Resources
Free tools to help you decide
Practical, no-pressure ways to understand where you stand. Every self-assessment is scored privately in your browser, and nothing here asks for your email.
Tools and resources
Not sure where to start?
- Want a quick health check? Take the Security Posture Check; the Roadmap then turns the same answers into a priority order.
- Have a specific goal? Check your cyber-insurance readiness, your ransomware resilience, or your incident response readiness.
- Choosing a direction? See which framework applies to you, or read the frameworks explained.
- Scoping an assessment? Decide between a pen test or vulnerability assessment, or see whether a gap analysis is worth it yet.
- Building out detection? Learn whether a SIEM, XDR, or MDR fits your team.
Step 1 · Self-assessment
Security Posture Check
Fourteen quick questions, two per layer of defence, for an instant read on where you’re strong and where the gaps are.
Take the checkStep 2 · Roadmap
Security Priorities Roadmap
Can’t fix everything at once? Get your seven layers in priority order: what to tackle first, second, and third. Took the Posture Check? Your answers carry over.
Build my roadmapReadiness check
Cyber Insurance Readiness Check
Sixteen questions based on what cyber insurers actually require: MFA, EDR, immutable backups, and more. See where you’d likely qualify and where the gaps are.
Check your readinessResilience check
Ransomware Resilience Check
Could you stop ransomware and recover without paying? Ten quick questions on prevention and recovery give you an honest read on both.
Check your resilienceReadiness check
Incident Response Readiness Check
If an incident started right now, would your team know what to do? Ten questions on your plan, your people, and the practical details that either exist at 2 a.m. or don’t.
Check your readinessDecision tool
Pen Test or Vulnerability Assessment?
Not sure which you need? Answer eight quick questions for a clear recommendation: vulnerability assessment, penetration test, or both, in the right order.
Find out whichDecision tool
SIEM, XDR, or MDR?
Three acronyms, sold interchangeably, solving different problems. Answer eight quick questions to learn which detection approach fits your requirements, systems, and team.
Find out whichDecision tool
Do You Need a Gap Analysis?
Sometimes a maturity gap analysis is exactly what’s needed; sometimes it’s premature. Answer seven quick questions for an honest read on whether it’s worth it yet.
Get an honest answerGuide
Cybersecurity Frameworks Explained
NIST, CIS, ISO 27001, SOC 2, PCI DSS, CIRO: what each framework actually is, who it’s for, and how they fit together. Each guide ends with a free readiness checklist, scored in your browser.
Explore frameworksDecision tool
Which Framework Do You Need?
NIST, CIS, ISO, SOC 2, PCI, CIRO? Answer six questions for a personalized read on the framework to build on, the obligations that apply to you, and the proof customers may ask for.
Find your frameworkReference
Industry Resources
A curated directory of trusted external resources: MITRE ATT&CK, CISA KEV, NIST, CIS, OWASP, the Verizon DBIR, the Canadian Centre for Cyber Security, and more.
Browse the directoryQuick tool
What’s My IP?
See your public IP address and what your browser reveals about you: device, operating system, screen, time zone, and more. Read right in your browser; no third-party services involved.
See what you revealLearn
Cybersecurity FAQ
Plain-language answers to the questions we hear most, from MFA and EDR to frameworks and layered defence.
Browse the FAQArticles
What’s New
Plain-language insights and guidance from the FioSec team on cybersecurity for Ontario organizations.
Read the blogPrefer to just talk it through?
Whatever your result, our team can help you interpret it and decide what's right for your environment.