Baseline Controls News Resources Glossary About

Man-in-the-Middle Attack (MitM)

What is Man-in-the-Middle Attack (MitM)?

An attack where a criminal secretly intercepts and potentially alters communication between two parties who believe they are talking directly to each other. Common examples include eavesdropping on unencrypted public Wi-Fi, intercepting email between a business and its bank, or redirecting DNS queries to fake websites. HTTPS, VPNs, and encrypted email protocols defend against MitM attacks.

Why public Wi-Fi is dangerous for business →

Why this matters for Canadian businesses

Understanding Man-in-the-Middle Attack (MitM) is part of building a security programme that meets the 13 Baseline Cyber Security Controls published by the Canadian Centre for Cyber Security (ITSM.10.089) — the Government of Canada's recommended minimum standard for small and medium organizations. You can measure your organization against all 13 controls with our free cybersecurity assessment.

For the wider picture on how Canadian small and medium businesses are performing, see The Cybersecurity Canada Report 2026, our annual benchmark of incident rates, breach costs, and regulation affecting Canadian organizations.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Man-in-the-Middle Attack (MitM). Retrieved from https://cybersecuritycanada.ca/glossary/man-in-the-middle/

Disclaimer: The information provided on this website is for general educational and informational purposes only and does not constitute professional cybersecurity, legal, IT, compliance, or risk management advice. All content, including assessment results, scores, grades, and recommendations, is provided on a best-effort, "as is" basis without warranties of any kind. We expressly disclaim liability for any errors, omissions, or inaccuracies. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation. Use of this website or the assessment tool does not create a professional-client relationship. See our Terms of Use for full details.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential — your answers never leave your browser.

Take the Free Assessment