Canadian Centre for Cyber Security
Cyber security guidance
Practical guidance, alerts, and advice for protecting information and technology assets.
Visit external resource (opens in a new tab)
Talk to an ExpertFind approved checklists, guides, executive briefs, and whitepapers designed to support practical business and technology decisions.
Direct access to official Canadian guidance and established public cybersecurity frameworks. External resources open on their source websites.
Canadian Centre for Cyber Security
Practical guidance, alerts, and advice for protecting information and technology assets.
Visit external resource (opens in a new tab)Government of Canada
Plain-language Canadian guidance for securing accounts, devices, connections, and everyday online activity.
Visit external resource (opens in a new tab)CISA
A reference for identifying vulnerabilities with evidence of active exploitation and informing remediation priorities.
Visit external resource (opens in a new tab)NIST
A flexible framework for governing, understanding, and improving organizational cybersecurity risk.
Visit external resource (opens in a new tab)External links are provided for convenience. Their inclusion does not imply partnership, certification, endorsement, or ownership by Sixway.
Use these prompts to support internal planning. Apply them in the context of your environment, risk profile, and obligations.
Require multi-factor authentication, remove dormant accounts, and review privileged access on a defined schedule.
Combine asset ownership, internet exposure, business criticality, and evidence of active exploitation when setting remediation order.
Validate restore procedures, dependencies, recovery roles, and achievable recovery objectives through regular exercises.
Document decision owners, escalation paths, critical contacts, evidence handling, and communications responsibilities before an incident.
Assign an internal owner, limit access to what is required, and include timely access revocation in supplier exit processes.
Connect each material issue to an affected business service, accountable owner, next action, and target date.
This general information is not a substitute for a security assessment, legal advice, or regulatory guidance specific to your organization.
Only reviewed and approved downloadable resources are published in the library.
A decision-focused checklist for understanding material cyber risk, clarifying ownership, and setting defensible priorities.
Explore Cyber Risk Executive ChecklistA practical preparation guide for establishing scope, stakeholders, business context, and useful evidence before an assessment begins.
Explore Preparing for a Cybersecurity AssessmentSixway can help identify an appropriate assessment, advisory, implementation, or managed-service next step.
Request an Assessment