Guide · July 23, 2026

Five Pieces of Security Evidence Every Ontario Business Should Maintain

A practical evidence checklist for Ontario organizations.

1. Identity and access records

Maintain a current view of who can access critical systems, which accounts are privileged, and how MFA is applied. Keep ownership and review dates visible.

Action checklist

  • Confirm the current owner and review date.
  • Record the evidence and any limitations.
  • Assign the next practical action.

2. Backup restoration evidence

A backup report is not the same as restoration evidence. Record what was restored, when it was tested, any limitations, and the next test date.

Action checklist

  • Confirm the current owner and review date.
  • Record the evidence and any limitations.
  • Assign the next practical action.

3. Patch and endpoint reporting

Use a repeatable report that shows coverage, exceptions, owners, and follow-up actions.

Action checklist

  • Confirm the current owner and review date.
  • Record the evidence and any limitations.
  • Assign the next practical action.

4. Incident responsibilities

Keep a short, current contact and decision checklist. Explain who can authorise containment, communicate with customers, and contact insurers or advisers.

Action checklist

  • Confirm the current owner and review date.
  • Record the evidence and any limitations.
  • Assign the next practical action.

5. Customer and insurer evidence register

List recurring questionnaires and the documents that support each response. Recheck statements before each use.

Action checklist

  • Confirm the current owner and review date.
  • Record the evidence and any limitations.
  • Assign the next practical action.
Discuss a Security Evidence Review