Identity protection
ReviewMFA coverage, admin role separation, conditional access, legacy authentication, and guest/external access in Microsoft 365.
A practical review of Microsoft 365 identity, endpoints, backups, firewall and remote access, and email security for small offices in the GTA. You get a plain-English findings summary and a prioritized action plan you can act on with us, your existing IT provider, or on your own.
Built for businesses with roughly 5–50 staff that want to understand their security gaps before committing to managed IT, renewing cyber insurance, or hardening Microsoft 365.
Five areas where small business security usually breaks down. We look at how each is configured today, what risk it carries, and what the practical next step looks like.
MFA coverage, admin role separation, conditional access, legacy authentication, and guest/external access in Microsoft 365.
EDR / antivirus coverage, patch level, disk encryption, local admin rights, and how alerts are actually handled.
SPF, DKIM, DMARC alignment, anti-impersonation, attachment and link policies, and how staff report suspicious mail.
What is backed up (M365, file server, SaaS), how often, and whether anyone has tested a real restore in the last year.
Firewall rules, VPN/remote access, exposed services, shared accounts, onboarding/offboarding, and Wi-Fi exposure.
Concrete configuration checks across the controls that matter most for small offices and that show up most often on cyber insurance questionnaires.
Most assessments we run are kicked off by one of these moments. If any of them sound familiar, this is usually the right time.
You have a renewal coming up and want to know which questionnaire controls (MFA, EDR, backups, admin separation) you can honestly tick.
Someone clicked a link, paid a fake invoice, or had their account taken over — and you want a structured second look at identity and email security.
You want an independent baseline of where things stand today before signing a managed IT contract or transitioning IT providers.
Senior staff or technical contacts have left and nobody is fully sure which Microsoft 365, SaaS, or VPN accounts and admin rights are still active.
An office move is a natural time to clean up firewall rules, network exposure, Wi-Fi configuration, and remote access before everything gets reconnected.
Remote work changed how people access systems and where data lives. The original security baseline likely no longer matches the way the team actually works.
You believe you have backups, but no one has ever performed a real restore — so it is not clear whether recovery would actually work.
SharePoint sites, OneDrive sharing, and Teams memberships have grown organically over years and nobody is sure who can see what.
The visual centerpiece of every assessment. For each area we look at the common risk, the specific things CtrlShift checks, and the typical next step. No vendor pitch — just a practical reference.
MFA gaps, drifted admin roles, legacy auth still enabled.
MFA coverage, conditional access, admin separation, guest access.
Unmanaged laptops, missing EDR, patch drift across devices.
EDR coverage, alert handling, encryption, patch level, local admin.
Backup is configured, but restore has never been tested.
Backup scope, retention, evidence, and SaaS coverage (M365 / Workspace).
Exposed services, weak VPN, leftover rules from prior IT.
Firewall rules, VPN/RDP exposure, admin credentials, Wi-Fi setup.
Spoofing, phishing, brand impersonation, invoice fraud.
SPF / DKIM / DMARC, anti-impersonation, link & attachment policies.
Questionnaire answers do not match what is actually configured.
Map current controls to common insurer questions and required evidence.
Six steps designed to be light on your team — most of the time is configuration review on our side, not interviews.
Short scoping call to understand the business, what is keeping the owner up at night, and what triggered the assessment.
Confirm which Microsoft 365 tenant, endpoints, backup tool, and firewall we will review, and how access will work.
Tenant review: admin roles, MFA, conditional access, mail flow, sharing, and licensing fit.
Inventory device coverage, validate backups and restore evidence, and walk through firewall and remote access exposure.
A short, plain-English document grouping issues as fix-now / soon / later — mapped to risk, not vendor stack.
You can implement the plan yourself, hand it to your existing IT provider, or move to one of our managed IT plans.
Concrete artifacts you can keep, share with insurers, or hand to any IT provider — not a verbal walkthrough.
What was reviewed and what we found, written for an owner or office manager.
Issues grouped as fix-now, soon, and later — each with the risk it reduces.
Specific tenant changes for identity, mail flow, sharing, and admin roles.
Devices missing EDR, encryption, or current patches, and how to close the gap.
What is currently protected, what is not, and how a real restore would play out.
Findings on firewall rules, VPN, exposed services, and Wi-Fi configuration.
Where current controls map to common insurer questionnaires and required evidence.
A short, prioritized roadmap an owner can use to plan the next quarter of IT work.
Common cyber-insurance blockers we look for
We do not promise coverage or compliance. We help you identify technical gaps that often create friction during cyber-insurance applications, renewals, or claim reviews.
What this assessment is — and isn't
An honest scope so you know exactly what you get and what lies beyond it.
Small businesses with roughly 5–50 staff that handle sensitive data and want a practical, no-nonsense view of where their security stands today.
Clinics handling PHIPA-sensitive workflows and practice-management systems.
Accounting and bookkeeping firms managing CRA-sensitive client documents.
Law firms protecting confidential client records and matter files.
Engineering and consulting teams with project, IP, and client data on the line.
Get a structured small-business security baseline review — Microsoft 365, endpoints, backups, firewall, email, and cyber insurance readiness — written in plain English you can actually act on.
FAQ
Questions offices ask before starting with CtrlShift IT Services.
No. A penetration test actively tries to exploit a system. A security baseline assessment is a structured review of practical IT and security controls — Microsoft 365 identity, endpoints, backups, firewall and remote access, and cyber insurance readiness — and produces a plain-English findings summary and prioritized action plan.
It can help you identify the technical controls insurers commonly ask about — MFA, EDR, backups, admin separation, incident response — and document where you stand today. It does not guarantee coverage, premium reduction, or claim approval. Underwriting decisions are made by the insurer, not by us.
For most reviews we need read-level visibility into your Microsoft 365 tenant, endpoint protection console, backup tool, and firewall. Where read-only access is not possible, we walk through configuration with your team on a screen-share. We never install persistent tooling without explicit written approval.
A typical small-business security baseline assessment runs over a few business days end-to-end, depending on scope and how quickly we can get the access we need. Most of that time is configuration review on our side, not interviews with your team.
You receive a plain-English findings summary, a prioritized remediation checklist (fix-now / soon / later), Microsoft 365 hardening notes, an endpoint protection gap list, backup and restore readiness notes, firewall and remote access observations, optional cyber insurance readiness notes, and a short next-step roadmap.
Yes. We can implement remediations directly, hand the plan to your existing IT provider, or fold the work into one of our managed IT plans. The assessment is useful on its own — there is no requirement to engage us for ongoing services.
No. We are based in the GTA and primarily work with small businesses in Vaughan, Toronto, Mississauga, Thornhill, and Richmond Hill, but the assessment runs remotely and is suitable for small offices anywhere in Ontario.