How exposed is your business to a cyber attack?
Answer 14 questions about the controls that decide how bad an incident gets, and see a weighted risk score, your weakest areas in priority order, and what to do about each one. Built for Ontario businesses by IT Rapid Support in Vaughan.
How are your business data and systems backed up — and have you tested a restore?
Is multi-factor authentication enforced on email and your other key applications?
What protects your computers and servers from malware and ransomware?
How are administrator accounts handled?
Is your network and email monitored for threats outside office hours?
How do operating systems and third-party software get updated?
Is your domain protected against someone spoofing your email address?
If you use Microsoft 365, how are its security settings configured?
When someone leaves, how quickly do their accounts and access actually get removed?
Who else can get into your systems remotely — vendors, contractors, remote support tools?
Do employees get security awareness and phishing training?
Do you have a plan for a cyber attack or a major outage — and has it been tested?
Are laptops, desktops and phones encrypted, and can you wipe a lost device?
How is day-to-day IT handled today?
How the score is calculated
No black box. Every control carries a weight based on how much damage its absence tends to cause, and each answer contributes between zero and that weight. The total is divided by 135 — the maximum possible — and expressed out of 100.
- 12 points — backups, multi-factor authentication, endpoint protection. Each of these alone can turn a routine incident into weeks of downtime.
- 10 points — admin account hygiene, monitoring, patching, email authentication. These decide how far an intruder gets and how quickly anyone notices.
- 9 points — Microsoft 365 configuration, offboarding, vendor and remote access. Common, quiet routes in.
- 8 points — staff training, incident response planning, device encryption, support model. These mostly limit damage rather than prevent access.
What this is
A structured self-assessment covering the control areas that decide how a common incident plays out. Useful for prioritising, and for showing a management team where the gaps are in language they can act on.
What this is not
It is not an audit and not a scan. It cannot see your network, and it believes whatever you tell it. A real assessment means looking at the actual tenant, devices and configuration — this just tells you where to look first.
The control areas mirror the Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations, a free public control set aimed at organisations without a dedicated security team. The weighting is ours, and you are welcome to disagree with it — it is printed above so you can.
Free tools and reading
Email spoofing checker
Check whether your domain publishes SPF, DKIM and DMARC — and whether DMARC is actually enforcing.
OpenGTA SMB Cybersecurity Report 2026
Our own measurement of 481 mail-enabled GTA business domains, plus the Toronto and Hamilton cybercrime numbers from Statistics Canada.
OpenSmall business cybersecurity checklist
The practical version of this calculator — what to put in place, in what order, without a security team.
OpenManaged IT quote checker
Holding a proposal from an IT provider? Score it against 22 checks and get the questions to ask before you sign.
OpenIT Risk Calculator FAQs
How does the IT risk calculator work?
You answer 14 questions covering backups, multi-factor authentication, endpoint protection, admin accounts, monitoring, patching, email authentication, Microsoft 365 settings, offboarding, vendor and remote access, staff training, incident response, device encryption, and your IT support model. Each control carries a weight based on how much damage its absence tends to cause, your answers are added up, and the total is expressed as a 0-100 risk score with the weak areas listed in priority order.
Is anything I enter sent to IT Rapid Support?
No. The calculator runs entirely in your browser. There is no form to submit, no account, no analytics event carrying your answers, and no server receiving them. Nothing is stored — closing or refreshing the page clears it. If you want us to look at your results you have to contact us and tell us yourself — the "email me these results" button simply opens your own mail app with a prefilled message, and nothing is sent unless you press send.
Is this a security audit?
No, and it should not be presented as one. It is a structured self-assessment: it reflects what you tell it, it scans nothing, and it cannot see your network. It is useful for deciding what to look at first and for showing a management team where the gaps are. A real assessment involves looking at the actual tenant, devices and configuration.
Why are some questions worth more than others?
Because the consequences are not equal. Missing backups, missing multi-factor authentication and unmanaged endpoint protection carry the heaviest weight (12 points each) because each one on its own can turn a routine incident into weeks of downtime. Staff training and incident response planning carry 8 points — they matter, but they reduce damage rather than prevent access. The weights are shown so you can disagree with them.
What should I do with my score?
Work the flagged items top-down. The list is already ordered by how much each gap contributes to your score, so the first two or three items are where the effort pays off most. If you would rather have someone go through it with you, IT Rapid Support serves businesses across the Greater Toronto Area from Vaughan — call (289) 582-9930.
Who is this for?
Small and mid-sized Ontario businesses that want a fast, honest read on where their IT and security posture is weak — including professional services, healthcare, real estate, construction and trades, and any business running on Microsoft 365.
Ready to close the gaps?
Talk to our GTA team about managed IT, cybersecurity and 24/7 support built around how your business actually runs.