectives — taking backup ownership off your IT team so they can spend their time on work that needs their expertise. |
| IT Team Capacity & Service Coverage | 3 of 4 · 58% aligned |
| How does your IT team currently handle support requests when volume spikes, key staff are unavailable, or multiple issues arise simultaneously? | Mostly in place |
Your answer: We manage as best we can — some things wait when the team is stretched One of the clearest indicators of IT team strain is what happens during peaks. When a single person's absence creates a backlog, or simultaneous issues mean something critical waits, the team is operating without redundancy — and the business absorbs the cost. How Sunco closes this Reactive management during peaks means unpredictable service levels. Business-critical systems waiting for attention during a busy period or a staff absence represents real operational risk — and compounds over time as the team's workload grows. |
|
| How often does day-to-day support and break-fix work crowd out your IT team's capacity for proactive improvements and strategic projects? | Partly in place |
Your answer: Often — strategic projects regularly get pushed back or abandoned This is one of the most telling measures of IT team health. Teams spending the majority of their time on reactive work are effectively trapped — unable to invest in the improvements that would reduce that reactive load, creating a self-reinforcing cycle. How Sunco closes this When strategic work is regularly deferred, technical debt accumulates and the team's ability to contribute at a higher level erodes. A managed service provider absorbing routine support load can restore the capacity your team needs. |
|
| How does your business ensure IT support coverage outside of standard business hours — evenings, weekends, and holidays? | Partly in place |
Your answer: We have no after-hours IT coverage — issues wait until the next business day Business systems don't stop operating at 5pm — and neither do the threats and failures that affect them. For businesses that operate beyond standard hours, or whose systems are accessed remotely, after-hours IT coverage isn't a luxury, it's a requirement. How Sunco closes this For any business operating beyond standard hours or exposed to cybersecurity risk, no after-hours coverage means incidents that start at 6pm on a Friday run undetected until Monday morning. An MSP provides the 24/7 coverage your internal team can't sustain. |
CIS Controls v8.1 · Control 15 · Service Provider Management Where IT support is provided outside business hours, is that provider’s coverage and responsibility defined? This is the nearest applicable control; CIS does not publish one for internal after-hours staffing. |
|
| IT Team Capacity & Service Coverage: Sunco acts as a seamless extension of your internal team — absorbing routine support load, providing guaranteed response SLAs (Service Level Agreements), and freeing your IT staff to focus on the strategic work that moves your business forward. |
| Incident Response & Security Awareness | 5 of 6 · 61% aligned |
| Does your organization have a documented IT security incident response process — with defined roles, escalation paths, and communication procedures? | Partly in place |
Your answer: We handle incidents as they arise — there's no documented process An incident response plan is not a document, it is a set of decisions made in advance: who declares an incident, who is called, who can authorise taking systems offline, and who talks to clients and to the regulator. Without those decided beforehand, response becomes improvisation — and improvisation under pressure, at 2am, produces the outcomes that end up in claims. Insurers ask for this plan by name. How Sunco closes this Improvising the response costs time in the hours when time is the whole game — deciding who calls whom, who can authorise taking a system offline, and who talks to clients, while the incident continues. The time to define your response process is before an incident, not while one is actively unfolding. |
CIS Controls v8.1 · Control 17 · Incident Response Management Are incident-handling roles designated, and is there a documented process for reporting and escalation? |
|
| How does your organization deliver cybersecurity awareness training and phishing simulation to staff? | Mostly in place |
Your answer: We deliver occasional security training but don't run simulations or measure effectiveness The human element was involved in 62% of breaches in Verizon’s 2026 Data Breach Investigations Report — phishing, stolen credentials and social engineering remain the primary attack surface. KnowBe4’s 2026 benchmark, across 42 million simulated phishing tests, found 33.2% of staff engaged with a simulated phish before any training and 4.2% after a year of it, with organizations under 250 people starting lower at a 24.7% baseline. Staff who have never been tested against current attack patterns are consistently easier to compromise than any technical control is to bypass. How Sunco closes this Occasional training without measurement is compliance theatre. Phishing tactics evolve continuously — staff trained 12 months ago on last year's attack patterns are undertrained today. Effective awareness programs are continuous, tested, and adapted to current threats. |
CIS Controls v8.1 · Control 14 · Security Awareness and Skills Training Is a security awareness programme delivered on a recurring basis, including recognition of social engineering? |
|
| Does your organization know what sensitive data it holds — including personal information, health records, payment card data, or legal files — and where that data is stored? | Mostly in place |
Your answer: We have a general sense of our sensitive data but no formal inventory — classification is informal and not consistently applied What data you hold is one of the things that shapes your premium and your available limits: a law firm holding client files, a clinic holding patient records and a distribution company carry fundamentally different risk profiles at identical sizes. Insurers ask what data you hold, how much of it, and whether it is inventoried and protected accordingly. Organizations that cannot answer accurately cannot scope their coverage correctly — and cannot contain a breach quickly, because containment starts with knowing where the data is. How Sunco closes this An informal understanding of your data holdings is not sufficient for accurate insurance coverage or breach response. Without a formal inventory, you cannot scope your exposure, respond effectively to an incident, or answer insurer questions accurately at renewal. A Sunco MSP engagement includes data discovery and classification as part of your documented security baseline. |
CIS Controls v8.1 · Control 3 · Data Protection (Safeguards 3.1 and 3.2) Is there a data management process, and an inventory identifying where sensitive data is held? |
|
| Is your organization clear about which privacy law governs it — Alberta’s, the federal one, or both — and does it have a documented process for responding to a breach? | Mostly in place |
Your answer: We are aware there are obligations, but we have not documented a breach notification process or worked out which statute applies to us Which statute governs you depends on where you operate. Alberta’s Personal Information Protection Act (PIPA) has been declared substantially similar to the federal Personal Information Protection and Electronic Documents Act (PIPEDA), so for commercial activity inside Alberta PIPA is your governing law, not PIPEDA. Under PIPA section 34.1 you must notify the Information and Privacy Commissioner of Alberta “without unreasonable delay” where a reasonable person would consider there is a real risk of significant harm — and it is then the Commissioner who decides whether affected individuals must be told. PIPEDA still reaches you for personal information that crosses a provincial or national border in the course of commercial activity, which covers most cloud services, and it adds a duty PIPA does not: a record of every breach, kept for 24 months, including the ones you decide not to report. Only 26% of Canadian businesses had written cyber security policies in 2023 (Statistics Canada), and a notification process written during an incident is how deadlines get missed. How Sunco closes this Awareness is the starting point, not the finish line. Both Alberta’s Personal Information Protection Act (PIPA) and the federal PIPEDA turn on the same threshold — whether a breach creates a real risk of significant harm — and both require you to assess it. Which regulator you notify depends on which statute the incident falls under: for commercial activity inside Alberta it is the Information and Privacy Commissioner of Alberta, who then decides whether the affected individuals must be told. Without a documented process, that assessment happens under pressure during an active incident, which is the worst possible time to work out what you owe and to whom. |
Alberta PIPA · PIPEDA · PIPA s. 34.1 (notice to the Commissioner) · PIPEDA ss. 10.1, 10.2 and 10.3 (report, notification, records) Is there a documented process for assessing a breach against the real-risk-of-significant-harm threshold, notifying the right regulator, and recording every breach? |
|
| Are security logs from your systems collected and kept — and if you had an incident, could you show what happened and when? | Partly in place |
Your answer: Individual systems log locally with whatever the default settings are — we have not decided what is kept or for how long Logs are the evidence base for everything that happens after an incident. Without them nobody can establish when an intrusion began or what it reached, which means the business cannot demonstrate the scope of its loss to an insurer or the scope of a privacy breach to a regulator. IBM puts the average breach lifecycle at 247 days in 2026, up from 241 — and that clock is measured from logs or it is not measured at all. CIS asks at its Implementation Group 1 baseline for a documented process defining what is collected, reviewed and retained; the 90-day minimum retention sits one tier up at Implementation Group 2. How Sunco closes this Default local logging is usually short and is often the first thing an attacker clears. Deciding what you collect and how long you keep it is the Implementation Group 1 ask, and it is a documentation exercise rather than a purchase. |
CIS Controls v8.1 · Control 8 · Audit Log Management (Safeguard 8.1 at Implementation Group 1; 90-day retention at Safeguard 8.10, Implementation Group 2) Is there a documented audit log management process defining collection, review and retention — and are logs retained long enough to investigate an incident? |
|
| Incident Response & Security Awareness: Sunco provides a structured incident escalation and communication framework with defined roles and management notification procedures, alongside an active staff security awareness program including phishing simulation and policy enforcement. |
| IT Documentation & Institutional Knowledge | 3 of 5 · 73% aligned |
| How well documented is your IT environment — network diagrams, system configurations, vendor credentials, and support procedures? | Mostly in place |
Your answer: We have some documentation but it's incomplete, outdated, or scattered across different locations Documentation is the most commonly deferred IT task in resource-constrained teams — and the one with the highest cost when it's missing. When a critical system fails and the person who knows it isn't available, the quality of documentation determines whether recovery takes hours or days. CIS places maintained architecture diagrams (Safeguard 12.4) at Implementation Group 2 rather than at its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations. How Sunco closes this Partial documentation is better than none — but gaps surface at the worst moments. An incomplete network diagram, a missing vendor credential, or an outdated configuration record can turn a recoverable incident into an extended outage. |
CIS Controls v8.1 · Control 12 · Network Infrastructure Management (Safeguard 12.4) Are up-to-date architecture and network diagrams maintained? |
|
| When you set up a new laptop, server or network device, is it built from a documented standard configuration — or set up from scratch each time? | Mostly in place |
Your answer: We have a consistent way of doing it, but it is not written down — it lives with whoever does the setup CIS asks for a documented secure configuration process at Implementation Group 1, its baseline tier, and asks for it separately again for network devices — so this is genuinely expected of the smallest organizations rather than being an enterprise control. The concrete part most businesses miss is Safeguard 4.7: managing the default accounts that ship with equipment, the root and administrator and vendor accounts nobody knew were there. A device built from a standard image is one you can patch, encrypt, log and recover predictably. One built by hand is a one-off, and every one-off is a gap somebody has to remember. How Sunco closes this An unwritten standard is a standard until the person who holds it is away, and then every build is a judgement call. Writing down what you already do is most of Safeguard 4.1 and takes an afternoon. |
CIS Controls v8.1 · Control 4 · Secure Configuration of Enterprise Assets and Software (Safeguards 4.1, 4.2 and 4.7, Implementation Group 1) Is there a documented secure configuration process for enterprise assets and for network devices, and are default vendor accounts disabled or changed? |
|
| Does your organization maintain a current inventory of every device that connects to your network — laptops, phones, servers and network equipment? | Partly in place |
Your answer: We have a partial list — servers and company laptops, but not personal devices or network equipment This is CIS Control 1 of 18, and it is first because everything after it depends on it: you cannot patch, encrypt, monitor or recover a device you do not know exists. Safeguard 1.1 sits at the Implementation Group 1 baseline and asks for an owner and a department recorded against each asset, reviewed at least twice a year. It is also the question that decides whether the rest of your answers here are true — a control applied to “all devices” is only ever applied to the devices someone has counted. How Sunco closes this The devices missing from a partial list tend to be the ones nobody is patching: the network appliance, the machine in the shop, the phone with mail on it. Those are also the ones an attacker finds first, because nobody is looking at them. |
CIS Controls v8.1 · Control 1 · Inventory and Control of Enterprise Assets (Safeguard 1.1, Implementation Group 1) Is there an accurate, current inventory of all enterprise assets recording owner and department, reviewed at least bi-annually? |
|
| IT Documentation & Institutional Knowledge: Sunco maintains living documentation of your IT environment in a platform your business owns — network diagrams, system configurations, vendor credentials, and support procedures — updated continuously and accessible to your team at any time. |
|
HIGH RISK · 3 Your biggest risks These are the answers we would address first. Most carry direct exposure — to a claim, to a premium, or to a coverage exclusion — and the rest are the ones that make everything else harder to fix. |
| Strategic IT Planning & Long-Term Capacity | 1 of 4 · 42% aligned |
| Does your organization have a written information security policy — a document setting out how data is protected, who is responsible, and what staff are required to do? |
Your answer: No — our security expectations are understood rather than written down Only 26% of Canadian businesses had written cyber security policies in place in 2023, according to Statistics Canada. Insurers ask for this document by name on an application, and its absence is one of the fastest ways to stall a submission — not because the document itself stops an attack, but because it is the evidence that someone owns the problem. How Sunco closes this Puts you with roughly three-quarters of Canadian businesses, which is no comfort at renewal. A short policy naming what is protected, who owns it and what staff must do answers the application question and gives you something to hold people to. |
CIS Controls v8.1 · Control 14 · Security Awareness and Skills Training Are the behaviours expected of the workforce documented, and is the document maintained? CIS publishes no safeguard for an information security policy itself; Control 14 is the nearest applicable control and is shown as such. |
|
| Strategic IT Planning & Long-Term Capacity: Sunco provides Strategic Planning services — a documented one-to-three-year technology roadmap, annual budget planning, vendor governance and alignment of IT investment to operational priorities — so that technology spending serves the business plan rather than reacting to whatever broke most recently. |
| Cybersecurity & Threat Protection | 2 of 11 · 45% aligned |
| Does your organization have continuous dark web monitoring to detect if employee credentials have been compromised in a data breach? |
Your answer: We weren't aware this was something we should have in place Credential theft is industrialised. SpyCloud’s 2026 Identity Exposure Report recorded 642.4 million exposed credentials taken from 13.2 million infostealer malware infections during 2025, against a recaptured collection that has grown to 65.7 billion distinct identity records in total. Without continuous monitoring, you find out that an employee’s credentials are circulating at the moment they are used against you — by which point the attacker may already hold persistent access. How Sunco closes this This is an extremely common gap — and exactly the type of security layer that gets missed when IT teams are focused on keeping the lights on rather than proactive security hardening. It is also one of the cheapest gaps on this list to close. |
CIS Controls v8.1 · Control 5 · Account Management Are compromised credentials detected and rotated? No CIS control covers dark web monitoring directly; this is the nearest applicable control and is shown as such. |
|
| Does anyone scan your systems for known vulnerabilities on a schedule — as distinct from applying the patches you already know about? |
Your answer: No — we rely on patching alone, or we are not sure whether anyone scans Patching fixes what you know about; scanning finds what you do not. Exploitation of a known vulnerability became the leading initial access vector in Verizon’s 2026 Data Breach Investigations Report, appearing in 31% of breaches and passing stolen credentials for the first time in nineteen editions. CIS places automated scanning at Implementation Group 2 — quarterly for internal systems, monthly for anything reachable from the internet — so this is a step beyond the small-business baseline rather than part of it. It is increasingly the step an insurer asks about. How Sunco closes this Patching handles the vulnerabilities your vendors told you about in products you know you are running. Scanning finds the forgotten server, the appliance nobody owns, and the service exposed to the internet by accident — which is the category that gets exploited. |
CIS Controls v8.1 · Control 7 · Continuous Vulnerability Management (Safeguards 7.5 and 7.6, Implementation Group 2) Are automated vulnerability scans run at least quarterly on internal assets and monthly on externally-exposed assets? |
|
| Cybersecurity & Threat Protection: Sunco's managed security stack provides round-the-clock monitoring from a Security Operations Centre, active endpoint threat blocking, dark web credential scanning and enforced multi-factor authentication — running continuously alongside your internal team so your staff can focus on the business while Sunco maintains vigilance. |
|
⚡ Quick Wins — Act On These Now | | Turn on continuous dark web credential monitoring for your email domain. It tells you which of your staff credentials are already circulating, which is usually a surprise. |
| | Run one external vulnerability scan against everything of yours that faces the internet. Exploitation of known vulnerabilities is now the leading way in, at 31% of breaches. A first scan usually finds something nobody knew was exposed. |
| | Write a two-page information security policy with a named owner. Only 26% of Canadian businesses have one, and insurers ask for it by name on the application. |
|
Assessment Framework & Standards Alignment Your results have been evaluated against the following frameworks and Canadian regulatory obligations. CIS CONTROLS v8.1 Critical Security Controls, from the Center for Internet Security Eighteen prioritized controls published by the Center for Internet Security (CIS). The framework cyber insurers most commonly map their application questions to. | NIST CSF 2.0 Cybersecurity Framework, from the US National Institute of Standards and Technology Six functions — Govern, Identify, Protect, Detect, Respond, Recover — used as the common language for describing security posture. | ALBERTA PIPA Personal Information Protection Act Alberta’s private-sector privacy law, including the obligation to protect personal information and to report breaches involving a real risk of significant harm. | PIPEDA Personal Information Protection and Electronic Documents Act Canada’s federal private-sector privacy law, governing safeguards and mandatory breach reporting for organizations operating across provincial lines. | CCCS Canadian Centre for Cyber Security Canada’s national cyber security authority, whose baseline controls for small and medium organizations align closely with insurer expectations. |
This assessment surfaces readiness gaps and does not certify compliance with any standard. Insurance decisions rest with your carrier and broker; consult qualified counsel regarding your specific obligations. |
|
Indicative IT & Security Spend Snapshot |
See how you stand against your peers Statistics Canada publishes what Canadian businesses actually spend on cyber security prevention and detection, and how many spend nothing at all. It is the only way to know whether your number is normal for a business your size. Everything here is either a published figure or one of your own — no prices, and nothing estimated. |
| The figures below use typical values for a business of about this size, because the snapshot was left unfilled. Re-run it with your own numbers for a comparison that reflects your organization. |
What the alternatives cost | Your spend across 50 users | $125 per user / month | | | | One cybersecurity specialist in Alberta, fully loaded | $137,000 | | That one hire, expressed the way you buy IT | $228 per user / month |
You spend about $125 per user per month on IT and security. One fully loaded cybersecurity specialist in Alberta is about $137,000 a year — $228 per user per month across your 50 people, for one person’s salary, before any security tooling and with no cover for nights, weekends or vacation. Meanwhile 44% of Canadian businesses spend nothing at all on prevention and detection. What adequate coverage costs for your environment depends on your environment, and that is worth half an hour of conversation rather than a number on a web page. |
How you stand against your peers | Canadian businesses that spend anything at all on cyber security prevention and detection | 56% | | Which means 44% spend nothing. Down from 61% in 2021. | | Canadian businesses with employees dedicated to cyber security | 50% | | Down from 61% in 2021, while incidents continued. | | Canadian businesses impacted by a cyber security incident in 2023 | 16% | | About one in six. Recovery spending across all businesses doubled from $600 million in 2021 to $1.2 billion in 2023. | | Spent on prevention and detection by medium-sized Canadian businesses, 50 to 249 people | $3.6B | | Small businesses of 10 to 49 spent $2.6 billion; large businesses of 250 or more spent $4.8 billion. $11.0 billion in total. | | What one incident costs a small or medium business, on average | ~$363,000 | | US$264,000 across claims from 2020 to 2024, about C$363,000 at the Bank of Canada rate for 21 August 2026. Crisis services alone averaged US$152,000, and insurance covered 69% of the total — down from 81%. |
Indicative estimate based on published benchmarks and your own figures. Numbers are rounded and intended to frame a conversation, not to predict your costs. What managed coverage would cost for your environment is a conversation, not a figure on a web page. |
Sunco’s Recommendation Coverage at Risk: Gaps an insurer would question or exclude. |
|
Book Your Cyber Readiness Review A Sunco advisor will walk through your results and identify the highest-impact next steps for your organization. 30 minutes • Free • No obligation |
Research Sources and Methodology Every figure and framework reference in this report is listed below with a link to the original source, so you can verify any of it yourself. Statistics Canada — The Daily — Impact of cybercrime on Canadian businesses, 2023 (Canadian Survey of Cyber Security and Cybercrime) In 2023, 56% of Canadian businesses spent on cyber security prevention and detection, down from 61% in 2021 — a total of $11.0 billion, of which $2.6 billion was spent by small businesses of 10 to 49 employees, $3.6 billion by medium businesses of 50 to 249 and $4.8 billion by large businesses of 250 or more. Recovery spending doubled to $1.2 billion. 16% of businesses were impacted by a cyber security incident, and 50% had employees dedicated to cyber security, down from 61% in 2021. Just over 1 in 4 (26%) had written cyber security policies in place, and 22% provided formal cyber security training to non-IT employees. Tier 1 source · Canada · figures in CAD · verified 2026-08-23 |
Job Bank / Statistics Canada Labour Force Survey — Wage report — Cybersecurity Specialist, National Occupational Classification 21220, Alberta Cybersecurity Specialist wages in Alberta, 2024 reference period: low $35.40 an hour, median $50.51, high $87.09. At the median that is about $105,000 a year before employer costs. Tier 1 source · Alberta · figures in CAD · verified 2026-08-23 |
NetDiligence — 2025 Cyber Claims Study (10,402 claims analysed; 9,171 above the $1,000 analysis threshold) Across claims from incidents occurring between 2020 and 2024, the average total incident cost for small and medium enterprises was US$264,000, with crisis services averaging US$152,000. SMEs accounted for 98% of claims. Of all claims carrying a business interruption component, 81% occurred at SMEs. Over five years, insurance paid 69% of the total incident cost for SMEs. NetDiligence defines an SME as an organization with less than US$2 billion in annual revenue, which is far broader than a small business as an Alberta reader would understand it — so this is a claims-severity anchor rather than a figure to expect. Tier 2 source · North America / global · figures in USD · verified 2026-08-23 |
Bank of Canada — Daily exchange rates Bank of Canada daily average exchange rate, 21 August 2026: 1 US dollar = 1.3760 Canadian dollars. Used to convert the NetDiligence figures, which are published in US dollars. Tier 1 source · Canada · verified 2026-08-23 |
Center for Internet Security — CIS Critical Security Controls, version 8.1 — official list The CIS Critical Security Controls v8.1 comprise 18 prioritized controls, each divided into Safeguards assigned to Implementation Groups 1, 2 and 3, where Implementation Group 1 is the baseline CIS expects of the smallest organizations. This assessment cites Controls 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 and 17. The Implementation Group assignments relied on: Safeguards 1.1, 2.1, 2.2, 3.6, 4.1, 4.2, 4.7, 5.2, 5.4, 7.3, 7.4, 8.1 and 15.1 are Implementation Group 1; Safeguards 5.6, 7.5, 7.6, 8.10, 9.5, 10.6, 11.5, 12.2, 12.4, 12.7 and 15.4 are Implementation Group 2; Safeguard 15.5 is Implementation Group 3 only; and Control 13 contains no Implementation Group 1 Safeguard at all. Safeguards 7.3 and 7.4 specify a monthly patching cycle, and Safeguard 8.10 sets the 90-day log retention minimum. Tier 1 source · Global · verified 2026-08-23 |
Microsoft — Windows 10 support has ended on October 14, 2025 Windows 10 mainstream support ended on 14 October 2025: Microsoft states that affected computers still function but receive no technical support, no software updates, and no security updates or fixes. Extended Security Updates remain available as a paid, time-limited bridge — the consumer programme runs to 12 October 2027 (extended from 13 October 2026 in June 2026) and commercial coverage is renewable yearly to a maximum of 10 October 2028. A machine not enrolled receives nothing. Tier 1 source · Global · verified 2026-08-23 |
International Organization for Standardization — ISO/IEC 33020:2019 — Process measurement framework for assessment of process capability ISO/IEC 33020:2019 defines the process attribute achievement scale used for the band boundaries in this assessment: Not achieved (0 to 15%), Partially achieved (>15 to 50%), Largely achieved (>50 to 85%), Fully achieved (>85 to 100%). Tier 1 source · International · verified 2026-08-23 |
Office of the Privacy Commissioner of Canada — What you need to know about mandatory reporting of breaches of security safeguards Office of the Privacy Commissioner of Canada guidance on mandatory breach reporting: when assessing whether a breach creates a real risk of significant harm, one of the considerations under probability of misuse is “Is the personal information adequately encrypted, anonymized or otherwise not easily accessible?” Encryption appears as one consideration among the factors listed, and the guidance nowhere exempts encrypted data from the assessment — the reading that there is no safe harbour is Sunco’s, not a quotation. PIPEDA requires a record to be kept of all breaches of security safeguards whether or not there is a real risk of significant harm. Tier 1 source · Canada · verified 2026-08-23 |
Office of the Information and Privacy Commissioner of Alberta; Office of the Privacy Commissioner of Canada; Department of Justice Canada — Breach notification under PIPA; PIPEDA and provincial privacy legislation; PIPEDA ss. 14, 16 and 28 Alberta’s Personal Information Protection Act has been declared substantially similar to PIPEDA, so PIPEDA does not apply to provincially-regulated organizations for personal information collected, used or disclosed within Alberta; it continues to apply to federal works, undertakings and businesses, and to personal information crossing a provincial or national border in the course of commercial activity. PIPA section 34.1 requires an organization to provide notice to the Information and Privacy Commissioner of Alberta “without unreasonable delay” where a reasonable person would consider there is a real risk of significant harm; the Commissioner then decides under section 37.1 whether affected individuals must be notified. Alberta PIPA contains no obligation to record breaches that fall below that threshold. Under PIPEDA the Privacy Commissioner of Canada has neither order-making nor fining power: the Commissioner investigates and recommends, the Federal Court holds the remedial power under section 16, and knowingly failing to report a breach or keep breach records is an offence under section 28 carrying a fine of up to $100,000. British Columbia’s PIPA contains no mandatory private-sector breach notification requirement. Tier 1 source · Alberta / Canada · verified 2026-08-23 |
Verizon — 2026 Data Breach Investigations Report Verizon 2026 Data Breach Investigations Report, 19th edition, dataset 1 November 2024 to 31 October 2025: ransomware appeared in 48% of breaches, up from 44%. Exploitation of a known vulnerability became the leading initial access vector at 31% of breaches — the first time in nineteen editions it has surpassed stolen credentials. The human element was involved in 62% of breaches. Breaches involving a third party reached 48%, up 60% year over year. Employee use of unapproved artificial intelligence (AI) tools rose from 15% to 45% in a single year. Based on 2025 data. Tier 2 source · Global (145 countries) · verified 2026-08-23 |
Coalition — 2026 Cyber Claims Report Coalition 2026 Cyber Claims Report, full-year 2025 claims: ransomware was the costliest claim type, averaging a US$269,000 loss; initial ransom demands rose 47% year over year; a record 86% of businesses refused to pay; overall claims severity fell 19% to an average US$116,000. Figures are Coalition’s own global policyholder book, not Canadian market data. Tier 2 source · Global (Coalition policyholders) · figures in USD · verified 2026-08-23 |
Coalition — Cyber Threat Index 2025 Coalition Cyber Threat Index 2025, full-year 2024 claims: 58% of ransomware claims began with a compromised perimeter security appliance, with remote desktop products second at 18%. The most common initial access vectors overall were stolen credentials (47%) and software exploits (29%). Coalition’s own global policyholder book, not Canadian market data. Tier 2 source · Global (Coalition policyholders) · verified 2026-08-23 |
Microsoft Research — How Effective Is Multifactor Authentication at Deterring Cyberattacks? Microsoft Research measured multi-factor authentication reducing the risk of account compromise by 99.22% across the studied population and by 98.56% in cases of leaked credentials, over 22 April to 22 September 2022 on commercial Azure Active Directory accounts. This supersedes the widely-quoted 99.9% figure from a 2019 Microsoft blog post, which disclosed no methodology. Tier 2 source · Global (commercial Azure Active Directory accounts) · verified 2026-08-23 |
SpyCloud — SpyCloud Annual Identity Exposure Report 2026 SpyCloud 2026 Annual Identity Exposure Report, covering 2025: 642.4 million exposed credentials were recaptured from 13.2 million infostealer malware infections; SpyCloud’s cumulative recaptured collection reached 65.7 billion distinct identity records, up 23% year over year. Tier 2 source · Global · verified 2026-08-23 |
FBI Internet Crime Complaint Center (IC3) — 2025 Internet Crime Report FBI Internet Crime Complaint Center 2025 Internet Crime Report: total reported losses were US$20.877 billion. Investment fraud was the largest single category at US$8,648,617,756; Business Email Compromise was second at US$3,046,598,558 across 24,768 complaints, and is the largest category that specifically targets businesses; ransomware accounted for US$32,320,105. IC3 states that its ransomware loss figure excludes lost business, time, wages, files, equipment and third-party remediation, so it is a floor rather than a total cost. Tier 1 source · United States (reported complaints) · figures in USD · verified 2026-08-23 |
Veeam — Data Trust and Resilience Report 2026 Veeam Data Trust and Resilience Report 2026, surveying 900+ senior IT, security and risk leaders: 90% of organizations expressed confidence in their ability to recover from a cyber incident, while organizations actually attacked recovered an average of 72% of affected data; only 28% fully recovered their data — fewer than one in three; 44% recovered less than 75%. Tier 2 source · Global · verified 2026-08-23 |
Microsoft — Recoverable Items folder; SharePoint and OneDrive retention and deletion; Shared responsibility in the cloud Microsoft documentation: the default deleted-item retention period for Exchange Online is 14 days, configurable to a maximum of 30 days; SharePoint and OneDrive retain deleted items in the recycle bin for 93 days in total across both stages. Microsoft’s shared responsibility model assigns customer data — including data protection — to the customer in software-as-a-service (SaaS) deployments, and the Microsoft Services Agreement recommends that customers regularly back up their own content. Microsoft 365 Backup is a separate first-party product, billed on consumption and not enabled by default. Tier 1 source · Global · verified 2026-08-23 |
KnowBe4 — 2026 Phishing by Industry Benchmarking Report KnowBe4 2026 Phishing by Industry Benchmarking Report, based on 42 million simulated phishing tests across 14.8 million users at 64,000 organizations: the global baseline phish-prone percentage before training was 33.2%, falling to 20.1% after 90 days of training and 4.2% after one year. For organizations under 250 employees the baseline was 24.7%. This is KnowBe4’s own customer base and is not a controlled study. Tier 2 source · Global · verified 2026-08-23 |
IBM (research conducted by Ponemon Institute) — Cost of a Data Breach Report 2026 IBM Cost of a Data Breach Report 2026, covering 602 organizations breached between March 2025 and February 2026: the mean time to identify and contain a breach rose to 247 days from 241, reversing five years of decline. The global average breach cost reached US$4.99 million and the Canadian average CA$7.11 million. IBM publishes no size-banded figure, and its sample is enterprise-weighted, so these averages should not be read as a small-business expectation. Tier 2 source · Global / Canada · verified 2026-08-23 |
Statistics are reproduced as published by the sources above and were verified on the dates shown. Regulatory positions reflect the law in force at the time of verification and may change. This assessment surfaces readiness gaps and does not certify compliance with any standard; consult qualified counsel regarding your specific obligations. |
 Sunco Communication and Installation Ltd. 18961 111 Ave NW, Edmonton, AB T5S X4 1-866-310-7007 | marketingteam@sunco.ca | sunco.ca |
© 2026 Sunco Communication & Installation Ltd. All rights reserved. |
|
|