Govern your security
Develop an incident response plan, assign responsibility, and consider cyber insurance: basic organizational readiness.
Frameworks · Canadian & regulatory
Canada’s own no-nonsense starting point for small and medium organizations.
The Baseline Cyber Security Controls are a practical, prioritized set of measures published by the Canadian Centre for Cyber Security (the Cyber Centre), Canada’s national authority on cyber security and part of the Communications Security Establishment. They are written specifically for small and medium organizations that do not have a dedicated security team.
Their whole design philosophy is "maximum protection for minimum effort." Instead of asking a small organization to adopt a sprawling framework, the Cyber Centre distilled the highest-value actions, drawing on the same evidence behind its widely cited Top 10 IT Security Actions, into a baseline that a non-specialist can understand and act on.
They are voluntary guidance, not a regulation or certification. The value is in their authority and clarity: free, Canadian-context advice from the national cyber agency, framed in plain language.
The baseline is organized into a set of recommended controls covering the essentials: governing your security, protecting accounts and information, securing devices and connections, and being ready to recover. It pairs naturally with the Cyber Centre’s Top 10 IT Security Actions: measures such as patching, enforcing strong authentication, hardening configurations, segmenting networks, training employees, and backing up data.
Because it is aimed at smaller organizations, the baseline favours concrete, achievable actions over exhaustive coverage. The areas below capture the essentials it emphasizes. Consult the Cyber Centre’s current publication for the full detail.
Develop an incident response plan, assign responsibility, and consider cyber insurance: basic organizational readiness.
Enforce strong, multi-factor authentication and manage administrative privileges carefully.
Patch and update promptly, harden configurations, and use modern malware protection on devices.
Protect the network and perimeter, secure remote access, and use secure cloud and mobile practices.
Back up data securely and test recovery; protect information at rest and in transit.
Educate employees so they can recognize and resist the most common attacks.
The baseline is built for Canadian small and medium organizations: the businesses, charities, and not-for-profits that know they need to improve their security but lack the time, budget, or in-house expertise for a full framework.
It is an ideal first step: a credible, free, government-backed checklist that delivers most of the practical risk reduction with a fraction of the overhead. Many organizations use it to get protected quickly, then graduate to NIST CSF or the CIS Controls as they mature.
It is intentionally not comprehensive enough for organizations with complex environments, high-value targets, or formal compliance obligations. Those should treat it as a floor, not a ceiling, and adopt a fuller framework.
The baseline is essentially a Canadian, small-business-friendly distillation of the same priorities found in the CIS Controls’ IG1 and NIST CSF: strong authentication, patching, backups, awareness, and a response plan. Adopting it puts you well along the path toward those broader frameworks.
Because it comes from the Cyber Centre, it also aligns with how Canadian regulators and insurers think about baseline diligence, which makes it a useful reference point alongside obligations like PIPEDA, PHIPA, or CIRO’s expectations.
CCCS Baseline is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Govern & prepare
—Protect accounts
—Secure devices & connections
—Protect information
—Train people
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: Canadian Centre for Cyber Security: Baseline Controls (cyber.gc.ca)
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.