Back to all resources
guide

What Does an IT Security Assessment Include? A Guide for GTA Businesses

October 5, 2026
9 min read
IT Rapid Support Team
What Does an IT Security Assessment Include? A Guide for GTA Businesses

An IT security assessment is a structured review of how well your business is protected right now: who can sign in to what, whether devices are patched, how email is protected, whether backups would actually restore, what the firewall and remote access allow, and whether anyone would notice an attack in progress. A useful one ends with a short, ranked list of fixes, each tied to evidence, not a score and a sales pitch. For most small and mid-sized businesses in the GTA it takes days rather than weeks, and it is the starting point for cyber insurance applications, a provider switch, or simply knowing where you stand.

This guide explains what a good assessment checks, what you should receive at the end, how free and paid assessments differ, and how to prepare. It is written by a provider, IT Rapid Support at 7810 Keele St in Vaughan, so read it with that in mind; the checklist works the same whoever carries it out.

What an IT Security Assessment Is, and What It Is Not

The terms get mixed up, and the difference matters when you compare quotes. A security assessment looks across the whole environment and asks whether the right controls exist and work. It is mostly configuration review, interviews and evidence gathering.

  • A vulnerability scan is an automated tool that looks for known weaknesses in devices and services. It is one input to an assessment, not a substitute for one. A scan will not tell you that a former employee still has a working Microsoft 365 account.
  • A penetration test is a person actively trying to break in, within agreed rules. It answers "can someone get in this way?" for a defined scope. It is valuable once the basics are in place; run before them, it mostly confirms what an assessment would have found more cheaply.
  • An audit measures you against a specific standard or contract, usually for a third party such as a client, a regulator or a certification body. An assessment is for you; an audit is for someone else.
  • An online self-assessment, like our free security self-assessment, is a questionnaire you answer yourself. It is a good way to see which areas you are unsure about before paying anyone, but it only knows what you tell it.

What a Good Assessment Actually Checks

The areas below are where small-business incidents in practice tend to start. An assessment that skips any of them is incomplete, whatever it is called.

Identity and sign-in

Most business systems now sit behind one sign-in, usually Microsoft 365 or Google Workspace, so this is where an assessment should start. It should confirm that multi-factor authentication is enforced for every account, not just offered; list who holds global or super-admin rights and whether those accounts are used for everyday work; find accounts belonging to people who have left; and check for older sign-in methods that bypass MFA. Shared mailboxes and service accounts with passwords nobody has changed in years are common findings.

Email

Email is still the most common way attacks start, through phishing and invoice fraud. The assessment should check the filtering in front of the mailboxes, the rules that forward mail outside the company, and whether your domain publishes SPF, DKIM and DMARC records so others cannot easily send mail that appears to come from you. When we checked public DNS for 290 mail-enabled Vaughan business domains in October 2026, only 17.9% enforced DMARC, so this is rarely a wasted check.

Devices and patching

Every laptop, desktop and server should be listed, running a supported operating system, receiving updates, encrypted, and protected by current endpoint security. The assessment should compare the device list against what the management tools actually see; the gap between the two is often where the risk is. Servers deserve their own line, because an old file or application server is frequently the most exposed machine in the office.

Network, firewall and remote access

This covers the firewall's firmware and rules, what is exposed to the internet, how staff and vendors connect remotely, whether guest Wi-Fi is separated from the business network, and who holds the admin credentials for each device. Remote access left open for a vendor years ago, or a firewall that no longer receives security updates, are typical findings.

Backups and recovery

Having backups is not the same as being able to recover. A good assessment asks what is backed up, including Microsoft 365 or Google data, where the copies live, whether at least one copy is isolated from the network so ransomware cannot reach it, and when a restore was last tested. If nobody can remember the last test restore, that is a finding in itself.

Data and access

Who can see the payroll folder, the client files, the shared drive? Assessments regularly find permissions that grew over years, and files shared with "anyone with the link". For businesses handling personal information, this ties directly to PIPEDA obligations, including reporting breaches that create a real risk of significant harm.

Monitoring and detection

If someone signed in from another country at 3 a.m. and started creating mailbox rules, would anyone know? The assessment should establish what is logged, how long logs are kept, and whether anyone, internal or external, actually reviews alerts. Many businesses have security tools that alert into a mailbox nobody reads.

People and process

Technology is only half of it. Is there a written process for starting and leaving staff? Do staff get any phishing awareness training? Is there a one-page plan for what to do in the first hour of an incident, with phone numbers that work outside office hours? Which outside vendors have access to your systems, and how?

What You Should Receive at the End

The deliverable is where assessments differ most. A useful report has:

  • A short summary a non-technical owner can read in five minutes: the few things that matter most and why.
  • Findings ranked by risk, each with the evidence behind it (a screenshot, a setting, an account name), so the finding can be checked and the fix verified later.
  • A practical fix for each finding, with a rough effort estimate, separating quick wins such as enforcing MFA from projects such as replacing a server.
  • A list of what was not checked and why, so nobody assumes coverage that was never there.

Be wary of a report that is mostly a colour-coded score, or one where every finding happens to be solved by a single product. The point is a plan you could hand to any competent provider, including the one you already have.

Free vs Paid Assessments

Free assessments from IT providers are common, ours included. They are genuinely useful for spotting the obvious gaps, but be clear about what they are: a provider spending a few hours to understand your environment, usually in the hope of a support agreement. That is a fair exchange as long as you know it. Ask what access they need, what they will check, and whether you keep the findings whether or not you sign anything.

Free online tools sit at the lighter end. Our Microsoft 365 security check and the self-assessment linked above are questionnaires; they help you ask better questions but do not inspect your systems.

A paid assessment is worth it when you need written evidence for a third party, such as a cyber insurance application or a client's security questionnaire, or when you want an independent view of your current provider's work. We do not publish package prices for assessments; outside a managed agreement, we bill IT work at CA$185 an hour plus HST and scope the work in writing before starting, so you know the hours up front.

How to Prepare

An assessment goes faster, and finds more, if a few things are gathered first:

  • Admin access, or at least the name of whoever holds it, for Microsoft 365 or Google Workspace, the firewall, and any server.
  • A rough list of staff, devices and the business applications you rely on.
  • Your current IT provider's contact details and any documentation they have given you.
  • What you know about backups: what is covered, where it goes, and when someone last restored a file.
  • Any questionnaire you need to answer, such as a cyber insurance renewal form, so the assessment collects the evidence it asks for.

Write down what you cannot find, too. Missing passwords and undocumented systems are findings, not failures on your part.

How Often to Reassess

Once a year is a sensible baseline for most small businesses. Reassess sooner after anything that changes the picture: a cyber insurance renewal, a switch of IT provider, an office move, a merger or a new location, a key IT person leaving, or a security incident. Each of those moments tends to leave accounts, devices or rules behind that nobody owns. If you are preparing for an insurer specifically, our cyber insurance readiness checklist lists the controls insurers commonly ask about.

Questions to Ask Whoever Does It

Before you agree to an assessment, ask: which of the areas above are in scope; whether it includes Microsoft 365 or Google configuration, not just the network; what access is needed and how it is removed afterwards; what the report looks like (ask for a redacted sample); who owns the findings; and whether fixing the findings is a separate decision. A provider confident in the work will answer all of these in writing.

Where We Fit

We carry out security assessments for businesses across Toronto and the GTA, from our office on Keele Street. Local businesses can read about our IT support in Vaughan, and if you already know you want ongoing protection rather than a one-off review, our managed security services page explains how monitoring and response work after the assessment.

Frequently Asked Questions

What does an IT security assessment include?

A complete one reviews identity and sign-in (MFA and admin accounts), email protection, device patching and encryption, the firewall and remote access, backups and test restores, data permissions, monitoring and alerting, and the people and process side such as staff offboarding and an incident plan. It ends with ranked findings, the evidence for each, and a practical fix list.

How long does a security assessment take for a small business?

For an office of roughly 10 to 50 people with Microsoft 365 or Google Workspace and a single site, the hands-on review usually takes a few days, plus time to write the report. More locations, servers or line-of-business systems add time. Having admin access and a device list ready shortens it.

Is a free security assessment worth it?

It can be, as long as you know a free assessment from a provider is also a sales conversation. Ask what will be checked, what access is required, and whether you keep the written findings regardless of whether you sign up. Online self-assessments are a good free first step, but they only reflect your own answers.

What is the difference between a security assessment and a penetration test?

An assessment reviews whether the right controls exist and work across the whole environment. A penetration test has a person actively attempt to break in within an agreed scope. Most small businesses get more value from an assessment first, then a penetration test once the basic gaps are closed.

How often should a business have a security assessment?

Annually as a baseline, and again after major changes: a cyber insurance renewal, a new IT provider, an office move or new location, a key staff departure, or any security incident. To arrange one, call (289) 582-9930 or contact us.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.

More from this author

Related Resources

All Resources
Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC
whitepaper
•
October 4, 2026

Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC

Original research: we checked the public SPF and DMARC records of 290 mail-enabled Vaughan business domains on 4 October 2026. Only 17.9% enforce DMARC; 48.6% have no DMARC record at all.

Read more: Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC
IT Support for Mississauga Logistics and Warehousing
guide
•
September 5, 2026

IT Support for Mississauga Logistics and Warehousing

IT support for Mississauga logistics and warehousing firms: WMS uptime, warehouse Wi-Fi and scanners, EDI and carrier portals, 24/7 shifts, ransomware.

Read more: IT Support for Mississauga Logistics and Warehousing
IT for Medical and Dental Offices in Mississauga
guide
•
September 5, 2026

IT for Medical and Dental Offices in Mississauga

What PHIPA expects of a Mississauga medical or dental office's IT: breach reporting, EMR vendors, backups, MFA, phishing and patient Wi-Fi separation.

Read more: IT for Medical and Dental Offices in Mississauga

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch