In short
- Eight areas decide whether a bad morning becomes a lost day.
- Backups, logins and the machines themselves carry the most risk. Missing half of any one of those three is urgent.
- Walk each list and mark what nobody in your business can answer today. Those marks are your gaps, in the order worth fixing.
You do not need to understand any of this to use it. Read each line and ask yourself one question: can somebody in this business answer that today? Anything you cannot answer is worth a conversation.
Take the list to whoever looks after your computers. Their answers, and how quickly they come, tell you a great deal.
It takes about an hour to walk the whole thing, and you can do it with a pen and this page on a phone. You need no technical vocabulary for any of it. Owners who work through it usually finish with three or four lines they cannot answer, which is exactly the point of the exercise: a short, specific list beats a vague worry about whether the computers are alright.
1. The network
Everything else sits on top of this.
- The switches and access points are business equipment, and somebody can show you what plugs in where
- Guest wifi is kept separate from the office network
- The office wifi password is not written on the whiteboard
- There is a proper firewall in front of the office, and someone reviews its rules at least once a year
- Battery backup sits under the server and the main network gear
- Staff working from home come in through a private connection rather than a port left open to the internet
2. The machines
Every desktop, laptop and phone that touches your files.
- Every machine has business-grade protection, and one screen somewhere shows the status of all of them
- Updates are applied on a schedule that somebody owns
- No machine is running a version of Windows or macOS that stopped getting security fixes
- Screens lock themselves after five to ten minutes
- Hard drives are encrypted, so a stolen laptop is a lost laptop rather than a lost client list
- Any laptop or phone can be wiped remotely
- There is a written rule about staff using their own phones and laptops for work
3. The logins
Most break-ins start with a password rather than a clever piece of code.
- Two-step sign-in is turned on for email, banking, your CRM and every cloud account
- Two-step sign-in uses an app or a key rather than a text message for anything valuable
- Administrator accounts are separate from the account somebody uses for daily email
- People can reach what their job needs and nothing more
- Access is reviewed once a year and whenever somebody changes role
- The day somebody leaves, their access ends. Somebody owns that step and it is written down
- Passwords live in a business password manager, and nowhere in a spreadsheet or a shared inbox
4. The backups
The rule is three copies, on two kinds of storage, with one of them somewhere else.
- Backups run on their own, without anyone remembering to start them
- Somebody restores a file on purpose every quarter to prove the backups work
- Failure warnings go to a person who reads them
- You know how long you can be down and how much work you can afford to lose, and both numbers are written down
- Someone other than the person who set it up can carry out a restore
- Microsoft 365 or Google Workspace is backed up separately. What the vendor keeps is shorter than most owners assume
- At least one copy sits somewhere ransomware cannot reach, and the keys to it are not stored on the systems being backed up
5. The cloud accounts
Most Canadian businesses now run on subscriptions, and the pile grows quietly.
- There is one list of every subscription in use, including the ones a department bought on a credit card
- Each one has a named owner who handles the contract, the users and the data
- Duplicates and unused seats have been cancelled. Most businesses are paying for a fifth of what they buy twice
- Administrator accounts have two-step sign-in and are separate from daily accounts
- There is a clear answer to "where do files live", and staff follow it
- Sharing with people outside the company is limited on purpose
- No client information sits in anybody’s personal cloud account
6. Email and the paperwork
- Your domain has SPF, DKIM and DMARC set up, so nobody can send email that looks like it came from you. These three settings are also what stands between your bookkeeper and the invoice scam
- Your domain, your website and your email are hosted somewhere you can name, under an account in your business name. What that covers is on the websites page
- Staff get a short phishing refresher at least once a year
- Somewhere accessible, written down: how to restart the server, how to restore a file, how to set up a new hire
- The network diagram matches what is actually in the building
7. Privacy duties in Canada
PIPEDA, which covers most private companies:
- Your privacy policy is published and current
- You can say what personal information you hold, why you hold it, and how long you keep it
- There is a written plan for the day something leaks, and somebody has read it
- One person is responsible for privacy
- Every supplier that touches personal information has an agreement covering it
Quebec’s Law 25, if you operate there:
- High-risk uses of personal information get a written assessment first
- Consent is recorded, and you can technically delete or hand over somebody’s data on request
PHIPA, if you hold health records in Ontario:
- Access to patient records is logged and somebody reviews the log
- Patient data is encrypted while stored and while moving
- Anyone outside the practice who touches patient data has an agreement covering it
- Breach notice steps are written down before you need them
Your profession may add more. Law Society guidance for firms, OSFI guidance in financial services, FIPPA for public bodies.
8. Contracts and suppliers
Almost nobody has a process here, and it is the cheapest one to fix.
- One list of every technology supplier and contract
- Renewal dates tracked with at least 90 days of warning before anything renews on its own
- You know who to call at each supplier, and who to escalate to when the first call goes nowhere
- You know which single supplier failing would stop your business
- There is a rough budget for the next 12 to 24 months of replacements and renewals
How to read your answers
Count the gaps. Missing more than a third of any section is a real gap. Missing half of section 2, 3 or 4 is urgent, because those three carry the most risk.
Rank by what it would cost you. An untested backup matters more than an undocumented cable. Judge each gap by what a failure there would do to your week.
Fix in order, over months. A realistic plan takes the highest-risk gaps first and spreads the rest across three to six months — the steady, scheduled work monthly IT support is built for — so the budget and the office both survive it.
Do it again next year. Staff change, systems get added, a new location opens. A list that was clean last year rarely stays clean.
Two questions from this list come up more than any other, and both have short answers of their own: how do I know if our backups work, and what does an IT company do for a dental office for practices holding patient records. If you are in the western suburbs, what we cover locally is on the Mississauga page.
Have someone walk it with you
The free infrastructure audit walks all eight areas with you and gives you a written report in plain English, with the gaps in priority order. It costs nothing and there is nothing to sign.
If you would rather talk first, leave your name and number on the contact page. A real person calls you back the same business day, usually within an hour.
itopsi is a managed IT provider working with Canadian businesses from a Toronto base.

