SAMPLE REPORT — fictional company, illustrative resultsThis is a sample report for a fictional company, prepared to show the format and depth of what you receive. The figures are illustrative.
Your coverage by layer, the gaps that matter most today, the software layer that closes each one, and the next step we would recommend.
Sunco
Sunco Communication and Installation Ltd.
Cybersecurity Software Gap Assessment
Prepared for
Northgate Millwork Ltd.
 

Hello Dana Whitfield,

Thank you for completing the Sunco Cybersecurity Software Gap Assessment. Your personalized results are below.

Assessment completed: August 24, 2026

Your Score
58%
aligned · grade C
Gaps to close
Coverage Signal
Coverage gaps
Several layers are missing, and at least one of them is a baseline expectation
HOW THIS SCORE WAS CALCULATED
Your Security Coverage Score is the share of the controls assessed here that your organization has in place. Every one of the 28 questions maps to a named safeguard in the Critical Security Controls version 8.1 published by the Center for Internet Security (CIS), and the reference is shown beside the question. Where CIS places a safeguard above its Implementation Group 1 baseline — the tier it expects of the smallest organizations — the question says so, because a target and a minimum are different things. Two questions map to nothing CIS publishes: there is no safeguard for simulated phishing, and none for a security operations centre or a 24/7 staffing model, so both are shown as a nearest fit and the recommendation is Sunco’s rather than the framework’s. This assessment is about software rather than staffing. It assumes your organization has people who can administer security tooling, and asks which tooling is missing — so the recommendation is a software package your own team runs, and no part of it proposes outsourcing what your team already does. Each question scores 0 to 3, where 0 means the control is fully in place and 3 means it is not, so your score is the share of the 84 available points you did not lose. Answer options are shuffled so the scoring key cannot be inferred from position, except that an “I’m not sure” option is always shown last. Band boundaries — above 85% and above 50% — are the Fully achieved and Largely achieved thresholds of the ISO/IEC 33020:2019 process achievement scale, ISO/IEC being the joint International Organization for Standardization and International Electrotechnical Commission; the letter grades within them are Sunco’s own subdivision and are not part of that standard. Seven layers of four questions each means one answer moves a quarter of that layer’s score, so read a single layer percentage as direction rather than precision. The control alignment panel is a checklist rather than a second score, deliberately. This assessment surfaces coverage gaps — it does not certify compliance with any standard.
Section Breakdown
SectionAlignedRisk Level
Email Security & Cloud Backup50%SIGNIFICANT GAPS
Endpoint Protection58%Gaps to close
Server Backup & Recovery67%Gaps to close
Network & User Awareness50%SIGNIFICANT GAPS
Access & Credential Security92%Well covered
Security Operations25%SIGNIFICANT GAPS
Patch & Vulnerability Management67%Gaps to close
 
 
AT A GLANCE
6
in place
20
need work
2
high risk

Every answer you gave, sorted into three groups. Domains appear worst-first within each.

IN PLACE · 6
What you’re doing well
These layers are already in place. They are the reason the gaps below are worth closing rather than starting over, and they are what your team already runs successfully.
Server Backup & Recovery2 of 4 · 67% aligned
What type of backup do you have in place for your on-premises servers and virtual machines?
Image-based backup — we capture full server state including operating system (OS), applications, and data, enabling bare-metal restore.
Are your server backups encrypted, and does your organization control the keys?
Yes — backups are encrypted at rest and we hold or escrow the keys ourselves.
Patch & Vulnerability Management1 of 4 · 67% aligned
When a patch fails or a scan flags something, who closes it — and on what clock?
A named owner reviews what patching and scanning did not close, on a monthly or faster cadence, against a documented process.
Access & Credential Security3 of 4 · 92% aligned
How does your organization manage and store passwords for business accounts, systems, and applications?
All staff use an enterprise password manager — credentials are unique, strong, stored securely, and access is audited.
Is Multi-Factor Authentication (MFA) enforced across your organization's accounts and systems?
multi-factor authentication (MFA) is enforced on all accounts — email, virtual private network (VPN), cloud applications, admin tools, and any system accessible remotely.
When someone leaves the organization, what actually happens to their accounts — and how would you find out if one had been missed?
A documented checklist covers every system, access is revoked the same day, and dormant accounts are reviewed on a schedule.
NEEDS WORK · 20
What needs work
Partly in place, unmanaged, or not covering everything. None of these are emergencies — but each one is something an audit, a client questionnaire or an incident eventually exposes.
Security Operations3 of 4 · 25% aligned
Is your IT environment monitored 24/7 for threats and anomalous activity?Partly in place
Your answer: We review logs periodically or after incidents are reported, but we do not have active real-time threat monitoring.
Ransomware and account takeover attacks are most commonly triggered on Friday evenings and long weekends — exactly when monitoring gaps are widest. An attacker who enters Friday at 5pm has all weekend to operate before anyone sees an alert.
How Sunco closes this
Periodic log review means threats are discovered after they have caused damage. Real-time monitoring converts reactive incident response into proactive threat detection — reducing both breach duration and cost. How long an intrusion runs before anyone notices is one of the largest drivers of what it ends up costing. Real-time monitoring is the enabler of fast containment.
CIS Controls v8.1 · Control 13 · Network Monitoring and Defense (Safeguard 13.1 centralize security event alerting, Implementation Group 2)
Is security event alerting centralised for correlation and analysis? CIS publishes no safeguard establishing a security operations centre or a 24/7 staffing model — 13.1 covers the technology only — so this is the nearest applicable control and is shown as such. Control 13 contains no Implementation Group 1 safeguard at all.
Does your organization have a documented Incident Response Plan (IRP) that has been tested?Partly in place
Your answer: We have some informal procedures for handling incidents but nothing formally documented or tested.
What happens in the first half hour of an incident shapes everything that follows, and an untested plan is where that half hour gets spent deciding who to call. An untested response plan is a plan that will fail under pressure. Organizations that practise their response contain breaches faster and spend measurably less.
How Sunco closes this
Informal procedures create inconsistency and confusion during high-pressure events. Formalizing even a basic Incident Response Plan (IRP) — who calls whom, what gets isolated first, when to engage law enforcement — provides structure when it matters most. The first 30 minutes of a breach response are the most critical. Without a documented plan, those 30 minutes are spent figuring out what to do instead of doing it.
CIS Controls v8.1 · Control 17 · Incident Response Management (Safeguard 17.1 designate personnel, Implementation Group 1; 17.4 incident response process and 17.7 routine exercises, both Implementation Group 2)
Is someone named to manage incident handling with a documented backup — and beyond that baseline, is there a documented response process that is exercised at least annually? Naming the people is the Implementation Group 1 ask; the plan and the exercise sit one tier up.
How long are your security logs kept, and would you still have last quarter’s if you needed to reconstruct what happened?Partly in place
Your answer: Whatever each system keeps by default — we have not set a retention period.
Retention is what decides whether an investigation is possible. Intrusions are commonly discovered weeks or months after they began, and by the time anyone looks, the question is not whether the logs were collected but whether they still exist. Default retention on most platforms is measured in days to weeks, which is shorter than the time it typically takes to notice.
How Sunco closes this
Defaults vary from a few days to a few weeks and none of them were chosen with an investigation in mind. Establishing the actual retention on your main systems takes an afternoon, and it is the number that decides whether a future question is answerable.
CIS Controls v8.1 · Control 8 · Audit Log Management (Safeguard 8.10 retain audit logs, minimum 90 days, Implementation Group 2)
Are audit logs retained across enterprise assets for a minimum of 90 days? CIS states the period explicitly and places it at Implementation Group 2, above its baseline — so 90 days is a target rather than a minimum expectation of the smallest organizations, and it is a specific, checkable number rather than a judgement.
Security Operations: Most organizations discover a breach through a third party — not their own monitoring. The gap between a contained incident and a catastrophic one is almost always how fast the first alert fires.
Email Security & Cloud Backup4 of 4 · 50% aligned
What email security does your organization currently use beyond the built-in Microsoft or Google spam filter?Mostly in place
Your answer: Microsoft Defender for Office 365 or Google Workspace Advanced Protection only — no additional third-party layer.
Email is where most social engineering arrives, and the human element featured in 62% of breaches in Verizon’s 2026 report. The gap between basic spam filtering and dedicated threat protection is the difference between stopping a targeted phishing attack — and paying a ransom to recover from one.
How Sunco closes this
Adding a dedicated email security layer on top of Microsoft/Google significantly improves protection against business email compromise (BEC) and targeted phishing. Microsoft's native tools are a reasonable starting point, but a layered approach catches threats that bypass the built-in engine.
CIS Controls v8.1 · Control 9 · Email and Web Browser Protections (Safeguards 9.6 block unnecessary file types, Implementation Group 2; 9.7 email server anti-malware protections, Implementation Group 3)
Are email-borne threats filtered beyond the platform default, by blocking unnecessary file types and scanning or sandboxing attachments? CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
Are your Microsoft 365 or Google Workspace mailboxes, files, and collaboration data backed up to an independent third-party platform?Partly in place
Your answer: We rely on Microsoft/Google's built-in retention policies and recycle bins — no independent backup exists.
Microsoft and Google protect their infrastructure — not your data. Their recycle bins expire and their retention policies have limits. If ransomware or a malicious insider deletes your files, the cloud provider cannot recover them for you.
How Sunco closes this
Microsoft's retention policies protect against accidental deletion for a limited window only. They do not protect against ransomware, malicious deletion, or data corruption. Microsoft's recycle bin expires. If ransomware or a malicious insider deletes your data, Microsoft cannot recover it. An independent backup can.
CIS Controls v8.1 · Control 11 · Data Recovery (Safeguards 11.1 recovery process, 11.2 automated backups and 11.4 an isolated instance of recovery data — all Implementation Group 1)
Is data held in cloud services backed up automatically, on a defined process, to an instance isolated from the source?
How does your organization currently monitor and respond to email security alerts and threats?Partly in place
Your answer: Alerts exist but are largely ignored — we only investigate if users report a problem.
Having email security tools is not enough. Unreviewed alerts are the same as no alerts. The average undetected email threat dwells in an environment for months before it causes visible damage.
How Sunco closes this
Waiting for users to report problems means attackers have already succeeded. Email security alerts often catch attacks before users even realize they're being targeted. User-reported threats are reactive. By the time a user notices, credentials may already be compromised.
CIS Controls v8.1 · Control 8 · Audit Log Management (Safeguard 8.11 conduct audit log reviews, Implementation Group 2)
Are security alerts and logs actually reviewed on a cadence, rather than only collected? CIS publishes no safeguard for email alert triage specifically; this is the nearest applicable control and is shown as such. CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
When a staff member emails something sensitive outside the organization — a payroll file, a contract, a client’s personal information — is anything protecting or checking it on the way out?Mostly in place
Your answer: Encryption in transit is enforced, but nothing inspects what is being sent.
Almost every control in this layer faces inward, at what arrives. The traffic going the other way is the one nobody watches, and it is the one that causes a privacy breach without an attacker being involved at all: an attachment to the wrong recipient, a spreadsheet that should never have left. Encryption in transit and outbound content checking are both platform features rather than products for most organizations — the gap is usually that nobody has turned them on.
How Sunco closes this
The transport is protected and the judgement is still entirely the sender’s. That is a reasonable place to be, and the next increment is narrow: one rule on the two or three content types that would actually hurt — banking details, personal information, anything under a client confidentiality clause — rather than a broad policy nobody can tune.
CIS Controls v8.1 · Control 3 · Data Protection (Safeguard 3.10 encrypt sensitive data in transit, Implementation Group 2; Safeguard 3.13 deploy a data loss prevention solution, Implementation Group 3)
Is sensitive data encrypted in transit, and is there tooling that recognises sensitive content leaving the organization? CIS places both above its Implementation Group 1 baseline — data loss prevention at Implementation Group 3 — so these are a target beyond the minimum rather than part of it, and the honest first step is encryption rather than full content inspection.
Email Security & Cloud Backup: Phishing is one of the most common entry points for ransomware. Your email security and backup strategy determines whether a single click becomes a recoverable inconvenience — or a six-figure disaster.
Network & User Awareness4 of 4 · 50% aligned
Does your organization use Domain Name System (DNS) or web address (URL) filtering to block access to malicious, compromised, or inappropriate domains across your network?Partly in place
Your answer: We have some web content filtering in place but it is not specifically Domain Name System (DNS)-based and is not actively managed.
Your firewall checks traffic it is configured to inspect. DNS filtering intercepts every outbound domain request — including malware callbacks, phishing infrastructure, and command-and-control servers that firewall rules never see.
How Sunco closes this
Unmanaged filtering quickly falls behind the current threat landscape. Domain Name System (DNS) filtering with an actively updated threat feed is a significant upgrade from static web filtering rules. Threat intelligence updates matter as much as the filter itself. Stale rules miss newly registered malicious domains — and attackers register thousands of new domains daily.
CIS Controls v8.1 · Control 9 · Email and Web Browser Protections (Safeguard 9.2 use DNS filtering services, Implementation Group 1; 9.3 network-based URL filters, Implementation Group 2)
Is DNS filtering used on enterprise assets to block known malicious domains?
What cybersecurity awareness training does your organization provide to staff?Mostly in place
Your answer: We provide security training but it is not mandatory, completion is not tracked, and delivery is inconsistent.
Your staff make security decisions hundreds of times every day — every link clicked, every attachment opened, every login prompt. Without training, they make those decisions with no framework for recognizing what a threat looks like.
How Sunco closes this
Optional, untracked training provides limited protection and limited evidence of a security program. Mandatory, tracked training is a key differentiator for cyber-insurance premiums and renewals. Insurers increasingly require documented security training programs. Optional programmes reach the people who were already careful, which is not where the exposure is.
CIS Controls v8.1 · Control 14 · Security Awareness and Skills Training (Safeguards 14.1 awareness programme and 14.2 recognising social engineering, both Implementation Group 1)
Is a security awareness programme delivered at hire and at least annually, including recognition of phishing and business email compromise?
Does your organization run phishing simulations to test and measure employee readiness?Partly in place
Your answer: We plan to implement phishing simulations but have not started yet.
Training tells staff what to watch for. Simulation measures whether it changed their behaviour. You cannot improve what you do not measure — and your current click rate is your real-world human risk exposure.
How Sunco closes this
Phishing simulation is one of the most cost-effective controls available. Starting with a baseline measurement establishes your current risk level and provides the data to justify further investment in training. You can't improve what you don't measure. A baseline phishing simulation takes minutes to configure and gives you immediate, actionable insight into your human risk layer.
CIS Controls v8.1 · Control 14 · Security Awareness and Skills Training (Safeguard 14.2, Implementation Group 1)
Are workforce members trained to recognise social engineering? CIS publishes no safeguard requiring simulated phishing — 14.2 measures training completion rather than click rates — so simulation is industry practice and Sunco’s recommendation rather than a CIS requirement. This is the nearest applicable control and is shown as such.
Is there a managed firewall running on the devices themselves — laptops, desktops and servers — rather than only at the edge of the office network?Mostly in place
Your answer: Host firewalls are on and left at their defaults, without central management or a default-deny rule.
The office firewall protects the office. It does nothing for a laptop on hotel wireless, nothing for a device sitting next to an already-infected one on your own network, and nothing for a server reachable from a workstation somebody has compromised. Windows and macOS both include a host firewall; the two things organizations lack are a default-deny rule and central management of what is allowed through.
How Sunco closes this
Defaults are much better than nothing and they allow more than you would choose. The increment is central management: one place that sets the rule, reports which machines match it, and tells you when one stops.
CIS Controls v8.1 · Control 4 · Secure Configuration (Safeguard 4.5 implement and manage a firewall on end-user devices and Safeguard 4.4 on servers, both Implementation Group 1 — the tier CIS expects of the smallest organizations)
Is a host-based firewall or port-filtering tool running on end-user devices and servers, with a default-deny rule that drops all traffic except explicitly allowed services and ports? Both safeguards sit at CIS’s Implementation Group 1 baseline, so this is a minimum expectation rather than a target.
Network & User Awareness: Technology stops the attacks your tools are configured to detect. Your people stop the ones that get through. Both layers have significant gaps in most small and medium-sized business (SMB) environments — and attackers know which one is weaker.
Endpoint Protection4 of 4 · 58% aligned
What type of endpoint protection is deployed on workstations and laptops across your organization?Mostly in place
Your answer: Modern antivirus with some heuristic detection (e.g. Microsoft Defender, Sophos Home) — but not a full endpoint detection and response (EDR) platform.
Signature-based antivirus compares files against a list of known threats. Modern attacks are specifically engineered to look like nothing on that list. Behavioural detection catches what signatures cannot.
How Sunco closes this
Modern antivirus (AV) with heuristics provides better coverage than signature-only tools, but lacks the behavioral analysis, automated containment, and forensic capabilities of a true endpoint detection and response (EDR) solution. Microsoft Defender is a solid foundation, but EDR adds the detection depth and response capability that insurers and compliance frameworks now require.
CIS Controls v8.1 · Control 10 · Malware Defenses (Safeguard 10.1, Implementation Group 1)
Is anti-malware software deployed and maintained on all enterprise assets?
Does your organization use Extended Detection and Response (XDR) — correlating signals from endpoints, email, and identity into a unified threat picture?Partly in place
Your answer: We are aware of extended detection and response (XDR) but have not evaluated or implemented it — our tools are siloed.
Most damaging breaches are not single-system events. An attacker compromises an email account, moves to endpoints, then escalates to servers. endpoint detection and response (EDR) sees one system. XDR sees the full attack chain across all of them.
How Sunco closes this
Siloed security tools create blind spots. A lateral movement that starts in email and ends on a server may not trigger any single tool's alerting threshold. Without correlation, an attacker can move through your environment in stages that each look innocent individually.
CIS Controls v8.1 · Control 13 · Network Monitoring and Defense (Safeguard 13.7 host-based intrusion prevention, Implementation Group 3)
Is host-based intrusion prevention deployed, correlating signals across endpoints, identity and cloud? This is the safeguard whose guidance names endpoint detection and response tooling, and CIS places it two tiers above its small-business baseline. CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
How is endpoint protection managed and monitored across your organization?Mostly in place
Your answer: Mostly managed — most devices are enrolled and monitored, but remote workers or personal devices have gaps.
Security tools that are not actively managed quickly become stale. Updates lapse, policies drift, and alerts go unseen. Centralized visibility turns endpoint security from a passive installation into an active, responsive defence.
How Sunco closes this
Remote and personal device gaps are frequently exploited. Extending endpoint management to all devices that access company data is a high-priority step. Remote worker devices accessing corporate resources are increasingly targeted — they often lack the same protections as office machines.
CIS Controls v8.1 · Control 10 · Malware Defenses (Safeguard 10.6 centrally manage anti-malware software, Implementation Group 2)
Is anti-malware software centrally managed rather than configured per device? CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
Are the drives on your laptops and desktops encrypted — and could you prove which ones, from one place, if a device went missing tomorrow?Mostly in place
Your answer: Encryption is on across the fleet, but the recovery keys live with the devices or with individual staff rather than centrally.
A lost or stolen laptop is one of the most common reportable privacy incidents there is, and encryption is the difference between an inconvenience and a notification. Both Windows and macOS include full-disk encryption at no extra cost. What organizations usually lack is not the encryption — it is central proof of which machines have it and custody of the recovery keys, which is what a regulator or an insurer asks for.
How Sunco closes this
Encryption without custody of the keys protects you from a thief and not from yourself: the first time a machine needs recovering and the key is on a sticky note in a drawer that person no longer has, the data is as gone as if it had been ransomed. Central key escrow is a setting in the same console that enforces the encryption.
CIS Controls v8.1 · Control 3 · Data Protection (Safeguard 3.6 encrypt data on end-user devices, Implementation Group 2)
Is data on end-user devices encrypted? CIS places this at Implementation Group 2, above its Implementation Group 1 baseline — which is worth stating plainly, because full-disk encryption ships with the operating system and therefore reads like a baseline expectation. It is a target, not a minimum.
Endpoint Protection: Traditional antivirus cannot detect what it has never seen before. Modern attacks use fileless execution and zero-day techniques specifically to bypass signature-based tools — and those attacks are now common.
Server Backup & Recovery1 of 4 · 67% aligned
Where are your server backups stored?Mostly in place
Your answer: Backups are stored on a separate physical device at the same location as our servers — but on a different network segment.
Ransomware operators specifically target backup directories on the network before triggering encryption. Backups stored in the same environment as your production systems are part of the attack surface — not outside it.
How Sunco closes this
On-site backup is better than nothing, but fire, flood, or a ransomware attack that reaches your backup network could destroy both. Adding a cloud copy provides a true air-gapped recovery option. Network-segmented on-site backup protects against some threats but not physical disasters or sophisticated ransomware that scans for backup solutions.
CIS Controls v8.1 · Control 11 · Data Recovery (Safeguards 11.3 protect recovery data and 11.4 isolated instance of recovery data, both Implementation Group 1)
Is recovery data protected to the same standard as the original, and is at least one instance isolated — offline, off-site or otherwise out of reach of the source environment?
Server Backup & Recovery: A backup that has never been tested is a hypothesis, not a recovery plan. The only way to know you can restore is to have proven it — before you need it under pressure.
Patch & Vulnerability Management3 of 4 · 67% aligned
How does your organization manage software and operating system (OS) patching across workstations, servers, and network devices?Mostly in place
Your answer: IT-managed manual patching — patches are applied by your IT team but on an inconsistent schedule, not automated.
Exploitation of a known vulnerability is now the leading initial access vector, at 31% of breaches in Verizon’s 2026 report. Your patch cycle is your window — automated management is the only reliable way to close it consistently.
How Sunco closes this
Manual patching consistently lags automated processes. Defining patch windows and automating where possible closes the gap between disclosure and deployment. Manual patching moves at the speed of whoever remembers, and exploitation of a known vulnerability is now the leading initial access vector at 31% of breaches — so the window between a patch being available and a patch being applied is the exposure.
CIS Controls v8.1 · Control 7 · Continuous Vulnerability Management (Safeguards 7.3 operating system and 7.4 application patch management, both Implementation Group 1)
Is automated patch management applied to operating systems and applications on at least a monthly cycle?
Does your organization run vulnerability scans to identify unpatched or misconfigured systems?Partly in place
Your answer: We have never run a vulnerability scan on our environment.
Patch management closes known vulnerabilities — but misconfigurations, open ports, and rogue services require active scanning to detect. Vulnerability scanning finds what patch management misses.
How Sunco closes this
Without scanning, you have no visibility into your actual attack surface. A single scan typically reveals multiple critical vulnerabilities present for months undetected. Most SMBs running their first vulnerability scan discover at least one critical vulnerability present for over 90 days — often much longer.
CIS Controls v8.1 · Control 7 · Continuous Vulnerability Management (Safeguards 7.5 internal and 7.6 externally-exposed vulnerability scans, both Implementation Group 2)
Are automated vulnerability scans run — internally at least quarterly, and against internet-facing assets at least monthly? CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
How does your organization track and manage software installed across all devices?Mostly in place
Your answer: Partial visibility — most business-critical software is tracked but personal devices or remote workers may have gaps.
You can't patch software you don't know exists. Untracked software on remote worker devices introduces vulnerabilities invisible to your patch management tools and creates unmonitored attack surfaces.
How Sunco closes this
Partial inventory visibility creates blind spots in patch management. Extending device management to all endpoints accessing company data closes these gaps. Unmanaged software on remote worker devices is a common initial access vector. If IT can't see it, it can't be patched, monitored, or removed.
CIS Controls v8.1 · Control 2 · Inventory and Control of Software Assets (Safeguards 2.1 software inventory and 2.2 currently supported software, both Implementation Group 1)
Is there an inventory of authorised software recording its business purpose, reviewed at least twice a year, with unsupported software identified?
Patch & Vulnerability Management: The average time between a vulnerability being published and it being actively exploited is now less than 5 days. Your patch cycle determines whether attackers get there first.
Access & Credential Security1 of 4 · 92% aligned
How does your organization control and audit access to privileged and administrative accounts?Mostly in place
Your answer: Admin rights are restricted to specific roles but we do not have a formal PAM tool — access is managed manually.
Admin credentials are the highest-value target in any environment. Once an attacker has admin access, the entire organization is compromised. Every unmonitored admin account is an undetected path to full control.
How Sunco closes this
Manual access management is difficult to audit and easy to miss during offboarding or role changes. A PAM solution automates enforcement, reduces the risk of human error, and provides forensic evidence. Manual admin access management relies on consistent, error-free human processes. Offboarding depends on somebody remembering every system on the day they are busiest, which is why a leaver’s account is so often still live weeks later.
CIS Controls v8.1 · Control 5 · Account Management (Safeguard 5.4 restrict administrator privileges to dedicated administrator accounts, Implementation Group 1)
Are administrative privileges confined to dedicated administrator accounts, with day-to-day work done from a non-privileged account?
Access & Credential Security: Credential abuse was involved in 13% of breaches in Verizon’s 2026 report, behind exploitation of a known vulnerability at 31%. Every account without multi-factor authentication (MFA), every shared password, and every unrevoked access is an open door — and attackers are methodical about finding them.
HIGH RISK · 2
Your biggest risks
These are the gaps we would close first. Most carry direct exposure, and the rest are the ones that make everything else harder to detect.
Security Operations1 of 4 · 25% aligned
Does your organization use a security information and event management (SIEM) (Security Information and Event Management) to centralize and correlate security logs?
Your answer: We have no centralized logging or security information and event management (SIEM) capability — system logs are not collected or reviewed.
Individual security tools see their own events in isolation. A SIEM correlates logs across email, endpoints, identity, and network — turning disconnected signals into a complete picture of an attack in progress.
How Sunco closes this
Without centralized logging, there is no forensic trail after an incident and no detection capability during one. Implementing logging and security information and event management (SIEM) is a foundational security operations requirement. After a breach, forensic investigation depends entirely on logs. Organizations without logging often cannot determine what was accessed, when, or by whom — which dramatically increases legal and regulatory exposure.
CIS Controls v8.1 · Control 8 · Audit Log Management (Safeguard 8.9 centralize audit logs, Implementation Group 2)
Is audit log collection and retention centralised across enterprise assets? CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
Security Operations: Most organizations discover a breach through a third party — not their own monitoring. The gap between a contained incident and a catastrophic one is almost always how fast the first alert fires.
Server Backup & Recovery1 of 4 · 67% aligned
When did you last successfully test a complete restore from your server backups?
Your answer: We have no backup testing process and are not confident our backups would restore successfully.
A backup job that completes is not a backup — it is a file that has not yet been tested. Veeam’s 2026 report found organizations attacked recovered an average of 72% of their affected data and only 28% recovered all of it — the distance between a backup reporting success and a restore working.
Source: Veeam (2026)
How Sunco closes this
If you are not confident in your backups, your organization has no reliable recovery capability. Establishing both consistent backup coverage and regular restore testing is a critical immediate priority. An untested backup is a hypothesis. Until you've successfully restored from it, you don't have a backup — you have a hope.
CIS Controls v8.1 · Control 11 · Data Recovery (Safeguard 11.5 test data recovery, Implementation Group 2)
Is backup recovery tested quarterly or more frequently, on a sample of in-scope assets? CIS places this above its Implementation Group 1 baseline, so it is a step beyond the minimum expected of the smallest organizations rather than part of it.
Server Backup & Recovery: A backup that has never been tested is a hypothesis, not a recovery plan. The only way to know you can restore is to have proven it — before you need it under pressure.
⚡ Quick Wins — Act On These Now
 
Schedule quarterly backup restore tests today and document the results as your recovery baseline.
Confirms your backup actually works before you need it. Typically 1 day to schedule.
 
Assign an alert owner and define a simple weekly email security review process.
Reduces average breach dwell time from months to days. Typically 1 week.
 
Deploy Domain Name System (DNS) filtering — most platforms configure and go live in under a day, no hardware required.
Blocks ransomware callbacks and phishing infrastructure your firewall never sees. Typically 1 day.
 
Assessment Framework & Standards Alignment
 

Your results have been evaluated against the following frameworks and Canadian regulatory obligations.

CIS CONTROLS v8.1
Critical Security Controls, from the Center for Internet Security
Eighteen prioritized controls published by the Center for Internet Security (CIS), each safeguard tagged with an Implementation Group tier so a baseline expectation for the smallest organizations can be told from a target.
NIST CSF 2.0
Cybersecurity Framework, from the US National Institute of Standards and Technology
Six functions — Govern, Identify, Protect, Detect, Respond, Recover — used as the common language for describing security posture.
ALBERTA PIPA
Personal Information Protection Act
Alberta’s private-sector privacy law, including the obligation to protect personal information and to report breaches involving a real risk of significant harm.
PIPEDA
Personal Information Protection and Electronic Documents Act
Canada’s federal private-sector privacy law, governing safeguards and mandatory breach reporting for organizations operating across provincial lines.
CCCS
Canadian Centre for Cyber Security
Canada’s national cyber security authority, whose baseline controls for small and medium organizations are the closest Canadian equivalent to the layers this assessment measures.

This assessment surfaces coverage gaps and does not certify compliance with any standard. It assumes your own people administer the tooling; consult qualified counsel regarding your specific obligations.

Indicative IT & Security Spend Snapshot
See how you stand against your peers
Statistics Canada publishes what Canadian businesses actually spend on cyber security prevention and detection, and how many spend nothing at all. It is the only way to know whether your number is normal for a business your size. Everything here is either a published figure or one of your own — no prices, and nothing estimated.
The figures below use typical values for a business of about this size, because the snapshot was left unfilled. Re-run it with your own numbers for a comparison that reflects your organization.
What the alternatives cost
Your spend across 50 users$125 per user / month
 
One cybersecurity specialist in Alberta, fully loaded$137,000
That one hire, expressed the way you buy IT$228 per user / month
You spend about $125 per user per month on IT and security. One fully loaded cybersecurity specialist in Alberta is about $137,000 a year — $228 per user per month across your 50 people, for one person’s salary, before any security tooling and with no cover for nights, weekends or vacation. Meanwhile 44% of Canadian businesses spend nothing at all on prevention and detection. What adequate coverage costs for your environment depends on your environment, and that is worth half an hour of conversation rather than a number on a web page.
How you stand against your peers
Canadian businesses that spend anything at all on cyber security prevention and detection56%
Which means 44% spend nothing. Down from 61% in 2021.
Canadian businesses with employees dedicated to cyber security50%
Down from 61% in 2021, while incidents continued.
Canadian businesses impacted by a cyber security incident in 202316%
About one in six. Recovery spending across all businesses doubled from $600 million in 2021 to $1.2 billion in 2023.
Spent on prevention and detection by medium-sized Canadian businesses, 50 to 249 people$3.6B
Small businesses of 10 to 49 spent $2.6 billion; large businesses of 250 or more spent $4.8 billion. $11.0 billion in total.
What one incident costs a small or medium business, on average~$363,000
US$264,000 across claims from 2020 to 2024, about C$363,000 at the Bank of Canada rate for 21 August 2026. Crisis services alone averaged US$152,000, and insurance covered 69% of the total — down from 81%.

Indicative estimate based on published benchmarks and your own figures. Numbers are rounded and intended to frame a conversation, not to predict your costs. What managed coverage would cost for your environment is a conversation, not a figure on a web page.

Sunco’s Recommendation
Coverage gaps: Several layers are missing, and at least one of them is a baseline expectation.
Book Your Security Software Review

A Sunco advisor will walk through your results and identify the highest-impact next steps for your organization.

Book Your Review →
30 minutes • Free • No obligation
Research Sources and Methodology

Every figure and framework reference in this report is listed below with a link to the original source, so you can verify any of it yourself.

Statistics Canada — The Daily — Impact of cybercrime on Canadian businesses, 2023 (Canadian Survey of Cyber Security and Cybercrime)
In 2023, 56% of Canadian businesses spent on cyber security prevention and detection, down from 61% in 2021 — a total of $11.0 billion, of which $2.6 billion was spent by small businesses of 10 to 49 employees, $3.6 billion by medium businesses of 50 to 249 and $4.8 billion by large businesses of 250 or more. Recovery spending doubled to $1.2 billion. 16% of businesses were impacted by a cyber security incident, and 50% had employees dedicated to cyber security, down from 61% in 2021. Just over 1 in 4 (26%) had written cyber security policies in place, and 22% provided formal cyber security training to non-IT employees.
Tier 1 source · Canada · figures in CAD · verified 2026-08-23
Job Bank / Statistics Canada Labour Force Survey — Wage report — Cybersecurity Specialist, National Occupational Classification 21220, Alberta
Cybersecurity Specialist wages in Alberta, 2024 reference period: low $35.40 an hour, median $50.51, high $87.09. At the median that is about $105,000 a year before employer costs.
Tier 1 source · Alberta · figures in CAD · verified 2026-08-23
NetDiligence — 2025 Cyber Claims Study (10,402 claims analysed; 9,171 above the $1,000 analysis threshold)
Across claims from incidents occurring between 2020 and 2024, the average total incident cost for small and medium enterprises was US$264,000, with crisis services averaging US$152,000. SMEs accounted for 98% of claims. Of all claims carrying a business interruption component, 81% occurred at SMEs. Over five years, insurance paid 69% of the total incident cost for SMEs. NetDiligence defines an SME as an organization with less than US$2 billion in annual revenue, which is far broader than a small business as an Alberta reader would understand it — so this is a claims-severity anchor rather than a figure to expect.
Tier 2 source · North America / global · figures in USD · verified 2026-08-23
Bank of Canada — Daily exchange rates
Bank of Canada daily average exchange rate, 21 August 2026: 1 US dollar = 1.3760 Canadian dollars. Used to convert the NetDiligence figures, which are published in US dollars.
Tier 1 source · Canada · verified 2026-08-23
Center for Internet Security — CIS Critical Security Controls, version 8.1 — official list
The CIS Critical Security Controls v8.1 comprise 18 prioritized controls, each divided into Safeguards assigned to Implementation Groups 1, 2 and 3, where Implementation Group 1 is the baseline CIS expects of the smallest organizations. This assessment cites Controls 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 and 17. The Implementation Group assignments relied on: Safeguards 1.1, 2.1, 2.2, 3.6, 4.1, 4.2, 4.7, 5.2, 5.4, 7.3, 7.4, 8.1 and 15.1 are Implementation Group 1; Safeguards 5.6, 7.5, 7.6, 8.10, 9.5, 10.6, 11.5, 12.2, 12.4, 12.7 and 15.4 are Implementation Group 2; Safeguard 15.5 is Implementation Group 3 only; and Control 13 contains no Implementation Group 1 Safeguard at all. Safeguards 7.3 and 7.4 specify a monthly patching cycle, and Safeguard 8.10 sets the 90-day log retention minimum.
Tier 1 source · Global · verified 2026-08-23
International Organization for Standardization — ISO/IEC 33020:2019 — Process measurement framework for assessment of process capability
ISO/IEC 33020:2019 defines the process attribute achievement scale used for the band boundaries in this assessment: Not achieved (0 to 15%), Partially achieved (>15 to 50%), Largely achieved (>50 to 85%), Fully achieved (>85 to 100%).
Tier 1 source · International · verified 2026-08-23
Verizon — 2026 Data Breach Investigations Report
Verizon 2026 Data Breach Investigations Report, 19th edition, dataset 1 November 2024 to 31 October 2025: ransomware appeared in 48% of breaches, up from 44%. Exploitation of a known vulnerability became the leading initial access vector at 31% of breaches — the first time in nineteen editions it has surpassed stolen credentials. The human element was involved in 62% of breaches. Breaches involving a third party reached 48%, up 60% year over year. Employee use of unapproved artificial intelligence (AI) tools rose from 15% to 45% in a single year. Based on 2025 data.
Tier 2 source · Global (145 countries) · verified 2026-08-23
Microsoft Research — How Effective Is Multifactor Authentication at Deterring Cyberattacks?
Microsoft Research measured multi-factor authentication reducing the risk of account compromise by 99.22% across the studied population and by 98.56% in cases of leaked credentials, over 22 April to 22 September 2022 on commercial Azure Active Directory accounts. This supersedes the widely-quoted 99.9% figure from a 2019 Microsoft blog post, which disclosed no methodology.
Tier 2 source · Global (commercial Azure Active Directory accounts) · verified 2026-08-23
SpyCloud — SpyCloud Annual Identity Exposure Report 2026
SpyCloud 2026 Annual Identity Exposure Report, covering 2025: 642.4 million exposed credentials were recaptured from 13.2 million infostealer malware infections; SpyCloud’s cumulative recaptured collection reached 65.7 billion distinct identity records, up 23% year over year.
Tier 2 source · Global · verified 2026-08-23
Veeam — Data Trust and Resilience Report 2026
Veeam Data Trust and Resilience Report 2026, surveying 900+ senior IT, security and risk leaders: 90% of organizations expressed confidence in their ability to recover from a cyber incident, while organizations actually attacked recovered an average of 72% of affected data; only 28% fully recovered their data — fewer than one in three; 44% recovered less than 75%.
Tier 2 source · Global · verified 2026-08-23
Microsoft — Recoverable Items folder; SharePoint and OneDrive retention and deletion; Shared responsibility in the cloud
Microsoft documentation: the default deleted-item retention period for Exchange Online is 14 days, configurable to a maximum of 30 days; SharePoint and OneDrive retain deleted items in the recycle bin for 93 days in total across both stages. Microsoft’s shared responsibility model assigns customer data — including data protection — to the customer in software-as-a-service (SaaS) deployments, and the Microsoft Services Agreement recommends that customers regularly back up their own content. Microsoft 365 Backup is a separate first-party product, billed on consumption and not enabled by default.
Tier 1 source · Global · verified 2026-08-23
KnowBe4 — 2026 Phishing by Industry Benchmarking Report
KnowBe4 2026 Phishing by Industry Benchmarking Report, based on 42 million simulated phishing tests across 14.8 million users at 64,000 organizations: the global baseline phish-prone percentage before training was 33.2%, falling to 20.1% after 90 days of training and 4.2% after one year. For organizations under 250 employees the baseline was 24.7%. This is KnowBe4’s own customer base and is not a controlled study.
Tier 2 source · Global · verified 2026-08-23
IBM (research conducted by Ponemon Institute) — Cost of a Data Breach Report 2026
IBM Cost of a Data Breach Report 2026, covering 602 organizations breached between March 2025 and February 2026: the mean time to identify and contain a breach rose to 247 days from 241, reversing five years of decline. The global average breach cost reached US$4.99 million and the Canadian average CA$7.11 million. IBM publishes no size-banded figure, and its sample is enterprise-weighted, so these averages should not be read as a small-business expectation.
Tier 2 source · Global / Canada · verified 2026-08-23

Statistics are reproduced as published by the sources above and were verified on the dates shown. Regulatory positions reflect the law in force at the time of verification and may change. This assessment surfaces readiness gaps and does not certify compliance with any standard; consult qualified counsel regarding your specific obligations.

Sunco
Sunco Communication and Installation Ltd.
18961 111 Ave NW, Edmonton, AB T5S X4
1-866-310-7007  |  marketingteam@sunco.ca  |  sunco.ca

© 2026 Sunco Communication & Installation Ltd. All rights reserved.