A vulnerability scan and a cybersecurity assessment aren't the same thing. Here's what a real one reviews, how it runs, and what you should walk away with.
Ask 3 IT providers for a cybersecurity assessment and you can get 3 very different things. One runs an automated scan overnight and emails a list of open ports. Another sends a 20-question survey. A third spends a week inside your Microsoft 365 tenant, your firewall, your backups, and your payment approval process. All 3 will call it an assessment.
This guide is for owners, controllers, and operations leads at small and mid-sized Ontario businesses who want to know what a real assessment should cover before they book one, or who are trying to judge the one they already have. It explains each area that gets reviewed, how the process runs, what the report should look like, and where a quick scan falls short. It also shows how the review fits alongside ongoing cybersecurity services for Ontario businesses, so you know what happens after the findings land. Where we describe ACT360’s own approach, we say so. Where an outside framework or study applies, we link to it.
TL;DR. A proper cybersecurity assessment reviews 7 areas together, which are identity and access, devices and patching, network and perimeter, email and payment fraud controls, backup and recovery, vendors and cloud apps, and people and policies. It tests things rather than asking about them, and it ends with a written report that ranks risks by business impact. A vulnerability scan covers only a small slice of that.
What Is a Cybersecurity Assessment, and How Is It Different From a Scan?
A cybersecurity assessment is a structured review of how well a business protects its data, systems, and money. It looks at technology, day-to-day processes, and staff behaviour together, then ranks the gaps it finds by how much harm each one could realistically cause the business.
That definition matters because the word gets stretched. A vulnerability scan, a penetration test, and a compliance audit are all useful, and none of them is the same thing as an assessment. Here’s how they compare when you’re deciding what to ask for.
| Option | What It Checks | What It Misses | Best For |
|---|---|---|---|
| Vulnerability scan | Systems compared against a database of known weaknesses, such as missing patches and exposed services | Staff behaviour, payment processes, backup restores, and whether policies exist at all | Regular technical hygiene, monthly or quarterly, between fuller reviews |
| Cybersecurity assessment | Technology, processes, and people together, with findings ranked by business risk | Deep exploit testing of a specific system, which is a pen test’s job | Knowing where you actually stand and what to fix first |
| Penetration test | Whether a skilled tester can actively break into specific systems or applications | Most process and human gaps outside the agreed test scope | Proving a specific system can withstand attack, often for a client or insurer |
| Compliance audit | Whether controls match a named standard or regulation | Risks the standard doesn’t mention | Businesses that must show conformance to a specific framework |
NIST’s Technical Guide to Information Security Testing and Assessment (SP 800-115) describes scanning, penetration testing, and review techniques as separate methods with different strengths, which is the same split shown above.
If you only remember one row, make it the scan. It’s the cheapest and fastest option, and it’s the one most often sold as an assessment. A clean scan tells you your systems don’t have known holes on the day it ran. It says nothing about whether your accounts clerk would change a supplier’s banking details because an email asked nicely.
What Does a Cybersecurity Assessment Actually Cover?
A full cybersecurity assessment covers 7 areas, which are identity and access, devices and patching, network and perimeter, email and payment fraud controls, backup and recovery, vendors and cloud apps, and people and policies. Most shallow reviews stop after the first 3.
Here’s what each area involves in practice, and what a reviewer should actually be checking.
- Identity and access. Is multi-factor authentication turned on for every Microsoft 365 account, including the shared mailbox nobody thinks about? How many people hold Global Administrator rights? Are old sign-in methods that skip MFA still allowed? Microsoft reports that more than 99.9% of common identity-related attacks are stopped by using multifactor authentication and blocking legacy authentication, which is why this is usually the first thing we look at.
- Devices and patching. Every laptop, desktop, and server should run endpoint protection such as Microsoft Defender, and updates should be installing rather than failing quietly. The gap we see most is 1 or 2 machines that dropped out of management months ago and nobody noticed.
- Network and perimeter. Firewall firmware, open ports, remote desktop exposed to the internet, VPN setup, and whether guest Wi-Fi is actually separate from the network your accounting system runs on.
- Email and payment fraud controls. Email authentication records, suspicious forwarding rules inside mailboxes, lookalike domains, and the human process for approving a change to someone’s banking details.
- Backup and recovery. Whether Microsoft 365 data is backed up at all, whether a copy sits somewhere ransomware can’t reach, and when a restore was last proven to work. Our guide on how often to test your backups goes deeper on this one.
- Vendors and cloud apps. Which outside companies and connected apps have access to your data or systems. This area has grown fast. Verizon’s 2025 Data Breach Investigations Report found that breaches involving a third party doubled from 15% to 30% in a single year.
- People and policies. Whether staff can spot a convincing phishing attempt, whether there’s a written incident response plan with names and phone numbers in it, and whether offboarding actually removes access on someone’s last day.

None of this list is invented for sales purposes. The Canadian Centre for Cyber Security’s baseline cyber security controls for small and medium organizations set out 13 controls that include an incident response plan, automatic patching, strong authentication, employee awareness training, backups, and securing cloud and outsourced IT services. A good assessment is essentially an honest check of how far a business is from that baseline.
How Do You Test the Human Side of Security?
Human risk is tested with realistic simulations, not questionnaires. A reviewer sends a controlled phishing email, checks who clicks or enters a password, and walks through how a payment change request would actually be handled. What people do under realistic conditions tells you far more than what they say they’d do.
This is the part of an assessment most businesses skip, and it’s hard to justify skipping it. Verizon’s same 2025 report found the human element was involved in roughly 60% of breaches. Closer to home, Statistics Canada found that only 22% of Canadian businesses gave formal cyber security training to non-IT employees in 2023.

A useful human risk review usually includes these checks.
- A simulated phishing email sent to staff, with results reported by department rather than by name so nobody is shamed.
- A walkthrough of the payment approval process, asking what happens when a supplier emails new banking details.
- A review of who can approve money movement alone, and whether a phone call to a known number is required first.
- A conversation with the person who handles offboarding, to see whether access removal is a checklist or a memory exercise.
In our experience, the phishing numbers are rarely the most useful finding. The payment process usually is. A single missing verification step can matter more than a dozen unpatched laptops, because it’s the step standing between a fake email and a six-figure transfer.
What Happens During a Cybersecurity Assessment?
Expect 4 stages, which are a scoping conversation, a technical review, process and people checks, and a written report with a walkthrough. In ACT360’s experience the whole cycle takes a few days to about a week, and most of the technical work happens in the background without disrupting staff.
We haven’t found a published industry benchmark for how long an assessment should take, so treat any timeline, ours included, as a scoping estimate. A single office running mostly on Microsoft 365 moves faster than 3 locations with an on-site server and a line-of-business application nobody ever documented.
You don’t need to prepare much. It speeds things up if you can find these 5 items before the first call.
- The name of whoever holds the admin passwords for Microsoft 365, the firewall, and the backup system.
- A rough list of the software and cloud apps your team uses every week.
- Your current cyber insurance questionnaire or policy, if you have one.
- Any existing IT or security policies, even if they’re out of date.
- Contact details for outside vendors that connect to your systems, such as your accounting or payroll provider.
If nobody’s sure who holds the admin passwords, that’s fine. It’s also your first finding.
What Should a Cybersecurity Assessment Report Include?
A useful report ranks every finding by business impact, explains each one in plain language, gives a rough effort or cost to fix it, and says clearly what’s already fine. An owner or controller should be able to act on it without an IT background.
A good cybersecurity assessment report usually contains these 5 parts.
- A 1-page summary written for leadership.
- Findings grouped as high, medium, or low priority, each with a sentence on what it means for the business.
- A rough effort or cost range for each fix, so you can plan a budget rather than react to one.
- A list of what’s fine as-is, because knowing where not to spend money is useful too.
- What isn’t being recommended yet, and why.
| Finding | What it means for the business | Priority | Rough effort |
|---|---|---|---|
| MFA missing on 4 of 26 Microsoft 365 accounts, including a shared finance mailbox | A single stolen password could open email and payment approvals | HIGH | Hours |
| Banking detail changes can be approved by email alone | A spoofed supplier email could redirect a payment | HIGH | 1 day to change the process |
| Backups run nightly but have never been restore-tested | Nobody knows how long recovery would take | MEDIUM | 1 day |
| 2 former employees still have active accounts | Access that should have ended months ago | MEDIUM | Minutes |
| No written incident response plan | Slower, more expensive decisions during an actual incident | LOW | 2 to 3 days |
| Firewall firmware current and supported | No action needed right now | FINE AS-IS | None |
Notice what sits at the top of that sample. It isn’t a missing patch. It’s an account without MFA and a payment process with no second check, both cheap to fix and both capable of causing real financial damage. A report that ranks by technical severity alone would likely have buried them under a long list of scanner results.
What Can an Assessment Catch That a Scan Can’t?
An Ontario organization with multiple locations and complex finance operations received a fraudulent email asking a business partner to update banking details for a pending payment worth over six figures. ACT360’s investigation confirmed there was no breach and traced the email to a lookalike domain.
The email impersonated a real employee, referenced a payment conversation that was actually happening, and copied wording from genuine earlier messages. The recipient paused and asked for confirmation before sending anything, which is the only reason the story ends well.
The investigation covered the same ground a proper assessment covers. ACT360 reviewed sign-in history, mailbox rules, delegated access and permissions, connected applications, and email forensics, and validated the security monitoring already in place. No suspicious successful sign-ins turned up. The message had come from a newly registered domain that differed from the real one by a single letter.
The recommendations that followed were mostly about process, not technology. No banking changes by email alone. Phone verification using contact details already on file. Dual approval for payment changes. Staff awareness training, and a review of every workflow that moves money.
That’s the point worth taking from it. A scan of that environment would have come back clean, and it would have been right. The exposure was in how a payment change gets approved. You can read the full payment fraud investigation case study for the details.
How Often Should a Business Get a Cybersecurity Assessment?
ACT360 recommends a full cybersecurity assessment at least once a year, with lighter technical scans in between. A new review also makes sense after a major change, such as a merger, a move to the cloud, a new office, or a cyber insurance renewal that asks harder questions.
There’s no single legal requirement setting that frequency for most Ontario small businesses, so treat annual as our working recommendation rather than a rule. The Canadian numbers suggest plenty of businesses aren’t doing it at all. Statistics Canada reported that 59% of Canadian businesses carried out any activity to identify cyber security risks in 2023, and just 26% had written cyber security policies.
Beyond the annual review, these events are good reasons to book one sooner.
- Your insurer sends a longer questionnaire at renewal. Our guide to cyber insurance requirements in Ontario covers what underwriters usually ask about.
- You’re moving servers or files to Microsoft 365 or Azure.
- A client, often a larger company or public-sector buyer, asks you to prove your security controls.
- You handle personal information and want confidence in your safeguards under federal privacy law. Our overview of PIPEDA compliance for Ontario businesses explains the obligations.
- You’ve had a near miss, like the payment fraud attempt above.
How Does ACT360 Approach Cybersecurity Assessments?
At ACT360, the cybersecurity review is part of our free, no-obligation IT Readiness Assessment. It’s led by Jeffrey Bowles, Partner and Director of IT Services, and it covers the technical, process, and people layers together before any recommendation is made.
We start with how the business runs, not with a scanner. Where does client data live? Who can approve a payment? What would stop the business from operating for a day? Those answers decide which technical findings matter most, and they’re what keep the report tied to your operations rather than a generic checklist.
“I’d rather we catch this now, in a review, than have it show up as an incident in six months.”
Jeffrey Bowles, Partner & Director of IT Services, ACT360
The report is written for the owner or controller, not for a technician, and it includes what we’d hold off on. If your setup is mostly sound, that’s what you’ll hear. Security is only one part of the broader review, so if you want to see how infrastructure, licensing, and documentation fit in, here’s what to expect during a full IT assessment. If hybrid or remote staff are part of the picture, our piece on security risks in hybrid work environments covers the gaps that setup tends to create.
Questions Owners Ask Before a Cybersecurity Assessment
Will a cybersecurity assessment slow down my team while it’s running?
Hardly at all, if it’s run properly. Most of the technical review happens in the background through read-only admin access, and staff time usually comes down to a few short questions and 1 simulated phishing email.
What’s the real cost of a cybersecurity assessment?
ACT360’s version is free, as part of our IT Readiness Assessment, with no obligation afterward. Across the industry, pricing varies widely. A penetration test or a formal compliance audit is normally a separate paid engagement because it goes much deeper on specific systems. Whatever the price, ask what will actually be examined and whether you’ll receive a written report you keep.
We already had a penetration test last year. Do we still need this?
Probably, because the 2 answer different questions. A pen test shows whether a skilled tester can break into specific systems. An assessment looks wider, at payment processes, staff behaviour, backups, vendors, and policies that a pen test usually leaves out of scope.
How often should a small business actually get one?
Once a year is ACT360’s working recommendation, with lighter technical scans running monthly or quarterly in between. Book one sooner after a big change, like a cloud migration, a new location, or an insurance renewal with tougher questions.
Can the results help with our cyber insurance renewal?
It often can, because insurer questionnaires tend to ask about the same controls an assessment checks, such as MFA, backups, endpoint protection, and staff training. Having a recent written report makes those answers faster and more accurate, and it shows you which gaps to close before the application goes in. It won’t guarantee coverage or a lower premium, though. That decision stays with the insurer.
Do we have to switch IT providers if the assessment finds problems?
No obligation should come attached to any assessment. The report is yours to act on alone, with your current provider, or with us. Some businesses book one specifically to find out whether their current setup is as solid as they’ve been told. If you’d like to see what ACT360’s version includes, the IT Readiness Assessment page walks through it.
Final Thought
A cybersecurity assessment is only as useful as what it actually looks at. A scan checks your systems against known weaknesses, which is worth doing and nowhere near the whole picture. The gaps that cause real losses for small businesses tend to sit in accounts without MFA, payment processes without a second check, and backups nobody has restored. A proper assessment finds those, ranks them honestly, and tells you what can wait.
If you’d rather know than guess, ACT360’s free IT Readiness Assessment includes a cybersecurity review of your accounts, devices, network, backups, and payment controls, with a plain-language report you keep either way.
Call 705-739-2281 or email [email protected]