# Cybersecurity Canada — Full Content > Free, independent cybersecurity guidance and a free self-assessment for Canadian small and medium businesses, organised around the Canadian Centre for Cyber Security's 13 Baseline Cyber Security Controls (ITSM.10.089). This file contains the full text of every article, Baseline Control guide, and glossary definition published on https://cybersecuritycanada.ca. For a short index of the same material, see https://cybersecuritycanada.ca/llms.txt Published by Cyber Unit Security Inc. Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada. All content is educational and does not constitute legal, compliance, insurance, or professional cybersecurity advice. Figures are in Canadian dollars unless stated otherwise. Language: en-CA. Contact: info@cybersecuritycanada.ca When citing this material, use the suggested citation printed on each page, or: Cybersecurity Canada (year). *Page title*. Retrieved from https://cybersecuritycanada.ca/path/ --- # Glossary of Cybersecurity Terms for Canadian Businesses Source: https://cybersecuritycanada.ca/glossary/ — 71 terms. ## Access Control URL: https://cybersecuritycanada.ca/glossary/access-control/ The practice of restricting who can access which systems, data, and resources within your organization. Good access control means employees only have access to what they need for their role — nothing more. This limits the damage if an account is compromised. Related: The Canadian Centre for Cyber Security addresses this under Baseline Control BC.12. Learn why least-privilege access matters during incidents ## Air-Gapped Backup URL: https://cybersecuritycanada.ca/glossary/air-gapped-backup/ A backup copy of your data that is physically disconnected from your network and the internet. Because it has no network connection, ransomware cannot reach it — making it your most reliable recovery option after an attack. Related: Five backup assumptions that commonly fail ## Anti-Malware URL: https://cybersecuritycanada.ca/glossary/anti-malware/ Software that detects, prevents, and removes malicious software (malware) from your devices. Modern anti-malware goes beyond traditional antivirus to detect ransomware, spyware, and other threats using behavioural analysis — not just known virus signatures. Related: Addressed under Baseline Control BC.3. ## Attack Surface URL: https://cybersecuritycanada.ca/glossary/attack-surface/ The total number of points where an attacker could try to enter or extract data from your environment. Every internet-facing system, employee account, cloud service, remote access tool, and connected device adds to your attack surface. The goal is to make it as small as possible — disable what you don't need, patch what you keep, and monitor what remains. Related: How remote work expands your attack surface ## Adversary-in-the-Middle (AiTM) Phishing URL: https://cybersecuritycanada.ca/glossary/aitm-phishing/ A phishing attack that places an attacker-controlled reverse proxy between you and the real login page. You enter your password and approve your multi-factor authentication prompt as normal, the proxy relays both to the genuine identity provider in real time, and the attacker captures the session token that comes back. Nothing is broken and no prompt fails — which is why AiTM defeats SMS codes, authenticator app codes, and push approvals. Related: How AiTM phishing defeats first-generation MFA ## Backdoor URL: https://cybersecuritycanada.ca/glossary/backdoor/ A hidden method of bypassing normal authentication to gain access to a system. Backdoors can be installed by malware, left behind by attackers after an initial breach, or even built into software by compromised developers. Once in place, a backdoor allows the attacker to return at will — even after you've changed passwords or patched the original vulnerability. Related: How backdoors are planted through supply chain attacks ## Baseline Cyber Security Controls URL: https://cybersecuritycanada.ca/glossary/baseline-cyber-security-controls/ A set of 13 fundamental cybersecurity practices published by the Canadian Centre for Cyber Security (document ITSM.10.089), designed specifically for small and medium organizations. They represent the Government of Canada's recommended minimum security standard for Canadian businesses. Related: Read our full guide to the 13 Baseline Controls ## Business Email Compromise (BEC) URL: https://cybersecuritycanada.ca/glossary/bec/ A type of fraud where an attacker impersonates a trusted person — typically a CEO, vendor, or lawyer — via email to trick an employee into transferring money, sharing sensitive data, or changing payment details. BEC does not use malware; it exploits trust and urgency. It is the most financially damaging form of cybercrime globally. Related: How BEC works and how to protect your business ## Brute Force Attack URL: https://cybersecuritycanada.ca/glossary/brute-force-attack/ An attack method where automated tools systematically try every possible password or key combination until the correct one is found. Short, simple passwords can be cracked in minutes. Strong passwords and multi-factor authentication make brute force attacks impractical. Related: Why password length matters more than complexity ## Botnet URL: https://cybersecuritycanada.ca/glossary/botnet/ A network of compromised computers or devices secretly controlled by an attacker. Each infected device (a "bot") can be remotely commanded to send spam, launch denial-of-service attacks, distribute malware, or mine cryptocurrency — often without the owner knowing. Your business devices can become part of a botnet if they lack anti-malware protection or are running unpatched software. Related: Anti-malware protection (BC.3) is your first line of defence against botnet infection. ## BYOD (Bring Your Own Device) URL: https://cybersecuritycanada.ca/glossary/byod/ A policy where employees use their personal phones, laptops, or tablets for work. BYOD can reduce hardware costs but introduces security risks — personal devices may lack encryption, anti-malware, or automatic updates, and business data on personal devices is harder to control when an employee leaves. Related: Remote work security best practices ## Canadian Centre for Cyber Security (CCCS) URL: https://cybersecuritycanada.ca/glossary/cccs/ Canada's national authority on cybersecurity, part of the Communications Security Establishment (CSE). The CCCS publishes threat assessments, security guidance, and alerts for Canadian organizations, and operates the cyber incident reporting line at 1-833-CYBER-88. Related: View Canadian government cybersecurity resources ## Credential Stuffing URL: https://cybersecuritycanada.ca/glossary/credential-stuffing/ An automated attack that uses stolen username and password combinations from previous data breaches to try to log in to other services. It works because people reuse passwords across multiple accounts. If an employee uses the same password for a personal account and their work email, a breach at the personal service can compromise your business. Related: Why password reuse is so dangerous ## Cyber Insurance URL: https://cybersecuritycanada.ca/glossary/cyber-insurance/ Insurance coverage designed to help organizations manage the financial impact of cyber incidents, including breach response costs, business interruption, regulatory fines, and liability claims. Cyber insurers increasingly require specific security controls — particularly multi-factor authentication — as conditions of coverage. Related: What Canadian SMBs need to understand about cyber insurance ## Cloud Security URL: https://cybersecuritycanada.ca/glossary/cloud-security/ The practices, tools, and policies that protect data, applications, and infrastructure hosted in cloud environments (e.g., Microsoft 365, Google Workspace, AWS). Cloud providers secure the underlying infrastructure, but you are responsible for configuring access controls, enabling MFA, managing permissions, and protecting your data. This "shared responsibility model" means a misconfigured cloud account is your problem, not the provider's. Related: Addressed under Baseline Control BC.11 (Cloud and Outsourced IT Security). ## Cybercrime-as-a-Service (CaaS) URL: https://cybersecuritycanada.ca/glossary/cybercrime-as-a-service/ A criminal business model where attack tools, infrastructure, and expertise are rented or sold to other criminals — much like legitimate software-as-a-service. CaaS has lowered the barrier to entry for cybercrime, meaning attackers no longer need technical skills to launch sophisticated attacks against your business. Related: Highlighted in the CCCS National Cyber Threat Assessment 2025-2026. ## CyberSecure Canada URL: https://cybersecuritycanada.ca/glossary/cybersecure-canada/ A federal cybersecurity certification program operated by Innovation, Science and Economic Development Canada (ISED). It allows small and medium organizations to demonstrate they have implemented the Baseline Cyber Security Controls through a voluntary certification process. Related: Understanding the Baseline Controls ## Dark Web URL: https://cybersecuritycanada.ca/glossary/dark-web/ A part of the internet that is not indexed by search engines and requires specialized software (such as the Tor browser) to access. The dark web hosts marketplaces where stolen credentials, personal data, and hacking tools are bought and sold. After a data breach, your employees' usernames and passwords often appear on dark web markets within hours. Related: Why stolen credentials end up on the dark web ## Data Breach URL: https://cybersecuritycanada.ca/glossary/data-breach/ An incident where personal, confidential, or protected information is accessed, disclosed, or stolen by an unauthorized party. Under PIPEDA, Canadian organizations must report breaches involving personal information to the Privacy Commissioner and notify affected individuals when there is a real risk of significant harm. Related: Canada's privacy obligations for small businesses ## DDoS (Distributed Denial of Service) URL: https://cybersecuritycanada.ca/glossary/ddos/ An attack that floods a website, server, or network with so much traffic that it becomes unavailable to legitimate users. "Distributed" means the traffic comes from thousands of compromised devices (a botnet) simultaneously, making it difficult to block. DDoS attacks are increasingly used as a smokescreen to distract your IT team while attackers breach other systems. Related: The real cost of downtime ## Defence in Depth URL: https://cybersecuritycanada.ca/glossary/defence-in-depth/ A security strategy that layers multiple independent defences so that if one control fails, others still protect you. Rather than relying on a single firewall or antivirus, defence in depth combines network security, access controls, encryption, employee training, backups, and monitoring. The 13 Baseline Controls are structured as a defence-in-depth framework — each control covers a different layer. Related: The Baseline Controls as a layered defence ## DMARC, SPF, and DKIM URL: https://cybersecuritycanada.ca/glossary/dmarc/ Three email authentication protocols that work together to prevent attackers from sending emails that appear to come from your domain. SPF specifies which servers can send email for your domain. DKIM adds a digital signature to verify the email hasn't been altered. DMARC tells receiving servers what to do when an email fails SPF or DKIM checks. Related: How email authentication helps prevent BEC ## Endpoint Detection and Response (EDR) URL: https://cybersecuritycanada.ca/glossary/edr/ Security software that continuously monitors devices (endpoints) for suspicious activity and can respond automatically to threats. EDR goes beyond traditional antivirus by detecting unusual behaviour patterns — not just known malware signatures. Many cyber insurers now require EDR as a condition of coverage. Related: What cyber insurers require ## Exploit URL: https://cybersecuritycanada.ca/glossary/exploit/ A piece of code or technique that takes advantage of a specific vulnerability in software or hardware to gain unauthorized access or cause harm. Exploit kits — ready-made toolkits that bundle exploits for multiple vulnerabilities — are sold on the dark web, allowing attackers to automate attacks against unpatched systems. Related: How an exploit targets a real vulnerability ## Encryption URL: https://cybersecuritycanada.ca/glossary/encryption/ The process of converting data into a coded format that can only be read with the correct key. Encryption protects data both in transit (e.g., HTTPS connections) and at rest (e.g., encrypted hard drives). If an encrypted device is lost or stolen, the data remains unreadable without the decryption key. Related: The Baseline Controls require encryption on all portable media (BC.13) and backups (BC.7). ## Firewall URL: https://cybersecuritycanada.ca/glossary/firewall/ A security device or software that monitors and controls network traffic based on predefined rules, acting as a barrier between your trusted internal network and untrusted external networks like the internet. Most businesses use both a network firewall (hardware at the perimeter) and host-based firewalls (software on individual devices). Related: Addressed under Baseline Control BC.9 (Network Security). ## Get Cyber Safe URL: https://cybersecuritycanada.ca/glossary/get-cyber-safe/ The Government of Canada's public awareness campaign on cybersecurity, operated by the Canadian Centre for Cyber Security. Get Cyber Safe provides free, plain-language tips and resources aimed at helping individuals and small businesses protect themselves online. It's one of the best starting points for businesses that are new to cybersecurity. Related: View all Government of Canada cybersecurity resources ## HTTPS URL: https://cybersecuritycanada.ca/glossary/https/ The secure version of HTTP — the protocol your browser uses to communicate with websites. HTTPS encrypts data in transit using TLS (Transport Layer Security), preventing attackers from intercepting information exchanged between your browser and the website. If your business website doesn't use HTTPS (look for the padlock icon), customers' form submissions, login credentials, and payment information are transmitted in plain text. Related: Addressed under Baseline Control BC.9 (Network Security). ## Identity Theft URL: https://cybersecuritycanada.ca/glossary/identity-theft/ The fraudulent use of someone's personal information — name, Social Insurance Number, credit card details, or other identifying data — without their consent. When a data breach exposes customer or employee records, identity theft is often the downstream consequence. Under PIPEDA, your organization has a legal duty to protect this information and to notify affected individuals if it's compromised. Related: Your obligations under PIPEDA ## Incident Response Plan URL: https://cybersecuritycanada.ca/glossary/incident-response-plan/ A written document that defines who is responsible for what when a cybersecurity incident occurs, who to contact, which systems are critical, and what steps to follow. The Canadian Centre for Cyber Security designates incident response planning as BC.1 — the first of the 13 Baseline Controls — because everything else depends on having a plan before an incident hits. Related: How to build an incident response plan ## Insider Threat URL: https://cybersecuritycanada.ca/glossary/insider-threat/ A security risk that comes from within your organization — an employee, contractor, or business partner who either intentionally or accidentally compromises your systems. Insider threats include disgruntled employees stealing data, well-meaning staff falling for phishing, or former employees whose accounts were never deactivated. Timely offboarding and least-privilege access controls are your primary defences. Related: Include insider scenarios in your incident response plan ## Keylogger URL: https://cybersecuritycanada.ca/glossary/keylogger/ Malicious software or hardware that secretly records every keystroke you type — capturing passwords, credit card numbers, emails, and other sensitive information. Keyloggers are typically delivered through phishing emails or bundled with pirated software. Anti-malware tools with behavioural detection can identify keylogger activity, and password managers that auto-fill credentials bypass keystroke capture entirely. Related: Anti-malware protection (BC.3) detects most software-based keyloggers. ## Lateral Movement URL: https://cybersecuritycanada.ca/glossary/lateral-movement/ The techniques an attacker uses to move through your network after gaining initial access — jumping from one system to another to find valuable data or gain higher privileges. A ransomware attacker who compromises a single employee's workstation uses lateral movement to reach file servers, backup systems, and domain controllers. Network segmentation and least-privilege access are your primary defences. Related: How ransomware spreads through networks ## Least Privilege URL: https://cybersecuritycanada.ca/glossary/least-privilege/ A security principle that says users should have only the minimum level of access required to do their job — nothing more. If ransomware compromises an account with broad access, it can spread across your entire network. If that same account has only the minimum necessary permissions, the damage is contained. Related: Why access control matters during ransomware attacks ## Log Management URL: https://cybersecuritycanada.ca/glossary/log-management/ The practice of collecting, storing, and reviewing records of activity across your systems — who logged in, what they accessed, what changed, and when. Logs are critical for detecting suspicious activity, investigating incidents, and proving compliance with privacy regulations. Without logs, you cannot determine what happened during a breach or prove what data was or wasn't accessed. Related: Addressed under Baseline Control BC.4 (Security Event Logging). Why logs are essential for incident response ## Malware URL: https://cybersecuritycanada.ca/glossary/malware/ Short for "malicious software." Any software intentionally designed to damage, disrupt, or gain unauthorized access to a computer system. Malware includes viruses, ransomware, spyware, trojans, and worms. It is commonly delivered through phishing emails, malicious websites, or compromised software updates. Related: How malware was delivered through a trusted software update ## Man-in-the-Middle Attack (MitM) URL: https://cybersecuritycanada.ca/glossary/man-in-the-middle/ An attack where a criminal secretly intercepts and potentially alters communication between two parties who believe they are talking directly to each other. Common examples include eavesdropping on unencrypted public Wi-Fi, intercepting email between a business and its bank, or redirecting DNS queries to fake websites. HTTPS, VPNs, and encrypted email protocols defend against MitM attacks. Related: Why public Wi-Fi is dangerous for business ## Managed Service Provider (MSP) URL: https://cybersecuritycanada.ca/glossary/managed-service-provider/ A company that remotely manages your IT infrastructure and systems on your behalf. MSPs typically have high-level administrative access to your network, making them both essential partners and high-value targets for attackers. A compromised MSP can give an attacker access to every client they manage. Related: Managing your MSP relationship securely ## Managed Detection and Response (MDR) URL: https://cybersecuritycanada.ca/glossary/mdr/ A cybersecurity service where a third-party provider monitors your systems around the clock, detects threats, and responds to incidents on your behalf. MDR combines EDR technology with human analysts who investigate alerts, triage threats, and take containment actions — giving small businesses access to 24/7 security expertise they couldn't afford to hire in-house. For most Canadian SMBs, MDR is the most practical path to enterprise-grade security monitoring. Related: Why insurers are increasingly requiring managed detection services ## Multi-Factor Authentication (MFA) URL: https://cybersecuritycanada.ca/glossary/mfa/ A security method that requires two or more verification steps to log in — typically something you know (password) plus something you have (phone or security key). MFA blocks over 99% of automated account compromise attacks. It is free to enable on most business platforms and is the single most impactful security upgrade a Canadian SMB can make. Related: Everything Canadian businesses need to know about MFA ## Network Segmentation URL: https://cybersecuritycanada.ca/glossary/network-segmentation/ The practice of dividing your network into separate zones so that a breach in one area cannot easily spread to others. For example, your point-of-sale system, employee workstations, and guest Wi-Fi should each be on separate network segments. If ransomware infects an employee's laptop on a segmented network, it cannot reach your payment systems or backup servers. Related: Addressed under Baseline Control BC.9 (Network Security). ## Password Manager URL: https://cybersecuritycanada.ca/glossary/password-manager/ Software that securely generates, stores, and auto-fills unique, strong passwords for every account. Password managers eliminate the need to remember dozens of passwords and remove the temptation to reuse them — one of the most common security vulnerabilities in small businesses. Related: Password security best practices ## Patch Management URL: https://cybersecuritycanada.ca/glossary/patch-management/ The process of keeping software and operating systems up to date by applying security patches — fixes released by software vendors to close known vulnerabilities. Unpatched software is one of the most common ways attackers gain access to business systems. The Baseline Controls designate this as BC.2. Related: Why patch management is non-negotiable ## Penetration Testing (Pen Test) URL: https://cybersecuritycanada.ca/glossary/penetration-testing/ An authorized simulated attack on your systems, conducted by security professionals, to find vulnerabilities before real attackers do. A pen test report shows you exactly how an attacker could get in, what they could access, and how to fix it. Some cyber insurance policies require or incentivize regular pen testing as a condition of coverage. Related: Security requirements for cyber insurance ## Phishing URL: https://cybersecuritycanada.ca/glossary/phishing/ A social engineering attack where criminals send fraudulent messages — typically emails — designed to trick recipients into clicking malicious links, opening dangerous attachments, revealing credentials, or transferring money. Phishing remains the number one attack vector for businesses of all sizes and the most common delivery mechanism for ransomware. Related: How to recognize phishing emails ## Phishing-Resistant MFA URL: https://cybersecuritycanada.ca/glossary/phishing-resistant-mfa/ Multi-factor authentication that cannot be relayed through a fake login page, because the credential is cryptographically bound to the real site's domain. In practice this means FIDO2 security keys and passkeys (WebAuthn), or certificate-based PKI authentication. The Canadian Centre for Cyber Security and CISA both name these as the only widely available phishing-resistant methods; SMS codes, voice one-time passwords, and push prompts without number matching are explicitly not phishing-resistant. Related: Addressed under Baseline Control BC.5. Which MFA method to choose ## PIPEDA URL: https://cybersecuritycanada.ca/glossary/pipeda/ The Personal Information Protection and Electronic Documents Act — Canada's federal privacy law. It applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity. PIPEDA requires mandatory breach reporting to the Privacy Commissioner when there is a real risk of significant harm, with fines of up to $100,000 per violation. Related: Canada's privacy landscape explained ## RDP (Remote Desktop Protocol) URL: https://cybersecuritycanada.ca/glossary/rdp/ A Microsoft protocol that allows users to remotely access and control another computer over a network. RDP is widely used for remote work and IT administration, but exposed RDP ports are one of the most common entry points for ransomware attacks. Attackers use brute force or stolen credentials to log in through RDP. Securing RDP requires MFA, VPN access, and disabling it when not needed. Related: How attackers exploit RDP to deploy ransomware ## Ransomware URL: https://cybersecuritycanada.ca/glossary/ransomware/ Malicious software that encrypts your files and demands payment for their return. Modern ransomware often also steals data before encrypting it, threatening to publish it if the ransom is not paid (double extortion). The Canadian Centre for Cyber Security identifies ransomware as the top cybercrime threat facing Canada's critical infrastructure. Related: Complete guide to ransomware for Canadian businesses ## Ransomware-as-a-Service (RaaS) URL: https://cybersecuritycanada.ca/glossary/raas/ A criminal business model where ransomware developers lease their tools to other attackers (affiliates) in exchange for a percentage of ransom payments. RaaS has made ransomware attacks accessible to criminals with little technical skill, dramatically increasing the volume of attacks against organizations of all sizes. Related: Why no business is too small to be targeted ## Risk Assessment URL: https://cybersecuritycanada.ca/glossary/risk-assessment/ A systematic process of identifying what could go wrong (threats), how likely it is (probability), and how bad it would be (impact). A cybersecurity risk assessment helps you prioritize which security controls to implement first based on your specific business context — not every business faces the same risks. Our free assessment is built around this principle. Related: Take our free cybersecurity risk assessment ## Recovery Time Objective (RTO) URL: https://cybersecuritycanada.ca/glossary/rto/ The maximum acceptable amount of time that a system or business process can be offline before the organization's survival is at risk. Defining your RTO for each critical system helps prioritize which systems to restore first after an incident and determines how robust your backup and recovery procedures need to be. Related: The real cost of cyber downtime ## Security Awareness Training URL: https://cybersecuritycanada.ca/glossary/security-awareness-training/ Ongoing education that teaches employees to recognize and respond to cybersecurity threats — particularly phishing, social engineering, and unsafe data handling. Effective training is short, frequent, and contextual (e.g., simulated phishing campaigns followed by immediate feedback), not annual compliance checkboxes. The Baseline Controls designate this as BC.6. Related: Training approaches that actually change behaviour ## Shadow IT URL: https://cybersecuritycanada.ca/glossary/shadow-it/ Technology — cloud services, apps, AI tools, or devices — used by employees for work without organizational approval or oversight. Shadow IT creates data flows you cannot control, audit, or recover. Common examples include personal Dropbox accounts, unauthorized AI tools like ChatGPT used with business data, and messaging apps used for work communications. Related: Why your business needs an AI usage policy ## SIM Swapping URL: https://cybersecuritycanada.ca/glossary/sim-swapping/ An attack where a criminal convinces your mobile carrier to transfer your phone number to a device they control. Once they have your number, they can intercept SMS-based two-factor authentication codes, reset passwords, and access your accounts. This is why authenticator apps are more secure than SMS codes for MFA. Related: When cyber attacks become physical threats ## Spear Phishing URL: https://cybersecuritycanada.ca/glossary/spear-phishing/ A targeted form of phishing directed at a specific individual or organization, using personalized information to make the attack more convincing. Unlike mass phishing campaigns, spear phishing emails reference your real name, job title, colleagues, or recent transactions. Attackers research their targets using LinkedIn, company websites, and previously breached data to craft highly believable messages. Related: How to recognize even targeted phishing attempts ## Social Engineering URL: https://cybersecuritycanada.ca/glossary/social-engineering/ The use of psychological manipulation to trick people into revealing information, granting access, or taking actions that compromise security. Phishing, pretexting (creating a fabricated scenario), and impersonation are all forms of social engineering. It exploits human trust rather than technical vulnerabilities. Related: Training that actually changes behaviour ## Session Token URL: https://cybersecuritycanada.ca/glossary/session-token/ The credential your identity provider issues after you sign in successfully, so you are not asked for your password on every click. It is stored as a browser cookie and represents an already-authenticated session. If an attacker steals it — through adversary-in-the-middle phishing or infostealer malware — they can replay it from their own browser and be logged in as you, with no password and no MFA prompt, until the token expires. Shortening token lifetimes limits the damage. Related: Why token theft bypasses MFA entirely ## Supply Chain Attack URL: https://cybersecuritycanada.ca/glossary/supply-chain-attack/ An attack where criminals compromise a trusted vendor, software provider, or service to reach their actual targets downstream. Instead of attacking your business directly, attackers breach a tool or service you depend on — such as a software update mechanism, a managed service provider, or a SaaS platform — gaining access to every organization that trusts it. Related: The Notepad++ supply chain attack explained ## Threat Intelligence URL: https://cybersecuritycanada.ca/glossary/threat-intelligence/ Information about current and emerging cyber threats — who is attacking, how they operate, what tools they use, and what vulnerabilities they target. The Canadian Centre for Cyber Security publishes threat intelligence through alerts, advisories, and the biennial National Cyber Threat Assessment. For SMBs, staying current with CCCS alerts and advisories is the most practical form of threat intelligence. Related: Access CCCS alerts and advisories ## 3-2-1 Backup Rule URL: https://cybersecuritycanada.ca/glossary/3-2-1-backup-rule/ A widely recommended backup strategy: maintain 3 copies of your data, on 2 different types of storage, with 1 copy stored offline or offsite — disconnected from your network. This ensures that even if ransomware encrypts your primary systems and your connected backups, you have an untouched copy to restore from. Related: Backup assumptions that fail when it matters ## Two-Factor Authentication (2FA) URL: https://cybersecuritycanada.ca/glossary/two-factor-authentication/ A specific type of multi-factor authentication that uses exactly two verification steps. In practice, 2FA and MFA are often used interchangeably, though MFA can include three or more factors. See Multi-Factor Authentication (MFA). ## Unauthorized Software URL: https://cybersecuritycanada.ca/glossary/unauthorized-software/ Any software installed on business systems without organizational approval — including browser extensions, free utilities, cracked applications, and personal tools. Unauthorized software can contain malware, create unpatched vulnerabilities, or exfiltrate data. Maintaining a software inventory and restricting installation privileges are core requirements of the Baseline Controls. Related: Addressed under Baseline Controls — Patch Management and Software Inventory. ## VPN (Virtual Private Network) URL: https://cybersecuritycanada.ca/glossary/vpn/ A technology that creates an encrypted connection between an employee's device and your business network, protecting data in transit — especially important when working from home, coffee shops, or other locations outside the office. A business-grade VPN with MFA is essential for secure remote work. Related: Remote work security essentials ## Vishing (Voice Phishing) URL: https://cybersecuritycanada.ca/glossary/vishing/ A social engineering attack conducted over the phone, where the caller impersonates a trusted entity — such as a bank, government agency, tech support, or a senior executive — to extract sensitive information or convince the target to take an action. AI-generated voice cloning has made vishing dramatically more convincing, allowing attackers to mimic a specific person's voice from just a few seconds of audio. Related: When cyber attacks become physical threats ## Vulnerability URL: https://cybersecuritycanada.ca/glossary/vulnerability/ A weakness in software, hardware, or a process that an attacker can exploit to gain unauthorized access or cause harm. Vulnerabilities are assigned CVE numbers (Common Vulnerabilities and Exposures) for tracking. When a vendor releases a security patch, they are fixing a known vulnerability — and attackers begin scanning for unpatched systems almost immediately. Related: What a real vulnerability looks like ## Whaling URL: https://cybersecuritycanada.ca/glossary/whaling/ A highly targeted phishing attack aimed at senior executives, board members, or other high-value individuals within an organization. Whaling emails are carefully crafted to impersonate legal counsel, regulators, or board members, and often involve urgent requests related to wire transfers, mergers, or legal matters. Because the targets have the authority to approve large transactions, successful whaling attacks can result in massive financial losses. Related: How BEC and whaling target executives ## Wi-Fi Security URL: https://cybersecuritycanada.ca/glossary/wi-fi-security/ The practices and protocols that protect wireless networks from unauthorized access and eavesdropping. Business Wi-Fi should use WPA3 (or at minimum WPA2) encryption, strong passwords, and separate networks for employees and guests. An unsecured or poorly configured Wi-Fi network allows attackers within range to intercept traffic, access shared files, or pivot into your internal network. Related: Addressed under Baseline Control BC.9 (Network Security). ## XDR (Extended Detection and Response) URL: https://cybersecuritycanada.ca/glossary/xdr/ A security platform that unifies threat detection and response across multiple layers — endpoints, email, cloud, and network — into a single system. Where EDR monitors individual devices and MDR adds human analysts, XDR correlates signals across your entire environment to detect complex attacks that no single tool would catch. For example, XDR might connect a suspicious login from an unusual location, a new email forwarding rule, and a large file download into a single coherent incident. Related: See also EDR and MDR for related detection technologies. ## Zero Trust URL: https://cybersecuritycanada.ca/glossary/zero-trust/ A security model built on the principle "never trust, always verify." Instead of assuming that everything inside your network is safe, Zero Trust requires strict verification for every user and device before granting access to any resource — regardless of their location. In practice, this means MFA on every account, least-privilege access, network segmentation, and continuous monitoring. Zero Trust is the direction modern cybersecurity is heading, but SMBs can start with its core principles today. Related: Zero Trust principles underpin several Baseline Controls including BC.12 (Access Control) and BC.9 (Network Security). ## Zero-Day Vulnerability URL: https://cybersecuritycanada.ca/glossary/zero-day/ A software vulnerability that is unknown to the vendor and has no available patch at the time it is exploited. "Zero-day" refers to the fact that the vendor has had zero days to fix it. These are the most dangerous vulnerabilities because there is no defence other than layered security controls — which is why the Baseline Controls emphasize defence in depth across multiple areas, not reliance on any single control. Related: Why layered security matters --- # Canada's 13 Baseline Cyber Security Controls Source: https://cybersecuritycanada.ca/controls/ — the Canadian Centre for Cyber Security's recommended minimum security standard for small and medium organizations, published as ITSM.10.089. ## BC.1 — Incident Response URL: https://cybersecuritycanada.ca/controls/incident-response/ Summary: Learn what the Canadian Centre for Cyber Security recommends for incident response planning. Covers IRP templates, PIPEDA breach notification, and ITSAP.40.003 guidance. ### What Incident Response Planning Means An incident response plan (IRP) is a documented set of procedures your organization follows when a cybersecurity event occurs — whether that is a ransomware infection, a data breach, a phishing compromise, or unauthorized access to your systems. The Canadian Centre for Cyber Security (CCCS) designates incident response planning as BC.1, the first of its 13 Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). This is not a coincidence: having a plan in place before an incident happens is foundational to every other security measure your organization implements. This page summarizes what the CCCS recommends for incident response. It is educational content based on publicly available government guidance and is not professional cybersecurity advice. For your specific situation, consult a qualified professional. You can also take our free assessment to evaluate how your organization measures up across all 13 controls. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that every small and medium organization develop and maintain an incident response plan. The plan should be documented, regularly tested, and known to all relevant personnel. The CCCS also publishes supplementary guidance in ITSAP.40.003 (Developing Your Incident Response Plan), which provides more detailed direction. According to the CCCS guidance, an incident response plan should include: - Defined roles and responsibilities — Identify who is in charge of coordinating the response, who communicates with stakeholders, who handles technical containment, and who manages legal and regulatory obligations. - Contact lists — Maintain up-to-date contact information for your internal response team, your IT service providers, the Canadian Centre for Cyber Security, law enforcement, legal counsel, and your insurance provider. - Classification criteria — Define what constitutes a cybersecurity incident versus a routine IT issue, and establish severity levels so your team can prioritize appropriately. - Containment and eradication procedures — Document the steps to isolate affected systems, preserve evidence, remove the threat, and restore normal operations. - Communication procedures — Outline how and when you will communicate with employees, customers, regulators, and the public during and after an incident. - Recovery steps — Define how you will restore systems and data from backups, verify system integrity, and return to normal business operations. - Post-incident review — After resolving an incident, conduct a lessons-learned review to identify what worked, what did not, and what changes to make to your plan. #### ITSAP.40.003: Developing Your Incident Response Plan The CCCS publication ITSAP.40.003 provides additional guidance on building an IRP. It emphasizes that the plan should be a living document — reviewed and updated regularly, not created once and forgotten. It also recommends that organizations practice their plans through tabletop exercises, where team members walk through a hypothetical incident scenario to identify gaps and improve coordination. #### The CyberSecure Canada IRP Template The CyberSecure Canada certification program, administered by Innovation, Science and Economic Development Canada (ISED), provides a structured framework that aligns with the CCCS Baseline Controls. As part of this program, ISED publishes a fillable incident response plan template — a downloadable Word document with section-by-section instructions. The template covers: - Purpose statement — Why the plan exists and what it applies to - Definitions — Key terms including indicators of compromise (IOCs), maximum tolerable downtime, and incident classification - Cyber Security Incident Response Team (CSIRT) — Roles, responsibilities, and contact information - Incident severity matrix — How to classify incidents by impact level - Response phases — Detailed procedures for each stage of the response - Document control — Version history and review schedule - Testing plan — How and when the plan will be exercised This template was designed specifically to help small and medium organizations meet the CyberSecure Canada certification requirements, but it is freely available and useful regardless of whether certification is being pursued. For a detailed walkthrough of how to use this template and build your plan step by step, see our guide: Building an Incident Response Plan for Your Canadian Business. ### Why This Matters for Canadian Businesses For Canadian small and medium businesses, incident response planning is not just a technical exercise — it has legal and regulatory dimensions. Under the Personal Information Protection and Electronic Documents Act (PIPEDA), organizations that experience a breach of security safeguards involving personal information are required to: - Report the breach to the Office of the Privacy Commissioner of Canada (OPC) if it creates a real risk of significant harm to individuals. - Notify affected individuals as soon as feasible after determining that a reportable breach has occurred. - Keep records of all breaches of security safeguards, regardless of whether they meet the reporting threshold, for at least 24 months. Without a pre-established incident response plan, organizations often struggle to meet these obligations within the required timelines. Delayed or inadequate breach notification can result in regulatory penalties and reputational damage. Provincial privacy legislation — such as Alberta's PIPA and Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25) — may impose additional breach notification requirements depending on where your organization operates and where the affected individuals reside. #### The Cost of Being Unprepared Organizations without an incident response plan typically take longer to detect and contain breaches. Longer containment times generally translate to greater financial losses, more extensive data exposure, and more difficult recovery. Having a plan does not prevent incidents from happening, but it significantly improves how effectively your organization responds when they do. ### How to Get Started Building an incident response plan does not require a large budget or a dedicated security team. Here are practical steps for Canadian SMBs: - Start with the CCCS guidance. Read the Baseline Controls document (ITSM.10.089) and the incident response planning guide (ITSAP.40.003), both available free on the CCCS website. - Assign an incident response lead. Designate one person as the primary coordinator. In a small business, this might be the owner, a manager, or your most technically capable employee. The key is that someone is clearly responsible. - Build your contact list. Compile emergency contacts including your IT provider, internet service provider, the CCCS (for reporting), local law enforcement, your legal counsel, and your cyber insurance provider if applicable. - Document your critical assets. Identify which systems, data, and services are most important to your business operations. This helps you prioritize during an incident. - Write down basic procedures. Even a one- or two-page document that describes what to do first, whom to call, and how to isolate an affected system is far better than nothing. - Train your staff. Ensure all employees know the plan exists, know who to contact, and understand their role. Consider pairing this with security awareness training (BC.6). - Test the plan annually. Run a tabletop exercise at least once per year. Pick a realistic scenario — such as a ransomware attack or a phishing-related data breach — and walk through your response steps. - Review and update. After each test or real incident, update the plan to reflect lessons learned. Also update it whenever your IT environment changes significantly. For a more comprehensive walkthrough covering the full incident response lifecycle, government resources, PIPEDA obligations, and testing strategies, read our detailed guide: Building an Incident Response Plan for Your Canadian Business. To see how your organization currently measures up on incident response and the other 12 baseline controls, take the free assessment. ### Common Mistakes to Avoid Based on the CCCS guidance and common observations in the Canadian SMB landscape, here are frequent mistakes organizations make with incident response planning: - Not having a plan at all. Many small businesses assume they are too small to be targeted. The CCCS baseline controls exist precisely because organizations of all sizes face cyber threats. - Creating a plan but never testing it. An untested plan is unreliable. Tabletop exercises reveal gaps in coordination, outdated contact information, and unclear procedures that look fine on paper but fail in practice. - Keeping the plan in only one location. If your incident response plan is stored only on a server that gets encrypted by ransomware, you will not be able to access it when you need it most. Keep copies in multiple locations, including offline and printed copies. - Forgetting about legal obligations. Many organizations focus exclusively on the technical response and overlook PIPEDA's breach notification requirements. Include legal and regulatory steps in your plan from the start. - Not including non-technical staff. An incident response plan is not just for IT. It involves management, communications, legal, and potentially HR. All relevant parties should know their responsibilities. - Failing to update the plan. Personnel change, systems change, and contact details change. A plan written three years ago with outdated information will cause confusion during a real incident. ### Related Articles - Building an Incident Response Plan for Your Canadian Business - What to Do in the First 24 Hours After a Cyber Attack - Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack - Canada's Privacy Landscape — PIPEDA breach notification requirements ### Frequently Asked Questions See below for answers to common questions about incident response planning for Canadian businesses. For a comprehensive evaluation, take our free cybersecurity assessment. ### Frequently Asked Questions — Incident Response Q: Does my small business really need an incident response plan? A: Yes. The Canadian Centre for Cyber Security lists incident response planning as the first of its 13 Baseline Controls (ITSM.10.089) for small and medium organizations. Cyber incidents can affect businesses of any size, and having a documented plan helps reduce response time, limit damage, and meet legal obligations under PIPEDA. Q: What is PIPEDA's breach notification requirement? A: Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), organizations must report breaches of security safeguards involving personal information to the Office of the Privacy Commissioner, notify affected individuals, and keep records of all breaches. Failure to report can result in fines. Q: How often should we test our incident response plan? A: The Canadian Centre for Cyber Security recommends testing your incident response plan at least once a year, or whenever there are significant changes to your IT environment. Tabletop exercises — where your team walks through a hypothetical scenario — are a practical way to identify gaps without disrupting operations. --- ## BC.2 — Patch Management URL: https://cybersecuritycanada.ca/controls/patch-management/ Summary: Canadian Centre for Cyber Security guidance on patch management for SMBs. Covers automatic updates, critical patches, asset inventory, and end-of-life software risks. ### What Patch Management Means Patch management is the process of identifying, acquiring, testing, and installing software updates (patches) on your organization's systems and applications. These patches fix security vulnerabilities, correct bugs, and sometimes add new features. The Canadian Centre for Cyber Security (CCCS) designates patch management as BC.2 in its 13 Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), reflecting how fundamental timely patching is to preventing cyberattacks. This page summarizes what the CCCS recommends for patch management. It is educational content based on publicly available government guidance and is not professional cybersecurity advice. For your specific situation, consult a qualified professional. You can also take our free assessment to evaluate your organization across all 13 controls. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations establish a patch management process to keep all operating systems, applications, and firmware up to date. The guidance emphasizes several key practices: #### Enable Automatic Updates Where Possible For most small and medium organizations, enabling automatic updates is the most effective way to stay current with security patches. Modern operating systems including Windows, macOS, and Linux distributions provide built-in automatic update mechanisms. The CCCS recommends enabling these features on all systems and configuring them to install updates promptly rather than deferring them indefinitely. Automatic updates are especially important for: - Operating systems (Windows, macOS, Linux, Chrome OS) - Web browsers (Chrome, Firefox, Edge, Safari) - Email clients - Productivity software (office suites, PDF readers) - Mobile device operating systems and applications #### Prioritize Critical and High-Severity Patches Not all patches carry equal urgency. The CCCS recommends prioritizing patches based on severity, with critical vulnerabilities — particularly those being actively exploited in the wild — applied as soon as possible. Vendor severity ratings (such as Microsoft's "Critical" classification or the Common Vulnerability Scoring System) help organizations determine which patches need immediate attention versus those that can follow a regular maintenance schedule. #### Maintain an Asset Inventory You cannot patch what you do not know about. The CCCS recommends maintaining an inventory of all hardware and software assets in your organization. This includes workstations, servers, mobile devices, network equipment, cloud services, and all installed software. An accurate inventory ensures that no system is overlooked when patches are released. #### Patch Third-Party Software Operating system patches receive the most attention, but third-party applications are frequently targeted by attackers. Web browsers, browser plugins, PDF readers, Java, media players, and other commonly installed software all require regular patching. The CCCS guidance makes clear that patching must extend to all software, not just the operating system. #### Address End-of-Life Software Software that has reached end-of-life (EOL) no longer receives security updates from its vendor. Running EOL software means that any newly discovered vulnerabilities will remain permanently unpatched. The CCCS recommends identifying and replacing end-of-life software as a priority. Common examples include older versions of Windows, unsupported versions of server software, and legacy business applications. ### Why This Matters for Canadian Businesses Unpatched software is one of the most common attack vectors used by cybercriminals. When a vendor releases a security patch, the associated vulnerability becomes public knowledge. Attackers routinely scan for systems running unpatched software and exploit known vulnerabilities to gain access. The window between patch release and exploitation can be very short — sometimes measured in hours for critical vulnerabilities. For Canadian SMBs, the consequences of running unpatched systems can include: - Ransomware infections — Many ransomware campaigns exploit known, patched vulnerabilities in systems where the patch was never applied. - Data breaches — Unpatched vulnerabilities can allow attackers to access sensitive customer data, employee records, or financial information, potentially triggering breach notification obligations under PIPEDA. - Business disruption — Compromised systems often need to be taken offline for investigation and remediation, causing operational downtime. - Supply chain risk — Larger organizations increasingly require their suppliers and partners to demonstrate basic cybersecurity hygiene, including timely patching. The CCCS Baseline Controls position patch management as one of the highest-impact actions an organization can take to reduce its attack surface. Paired with anti-malware protection (BC.3) and secure configuration (BC.4), a consistent patching practice addresses a substantial portion of common threats. ### How to Get Started Implementing effective patch management does not require specialized tools for most small organizations. Here are practical steps to get started: - Inventory your systems and software. Create a spreadsheet or list of every device (computers, servers, routers, printers, mobile devices) and every software application used in your organization. Note the vendor, current version, and whether auto-updates are enabled. - Enable automatic updates everywhere possible. Turn on automatic updates for operating systems, browsers, and applications on all devices. For most SMBs, the benefits of automatic patching far outweigh the minimal risk of an update causing a problem. - Check for updates weekly. For software that does not support automatic updates, establish a weekly routine to check for and install available patches. Assign this responsibility to a specific person. - Prioritize critical patches. When critical security patches are released — particularly for actively exploited vulnerabilities — apply them as soon as possible rather than waiting for your regular maintenance window. - Identify end-of-life software. Review your inventory for any software that is no longer supported by its vendor. Plan a migration path to a supported alternative. If immediate replacement is not feasible, isolate the system and implement compensating controls. - Include firmware. Routers, firewalls, printers, and other network devices run firmware that also needs updating. Check your network equipment vendors' websites for firmware updates on a quarterly basis at minimum. - Document your process. Write down your patch management procedures, including who is responsible, how often updates are checked, and how critical patches are handled. This documentation supports your overall incident response planning (BC.1). - Consider centralized patch management tools. As your organization grows, tools such as Windows Server Update Services (WSUS), Microsoft Intune, or third-party patch management solutions can help manage updates across multiple devices efficiently. To evaluate your current patch management practices alongside the other 12 baseline controls, take the free assessment. ### Common Mistakes to Avoid Based on the CCCS guidance and common patterns in Canadian organizations, here are frequent patch management mistakes: - Deferring updates indefinitely. Clicking "Remind me later" on update notifications is one of the most common ways systems fall behind on patches. Configure automatic updates to install without requiring user action whenever possible. - Patching only operating systems. Third-party applications such as browsers, PDF readers, and plugins are targeted just as frequently as operating systems. All software needs to be kept current. - Not knowing what is on your network. Without an asset inventory, you cannot be confident that all systems are patched. Shadow IT — unauthorized software or devices introduced by employees — is a particular risk for SMBs. - Ignoring end-of-life software. Running software past its end-of-life date is a growing risk that only gets worse over time. Every new vulnerability discovered after EOL becomes a permanent exposure. - Forgetting network devices. Routers, switches, firewalls, and even printers run software that needs patching. These devices are often overlooked because they do not prompt users for updates the way desktop software does. - Treating patching as a one-time task. Patch management is an ongoing process. New vulnerabilities are discovered daily, and new patches are released on a continuous basis. It requires a sustained, repeatable routine. ### Related Articles - Windows Notepad Vulnerability: What Canadian Businesses Should Know — Why patch management is non-negotiable - Notepad++ Supply Chain Attack — When software updates become attack vectors - Ransomware: What Canadian Businesses Need to Know — How unpatched software enables ransomware ### Frequently Asked Questions See below for answers to common questions about patch management for Canadian organizations. For a comprehensive evaluation of your cybersecurity posture, take our free cybersecurity assessment. ### Frequently Asked Questions — Patch Management Q: How quickly should we apply critical security patches? A: The Canadian Centre for Cyber Security recommends applying critical security patches as soon as possible, ideally within 48 hours of release. Critical patches address vulnerabilities that are actively being exploited or that could allow an attacker to take control of a system without user interaction. Q: What should we do about software that no longer receives security updates? A: End-of-life (EOL) software that no longer receives security patches poses a significant risk because known vulnerabilities will never be fixed. The CCCS recommends replacing EOL software with supported alternatives. If replacement is not immediately possible, isolate the system from the network and apply compensating controls until migration is complete. Q: Do we need to patch third-party software, or just operating systems? A: Both. The CCCS Baseline Controls emphasize patching all software, including third-party applications such as web browsers, PDF readers, office suites, and plugins. Attackers frequently target vulnerabilities in third-party software because organizations often overlook these updates while focusing only on operating system patches. --- ## BC.3 — Anti-Malware URL: https://cybersecuritycanada.ca/controls/anti-malware/ Summary: CCCS guidance on anti-malware for SMBs. Covers endpoint protection, automatic scanning, email filtering, browser security, and keeping malware signatures updated. ### What Anti-Malware Protection Means Anti-malware protection refers to the use of software tools designed to prevent, detect, and remove malicious software (malware) from your organization's devices and networks. Malware encompasses viruses, ransomware, spyware, trojans, worms, and other hostile programs. The Canadian Centre for Cyber Security (CCCS) designates anti-malware as BC.3 in its 13 Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), recognizing it as one of the essential technical defenses every organization should have in place. This page summarizes what the CCCS recommends for anti-malware protection. It is educational content based on publicly available government guidance and is not professional cybersecurity advice. For your specific situation, consult a qualified professional. You can also take our free assessment to evaluate your organization across all 13 controls. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations install and maintain anti-malware software on all devices, keep definitions up to date, and configure regular scanning. The guidance covers several key areas: #### Endpoint Protection on All Devices The CCCS recommends installing anti-malware software on every endpoint in your organization — this includes desktops, laptops, servers, and mobile devices. The protection should be active (running continuously in real-time) rather than relying solely on manual or scheduled scans. Real-time protection monitors files as they are opened, downloaded, or executed, catching threats before they can cause damage. Key requirements include: - Anti-malware software installed on all workstations and servers - Real-time (on-access) scanning enabled - Scheduled full-system scans configured to run regularly - Protection active on all operating systems in use (Windows, macOS, Linux) #### Automatic Signature and Software Updates Anti-malware software is only as effective as its most recent definitions. New malware variants emerge daily, and anti-malware vendors release updated signatures to detect them. The CCCS recommends configuring anti-malware software to update its signature database automatically, ideally multiple times per day. The anti-malware application itself should also be kept up to date to ensure you have the latest detection capabilities and engine improvements. #### Email Filtering and Protection Email remains one of the most common delivery mechanisms for malware. The CCCS guidance recommends implementing email security measures to filter malicious attachments and links before they reach end users. This includes: - Attachment scanning — Automatically scanning email attachments for known malware before delivery to the recipient. - Link scanning — Checking URLs in emails against known malicious domains. - Blocking high-risk attachment types — Preventing delivery of executable files (.exe, .bat, .scr, .js) and other file types commonly used to distribute malware. - Spam filtering — Reducing the volume of unsolicited email, which is frequently used to distribute malware and phishing attempts. Most major email platforms (Microsoft 365, Google Workspace) include built-in email filtering capabilities that address these recommendations. #### Browser Protection Web browsers are another common attack vector. The CCCS recommends keeping browsers up to date (aligned with patch management practices under BC.2) and using browser-based security features such as: - Safe browsing or SmartScreen features that warn users about known malicious websites - Blocking or restricting browser plugins and extensions to only those that are necessary and trusted - Configuring browsers to block automatic downloads and pop-ups ### Why This Matters for Canadian Businesses Malware is one of the most prevalent threats facing Canadian organizations. The CCCS regularly reports on malware campaigns targeting Canadian businesses, including ransomware operations that encrypt business data and demand payment, and information-stealing malware that harvests credentials and financial data. For Canadian SMBs, malware infections can result in: - Ransomware attacks — Malware that encrypts your files and demands payment for the decryption key. Without proper backups (BC.7), organizations may face a choice between paying a ransom or losing their data permanently. - Data theft — Malware can exfiltrate sensitive business data, customer information, and employee records, potentially triggering breach notification obligations under PIPEDA. - Financial fraud — Banking trojans and credential-stealing malware can lead to unauthorized financial transactions. - Operational disruption — Malware infections often require affected systems to be taken offline, rebuilt, or restored from backups, causing significant downtime. - Reputational harm — Customers and partners lose confidence when an organization suffers a malware-related incident, particularly if it involves the exposure of personal information. Anti-malware protection works best as part of a layered defense strategy. Combined with timely patching (BC.2), secure configuration (BC.4), and security awareness training (BC.6), anti-malware software provides an important technical safety net against threats that make it past other defenses. ### How to Get Started Implementing anti-malware protection is one of the more straightforward baseline controls. Here are practical steps for Canadian SMBs: - Verify protection on every device. Check that every computer, laptop, and server in your organization has anti-malware software installed and actively running. For Windows devices, ensure Microsoft Defender Antivirus is enabled at minimum, or that a third-party solution is installed and active. - Enable automatic updates. Confirm that your anti-malware software is configured to download signature updates automatically. Check that updates are being applied successfully — some systems may fail to update due to network issues or configuration problems without alerting the user. - Configure real-time scanning. Ensure that on-access (real-time) scanning is enabled, not just scheduled scans. Real-time scanning checks files as they are accessed, providing immediate protection. - Set up scheduled full scans. In addition to real-time scanning, configure a weekly full-system scan. Schedule it for a time when the device is likely to be on but not heavily used, such as during lunch hours or overnight for servers. - Review email security settings. If you use Microsoft 365 or Google Workspace, review your email security configuration. Enable attachment scanning, link protection, and spam filtering. Block delivery of high-risk file types such as .exe and .js attachments. - Enable browser safe browsing features. Ensure that Chrome's Safe Browsing, Edge's SmartScreen, or equivalent features are enabled on all workstations. These provide a warning layer when users attempt to visit known malicious websites. - Include mobile devices. If employees use smartphones or tablets for work, ensure those devices have appropriate protection as well, particularly Android devices where the malware landscape is more active. - Centralize management where possible. For organizations with more than a handful of devices, consider an endpoint protection solution that provides centralized management and reporting, allowing you to verify that all devices are protected and up to date from a single console. To evaluate your anti-malware practices alongside the other 12 baseline controls, take the free assessment. ### Common Mistakes to Avoid Based on the CCCS guidance and common patterns in Canadian organizations, here are frequent anti-malware mistakes: - Assuming one device does not matter. A single unprotected device on your network can serve as an entry point for malware that spreads to other systems. Every device needs protection, including those used infrequently. - Disabling protection for convenience. Users sometimes disable anti-malware software because it slows down a specific task or blocks a program they want to install. This creates a window of vulnerability. If legitimate software is being blocked, create a specific exception rather than disabling protection entirely. - Running multiple anti-malware products simultaneously. Installing two or more real-time anti-malware products on the same device can cause conflicts, performance problems, and reduced protection. Use one primary endpoint protection solution per device. - Neglecting to verify that updates are working. Anti-malware software configured for automatic updates may silently fail to update due to network issues, expired subscriptions, or configuration changes. Periodically check that definitions are current on your devices. - Relying solely on anti-malware. No anti-malware product catches every threat. Anti-malware is one layer of defense and should be combined with patching, secure configuration, user training, and other controls for effective protection. - Ignoring email security. Since email is the primary delivery vector for malware, neglecting email filtering and attachment scanning leaves a major gap in your defenses even if endpoint protection is in place. ### Related Articles - Ransomware: What Canadian Businesses Need to Know - Notepad++ Supply Chain Attack — How trusted software updates delivered malware - 5 Easy Cybersecurity Wins for Canadian Small Businesses ### Frequently Asked Questions See below for answers to common questions about anti-malware protection for Canadian businesses. For a comprehensive evaluation, take our free cybersecurity assessment. ### Frequently Asked Questions — Anti-Malware Q: Is Windows Defender sufficient for a small business? A: Windows Defender (Microsoft Defender Antivirus), included with Windows 10 and 11, provides a baseline level of anti-malware protection. The CCCS recommends that all devices run anti-malware software with automatic updates enabled. For many small businesses, Windows Defender meets this requirement when properly configured and kept up to date, though some organizations may benefit from additional endpoint protection features. Q: Do Mac computers need anti-malware software? A: Yes. While macOS includes built-in security features such as XProtect, Macs are not immune to malware. The CCCS Baseline Controls recommend anti-malware protection on all endpoints, regardless of operating system. Malware targeting macOS has increased in recent years, and business environments benefit from consistent protection across all devices. Q: How often should anti-malware signatures be updated? A: Anti-malware signature databases should be updated automatically and as frequently as the software allows — ideally multiple times per day. The CCCS recommends enabling automatic updates for anti-malware definitions. Outdated signatures leave your systems unable to detect the latest threats. Most modern anti-malware products handle this automatically when connected to the internet. --- ## BC.4 — Secure Configuration URL: https://cybersecuritycanada.ca/controls/secure-configuration/ Summary: CCCS guidance on secure configuration for SMBs. Covers changing defaults, disabling unnecessary services, CIS Benchmarks, and configuration management practices. ### What Secure Configuration Means Secure configuration is the practice of setting up hardware, software, and network devices with security in mind from the start — changing default settings, disabling unnecessary features, and enabling built-in security controls. The Canadian Centre for Cyber Security (CCCS) designates secure configuration as BC.4 in its 13 Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). Most devices and software ship with default settings optimized for ease of use rather than security, which means out-of-the-box configurations often leave unnecessary services running, use default credentials, and have security features turned off. This page summarizes what the CCCS recommends for secure configuration. It is educational content based on publicly available government guidance and is not professional cybersecurity advice. For your specific situation, consult a qualified professional. You can also take our free assessment to evaluate your organization across all 13 controls. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations apply secure configurations to all hardware and software before deployment. This includes workstations, servers, mobile devices, network equipment, cloud services, and applications. The guidance covers several core practices: #### Change Default Credentials One of the most fundamental secure configuration steps is changing default usernames and passwords on all devices and applications. Default credentials are widely known and publicly documented — they are among the first things attackers try. The CCCS recommends changing defaults on: - Network routers and switches - Wireless access points - Firewalls - Printers and multifunction devices - Network-attached storage (NAS) devices - Web applications and content management systems - Any software that ships with a default admin account Replace default passwords with strong, unique passwords following CCCS password guidance. Where possible, rename or disable default administrator accounts as well. #### Disable Unnecessary Services and Features Every running service, open port, and enabled feature represents a potential attack surface. The CCCS recommends disabling or removing any services, protocols, ports, and software components that are not required for the device's intended function. This principle — often called "least functionality" — reduces the number of potential entry points an attacker can exploit. Common examples include: - Disabling remote desktop services on workstations that do not need remote access - Turning off file sharing on devices that do not need to share files - Removing or disabling unused browser plugins and extensions - Disabling Bluetooth, NFC, or other connectivity features when not in use - Removing trial software and bloatware that comes pre-installed on new devices #### Enable Built-In Security Features Most operating systems and applications include security features that are sometimes disabled by default or not configured optimally. The CCCS recommends reviewing and enabling: - Host-based firewalls — Enable the built-in firewall on every workstation and server (e.g., Windows Firewall, macOS firewall). - Disk encryption — Enable full-disk encryption (BitLocker on Windows, FileVault on macOS) to protect data if a device is lost or stolen. - Screen lock — Configure automatic screen lock after a period of inactivity. - Audit logging — Enable logging on systems and applications to support incident detection and investigation. #### Hardening Guidelines: CIS Benchmarks The Center for Internet Security (CIS) publishes free, detailed configuration guides known as CIS Benchmarks for a wide range of operating systems, applications, cloud platforms, and network devices. These benchmarks provide specific, actionable configuration recommendations developed through consensus among cybersecurity professionals. The CCCS recognizes CIS Benchmarks as a reputable source of hardening guidance. CIS Benchmarks are available for common platforms including: - Windows 10, Windows 11, and Windows Server - macOS - Ubuntu, Red Hat Enterprise Linux, and other Linux distributions - Microsoft 365 and Google Workspace - Amazon Web Services, Microsoft Azure, and Google Cloud Platform - Network devices from Cisco, Palo Alto, and other vendors CIS Benchmarks can be downloaded at no cost from the CIS website. #### Configuration Management The CCCS recommends documenting your organization's standard secure configurations and applying them consistently to all devices. Configuration management ensures that: - New devices are set up with the same baseline security settings - Configuration changes are tracked and authorized - Deviations from the baseline can be identified and corrected - Systems can be rebuilt to a known-good state after an incident ### Why This Matters for Canadian Businesses Default and misconfigured settings are a leading cause of security incidents. Attackers routinely scan for systems with default credentials, unnecessary services exposed to the internet, and security features left disabled. For Canadian SMBs, insecure configurations can lead to: - Unauthorized access — Default credentials on routers, applications, or cloud services allow attackers to log in without any exploitation, simply using widely available default username and password lists. - Lateral movement — Unnecessary services and overly permissive configurations allow attackers who gain initial access to move through your network and access additional systems. - Data exposure — Misconfigured cloud storage, file shares, or databases can expose sensitive information to the internet without the organization's knowledge. - Compliance gaps — Organizations subject to privacy legislation (PIPEDA, provincial privacy laws) are expected to implement reasonable security safeguards. Default configurations generally do not meet this standard. Secure configuration works in concert with patch management (BC.2) — patching addresses vulnerabilities in the software itself, while secure configuration eliminates weaknesses introduced by how the software is set up. Combined with proper authentication (BC.5) and access control (BC.12), secure configuration significantly reduces your organization's attack surface. ### How to Get Started Implementing secure configuration is an incremental process. Start with the highest-impact changes and build from there: - Change all default passwords immediately. Survey every device and application in your organization — routers, wireless access points, printers, NAS devices, web applications — and change any default credentials. Use strong, unique passwords for each device. - Enable host-based firewalls. Verify that the built-in firewall is enabled on every workstation and server. On Windows, this means ensuring Windows Firewall is on and configured appropriately. On macOS, enable the application firewall in System Settings. - Enable disk encryption. Turn on BitLocker (Windows) or FileVault (macOS) on all laptops. This protects data if a device is lost or stolen. Most modern systems handle encryption with no noticeable performance impact. - Disable unnecessary services. Review what services are running on your workstations and servers. Disable remote desktop on machines that do not need it. Turn off file sharing where it is not required. Remove unused software and browser extensions. - Create a baseline configuration checklist. Document the standard security settings for each type of device in your organization (e.g., workstation, laptop, server, router). Use this checklist when setting up new devices. - Review CIS Benchmarks for your platforms. Download the relevant CIS Benchmarks for your operating systems and key applications. You do not need to implement every recommendation — focus on Level 1 (basic) recommendations first, which provide strong security with minimal operational impact. - Use centralized management where feasible. In Windows environments, Group Policy can enforce configuration settings across all domain-joined computers. Microsoft Intune or similar tools can manage both domain-joined and cloud-managed devices. For smaller organizations, a documented manual checklist applied consistently is a good starting point. - Review cloud service configurations. If you use Microsoft 365, Google Workspace, or cloud infrastructure services, review their security settings. Enable MFA, review sharing settings, and disable features you do not use. To evaluate your secure configuration practices alongside the other 12 baseline controls, take the free assessment. ### Common Mistakes to Avoid Based on the CCCS guidance and common observations in Canadian organizations, here are frequent secure configuration mistakes: - Leaving default credentials in place. This remains one of the most common security gaps. Default credentials for most devices are publicly available and are among the first things attackers check. - Assuming "out of the box" is secure. Vendors optimize default settings for ease of setup and broad compatibility, not for security. Every new device or application should be hardened before being put into production use. - Enabling everything "just in case." Running services and features that are not needed increases your attack surface with no benefit. If a feature is not actively used, disable it. It can always be re-enabled if needed later. - Inconsistent configurations across devices. When each device is configured differently, it becomes difficult to manage security effectively and to troubleshoot issues. Standardize on a baseline configuration for each device type. - Forgetting about network equipment. Routers, switches, and wireless access points are frequently left with default configurations and rarely reviewed after initial setup. These devices control network traffic and are high-value targets for attackers. - Not reviewing cloud service settings. Cloud platforms like Microsoft 365 and Google Workspace have many security-relevant settings that default to permissive configurations. External sharing, guest access, and legacy authentication protocols should all be reviewed. ### Related Articles - Business Email Compromise — DMARC/DKIM/SPF and external email warnings - Cloud Security Basics for Canadian Small Businesses - 5 Easy Cybersecurity Wins for Canadian Small Businesses ### Frequently Asked Questions See below for answers to common questions about secure configuration for Canadian organizations. For a comprehensive evaluation, take our free cybersecurity assessment. ### Frequently Asked Questions — Secure Configuration Q: What does 'secure configuration' mean in practical terms for a small business? A: Secure configuration means changing the default settings on your devices, software, and network equipment to reduce your attack surface. This includes changing default passwords, disabling services and features you do not use, enabling built-in security features like firewalls and encryption, and removing unnecessary user accounts. The CCCS Baseline Controls (ITSM.10.089) recommend these practices as a foundational security measure. Q: What are CIS Benchmarks and should we use them? A: CIS Benchmarks are free, consensus-based secure configuration guides published by the Center for Internet Security. They provide detailed, step-by-step hardening instructions for operating systems, applications, cloud platforms, and network devices. The CCCS references CIS Benchmarks as a recognized source of hardening guidance. They are a practical resource for organizations looking for specific configuration recommendations. Q: How do we handle configuration management across multiple devices? A: For organizations with more than a few devices, centralized configuration management tools help ensure consistent settings. Windows environments can use Group Policy or Microsoft Intune. For smaller organizations, documenting a standard configuration checklist and applying it manually when setting up each device is an effective starting point. The key is consistency — every device should meet the same baseline. --- ## BC.5 — Authentication URL: https://cybersecuritycanada.ca/controls/authentication/ Summary: CCCS guidance on authentication for SMBs. Covers multi-factor authentication, password policies (ITSAP.30.032), password managers, and eliminating shared accounts. ### What Authentication Means Authentication is the process of verifying that a user is who they claim to be before granting access to systems, applications, or data. The Canadian Centre for Cyber Security (CCCS) designates authentication as BC.5 in its 13 Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). Strong authentication practices — particularly the use of multi-factor authentication (MFA) — are among the most effective measures any organization can implement to prevent unauthorized access. This page summarizes what the CCCS recommends for authentication. It is educational content based on publicly available government guidance and is not professional cybersecurity advice. For your specific situation, consult a qualified professional. You can also take our free assessment to evaluate your organization across all 13 controls. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations implement strong authentication mechanisms, with particular emphasis on multi-factor authentication. The CCCS also publishes dedicated password guidance in ITSAP.30.032 (Best Practices for Passphrases and Passwords), which provides specific recommendations for password policies. #### Multi-Factor Authentication Everywhere The CCCS strongly recommends implementing MFA on all accounts where it is available, with priority given to: - Email accounts — Email is often the gateway to other systems through password reset functions, making it a high-priority target for attackers. - Remote access — VPN connections, remote desktop, and any other remote access methods should require MFA. - Cloud services — Microsoft 365, Google Workspace, and other cloud platforms should have MFA enabled for all users. - Administrative accounts — Any account with elevated privileges (admin, root, domain admin) should require MFA without exception. - Financial systems — Banking portals, accounting software, and payment platforms should use MFA to protect against fraud. - Social media and public-facing accounts — Compromised social media accounts can damage your organization's reputation. MFA typically involves a combination of: - Something you know — A password or passphrase - Something you have — A mobile phone (for SMS codes or authenticator apps), a hardware security key (such as a YubiKey), or a smart card - Something you are — Biometric verification such as a fingerprint or facial recognition #### Phishing-Resistant Authentication Not all MFA methods provide equal protection. SMS-based codes, while better than passwords alone, are vulnerable to SIM-swapping attacks and real-time phishing. The CCCS recommends moving toward phishing-resistant authentication methods where possible, including: - FIDO2 security keys — Hardware tokens that use public-key cryptography and are bound to the specific website, making them immune to phishing attacks. - Authenticator apps with number matching — Apps like Microsoft Authenticator that require the user to enter a number displayed on the login screen, rather than simply approving a push notification. - Passkeys — A newer standard based on FIDO2 that allows passwordless authentication using a device's built-in biometrics or PIN, bound to the specific service. #### Password Policies: ITSAP.30.032 The CCCS publication ITSAP.30.032 (Best Practices for Passphrases and Passwords) provides specific guidance on password policies. Key recommendations include: - Use passphrases over short complex passwords. The CCCS recommends passphrases — longer strings composed of four or more random words — as they are both easier to remember and harder to crack by brute force. Length is the most important factor in password strength. - Minimum length of 12 characters for passwords, with longer passphrases encouraged. - Do not force regular password changes unless there is evidence of compromise. Forced periodic rotation often leads to weaker passwords as users make minimal, predictable changes. Instead, require password changes only when a breach is suspected. - Use unique passwords for every account. Password reuse across multiple services means that a breach at one service can compromise all accounts using the same password. - Check passwords against known breached lists. Where technically feasible, screen new passwords against databases of previously compromised passwords to prevent users from choosing already-exposed credentials. #### Password Managers The CCCS recommends using password managers to help employees maintain unique, strong passwords for every account without having to memorize them all. Password managers generate random, complex passwords and store them securely, requiring the user to remember only one master password (or use biometric authentication) to access their vault. For business use, enterprise password managers offer additional features: - Centralized administration and user provisioning - Secure sharing of credentials for team accounts - Audit logs showing who accessed which credentials - Integration with single sign-on (SSO) systems - Emergency access procedures for account recovery #### Eliminating Shared Accounts The CCCS recommends that every user have their own individual account. Shared accounts — where multiple people use the same username and password — undermine accountability and make it impossible to determine who performed a specific action. They also make password management impractical, as changing the password requires communicating it to all users of the shared account. Where shared accounts cannot be immediately eliminated (for example, shared social media accounts or legacy systems), use a password manager to control and audit access, and plan a migration path to individual accounts. ### Why This Matters for Canadian Businesses Compromised credentials are one of the most common initial attack vectors in cybersecurity incidents. Attackers obtain passwords through phishing, credential stuffing (trying passwords from other breaches), brute-force attacks, and malware. For Canadian SMBs, weak authentication practices can lead to: - Account takeover — Attackers who gain access to email accounts can intercept communications, redirect payments, send phishing emails to your contacts, and reset passwords on other linked accounts. - Business email compromise (BEC) — One of the most financially damaging cyberattacks, where attackers use compromised email accounts to impersonate executives or vendors and redirect wire transfers or payments. - Data breaches — Unauthorized access to accounts containing personal information can trigger breach notification obligations under PIPEDA and result in regulatory scrutiny. - Ransomware deployment — Attackers frequently use compromised credentials to gain initial access to a network, then escalate privileges and deploy ransomware. MFA is one of the single most effective controls against these threats. Even when a password is compromised, MFA requires the attacker to also possess the second factor, which dramatically increases the difficulty of unauthorized access. Combined with proper access control (BC.12) and security awareness training (BC.6), strong authentication forms a critical layer of defense. ### How to Get Started Implementing stronger authentication is one of the highest-impact improvements most Canadian SMBs can make. Here are practical steps: - Enable MFA on email first. If you do nothing else, enable MFA on your organization's email accounts. Email is the most critical account to protect because it is often used as the recovery mechanism for other services. Both Microsoft 365 and Google Workspace support MFA at no additional cost. - Enable MFA on all cloud services. After email, enable MFA on cloud storage, collaboration tools, accounting software, CRM systems, and any other cloud-based services your organization uses. Check each service's security settings — most major platforms now support MFA. - Enable MFA on remote access. VPN connections and remote desktop services should require MFA. These are frequently targeted by attackers scanning for externally accessible services. - Deploy a password manager. Choose a reputable password manager and deploy it to all employees. For small teams, individual plans may suffice. For larger organizations, enterprise plans provide centralized management. Train employees on how to use it and make it part of your onboarding process. - Update your password policy. Adopt the CCCS recommendations from ITSAP.30.032: require a minimum length of 12 characters, encourage passphrases, stop forcing periodic password changes, and require unique passwords for each account. - Audit for shared accounts. Identify all shared accounts in your organization and plan a migration to individual accounts. Where shared accounts must remain temporarily, implement a password manager to manage and audit access. - Consider phishing-resistant MFA for high-value accounts. For administrator accounts and users with access to sensitive data, consider deploying FIDO2 security keys or passkeys for phishing-resistant authentication. - Train your team. Ensure employees understand why MFA is important, how to use their authenticator app or security key, and how to recognize phishing attempts that try to capture MFA codes. Pair this with security awareness training (BC.6). To evaluate your authentication practices alongside the other 12 baseline controls, take the free assessment. ### Common Mistakes to Avoid Based on the CCCS guidance and common patterns in Canadian organizations, here are frequent authentication mistakes: - Not enabling MFA when it is available. Many services offer MFA, but organizations do not enable it. This is one of the simplest and most effective security improvements you can make. - Enabling MFA only for administrators. While admin accounts should be prioritized, all user accounts benefit from MFA. Attackers often compromise regular user accounts first and then escalate privileges. - Relying solely on SMS-based MFA. SMS codes are better than passwords alone but are vulnerable to SIM-swapping and real-time phishing. Authenticator apps and security keys provide stronger protection. - Forcing frequent password changes. Requiring password changes every 30, 60, or 90 days without evidence of compromise leads to predictable password patterns (e.g., Password1, Password2, Password3). The CCCS recommends against forced rotation. - Allowing password reuse. Employees who use the same password for their work email, personal email, and social media accounts create a chain of risk. A breach at any one service compromises them all. - Using shared accounts. Shared accounts eliminate accountability and make credential management impractical. Every user should have their own individual account with their own credentials. - Not protecting the password manager itself. Your password manager's master account should be protected with a strong passphrase and MFA. If an attacker compromises the password manager, they gain access to all stored credentials. ### Related Articles - Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs - Password Security: What Canadian Businesses Get Wrong - Business Email Compromise: Canada's Most Costly Cyber Threat — Why MFA prevents the most damaging BEC attacks - Ransomware: What Canadian Businesses Need to Know — How weak authentication enables ransomware attacks - Cyber Insurance for Canadian SMBs — Why insurers are verifying MFA before approving claims ### Frequently Asked Questions See below for answers to common questions about authentication and MFA for Canadian businesses. For a comprehensive evaluation, take our free cybersecurity assessment. ### Frequently Asked Questions — Authentication Q: What is multi-factor authentication and why does the CCCS recommend it? A: Multi-factor authentication (MFA) requires users to verify their identity using two or more independent factors: something they know (password), something they have (phone, security key), or something they are (fingerprint, face). The CCCS recommends MFA because compromised passwords alone are responsible for a large proportion of security breaches. Even if an attacker obtains a password, MFA prevents them from accessing the account without the additional factor. Q: Are passphrases better than complex passwords? A: The Canadian Centre for Cyber Security's password guidance (ITSAP.30.032) recommends passphrases — longer phrases made up of four or more random words — as an alternative to shorter, complex passwords. Passphrases are generally easier for people to remember and harder for attackers to crack through brute force due to their length. A passphrase like 'correct-horse-battery-staple' is both more memorable and more secure than a short complex password. Q: Should we use a password manager for our business? A: Yes. The CCCS recommends using password managers to generate and store strong, unique passwords for each account. Password managers eliminate the need for employees to remember multiple complex passwords, which reduces the temptation to reuse passwords across accounts. Both individual and enterprise-grade password managers are available, with enterprise options offering centralized management and secure credential sharing for team accounts. --- ## BC.6 — Security Awareness Training URL: https://cybersecuritycanada.ca/controls/security-training/ Summary: Learn what the Canadian Centre for Cyber Security recommends for cybersecurity training employees in Canada. Covers phishing awareness, social engineering, and training cadence. ### What Security Awareness Training Means Security awareness training is the practice of educating employees about cyber threats and safe computing practices so they can recognize and avoid common attacks. Under the Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), control BC.6 addresses the need for organizations to establish an ongoing security awareness program that helps all staff understand their role in protecting business data and systems. Human error remains one of the most common factors in successful cyberattacks. Phishing emails, social engineering calls, and fraudulent websites exploit people rather than technology. A well-designed training program reduces this risk by giving employees the knowledge and habits they need to act as a first line of defence. This page provides educational information based on publicly available Canadian Centre for Cyber Security guidance. It is not professional cybersecurity advice. Organizations should consult qualified professionals for advice tailored to their specific circumstances. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations provide security awareness training to all employees on a regular basis. The guidance emphasizes that training should be practical, relevant, and ongoing rather than a one-time exercise. Key recommendations from the CCCS include: - Educate all staff on recognizing phishing emails, suspicious links, and social engineering techniques. - Establish acceptable use policies and ensure employees understand the rules for using organizational IT resources. - Conduct training regularly, not just at onboarding, to address evolving threats and reinforce good practices. - Tailor training to roles so that staff with access to sensitive data or administrative privileges receive additional, relevant instruction. - Encourage reporting of suspicious activity without fear of blame, so potential incidents are flagged early. The CCCS also maintains the Get Cyber Safe campaign, a Government of Canada public awareness initiative that provides free resources, guides, and materials that organizations can use to supplement their internal training programs. ### Why This Matters for Canadian Businesses Phishing and social engineering are consistently among the most reported cyber threats facing Canadian organizations. The CCCS National Cyber Threat Assessment has repeatedly highlighted that cybercriminals target employees as a primary entry point, particularly in small and medium businesses that may lack dedicated security teams. For Canadian SMBs, the consequences of a successful phishing attack can include: - Financial loss from business email compromise, wire fraud, or ransomware payments. - Data breaches involving customer or employee personal information, triggering obligations under PIPEDA and provincial privacy laws to notify affected individuals and the Office of the Privacy Commissioner of Canada. - Business disruption if systems are compromised and operations are halted during incident response and recovery. - Reputational damage that can erode customer trust and affect future business. Training is one of the most cost-effective security controls available. It does not require expensive technology purchases and can meaningfully reduce the likelihood of successful attacks across multiple threat categories. ### How to Get Started Implementing a security awareness training program does not require a large budget or a dedicated security team. The following steps provide a practical starting point for Canadian SMBs. #### 1. Assess Your Current State Before building a training program, understand where your organization stands. Our free cybersecurity assessment evaluates your organization across all 13 Baseline Controls, including security awareness training, and identifies gaps to prioritize. #### 2. Define Your Training Scope Identify what topics to cover based on your organization's risk profile. At a minimum, training should address: - Recognizing phishing emails and suspicious messages - Safe password practices and the importance of strong authentication - Identifying social engineering tactics (phone calls, impersonation, pretexting) - Safe web browsing habits and recognizing fraudulent websites - Your organization's policies for handling sensitive data and reporting incidents - Physical security basics such as locking screens and securing devices #### 3. Leverage Free Canadian Resources The Government of Canada's Get Cyber Safe website offers free materials including tip sheets, videos, and guides that can be distributed to employees. These resources are written in plain language and cover common threats relevant to Canadians. #### 4. Establish a Regular Training Cadence Conduct formal training sessions at least annually, with shorter refreshers throughout the year. Consider tying training to current events — for example, when a major phishing campaign is in the news, use it as a teaching moment. New employees should receive security orientation as part of onboarding. #### 5. Consider Phishing Simulations Simulated phishing exercises send realistic but harmless test emails to employees to measure how many click on suspicious links. These exercises provide measurable data on your organization's susceptibility and help identify individuals or departments that need additional training. Several Canadian and international vendors offer affordable phishing simulation platforms suitable for SMBs. #### 6. Make Training Role-Based Not all employees face the same threats. Staff who handle financial transactions may need focused training on business email compromise. IT administrators need training on securing systems and recognizing technical attacks. Executives, who are frequently targeted in whaling and spear-phishing campaigns, benefit from tailored awareness sessions. #### 7. Measure and Improve Track metrics that indicate the effectiveness of your program: - Phishing simulation click rates over time - Number of suspicious emails reported by staff - Training completion rates - Time to report actual incidents Use these metrics to identify areas where your training program needs improvement and to demonstrate progress to organizational leadership. ### Common Mistakes to Avoid Even organizations that invest in security awareness training can make errors that undermine their program's effectiveness. Watch out for these common pitfalls. #### One-and-Done Training Conducting a single annual session and assuming employees will retain the information for the entire year is insufficient. Cyber threats evolve constantly, and retention of training material decreases over time. Regular, shorter reinforcements throughout the year are more effective than a single lengthy session. #### Generic, Irrelevant Content Training that feels disconnected from employees' actual work environments generates disengagement. Use realistic examples relevant to your industry and your organization's specific tools and workflows. Where possible, reference real-world incidents that affected Canadian organizations. #### Punitive Approach to Failures Punishing employees who fail phishing simulations or make security mistakes discourages reporting and creates a culture of fear rather than awareness. The CCCS guidance emphasizes creating an environment where staff feel comfortable reporting suspicious activity. Focus on education and improvement rather than blame. #### Ignoring Non-Technical Staff Security training is sometimes treated as an IT department concern. In practice, every employee who uses a computer, email, or phone is a potential target. Reception staff, accounting teams, and senior executives all need appropriate training for their roles. #### Not Connecting Training to Policy Training is most effective when it reinforces documented policies. Ensure your organization has clear, written acceptable use policies and incident response procedures, and that training directly references these documents so employees know exactly what is expected of them. ### Connecting Security Training to Other Controls Security awareness training does not exist in isolation. It supports and is supported by other Baseline Controls: - Authentication (BC.5) — Training reinforces the importance of strong passwords and multi-factor authentication by helping employees understand why these measures are necessary. - Incident Response (BC.1) — Trained employees who recognize and report threats quickly are a critical component of effective incident response. - Anti-Malware (BC.3) — Awareness training teaches employees not to disable security software and to avoid downloading untrusted files, complementing technical anti-malware controls. For a complete view of how all 13 Baseline Controls work together, visit the controls overview page or take the free assessment to evaluate your organization's current posture. ### Related Articles - Employee Security Awareness Training: What Actually Works - How to Recognize Phishing Emails - Business Email Compromise: Canada's Most Costly Cyber Threat - Why Your Business Needs an AI Usage Policy — Training employees on AI risks ### Additional Resources - CCCS Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) - Get Cyber Safe — Government of Canada - Cybersecurity Canada Resources Page - Free Cybersecurity Baseline Assessment ### Frequently Asked Questions — Security Awareness Training Q: How often should Canadian businesses conduct cybersecurity awareness training? A: The Canadian Centre for Cyber Security recommends that security awareness training be conducted on a regular and ongoing basis, not as a one-time event. Most organizations find that annual formal training combined with shorter monthly or quarterly refreshers provides a reasonable balance between thoroughness and operational impact. Q: Is cybersecurity awareness training required by law in Canada? A: There is no single federal law mandating cybersecurity awareness training for all Canadian businesses. However, organizations subject to PIPEDA or provincial privacy legislation have obligations to protect personal information, which in practice requires staff training. Certain regulated industries such as finance and healthcare may have sector-specific training requirements. Q: What topics should a cybersecurity training program cover for employees? A: According to CCCS guidance, training should cover recognizing phishing emails and social engineering attempts, safe browsing and email practices, password hygiene, reporting suspicious activity, and understanding your organization's security policies. Training content should be tailored to the roles and responsibilities of different staff members. --- ## BC.7 — Data Backup & Recovery URL: https://cybersecuritycanada.ca/controls/backup-recovery/ Summary: Learn what the Canadian Centre for Cyber Security recommends for backup strategy for businesses in Canada. Covers the 3-2-1 rule, restore testing, and ransomware resilience. ### What Data Backup & Recovery Means Data backup and recovery is the practice of creating and maintaining copies of important business data so it can be restored if the original is lost, corrupted, or made inaccessible. Under the Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), control BC.7 addresses the need for organizations to implement reliable backup processes and verify that data can be recovered when needed. Whether caused by ransomware, hardware failure, accidental deletion, or a natural disaster, data loss can halt business operations entirely. A tested backup and recovery plan ensures your organization can resume critical functions within an acceptable timeframe. This page provides educational information based on publicly available Canadian Centre for Cyber Security guidance. It is not professional cybersecurity advice. Organizations should consult qualified professionals for advice tailored to their specific circumstances. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations back up important data and system configurations regularly, and that they test the ability to restore from those backups. The guidance emphasizes that backups must be protected from the same threats they are meant to defend against. Key recommendations from the CCCS include: - Back up important information and systems regularly, including data, system configurations, and application settings. - Store at least one backup copy offline or offsite, disconnected from the organization's network, to protect against ransomware and other network-based threats. - Test backup restoration regularly to confirm that data can actually be recovered and that the recovery process works as expected. - Encrypt backup data, particularly when it is stored offsite or transmitted over networks, to protect confidentiality. - Document backup procedures so that staff know what is being backed up, where backups are stored, and how to initiate a restore. The CCCS has also published guidance on ransomware specifically, emphasizing that offline backups are one of the most effective ways to recover from a ransomware incident without paying a ransom. ### Why This Matters for Canadian Businesses Data loss is not a theoretical risk for Canadian SMBs — it is a regular occurrence. Hardware failures, ransomware attacks, accidental deletions, and software errors can all result in the loss of critical business data. The consequences vary depending on the nature and volume of data affected, but can include: - Operational shutdown if essential business systems cannot function without the lost data. - Financial losses from downtime, lost productivity, and the cost of data reconstruction or ransom payments. - Regulatory consequences under PIPEDA and provincial privacy laws if personal information is permanently lost or exposed during a data loss event. - Loss of customer trust if client records, orders, or service histories cannot be recovered. The CCCS National Cyber Threat Assessment has consistently identified ransomware as one of the top threats to Canadian organizations. Ransomware attacks specifically target an organization's ability to access its own data, making reliable, isolated backups essential to recovery. ### How to Get Started Building a reliable backup and recovery capability does not require enterprise-grade infrastructure. The following steps provide a practical starting point for Canadian SMBs. #### 1. Identify What Needs to Be Backed Up Start by inventorying your critical data and systems. This typically includes: - Financial records and accounting data - Customer and client databases - Employee records - Email and communications - Business documents and intellectual property - System configurations and application settings - Website and e-commerce data Not all data has equal value. Prioritize based on what your business needs to operate and what would be most costly or difficult to reconstruct. Our free assessment can help identify gaps in your current backup practices. #### 2. Apply the 3-2-1 Backup Rule The 3-2-1 rule is a widely recognized backup strategy that aligns with CCCS recommendations: - 3 copies of your data (the original plus two backups) - 2 different storage types (for example, local disk and cloud storage, or local disk and external hard drive) - 1 copy offsite or offline (physically separated from your primary network) The offline or offsite copy is particularly important because ransomware and other malware can encrypt or destroy backups that are accessible on the same network as the compromised systems. #### 3. Automate Your Backups Manual backup processes are prone to being forgotten or performed inconsistently. Use automated backup solutions that run on a defined schedule. The appropriate frequency depends on how often your data changes: - Daily backups for data that changes frequently, such as transaction databases and email. - Weekly backups for data that changes less often, such as system configurations. - Real-time or near-real-time replication for systems where any data loss is unacceptable, though this is typically more relevant for larger organizations. #### 4. Encrypt Your Backups Backup media and files should be encrypted, especially when stored offsite or in cloud services. Unencrypted backups represent a data breach risk if the storage media is lost, stolen, or improperly disposed of. Use strong encryption standards and manage encryption keys securely and separately from the backup data itself. #### 5. Define Recovery Time and Recovery Point Objectives Two key metrics guide backup planning: - Recovery Time Objective (RTO) — How quickly you need to restore systems and data after a disruption. This determines how fast your recovery process must be. - Recovery Point Objective (RPO) — How much data loss is acceptable, measured in time. An RPO of 24 hours means you can afford to lose up to one day of data, which implies daily backups at minimum. These objectives should be determined in consultation with business leadership and should drive your backup frequency and recovery infrastructure decisions. #### 6. Test Your Restores Regularly A backup that has never been tested is not a reliable backup. Schedule regular test restores to verify that: - Backup files are complete and not corrupted - The restore process works as documented - Data can be recovered within your defined RTO - Staff know how to perform a restore Document the results of each test and address any issues promptly. Consider testing restores to a separate environment to avoid disrupting production systems. ### Common Mistakes to Avoid Backup and recovery programs frequently fall short due to avoidable errors. Be aware of these common pitfalls. #### Backups Connected to the Network If all of your backups are accessible from your primary network, ransomware can reach and encrypt them along with your production data. The CCCS specifically recommends maintaining at least one backup copy that is offline or otherwise isolated. This could be an external hard drive stored securely offsite, a tape backup, or a cloud backup with immutable storage settings. #### Never Testing Restores Organizations frequently discover their backups are incomplete, corrupted, or incompatible only when they attempt to restore after an actual incident. Regular test restores are essential. A backup process that has never been verified provides only a false sense of security. #### Backing Up Only User Files Restoring individual files is important, but full recovery from a major incident also requires system configurations, application settings, databases, and potentially operating system images. Ensure your backup scope covers everything needed to rebuild your environment. #### No Documentation of Backup Procedures If only one person knows how to perform and restore backups, you have a significant single point of failure. Document procedures clearly and ensure multiple staff members are trained. This documentation should be part of your incident response plan. #### Ignoring Cloud Data Many organizations assume that data stored in cloud services is automatically backed up by the provider. While cloud providers typically maintain infrastructure redundancy, they may not protect against accidental deletion, account compromise, or data corruption in the way an independent backup would. Understand your cloud provider's data protection capabilities and supplement them if necessary. ### Connecting Backup & Recovery to Other Controls Backup and recovery works alongside other Baseline Controls to provide comprehensive protection: - Incident Response (BC.1) — Your incident response plan should include detailed procedures for restoring from backups, including who is responsible and how to prioritize system recovery. - Cloud Services Security (BC.10) — If your organization uses cloud services, ensure that cloud data is included in your backup strategy and that you understand the shared responsibility model for data protection. - Anti-Malware (BC.3) — Anti-malware controls help prevent ransomware and other threats that cause data loss, while backups provide a recovery path if those preventive controls are bypassed. For a complete view of how all 13 Baseline Controls work together, visit the controls overview page or take the free assessment to evaluate your organization's current posture. ### Related Articles - Backup and Recovery: 5 Assumptions That Fail When It Matters - Ransomware: What Canadian Businesses Need to Know — Why tested backups are your last line of defense - The Real Cost of Cyber Downtime for Canadian SMBs ### Additional Resources - CCCS Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) - CCCS — Ransomware: How to Prevent and Recover (ITSAP.00.099) - Cybersecurity Canada Resources Page - Free Cybersecurity Baseline Assessment ### Frequently Asked Questions — Data Backup & Recovery Q: What is the 3-2-1 backup rule and does the CCCS recommend it? A: The 3-2-1 backup rule means keeping at least three copies of your data, on two different types of storage media, with one copy stored offsite or offline. The Canadian Centre for Cyber Security recommends maintaining offline or offsite backups as part of baseline security controls, and the 3-2-1 approach is a widely recognized method for achieving this. Q: How often should a Canadian small business test its backups? A: The CCCS recommends testing backups regularly to ensure data can actually be restored when needed. The specific frequency depends on how critical the data is and how often it changes, but many organizations test key backups at least quarterly. Backups that have never been tested may fail during an actual recovery situation. Q: Can backups protect against ransomware? A: Backups are one of the most effective defences against ransomware, but only if at least one copy is kept offline or otherwise isolated from your network. Ransomware frequently targets connected backup systems to prevent recovery. An offline backup that cannot be reached by the ransomware allows you to restore data without paying a ransom. --- ## BC.8 — Mobile Device Security URL: https://cybersecuritycanada.ca/controls/mobile-security/ Summary: Learn what the Canadian Centre for Cyber Security recommends for mobile device management in Canada. Covers MDM, BYOD policies, encryption, and remote wipe. ### What Mobile Device Security Means Mobile device security encompasses the policies, technologies, and practices used to protect smartphones, tablets, and other portable devices that access business data and systems. Under the Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), control BC.8 addresses the need for organizations to manage and secure mobile devices, whether organization-owned or personal devices used for work purposes. Mobile devices present unique security challenges because they operate outside the physical perimeter of the office, connect to various networks, and can be easily lost or stolen. As Canadian businesses increasingly rely on mobile access to email, cloud services, and internal systems, securing these devices becomes a necessary component of overall cybersecurity. This page provides educational information based on publicly available Canadian Centre for Cyber Security guidance. It is not professional cybersecurity advice. Organizations should consult qualified professionals for advice tailored to their specific circumstances. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations establish controls for mobile devices that access organizational data. The guidance recognizes that mobile devices are a significant and growing part of the business IT environment and must be managed accordingly. Key recommendations from the CCCS include: - Establish a mobile device policy that defines how mobile devices may be used to access business data, including rules for both organization-owned and personal (BYOD) devices. - Require device encryption so that data on the device is protected if it is lost or stolen. - Enable remote wipe capability to allow the organization to erase business data from a device that is lost, stolen, or when an employee departs. - Require screen locks and strong authentication on all devices that access business data, using PINs, passwords, or biometric authentication. - Keep devices updated by applying operating system and application updates promptly to address known vulnerabilities. - Control application installation to reduce the risk of malicious or insecure apps being installed on devices with access to business data. ### Why This Matters for Canadian Businesses Mobile devices are now a standard part of the work environment for most Canadian businesses. Employees access email, file storage, customer relationship management tools, and other business applications from their phones and tablets on a daily basis. This creates both productivity benefits and security risks. The security concerns associated with mobile devices include: - Device loss and theft — Mobile devices are portable and frequently used in public settings, making them vulnerable to loss or theft. An unsecured device can give an attacker direct access to business email, files, and applications. - Unsecured networks — Mobile devices commonly connect to public Wi-Fi networks at cafes, airports, and hotels, where data can potentially be intercepted if connections are not properly secured. - Malicious applications — Apps installed from unofficial sources, or even legitimate-looking apps with hidden malicious functionality, can compromise device security and access business data. - Data leakage — Without controls, business data can be copied to personal cloud storage, shared via personal messaging apps, or otherwise moved outside the organization's control. - Privacy obligations — Under PIPEDA and provincial privacy legislation, organizations that collect personal information are responsible for protecting it regardless of which device it resides on. ### How to Get Started Implementing mobile device security does not require an enterprise mobility platform from the outset. The following steps provide a practical starting point for Canadian SMBs. #### 1. Assess Your Current Mobile Landscape Understand how mobile devices are currently used in your organization. Determine which employees use mobile devices for work, whether they are company-owned or personal, and what business data and systems they can access. Our free cybersecurity assessment can help identify gaps in your mobile security posture across all 13 Baseline Controls. #### 2. Create a Mobile Device Policy Document clear rules for mobile device use. A practical mobile device policy should address: - Which devices are permitted to access business data (company-owned, personal, or both) - Minimum security requirements (encryption, screen lock, OS version) - Rules for installing applications - Acceptable use of business data on mobile devices - The organization's right to remotely wipe business data - What employees must do if a device is lost or stolen - What happens to business data when an employee leaves the organization #### 3. Implement Basic Device Security Controls Even without a formal MDM solution, you can improve mobile security immediately: - Require screen locks — All devices accessing business data should have a PIN, password, or biometric lock enabled. - Enable device encryption — Modern iOS and Android devices support full-device encryption. On most current devices, this is enabled by default when a screen lock is set. - Enable auto-lock — Devices should lock automatically after a short period of inactivity. - Enable Find My Device — Both iOS and Android include built-in capabilities to locate, lock, and erase lost devices. #### 4. Consider Mobile Device Management Software For organizations with more than a handful of mobile users, an MDM solution provides centralized control over device security policies. MDM platforms allow you to: - Enforce security policies (encryption, password complexity, auto-lock) across all managed devices - Remotely wipe business data from lost or stolen devices - Separate business and personal data on BYOD devices using containerization - Control which apps can be installed - Push security updates and configurations - Monitor device compliance with your security policies Several MDM solutions are available at price points suitable for SMBs, including cloud-based options that do not require on-premises infrastructure. #### 5. Address BYOD Specifically If employees use personal devices for work, consider these additional measures: - Containerization — Use solutions that create a separate, encrypted container for business data on personal devices, keeping work and personal data separate. - Conditional access — Configure business applications (such as email and cloud services) to require devices to meet minimum security standards before granting access. - Clear agreements — Have employees acknowledge the organization's BYOD policy, including the right to remotely wipe business data if needed. #### 6. Manage Application Security Control which applications can access business data: - Instruct employees to install apps only from official app stores (Apple App Store, Google Play Store) - Identify and approve specific apps for business use - Use multi-factor authentication for business applications accessed on mobile devices - Review app permissions to ensure they do not request excessive access to device data ### Common Mistakes to Avoid Mobile device security programs can be undermined by common oversights. Be aware of these pitfalls. #### No Policy at All Many SMBs allow mobile access to business data without any formal policy or security requirements. This creates an unmanaged risk. Even a simple, documented policy with basic requirements is significantly better than no policy. #### Ignoring BYOD Realities Prohibiting personal device use for work is often impractical for SMBs. Rather than pretending BYOD does not happen, acknowledge it and implement appropriate controls. Ignoring the reality of personal device use means having no security controls over a significant portion of your business data access. #### Relying Solely on Device Passwords A device screen lock is necessary but not sufficient. If the device is compromised or if business applications use single-factor authentication, a screen lock alone will not protect business data. Combine device security with strong authentication on business applications and services. #### No Plan for Lost or Departed Devices Organizations that do not have a process for handling lost devices or retrieving business data when employees leave are exposed to data loss and potential breaches. Establish and document these procedures before they are needed. #### Forgetting to Update Mobile operating systems and apps receive frequent security updates. Devices running outdated software are vulnerable to known exploits. Establish expectations for timely updates and use MDM tools to monitor compliance where possible. This aligns with secure configuration (BC.4) practices. ### Connecting Mobile Security to Other Controls Mobile device security intersects with several other Baseline Controls: - Authentication (BC.5) — Mobile devices should use strong authentication methods, and business applications accessed from mobile devices should require multi-factor authentication. - Secure Configuration (BC.4) — Mobile devices should be configured securely with encryption, auto-lock, and current software, following the same principles as other IT assets. - Access Control & Authorization (BC.12) — Access to business data from mobile devices should follow the principle of least privilege, granting only the access each employee needs for their role. For a complete view of how all 13 Baseline Controls work together, visit the controls overview page or take the free assessment to evaluate your organization's current posture. ### Related Articles - Remote Work Security for Canadian Businesses — BYOD and device management - 5 Easy Cybersecurity Wins for Canadian Small Businesses ### Additional Resources - CCCS Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) - CCCS — Mobile Device Security (ITSAP.00.034) - Cybersecurity Canada Resources Page - Free Cybersecurity Baseline Assessment ### Frequently Asked Questions — Mobile Device Security Q: Does the CCCS require businesses to use mobile device management software? A: The CCCS does not mandate a specific technology, but its baseline controls recommend that organizations manage and secure mobile devices that access business data. Mobile device management (MDM) solutions are one of the most practical ways to enforce security policies on smartphones and tablets, particularly when employees use personal devices for work. Q: Should Canadian small businesses allow employees to use personal phones for work? A: Bring-your-own-device (BYOD) arrangements are common in Canadian SMBs, but they introduce security risks. The CCCS recommends that if personal devices are used for work, organizations establish clear policies covering device security requirements, acceptable use, and the organization's ability to remotely wipe business data if a device is lost or the employee leaves. Q: What should a business do if an employee's work phone is lost or stolen? A: The CCCS recommends having remote wipe capability for devices that access business data. If a device is lost or stolen, the organization should be able to remotely erase business data from it. Employees should report lost devices immediately so this action can be taken quickly, and the incident should be handled according to your incident response plan. --- ## BC.9 — Network & Perimeter Security URL: https://cybersecuritycanada.ca/controls/network-security/ Summary: Learn what the Canadian Centre for Cyber Security recommends for network security for SMBs in Canada. Covers firewalls, segmentation, VPNs, and intrusion detection. ### What Network & Perimeter Security Means Network and perimeter security refers to the controls and technologies used to protect an organization's computer network from unauthorized access, misuse, and attacks. Under the Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), control BC.9 addresses the need for organizations to establish and maintain defences at the boundaries of their networks and to monitor network traffic for signs of malicious activity. Your network is the infrastructure that connects your computers, servers, printers, and other devices to each other and to the internet. Without proper controls, this infrastructure becomes a pathway for attackers to access business data, disrupt operations, or move laterally through your environment after an initial compromise. This page provides educational information based on publicly available Canadian Centre for Cyber Security guidance. It is not professional cybersecurity advice. Organizations should consult qualified professionals for advice tailored to their specific circumstances. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations implement network security measures to protect against unauthorized access and to detect and respond to network-based threats. The guidance covers both boundary protection and internal network controls. Key recommendations from the CCCS include: - Deploy and configure firewalls at the network perimeter to control inbound and outbound traffic. Firewalls should be configured to deny traffic by default and allow only traffic that is explicitly needed. - Segment the network to separate different zones based on sensitivity and function, limiting the ability of an attacker to move laterally after compromising one system. - Use encrypted connections such as VPNs for remote access to internal business systems, protecting data in transit between remote workers and the organization's network. - Secure wireless networks using strong encryption (WPA3 or WPA2 at minimum) and unique, complex passwords. Separate guest Wi-Fi from the business network. - Monitor network traffic for unusual activity that may indicate a compromise, such as unexpected data transfers, connections to known malicious addresses, or unusual patterns of access. - Use DNS security to block connections to known malicious domains. The Canadian Internet Registration Authority (CIRA) operates the Canadian Shield DNS service, a free tool that provides DNS-level protection for Canadians. ### Why This Matters for Canadian Businesses Network-based attacks are a persistent threat to Canadian organizations of all sizes. Attackers routinely scan the internet for poorly configured firewalls, exposed services, and vulnerable network devices. Small and medium businesses are frequently targeted because they often have fewer dedicated resources to monitor and defend their networks. The risks of inadequate network security include: - Unauthorized access to internal systems, business data, and customer information by external attackers. - Lateral movement — once an attacker gains access to one system, a flat (unsegmented) network allows them to reach other systems, databases, and file shares with minimal additional effort. - Data exfiltration — without network monitoring, large volumes of data can be copied out of the organization without detection. - Ransomware deployment — ransomware operators frequently move through a network to compromise as many systems as possible before deploying encryption, maximizing the impact and the ransom demand. - Regulatory exposure — under PIPEDA and provincial privacy laws, organizations that fail to implement reasonable safeguards to protect personal information may face regulatory consequences in the event of a breach. The CCCS National Cyber Threat Assessment notes that internet-connected infrastructure is routinely targeted by both cybercriminals and state-sponsored actors, making network defence a priority for all Canadian organizations. ### How to Get Started Implementing effective network security is achievable for SMBs with appropriate planning. The following steps provide a practical starting point. #### 1. Understand Your Network Before you can secure your network, you need to understand it. Document your network topology, including: - All devices connected to the network (computers, servers, printers, IoT devices) - How your network connects to the internet - Any remote access points or VPN connections - Wireless access points and their configurations - Cloud services that connect to your network Our free cybersecurity assessment can help identify gaps across all 13 Baseline Controls, including network security. #### 2. Configure Your Firewall Properly A firewall is the primary boundary defence for your network. Whether you use a hardware appliance or a software-based firewall, ensure it is configured according to these principles: - Default deny — Block all traffic by default and create explicit rules to allow only necessary traffic. - Limit inbound access — Only open ports that are required for legitimate business purposes. - Filter outbound traffic — Restrict outbound connections to prevent compromised systems from communicating with attacker-controlled servers. - Keep firmware updated — Firewalls themselves have vulnerabilities that are addressed through firmware updates. Apply these promptly. - Review rules regularly — Firewall rules accumulate over time. Review and remove unnecessary rules at least annually. - Change default credentials — Ensure the firewall's administrative password has been changed from the manufacturer's default, following secure configuration principles. #### 3. Segment Your Network Network segmentation divides your network into separate zones, limiting the blast radius of a compromise. Even basic segmentation provides meaningful benefit: - Separate guest Wi-Fi from the business network so that visitors and personal devices cannot access internal systems. - Isolate sensitive systems such as servers containing financial data, customer information, or proprietary business data. - Separate IoT devices (printers, security cameras, smart devices) from the main business network, as these devices often have limited security capabilities. Many modern business-grade routers and firewalls support VLANs (Virtual Local Area Networks) that enable segmentation without requiring separate physical infrastructure. #### 4. Secure Remote Access If employees access business systems remotely, secure those connections: - Use a VPN for connections to internal network resources, ensuring data is encrypted in transit. - Require multi-factor authentication for VPN and remote access connections, integrating with your authentication controls. - Limit remote access to only the systems and data each employee needs, following the principle of least privilege. - Monitor remote connections for unusual access patterns, such as connections from unexpected locations or at unusual times. #### 5. Secure Your Wireless Network Wireless networks require specific security measures: - Use WPA3 encryption if your equipment supports it, or WPA2 at minimum. Never use WEP or open (unencrypted) networks for business purposes. - Use strong, unique passwords for wireless networks and change them periodically. - Disable WPS (Wi-Fi Protected Setup), which has known vulnerabilities. - Hide your business SSID if appropriate, though this provides only minimal additional security. - Position access points to minimize signal coverage outside your premises where practical. #### 6. Implement DNS Security DNS security provides a layer of protection by blocking connections to known malicious domains. The CIRA Canadian Shield is a free DNS security service operated by the Canadian Internet Registration Authority that blocks malware, phishing, and botnet domains at the DNS level. Configuring your network to use a protective DNS service is one of the simplest and most cost-effective network security improvements available. #### 7. Monitor Network Activity Monitoring your network for unusual activity helps detect compromises early: - Enable logging on your firewall and review logs regularly for blocked connection attempts and unusual patterns. - Consider intrusion detection or intrusion prevention systems (IDS/IPS) if your budget and technical capability permit. - Watch for signs of compromise such as unexpected outbound connections, large data transfers, or connections at unusual hours. - Many business-grade firewalls and routers include basic monitoring and alerting capabilities that should be enabled and configured. ### Common Mistakes to Avoid Network security implementations frequently suffer from common oversights that reduce their effectiveness. #### Default Firewall Configurations Many organizations deploy firewalls but leave them in their default configuration, which may be more permissive than appropriate. A firewall is only as effective as its rule set. Take the time to configure it according to your specific needs and the default-deny principle. #### Flat Networks A flat network where all devices share the same network segment means that a compromise of any single device can potentially reach every other device. Even basic segmentation, such as separating servers from workstations and guest access from business access, meaningfully reduces this risk. #### Forgotten Network Devices Routers, switches, access points, and firewalls are themselves computers that require updates, strong passwords, and secure configuration. Organizations frequently deploy these devices and then neglect to update their firmware or review their configurations. Include network devices in your secure configuration and patch management processes. #### Overly Permissive Firewall Rules Over time, firewall rules accumulate as temporary exceptions become permanent and broad rules are added for convenience. Regularly review your firewall rules and remove or tighten any that are no longer necessary. Each unnecessary open port or permissive rule increases your attack surface. #### No Outbound Filtering Many organizations focus only on blocking inbound threats while allowing all outbound traffic. This means a compromised internal system can freely communicate with attacker-controlled servers. Implementing outbound filtering helps detect and prevent data exfiltration and command-and-control communications. ### Connecting Network Security to Other Controls Network security works in concert with other Baseline Controls: - Secure Configuration (BC.4) — Network devices must be securely configured with strong passwords, unnecessary services disabled, and firmware kept up to date. - Cloud Services Security (BC.10) — As business services move to the cloud, network security must extend to cover connections between your network and cloud environments. - Web Application Security (BC.11) — Network perimeter controls such as web application firewalls and DNS security help protect web-facing applications from attack. For a complete view of how all 13 Baseline Controls work together, visit the controls overview page or take the free assessment to evaluate your organization's current posture. ### Related Articles - How to Recognize Phishing Emails — Email-based threats that bypass network defenses - Remote Work Security for Canadian Businesses — VPN and WiFi security - When Cyber Attacks Become Physical Threats — WiFi jamming and network vulnerabilities ### Additional Resources - CCCS Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) - CIRA Canadian Shield — Free DNS Security for Canadians - Cybersecurity Canada Resources Page - Free Cybersecurity Baseline Assessment ### Frequently Asked Questions — Network & Perimeter Security Q: Does the CCCS recommend specific firewall products for Canadian small businesses? A: The CCCS does not endorse or recommend specific commercial products. Its baseline controls recommend that organizations use firewalls to control traffic between trusted internal networks and untrusted external networks, and that firewalls be configured to deny traffic by default and allow only what is explicitly needed. The choice of product depends on your organization's size, budget, and technical requirements. Q: Is a VPN necessary for remote employees at a Canadian small business? A: The CCCS recommends using encrypted connections such as VPNs when employees access internal business systems remotely. A VPN creates an encrypted tunnel between the employee's device and the organization's network, protecting data in transit. This is particularly important when employees work from home or connect from public networks. Q: What is network segmentation and do small businesses need it? A: Network segmentation divides your network into separate zones so that a compromise in one area does not automatically give an attacker access to everything. The CCCS recommends segmentation as a baseline control. Even small businesses can benefit from basic segmentation, such as separating guest Wi-Fi from the business network and isolating systems that process sensitive data. --- ## BC.10 — Cloud Services Security URL: https://cybersecuritycanada.ca/controls/cloud-security/ Summary: Learn what the Canadian Centre for Cyber Security recommends for cloud security for Canadian businesses. Covers shared responsibility, data residency, and secure configuration. ### What Cloud Services Security Means Cloud services security encompasses the policies, controls, and practices used to protect data, applications, and infrastructure hosted in cloud computing environments. Under the Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089), control BC.10 addresses the need for organizations to understand and manage the security of cloud services they use, including the shared responsibility between the cloud provider and the customer. Canadian businesses of all sizes increasingly rely on cloud services for email, file storage, collaboration, accounting, customer management, and many other business functions. While cloud services can offer security benefits such as automatic updates and professional infrastructure management, they also introduce risks that organizations must actively manage. This page provides educational information based on publicly available Canadian Centre for Cyber Security guidance. It is not professional cybersecurity advice. Organizations should consult qualified professionals for advice tailored to their specific circumstances. ### What the Canadian Centre for Cyber Security Recommends The CCCS Baseline Controls (ITSM.10.089) recommend that organizations take an active role in securing their use of cloud services. The guidance emphasizes that moving to the cloud does not transfer all security responsibility to the provider — organizations remain responsible for many aspects of their security. Key recommendations from the CCCS include: - Understand the shared responsibility model for each cloud service you use. Know which security controls are managed by the provider and which are your responsibility. - Configure cloud services securely, including enabling security features offered by the provider, restricting administrative access, and reviewing default settings. - Use strong authentication for cloud accounts, including multi-factor authentication (MFA) for all users, and especially for administrative accounts. - Understand data residency — know where your data is stored and processed, and consider the legal and regulatory implications for your organization. - Back up cloud data independently rather than relying solely on the cloud provider's infrastructure redundancy. - Review and manage cloud service permissions to ensure users have only the access they need and that unused accounts are disabled. - Assess cloud providers before adopting their services, evaluating their security practices, certifications, and terms of service. The CCCS has also published specific guidance on cloud security considerations, including its Cloud Security Risk Management publications, which provide more detailed recommendations for organizations adopting cloud services. ### Why This Matters for Canadian Businesses Cloud adoption among Canadian businesses has accelerated significantly. For many SMBs, cloud services are now the primary platform for email, document storage, and business applications. This reliance on cloud services makes their secure use a business-critical concern. Key risks associated with cloud services include: - Misconfiguration — Cloud services often ship with default settings that may not be secure for your use case. Misconfigured cloud storage, overly permissive sharing settings, or disabled security features are common causes of data exposure. - Account compromise — Cloud accounts accessible from anywhere on the internet are attractive targets. Compromised cloud credentials can give attackers access to email, documents, customer data, and other business information. - Data loss — While cloud providers maintain infrastructure redundancy, they typically do not protect against user-initiated data deletion, account-level compromise, or application-level data corruption. - Compliance risks — Canadian organizations subject to PIPEDA and provincial privacy legislation must ensure that personal information stored in cloud services is adequately protected, regardless of where the cloud provider's servers are located. - Vendor lock-in and continuity — Dependence on a single cloud provider without adequate backups or data portability planning can create business continuity risks. The CCCS National Cyber Threat Assessment has noted that cloud environments are increasingly targeted by threat actors, and that misconfiguration of cloud services is a common factor in data breaches affecting Canadian organizations. ### How to Get Started Securing your organization's use of cloud services requires a structured approach. The following steps provide a practical starting point for Canadian SMBs. #### 1. Inventory Your Cloud Services Start by identifying all cloud services your organization uses. This often reveals more services than expected, including: - Email platforms (Microsoft 365, Google Workspace) - File storage and sharing (OneDrive, Google Drive, Dropbox) - Accounting and payroll software - Customer relationship management (CRM) tools - Communication and collaboration platforms - Industry-specific SaaS applications Include services adopted by individual departments or employees without formal IT approval, sometimes called shadow IT. Our free cybersecurity assessment can help identify gaps across all 13 Baseline Controls, including cloud security. #### 2. Understand the Shared Responsibility Model For each cloud service, understand the division of security responsibilities: - The cloud provider is typically responsible for the security of the underlying infrastructure — physical data centres, networking hardware, hypervisors, and base platform services. - Your organization is typically responsible for securing your data within the cloud service, managing user accounts and access, configuring security settings, and ensuring data is backed up. The exact division varies depending on the type of cloud service (Infrastructure as a Service, Platform as a Service, or Software as a Service). Review each provider's documentation to understand what they secure and what falls to you. #### 3. Secure Your Cloud Accounts Cloud account security is one of the most important and achievable steps: - Enable multi-factor authentication for all cloud accounts. This is the single most effective measure against account compromise. See Authentication (BC.5) for detailed guidance. - Use strong, unique passwords for all cloud service accounts. - Protect administrative accounts with the highest level of security. Limit the number of people with administrative access and use dedicated admin accounts separate from day-to-day accounts. - Disable unused accounts promptly when employees leave or change roles. - Review access permissions regularly to ensure they follow the principle of least privilege. #### 4. Configure Cloud Services Securely Review and adjust the security settings of each cloud service: - Review sharing settings — Ensure files and folders are not shared more broadly than intended. Many cloud services default to allowing link sharing or broad access. - Enable audit logging where available, so you have a record of who accessed what and when. - Configure data loss prevention features if your cloud platform offers them, to help prevent sensitive data from being shared inappropriately. - Review connected third-party applications — Cloud platforms often allow third-party apps to connect via OAuth or API integrations. Review and remove any that are unnecessary. - Enable available security features — Many cloud services include security capabilities that are not enabled by default. Review your provider's security documentation and enable relevant features. #### 5. Address Data Residency For Canadian organizations, data residency is an important consideration: - Know where your data is stored — Determine which countries and regions your cloud provider uses for data storage and processing. - Understand the legal implications — Data stored in other countries may be subject to the laws of those jurisdictions. For example, data stored in the United States may be subject to U.S. law enforcement access under certain circumstances. - Check regulatory requirements — Some sectors and provinces have specific requirements about where certain types of data can be stored. Federal institutions are subject to the Government of Canada's cloud-first policy, which includes data residency considerations. - Choose Canadian data centre regions where available. Major cloud providers including Microsoft, Google, and Amazon Web Services operate data centre regions in Canada. #### 6. Back Up Your Cloud Data Do not assume your cloud provider's infrastructure redundancy is equivalent to a backup. Implement independent backups of important cloud data: - Use third-party backup solutions that can back up data from cloud platforms such as Microsoft 365 or Google Workspace. - Consider the 3-2-1 backup rule — maintain copies of cloud data on separate storage. - Test your ability to restore cloud data, just as you would test any other backup. - Ensure backup data is encrypted and stored securely. #### 7. Assess Cloud Providers Before adopting a new cloud service, evaluate the provider's security posture: - Security certifications — Look for relevant certifications such as SOC 2, ISO 27001, or FedRAMP (for services also used by U.S. government agencies). - Data protection practices — Review how the provider encrypts data at rest and in transit. - Terms of service — Understand the provider's responsibilities, liability limitations, and data handling practices. - Incident notification — Review the provider's commitment to notifying you of security incidents that affect your data. - Data portability — Ensure you can export your data in a usable format if you need to switch providers. ### Common Mistakes to Avoid Cloud security programs are frequently undermined by preventable errors. Be aware of these common pitfalls. #### Assuming the Cloud Provider Handles All Security The most common and significant mistake is believing that moving to the cloud transfers all security responsibility to the provider. Under the shared responsibility model, you remain responsible for securing your data, accounts, and configurations. A misconfigured cloud service is your organization's responsibility, not the provider's. #### Not Enabling Multi-Factor Authentication Cloud accounts are accessible from anywhere on the internet, making them high-value targets. Accounts protected only by passwords are vulnerable to credential stuffing, phishing, and password spraying attacks. MFA is available on virtually all major cloud platforms and should be enabled for every user. #### Overly Permissive Sharing Settings Cloud storage services make it easy to share files and folders, but default sharing settings can expose data more broadly than intended. Regularly audit sharing permissions and ensure that sensitive documents are shared only with specific, authorized individuals rather than via open links. #### Ignoring Shadow IT Employees often adopt cloud services without formal IT approval to solve immediate work problems. These unauthorized services may not meet your security standards and create unmanaged risk. Rather than simply prohibiting shadow IT, provide approved alternatives that meet employee needs while maintaining security standards. #### No Independent Backups of Cloud Data Cloud provider redundancy protects against infrastructure failures but not against accidental deletion, malicious deletion by a compromised account, or application-level corruption. Independent backups of cloud data are essential for comprehensive data protection. ### Connecting Cloud Security to Other Controls Cloud services security intersects with several other Baseline Controls: - Data Backup & Recovery (BC.7) — Cloud data should be included in your backup strategy. Do not rely solely on cloud provider redundancy for data protection. - Authentication (BC.5) — Cloud accounts must be protected with strong authentication, including multi-factor authentication for all users. This is perhaps the most critical security control for cloud environments. - Network & Perimeter Security (BC.9) — Connections between your organization's network and cloud services should be secured, and network controls should account for the reality that business data now resides both on-premises and in the cloud. For a complete view of how all 13 Baseline Controls work together, visit the controls overview page or take the free assessment to evaluate your organization's current posture. ### Related Articles - Cloud Security Basics for Canadian Small Businesses - Why Your Business Needs an AI Usage Policy — Vetting AI cloud providers - Remote Work Security for Canadian Businesses ### Additional Resources - CCCS Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) - CCCS — Cloud Security Risk Management (ITSM.50.062) - Cybersecurity Canada Resources Page - Free Cybersecurity Baseline Assessment ### Frequently Asked Questions — Cloud Services Security Q: Does the CCCS require Canadian businesses to store data in Canada when using cloud services? A: The CCCS does not mandate that all data be stored in Canada, but it recommends that organizations understand where their data is stored and processed and consider the legal and regulatory implications. Under PIPEDA, organizations must ensure adequate protection of personal information regardless of where it is stored. Some provincial laws and sector-specific regulations may have more specific data residency requirements. Q: What is the shared responsibility model in cloud security? A: The shared responsibility model means that cloud security is divided between the cloud provider and the customer. The provider secures the underlying infrastructure, while the customer is responsible for securing their data, user accounts, access controls, and application configurations within the cloud environment. The CCCS recommends that organizations clearly understand this division to avoid gaps in their security. Q: Should a small business back up data that is already in the cloud? A: Yes. Cloud providers typically protect against infrastructure failures through redundancy, but they generally do not protect against accidental deletion, account compromise, or application-level data corruption. The CCCS recommends maintaining independent backups of important data, including data stored in cloud services. This aligns with the baseline control for data backup and recovery (BC.7). --- ## BC.11 — Web Application Security URL: https://cybersecuritycanada.ca/controls/web-application-security/ Summary: What the Canadian Centre for Cyber Security recommends for web application security. HTTPS, input validation, WAFs, secure development, and OWASP awareness for SMBs. ### What the Canadian Centre for Cyber Security Recommends The Canadian Centre for Cyber Security (CCCS) identifies web application security as Baseline Control 11 (BC.11) in its Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). Organizations that operate websites, web portals, e-commerce platforms, or any web-based applications should implement protective measures to defend against common web-based attacks. This includes encrypting web traffic, validating user input, keeping web software up to date, and monitoring for known vulnerabilities. Web applications are frequently targeted because they are publicly accessible and often process sensitive data such as customer information, payment details, and login credentials. The CCCS guidance recognizes that even small organizations with basic websites face these risks and should take steps to protect their web presence. ### HTTPS Everywhere All web traffic should be encrypted using HTTPS (Hypertext Transfer Protocol Secure). HTTPS protects data transmitted between a user's browser and your web server from interception and tampering. Implementing HTTPS involves obtaining and installing a TLS (Transport Layer Security) certificate on your web server. Many hosting providers and services such as Let's Encrypt offer TLS certificates at no cost. Once HTTPS is enabled, organizations should: - Redirect all HTTP traffic to HTTPS — ensure that users who visit the non-encrypted version of your site are automatically redirected to the encrypted version - Use current TLS versions — disable outdated protocols such as SSL 3.0, TLS 1.0, and TLS 1.1, and use TLS 1.2 or TLS 1.3 - Enable HSTS (HTTP Strict Transport Security) — this tells browsers to only connect to your site over HTTPS, reducing the risk of protocol downgrade attacks - Renew certificates before expiry — expired certificates cause browser warnings that erode user trust and may expose data ### Input Validation Every piece of data that a user submits to your web application — form fields, URL parameters, file uploads, API requests — should be validated before the application processes it. Input validation is a primary defence against many of the most common web application attacks. Without proper input validation, attackers can inject malicious code into your application. The two most prevalent injection attacks are: - SQL injection — where an attacker inserts database commands into input fields, potentially gaining access to or modifying your entire database - Cross-site scripting (XSS) — where an attacker injects malicious scripts that execute in other users' browsers, potentially stealing session tokens or credentials Effective input validation practices include: - Validate input on both the client side (browser) and server side — server-side validation is essential, as client-side validation can be bypassed - Use allowlists (accept only known-good input) rather than denylists (block known-bad input) wherever possible - Use parameterized queries or prepared statements for all database interactions to prevent SQL injection - Encode output to prevent XSS — ensure that data displayed back to users is properly escaped - Limit file upload types, sizes, and storage locations ### Software Updates and Patch Management Web applications depend on multiple software layers — the content management system (CMS), plugins, themes, frameworks, programming language runtimes, web server software, and the underlying operating system. Each of these components may contain vulnerabilities that attackers can exploit. The CCCS emphasizes keeping all software components up to date as a critical web security practice. This aligns with Baseline Control BC.2 (Patch Management). Specific recommendations include: - Apply security patches promptly — prioritize patches for internet-facing components, as these are most exposed to attack - Update CMS platforms and plugins regularly — WordPress, Drupal, Joomla, Shopify apps, and similar platforms frequently release security updates - Remove unused plugins and themes — each installed component increases your attack surface, even if it is deactivated - Subscribe to security advisories — monitor announcements from your CMS vendor, hosting provider, and software framework developers - Test updates before deploying to production — use a staging environment where possible to verify that updates do not break functionality ### Web Application Firewalls A web application firewall (WAF) inspects incoming web traffic and blocks requests that match known attack patterns. A WAF provides a layer of defence between the internet and your web application, filtering out malicious requests before they reach your application code. WAFs can be deployed in several ways: - Cloud-based WAF services — provided by vendors such as Cloudflare, AWS WAF, or Azure WAF; these require minimal configuration and are often the most practical option for small and medium organizations - Host-based WAFs — installed directly on your web server, such as ModSecurity - Managed WAF services — offered by hosting providers as an add-on feature A WAF should be considered an additional layer of defence, not a replacement for secure coding practices. WAFs are effective at blocking known attack patterns but may not catch novel or application-specific vulnerabilities. ### Secure Development Practices Organizations that develop their own web applications — or commission custom development — should incorporate security throughout the development lifecycle. The CCCS guidance recommends that security is considered from the design phase, not added as an afterthought. Key secure development practices include: - Security requirements — define security requirements at the beginning of each project, including authentication, authorization, data protection, and logging - Code reviews — have a second developer review code for security issues before deployment - Automated security testing — use static application security testing (SAST) and dynamic application security testing (DAST) tools to identify vulnerabilities - Dependency management — track third-party libraries and components used in your application and monitor them for known vulnerabilities - Secure defaults — configure applications with secure settings by default, aligned with Baseline Control BC.4 (Secure Configuration) - Error handling — ensure that error messages do not expose sensitive information such as database structures, file paths, or stack traces ### OWASP Top 10 Awareness The Open Web Application Security Project (OWASP) publishes the OWASP Top 10, a widely recognized list of the most critical web application security risks. The CCCS references OWASP as a resource for organizations seeking to understand and mitigate common web vulnerabilities. The OWASP Top 10 categories include risks such as: - Broken access control — users can act outside their intended permissions - Cryptographic failures — sensitive data is not properly encrypted - Injection — untrusted data is sent to an interpreter as part of a command or query - Insecure design — security flaws in the application's architecture - Security misconfiguration — default or incomplete security settings - Vulnerable and outdated components — use of libraries or frameworks with known vulnerabilities - Server-side request forgery (SSRF) — the application can be tricked into making requests to unintended destinations Organizations do not need to become OWASP experts, but awareness of these common risk categories helps inform better decision-making about web application security. The OWASP Foundation provides free resources, checklists, and testing guides at owasp.org. ### Getting Started For Canadian small and medium organizations looking to improve web application security, the CCCS Baseline Controls suggest starting with the highest-impact measures: - Enable HTTPS on all web properties and redirect all HTTP traffic - Update all web software — CMS, plugins, themes, and server software — to current versions - Remove unused plugins, themes, and accounts from your web applications - Implement a web application firewall — a cloud-based WAF can often be deployed in under an hour - Review input handling — ensure that forms and data inputs are validated server-side - Take the free cybersecurity assessment to evaluate your organization's posture across all 13 Baseline Controls ### Related Articles - Vendor and Third-Party Risk — Web application security in your supply chain - 5 Easy Cybersecurity Wins for Canadian Small Businesses ### Frequently Asked Questions #### Do small businesses in Canada need to worry about web application security? Yes. Any organization that operates a website, web portal, or web-based application is a potential target. The Canadian Centre for Cyber Security includes web application security as one of its 13 Baseline Controls (ITSM.10.089) specifically because web-facing systems are among the most commonly exploited attack surfaces. #### What is the most important first step for web application security? Enabling HTTPS across your entire website is the most impactful first step. HTTPS encrypts data in transit between your users and your server, preventing interception of sensitive information. The CCCS recommends HTTPS everywhere as a foundational web security measure. #### Is a web application firewall required under Canadian cybersecurity guidelines? The CCCS Baseline Controls recommend implementing a web application firewall (WAF) as a protective measure for web-facing applications. While not a legal requirement, a WAF provides an additional layer of defence against common web attacks and is considered a best practice for Canadian organizations of all sizes. ### Frequently Asked Questions — Web Application Security Q: Do small businesses in Canada need to worry about web application security? A: Yes. Any organization that operates a website, web portal, or web-based application is a potential target. The Canadian Centre for Cyber Security includes web application security as one of its 13 Baseline Controls (ITSM.10.089) specifically because web-facing systems are among the most commonly exploited attack surfaces. Q: What is the most important first step for web application security? A: Enabling HTTPS across your entire website is the most impactful first step. HTTPS encrypts data in transit between your users and your server, preventing interception of sensitive information. The CCCS recommends HTTPS everywhere as a foundational web security measure. Q: Is a web application firewall required under Canadian cybersecurity guidelines? A: The CCCS Baseline Controls recommend implementing a web application firewall (WAF) as a protective measure for web-facing applications. While not a legal requirement, a WAF provides an additional layer of defence against common web attacks and is considered a best practice for Canadian organizations of all sizes. --- ## BC.12 — Access Control & Authorization URL: https://cybersecuritycanada.ca/controls/access-control/ Summary: What the Canadian Centre for Cyber Security recommends for access control. Least privilege, role-based access, access reviews, and privileged account management for SMBs. ### What the Canadian Centre for Cyber Security Recommends The Canadian Centre for Cyber Security (CCCS) identifies access control and authorization as Baseline Control 12 (BC.12) in its Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). Organizations should control who has access to their systems, data, and resources — and limit that access to only what each person needs to perform their job. This control focuses on managing permissions after a user's identity has been verified through authentication (BC.5). Inadequate access control is one of the most common contributors to data breaches and insider threats. When users have more access than they need, the potential impact of a compromised account, a malicious insider, or a simple mistake increases significantly. The CCCS guidance establishes access control as a foundational security practice for organizations of all sizes. ### The Principle of Least Privilege Users should be granted only the minimum level of access required to perform their job duties — nothing more. This is known as the principle of least privilege, and it is the foundation of the CCCS access control recommendations. Applying least privilege means: - Default to no access — new accounts should start with no permissions, and access should be granted only as needed and approved - Grant access based on job function — permissions should reflect what the role requires, not what the individual requests for convenience - Avoid permanent elevated access — administrative or privileged access should be granted only when needed and revoked when the task is complete - Apply least privilege to applications and services — not just human users; service accounts and automated processes should also operate with minimal permissions Least privilege reduces the blast radius of a security incident. If an attacker compromises a user account that has limited permissions, the damage they can do is correspondingly limited. ### Role-Based Access Control (RBAC) Rather than assigning permissions to individual users one at a time, the CCCS recommends organizing access permissions into roles that correspond to job functions. This approach — role-based access control (RBAC) — simplifies management and reduces the risk of permission errors. Implementing RBAC involves: - Defining roles — identify the job functions in your organization and the system access each function requires (e.g., "Accounting Clerk," "Sales Manager," "IT Administrator") - Assigning users to roles — grant access by assigning a user to the appropriate role, rather than configuring individual permissions - Documenting role definitions — maintain a written record of what each role can access and who approved the role definition - Limiting the number of roles — avoid creating so many roles that the system becomes difficult to manage; aim for a manageable set that covers your organization's functions - Handling exceptions — when a user needs access beyond their role, document the exception with a business justification and an expiry date Most modern business platforms — including Microsoft 365, Google Workspace, and cloud services — support role-based access configuration. Leveraging these built-in capabilities makes RBAC practical even for small organizations. ### Regular Access Reviews Access permissions tend to accumulate over time. Employees change roles, take on temporary projects, or receive access that is never revoked. The CCCS recommends that organizations conduct regular access reviews to ensure that current permissions still align with current job requirements. An effective access review process includes: - Scheduled reviews — review privileged accounts at least quarterly and standard accounts at least semi-annually - Manager involvement — each employee's direct manager should confirm that the access listed for their team members is still appropriate - Documentation — record the date of each review, who conducted it, and any changes made - Removing stale access — revoke permissions that are no longer needed, including access to old projects, former team resources, and deactivated systems - Identifying dormant accounts — flag accounts that have not been used for an extended period (e.g., 90 days) for investigation and potential deactivation ### Separation of Duties No single individual should have enough access to complete a critical or high-risk process entirely on their own. Separation of duties divides responsibilities so that errors, fraud, or misuse require collusion between multiple people, making them more difficult and more detectable. Common examples of separation of duties include: - Financial transactions — the person who initiates a payment should not be the same person who approves it - System administration — the person who administers a system should not be the only person who reviews the audit logs for that system - User account management — access requests should require approval from someone other than the requester - Code deployment — in development environments, the person who writes code should not be the same person who deploys it to production For very small organizations where strict separation of duties is not practical due to limited staff, compensating controls — such as detailed logging, regular audits, and management oversight — can help mitigate the risk. ### Privileged Account Management Privileged accounts — such as administrator accounts, root accounts, and service accounts — have elevated access that can affect entire systems or large volumes of data. The CCCS recommends that organizations apply additional safeguards to these accounts because the consequences of their compromise are far greater than those of standard user accounts. Recommendations for privileged account management include: - Use separate accounts for administrative tasks — administrators should have a standard account for daily work (email, web browsing) and a separate privileged account used only for administrative tasks - Require multi-factor authentication (MFA) — all privileged accounts should require MFA, aligned with Baseline Control BC.5 (Authentication) - Limit the number of privileged accounts — only personnel who require administrative access for their job function should have it - Monitor privileged account activity — log and review actions taken by privileged accounts on a regular basis - Use time-limited privileges where possible — just-in-time access grants administrative privileges only for the duration needed to complete a specific task - Secure service accounts — service accounts used by applications should have strong, unique credentials that are rotated regularly and should not be used for interactive logins ### Offboarding Procedures When an employee leaves the organization — whether through resignation, termination, or contract completion — their access must be revoked promptly and completely. Delayed offboarding is a common and preventable security gap. A complete offboarding procedure should include: - Immediate account deactivation — disable the user's accounts on the same day they depart, or before if circumstances warrant it - Revoke all access — including email, VPN, cloud services, SaaS platforms, internal applications, physical access cards, and shared accounts - Recover company devices and media — collect laptops, phones, USB drives, and access tokens, aligned with Baseline Control BC.4 (Secure Configuration) - Change shared credentials — if the departing employee had access to any shared passwords or service accounts, change those credentials immediately - Transfer data ownership — reassign ownership of files, mailboxes, and accounts to the appropriate person - Document the offboarding — maintain a checklist and record of completion for each departing employee Organizations should establish a standardized offboarding checklist and ensure that HR and IT coordinate closely on every departure. ### Getting Started For Canadian small and medium organizations looking to strengthen access control, the CCCS Baseline Controls suggest focusing on these practical steps: - Inventory current access — document who has access to what systems, at what permission level - Implement least privilege — review and reduce permissions to the minimum required for each role - Define roles — create a simple set of roles based on job functions and assign users accordingly - Establish an offboarding checklist — ensure departing employees lose access on their last day - Schedule regular access reviews — set calendar reminders for quarterly privileged account reviews - Take the free cybersecurity assessment to evaluate your organization's posture across all 13 Baseline Controls ### Related Articles - Ransomware: What Canadian Businesses Need to Know — How least privilege limits lateral movement - Remote Work Security for Canadian Businesses - Why Your Business Needs an AI Usage Policy — Managing who can use AI tools with what data ### Frequently Asked Questions #### What is the difference between access control and authentication? Authentication (BC.5) verifies who a user is — confirming their identity through passwords, multi-factor authentication, or other credentials. Access control (BC.12) determines what an authenticated user is allowed to do — which systems, files, and functions they can access. Both controls work together: authentication confirms identity, and access control enforces permissions. #### How often should Canadian businesses review user access permissions? The CCCS recommends conducting access reviews on a regular basis. Many organizations perform quarterly reviews for privileged accounts and semi-annual reviews for standard user accounts. At a minimum, access should be reviewed whenever an employee changes roles and immediately upon departure from the organization. #### Do small businesses need role-based access control? Yes. Even small organizations benefit from role-based access control (RBAC). The CCCS Baseline Controls recommend that access be granted based on job function rather than on an individual basis. RBAC simplifies permission management, reduces errors, and makes it easier to conduct access reviews — regardless of organization size. ### Frequently Asked Questions — Access Control & Authorization Q: What is the difference between access control and authentication? A: Authentication (BC.5) verifies who a user is — confirming their identity through passwords, multi-factor authentication, or other credentials. Access control (BC.12) determines what an authenticated user is allowed to do — which systems, files, and functions they can access. Both controls work together: authentication confirms identity, and access control enforces permissions. Q: How often should Canadian businesses review user access permissions? A: The CCCS recommends conducting access reviews on a regular basis. Many organizations perform quarterly reviews for privileged accounts and semi-annual reviews for standard user accounts. At a minimum, access should be reviewed whenever an employee changes roles and immediately upon departure from the organization. Q: Do small businesses need role-based access control? A: Yes. Even small organizations benefit from role-based access control (RBAC). The CCCS Baseline Controls recommend that access be granted based on job function rather than on an individual basis. RBAC simplifies permission management, reduces errors, and makes it easier to conduct access reviews — regardless of organization size. --- ## BC.13 — Portable Media Security URL: https://cybersecuritycanada.ca/controls/portable-media/ Summary: What the Canadian Centre for Cyber Security recommends for portable media security. USB risks, removable media policies, encryption, and secure disposal for SMBs. ### What the Canadian Centre for Cyber Security Recommends The Canadian Centre for Cyber Security (CCCS) identifies portable media security as Baseline Control 13 (BC.13) in its Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089). Organizations should establish policies and technical controls governing the use of USB drives, external hard drives, SD cards, and other removable storage devices. Portable media introduces risks including malware infection, data theft, and unauthorized data transfer. Despite the growing use of cloud storage and email for file sharing, portable media remains common in many Canadian workplaces. USB drives are inexpensive, convenient, and easy to lose — making them a persistent security concern. The CCCS includes portable media security as a baseline control because the risks are significant and the mitigations are straightforward. ### USB Device Risks USB drives and other portable media pose several distinct security risks to organizations. Understanding these risks is the first step toward managing them effectively. #### Malware Introduction USB devices are a well-documented vector for malware. A USB drive used on an infected personal computer can carry malware into the corporate network when plugged into a work system. Some malware is specifically designed to spread via USB — copying itself onto any removable media connected to an infected machine. Attackers have also been known to leave infected USB drives in public places (parking lots, lobbies, conference venues) in the hope that someone will pick one up and plug it into a corporate computer. This technique, known as "USB baiting" or "USB drop attacks," exploits human curiosity and is referenced in cybersecurity awareness guidance from the CCCS. #### Data Loss and Theft USB drives are small enough to fit on a keychain, which makes them easy to lose, misplace, or steal. A single USB drive can hold gigabytes of sensitive data — customer records, financial documents, intellectual property, employee information — and if that drive is unencrypted, anyone who finds it can access the contents. #### Unauthorized Data Transfer Without controls in place, employees can use USB drives to copy large volumes of organizational data, whether intentionally or inadvertently. This creates risks related to data governance, privacy obligations under PIPEDA, and intellectual property protection. ### Removable Media Policies The CCCS recommends that organizations establish a written policy governing the use of portable media. A clear policy sets expectations for employees and provides a basis for technical controls and enforcement. An effective removable media policy should address: - Permitted use cases — define when and why portable media may be used (e.g., transferring files to air-gapped systems, providing materials to a client) - Approved device types — specify which devices are permitted and whether they must be company-issued - Data classification — identify what types of data may and may not be stored on portable media - Personal device restrictions — state whether personal USB drives and storage devices are permitted on organizational systems - Reporting requirements — require employees to report lost or stolen portable media immediately - Consequences — outline the consequences for policy violations The policy should be communicated to all employees during onboarding and reinforced through regular security awareness training (BC.6). ### Encryption Requirements Any portable media used to store organizational data should be encrypted. Encryption ensures that if the device is lost or stolen, the data on it cannot be accessed without the correct password or encryption key. Encryption options for portable media include: - Hardware-encrypted USB drives — these devices have encryption built into the hardware and require a PIN or password to unlock; they are the most secure option for portable storage - Software-based encryption — tools such as BitLocker To Go (Windows), FileVault (macOS), or VeraCrypt can encrypt USB drives and external hard drives - File-level encryption — individual files can be encrypted before copying them to portable media, though this is less reliable than full-device encryption because users may forget to encrypt individual files Organizations should standardize on an encryption method and ensure that all approved portable media devices are encrypted before use. Company-issued, pre-encrypted USB drives reduce the risk of employees using unencrypted personal devices. ### Disabling Autorun Autorun (also called AutoPlay) is a feature in operating systems that automatically executes programs or opens files when a USB device is connected. This feature has been exploited by malware to execute malicious code the moment a USB drive is inserted into a computer. The CCCS recommends disabling autorun on all organizational systems. This aligns with Baseline Control BC.4 (Secure Configuration). Specific steps include: - Disable autorun via Group Policy — in Windows environments, use Group Policy to disable autorun and autoplay for all removable media across the organization - Disable autorun on individual machines — for organizations without centralized management, autorun can be disabled in system settings on each computer - Apply to all media types — ensure autorun is disabled for USB drives, optical media, and network drives Disabling autorun is a simple configuration change that eliminates an entire category of USB-based attack. ### Approved Device Lists Organizations can limit which USB devices are permitted to connect to their systems by maintaining an approved device list. This is a technical control that complements the written removable media policy. Approaches to device management include: - Endpoint management software — tools such as Microsoft Intune, Jamf, or similar endpoint management platforms can restrict USB device connections to specific approved devices based on vendor ID, product ID, or serial number - USB device control policies — many anti-malware solutions (BC.3) include USB device control features that can block, allow, or monitor USB connections - Disabling USB storage ports entirely — for high-security environments or workstations where USB storage is not needed, USB mass storage can be disabled at the operating system level while keeping USB keyboards and mice functional - Read-only mode — some organizations allow USB devices to be read but not written to, preventing data from being copied out of the organization onto portable media The appropriate level of restriction depends on the organization's operations and risk tolerance. Some businesses may need USB access for daily operations; others may be able to eliminate it entirely. ### Secure Disposal When portable media reaches the end of its useful life — or when it has contained sensitive data that is no longer needed — it must be disposed of securely. Simply deleting files or formatting a USB drive does not reliably remove data; recovery tools can often restore deleted files from formatted media. Secure disposal methods include: - Cryptographic erasure — if the device was encrypted, destroying the encryption key renders the data unrecoverable - Overwriting — using specialized software to write random data over the entire storage area multiple times - Degaussing — using a strong magnetic field to erase magnetic media (effective for hard drives, not for flash-based USB drives) - Physical destruction — shredding, crushing, or incinerating the device; this is the most certain method and is recommended for media that contained highly sensitive data Organizations should document their disposal process and maintain records of when and how portable media was destroyed, particularly for media that contained personal information subject to PIPEDA. ### Getting Started For Canadian small and medium organizations looking to address portable media risks, the CCCS Baseline Controls suggest the following practical steps: - Write a removable media policy — even a one-page document that states what is and is not permitted - Disable autorun on all organizational computers - Issue encrypted USB drives — if USB use is required, provide company-issued encrypted devices and prohibit personal drives - Configure anti-malware to scan removable media — ensure that USB devices are automatically scanned when connected, aligned with Baseline Control BC.3 - Train employees — include portable media risks in your security awareness training program (BC.6) - Take the free cybersecurity assessment to evaluate your organization's posture across all 13 Baseline Controls ### Related Articles - USB Drives and Portable Media: The Security Risk in Your Desk Drawer - Employee Security Awareness Training: What Actually Works ### Frequently Asked Questions #### Should Canadian businesses ban USB drives entirely? Not necessarily. The CCCS Baseline Controls recommend that organizations establish a policy governing the use of portable media rather than requiring an outright ban. For some organizations, restricting USB use to approved, encrypted devices is more practical. Others may choose to disable USB storage ports entirely if portable media is not required for business operations. #### What types of portable media does this control cover? This control covers all forms of removable storage that can be connected to organizational systems. This includes USB flash drives, external hard drives, SD cards, optical media (CDs and DVDs), and any other device capable of storing and transferring data. The risks are similar across all types: data loss, data theft, and malware introduction. #### How should a small business dispose of old USB drives and external hard drives? The CCCS recommends secure disposal of portable media that has contained sensitive information. Simply deleting files or formatting the drive is not sufficient, as data can often be recovered. Organizations should use certified data destruction methods — such as cryptographic erasure, degaussing, or physical destruction — depending on the sensitivity of the data and the type of media. ### Frequently Asked Questions — Portable Media Security Q: Should Canadian businesses ban USB drives entirely? A: Not necessarily. The CCCS Baseline Controls recommend that organizations establish a policy governing the use of portable media rather than requiring an outright ban. For some organizations, restricting USB use to approved, encrypted devices is more practical. Others may choose to disable USB storage ports entirely if portable media is not required for business operations. Q: What types of portable media does this control cover? A: This control covers all forms of removable storage that can be connected to organizational systems. This includes USB flash drives, external hard drives, SD cards, optical media (CDs and DVDs), and any other device capable of storing and transferring data. The risks are similar across all types: data loss, data theft, and malware introduction. Q: How should a small business dispose of old USB drives and external hard drives? A: The CCCS recommends secure disposal of portable media that has contained sensitive information. Simply deleting files or formatting the drive is not sufficient, as data can often be recovered. Organizations should use certified data destruction methods — such as cryptographic erasure, degaussing, or physical destruction — depending on the sensitivity of the data and the type of media. --- # Articles Source: https://cybersecuritycanada.ca/news/ — 45 articles. ## Token Theft and AiTM Phishing: Why First-Generation MFA Is Failing Canadian Businesses URL: https://cybersecuritycanada.ca/news/posts/token-theft-and-aitm-phishing-why-first-generation-mfa-is-failing-canadian-businesses/ Category: Threats Published: August 6, 2026 Summary: Attackers no longer break multi-factor authentication — they wait for you to complete it and steal the session token instead. In April 2026 Microsoft documented a threat actor targeting Canadian employees specifically, redirecting salary deposits through hijacked Microsoft 365 sessions. Attackers targeting Canadian businesses have largely stopped trying to break multi-factor authentication. They wait for you to complete it, then steal the session token your identity provider hands back. The result is that an organization which deployed MFA in 2022 and assumes it is protected against phishing in 2026 is, in the median case, mistaken — and Canada is now being singled out for this specific attack. On April 9, 2026, Microsoft Threat Intelligence published an investigation into a financially motivated actor it designates Storm-2755, noting that "rather than focusing on a specific industry or organization, the actor relied exclusively on geographic targeting of Canadian users." The goal was not data. It was payroll: hijack a Microsoft 365 session, then quietly rewrite the employee's salary-deposit account. ### What token theft is, and why MFA does not stop it Session token theft is the theft of the cookie your identity provider issues after you sign in successfully, rather than the theft of your password. That cookie is proof of an already-authenticated session, so replaying it from the attacker's browser produces access with no password prompt and no MFA challenge. The token remains valid until it expires — by default, hours or days later. The delivery mechanism is adversary-in-the-middle (AiTM) phishing. The victim receives a phishing email and clicks through to what looks like a legitimate Microsoft 365 or Google Workspace login page. The page is actually a real-time reverse proxy operated by the attacker. When the victim enters their credentials and approves the MFA prompt, the proxy forwards both upstream to the real identity provider, which authenticates the session normally and issues a session cookie. The proxy captures that cookie and replays it. The critical point for business owners is that nothing was defeated. The password was correct. The MFA prompt was genuine and the user approved it legitimately. Every control worked exactly as designed, and the attacker is still logged in as the user. This is why "we have MFA" is no longer a sufficient answer, and why our guide to multi-factor authentication describes MFA as the floor rather than the ceiling. A second route to the same outcome is the infostealer ecosystem. Malware harvests saved passwords and live session tokens from infected browser profiles, packages them as "logs," and sells them on criminal marketplaces. Buyers replay the stolen cookies exactly as an AiTM proxy would, with the same result: authenticated access without ever engaging with the user's MFA. ### Canada was targeted specifically in the Storm-2755 campaign The Storm-2755 investigation is the clearest documented case of a financially motivated actor selecting victims by nationality rather than industry. Based on Microsoft's account, the chain ran as follows. - Malvertising and SEO poisoning. Storm-2755 positioned an actor-controlled domain (bluegraintours[.]com) at the top of search results for generic queries such as "Office 365" and common misspellings like "Office 265." Victims searching for their own webmail were led to the attacker's page. - AiTM credential and token capture. The fake sign-in page proxied the real Microsoft login. Microsoft notes victims saw a sign-in interrupt error (code 50199) at the point of compromise. - Token replay. In the compromised sessions, the session ID stayed consistent while the user-agent changed to Axios — an indication the token had been replayed rather than re-authenticated. Persistence showed up as non-interactive sign-ins to the OfficeHome application roughly every 30 minutes. - Silencing the victim. The actor created inbox rules to move messages containing the keywords "direct deposit" or "bank" out of the user's inbox, so HR's confirmation of a banking change would not be seen. - Redirecting the salary. Storm-2755 then either socially engineered the victim's HR or finance team into updating direct-deposit details, or signed in to Workday as the victim and changed the banking information directly — sending the next payroll deposit to an attacker-controlled account. Attribution during an active investigation should be read as an assessment rather than a certainty, and this account rests principally on Microsoft's own telemetry. What makes the campaign instructive is step four: the attack was not caught by a failed login, because there was no failed login. It was designed to be invisible in exactly the place a small business would look. That monetisation route — a hijacked mailbox used to redirect money — is the same pattern behind business email compromise, which remains the most costly single incident category at the small-business scale in Canada. ### How much of this is happening in Canada Canada-specific volume is documented, though incompletely. In its 2025 guidance publication ITSM.30.031 — Defending against adversary-in-the-middle threats with phishing-resistant multi-factor authentication, the Canadian Centre for Cyber Security reported detecting more than 100 AiTM phishing campaigns targeting Canadian Microsoft Entra ID tenants between 2023 and early 2025. That figure counts campaigns the Cyber Centre specifically attributed and tracked, not total national exposure, so it should be read as a floor. Global campaign data gives a sense of scale. Between April 14 and 16, 2026, Microsoft Defender observed a single coordinated AiTM campaign that reached more than 35,000 users across over 13,000 organizations in 26 countries, using "code of conduct" and HR-disciplinary lures impersonating internal compliance communications. Microsoft reports 92% of that activity was concentrated in the United States, so this campaign was not primarily Canadian — but the most-targeted sectors were healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%), all verticals with substantial Canadian SMB populations. The transferable lesson is the lure, not the geography: an HR-themed message about a conduct review is precisely the email an employee opens without thinking. ### Why the Tycoon 2FA takedown did not solve the problem What turned AiTM from a sophisticated technique into a commodity threat is that the tooling has been sold on subscription since 2023. On March 4, 2026, a Europol-coordinated operation with Microsoft and law-enforcement partners across six countries seized 330 domains underpinning Tycoon 2FA, the dominant AiTM phishing-as-a-service platform, which had been linked to more than 64,000 large-scale phishing attacks since 2023. Microsoft tracks the operators as Storm-1747 and had blocked roughly 13 million malicious emails tied to the service in October 2025 alone. It was a genuine success, and it did not last. Reporting on the aftermath found activity volumes fell to roughly 25% of pre-disruption levels on March 4 and 5, then returned to early-2026 levels within days, with no meaningful change in the operators' tactics — evidence the core service was never fully offline. Displaced affiliates also migrated to competing kits sold on Telegram for a few hundred dollars a month. The market has continued to add entrants since. Kali365, a phishing-as-a-service platform first observed in April 2026, became the subject of an FBI public service announcement on May 21, 2026, which warned that the Telegram-distributed kit enables threat actors to obtain Microsoft 365 access tokens and bypass MFA without intercepting the user's credentials at all. Reported features include AI-generated phishing lures, automated campaign templates, and OAuth token capture. For a Canadian small business the practical implication is uncomfortable but clear: this threat is not going to be arrested away. It has to be engineered out. ### Which MFA methods actually resist this The defence is well understood, already licensed in most Canadian SMBs' existing subscriptions, and unusually effective. The distinction that matters is phishing-resistant versus everything else. - Resistant: FIDO2 security keys and passkeys. The credential is cryptographically bound to the real site's domain, so it will not authenticate to an attacker's proxy — the authentication flow simply breaks. Microsoft's telemetry attributes over 99% prevention of identity-based attacks to phishing-resistant methods. The CCCS names FIDO/WebAuthn and PKI as the phishing-resistant options in its guidance, as does the equivalent guidance from CISA. - Not resistant: SMS and voice one-time passwords. Relayed straight through an AiTM proxy, and separately exposed to SIM-swapping. - Not resistant: authenticator app codes (TOTP). The user types the code into the proxy, which forwards it upstream. - Weak: push approvals without number matching. Vulnerable to relay and to MFA-fatigue prompting. Number matching helps, but does not make push phishing-resistant. Treat SMS and TOTP as transitional steps, not as the destination. The Canadian Centre for Cyber Security frames authentication as Baseline Control BC.5, and its AiTM guidance is explicit that phishing-resistant MFA continues to prevent these campaigns whether the attacker uses a traditional or a proxy-based kit. ### What Canadian businesses should do this quarter These steps are ordered by return on effort, and all five are available in Microsoft 365 Business Premium or Google Workspace Business without additional purchase. - Make passkeys or FIDO2 keys mandatory for the accounts that touch money. Administrators, finance, payroll, HR, and anyone who can change banking details. Not an option for those roles — a requirement. This is the single highest-value control on the list. - Shorten session token lifetimes for privileged roles from the default of days to hours, and require re-authentication on token age or a risk signal. A stolen token that expires in one hour is a much smaller problem than one valid for a week. - Bind sessions to managed devices and known locations with Conditional Access policies, and scope controls specifically over OAuth device-code sign-in flows, which are now a documented token-theft vector that phishing-resistant MFA alone does not fully close. - Alert on suspicious inbox-rule creation. Storm-2755's rules hiding "direct deposit" and "bank" messages are the detection opportunity most small businesses miss, and Microsoft names this alerting explicitly among its recommended mitigations. - Add an out-of-band verification step for payment and payroll changes. Any request to change banking or direct-deposit details gets confirmed by a phone call to a number already on file — never a number supplied in the request. This control costs nothing and defeats the entire monetisation step, which is why it belongs in your security awareness training as a documented procedure rather than a habit. Roll passkeys out to remaining staff over a defined period afterward. Attackers have shifted from exploiting software to exploiting sessions, which is the same lesson the Canada Life breach taught from a different direction: identity is now the perimeter. ### How to tell whether it has already happened Because the sign-in itself looks legitimate, login telemetry is usually the last place a compromise shows up. Most successful AiTM intrusions are first noticed through anomalous mailbox or business-system activity. The indicators worth checking now: - New MFA methods registered on user accounts that the user did not add - Inbox rules that forward, delete, or hide messages — particularly ones keyed to finance vocabulary - OAuth grants to applications nobody in the organization recognises - Payroll, banking, or direct-deposit changes made from unusual locations or at unusual hours - Sessions where the session ID stays constant but the user-agent changes, or repeated non-interactive sign-ins on a fixed interval If you suspect a session has been hijacked, revoking active sessions and tokens matters more than resetting the password. A password reset alone does not invalidate a stolen session cookie, which means the attacker keeps their access while you believe you have removed it. Remove malicious inbox rules, reset MFA methods for the affected accounts, and then work through your incident response plan. For the wider Canadian threat picture, including how identity attacks compare against ransomware and fraud losses, see The Cybersecurity Canada Report 2026. If you are not certain where your organization stands on authentication and access, our free cybersecurity assessment evaluates you against all 13 Baseline Controls in under 30 minutes, without collecting your data. MFA has become table stakes rather than a differentiator. The businesses that stay ahead of token theft in 2026 are the ones that stopped asking whether they have MFA and started asking which kind. ### Frequently Asked Questions — Token Theft and AiTM Phishing: Why First-Generation MFA Is Failing Canadian Businesses Q: What is session token theft? A: Session token theft is an attack in which a criminal steals the session cookie your identity provider issues after you successfully sign in, rather than stealing your password. Because the token represents an already-authenticated session, replaying it from the attacker's browser grants access without any password or MFA prompt. The token stays valid until it expires — by default, hours or days later. Q: Does multi-factor authentication still stop phishing in 2026? A: It depends entirely on which kind of MFA you use. SMS codes, voice one-time passwords, authenticator app codes, and push prompts without number matching are all defeated by adversary-in-the-middle phishing, because the attacker simply relays whatever you enter to the real login page and takes the resulting session token. Phishing-resistant MFA — FIDO2 security keys and passkeys — is not defeated this way, because the credential is cryptographically bound to the real site's domain and will not authenticate to a proxy. Q: What is AiTM phishing? A: Adversary-in-the-middle (AiTM) phishing puts an attacker-controlled reverse proxy between the victim and the genuine login page. The victim sees what looks like a real Microsoft 365 or Google Workspace sign-in screen, enters their password, and approves the MFA prompt. The proxy passes everything upstream to the real identity provider in real time, so authentication succeeds — and captures the session cookie the provider issues back. Q: Is Canada being targeted specifically? A: In at least one documented case, yes. On April 9, 2026 Microsoft Threat Intelligence published an investigation into an actor it designates Storm-2755, stating that "rather than focusing on a specific industry or organization, the actor relied exclusively on geographic targeting of Canadian users." Separately, the Canadian Centre for Cyber Security reported detecting more than 100 AiTM phishing campaigns against Canadian Microsoft Entra ID tenants between 2023 and early 2025. Q: What is a payroll pirate attack? A: Payroll pirate is the term Microsoft uses for an attack that monetises a hijacked email session by redirecting the victim's salary. After replaying a stolen session token, Storm-2755 either socially engineered the victim's HR or finance team into changing direct-deposit details, or signed in to Workday as the victim and changed the banking information directly. It also created inbox rules to move messages containing the keywords "direct deposit" or "bank" out of sight, so the employee would not see HR's confirmation. Q: Did the Tycoon 2FA takedown reduce AiTM phishing? A: Not durably. On March 4, 2026 a Europol-coordinated operation with Microsoft seized 330 domains underpinning Tycoon 2FA, the dominant AiTM phishing-as-a-service kit, which had been linked to more than 64,000 phishing attacks since 2023. Reporting on the aftermath found activity dropped to roughly 25% of pre-disruption levels on March 4 and 5, then returned to early-2026 levels within days, with no meaningful change in tactics. A newer kit, Kali365, was the subject of an FBI public service announcement on May 21, 2026. Q: What should a Canadian small business do first? A: Make phishing-resistant MFA — passkeys or FIDO2 security keys — a hard requirement for administrator, finance, payroll, and HR accounts, which is where the money is. Then shorten session token lifetimes for privileged roles from the default of days to hours, require re-authentication on risk signals, restrict OAuth device-code sign-in flows, and set up alerting on suspicious inbox-rule creation. On Microsoft 365 Business Premium or Google Workspace Business these controls are already included in your licence. Q: How do I know if a session token has already been stolen? A: Most successful AiTM intrusions are detected through anomalous mailbox or HR-system activity rather than login telemetry, because the sign-in itself looks legitimate. Watch for new MFA methods added to accounts, inbox rules that forward or hide messages, OAuth grants to unfamiliar applications, changes to payroll or banking details from unusual locations, and sign-ins that keep the same session ID while the user-agent changes. If you suspect a compromise, revoking sessions and tokens matters more than resetting the password. --- ## Frontier AI and Cyber Security: What Canada's Cyber Centre Wants Businesses to Do Now URL: https://cybersecuritycanada.ca/news/posts/frontier-ai-cyber-security-cyber-centre-statement/ Category: Insights Published: June 25, 2026 Summary: On June 24, 2026, the Canadian Centre for Cyber Security warned that frontier AI is shrinking the time defenders have to respond — from days or weeks to hours. Here's what the statement means for Canadian businesses. On June 24, 2026, the Canadian Centre for Cyber Security (Cyber Centre) — the operational arm of the Communications Security Establishment (CSE) — issued a public statement urging every organization in Canada to strengthen its cyber defences now, before AI-enabled attacks outpace them. The headline figure: frontier AI is helping attackers find and exploit weaknesses so quickly that the window defenders have to respond is collapsing "in some cases from days or weeks to hours." The statement follows a joint warning from the leaders of the Five Eyes cyber security agencies, and it lands a specific message on Canadian decision-makers: this is a leadership problem, not just an IT problem. "Strengthening cyber resilience requires sustained leadership attention, not just IT action," the Cyber Centre writes. This post translates the statement for Canadian small and medium-sized business owners and executives — what frontier AI actually changes, and the eight concrete steps the Cyber Centre is asking you to take. ### What Did the Cyber Centre Actually Say About Frontier AI? The Cyber Centre's core claim is that frontier AI — the most recent and capable AI models — is reshaping the cyber threat landscape fast enough to demand action now, not later. According to the statement, these models help threat actors find and exploit vulnerabilities, including software flaws and weaknesses in security controls, far faster than before. That compresses the defender's response window from days or weeks down to hours and raises the odds that an attack succeeds. Two of the Cyber Centre's own assessments — the National Cyber Threat Assessment 2025-2026 and the Ransomware Threat Outlook 2025-2027 — conclude that AI is also lowering the barrier to entry for cybercrime. In plain terms, attacks that once required skill and time are becoming cheaper, faster, and available to less capable actors. The statement is signed by Rajiv Gupta, Head of the Canadian Centre for Cyber Security, who frames strong cyber hygiene as "your most powerful and effective advantage in a rapidly evolving threat landscape." ### How Are Attackers Already Using AI? The Cyber Centre is specific that this is not a future risk — threat actors are using AI today. The statement names three patterns Canadian businesses are already exposed to, plus a set of risks that originate inside the organization. - Faster, more convincing social engineering. AI is being used to produce phishing emails, vishing (voice scam) calls, and deepfake impersonation that are more convincing, produced faster, and deployed at greater scale. Our breakdown of AI-powered phishing covers why the old "look for spelling mistakes" advice no longer holds. - Vulnerability chaining. AI helps attackers find and combine multiple smaller weaknesses into a single working attack path — a technique the Cyber Centre calls vulnerability chaining. - Lower skill required. AI makes it easier for less-skilled actors to carry out more sophisticated attacks than they could on their own, which expands the pool of people who can hurt you. The statement also flags risks that come from inside the business: unapproved use of AI tools (often called shadow AI), exposure of sensitive data through those tools, and the danger of relying on AI outputs that are inaccurate or have been deliberately manipulated. This is exactly the gap a clear AI usage policy is meant to close. ### Why Is This a Leadership Issue and Not Just an IT Problem? The Cyber Centre is deliberate in addressing leaders rather than technical teams, because the consequences of an AI-enabled incident land on the business, not just the IT department. The statement warns that these incidents can disrupt operations, expose sensitive data, damage trust, and create financial and regulatory risk — outcomes a CIO cannot own alone. There is also an upside the statement asks leaders to act on: the same technology works for defenders. The Cyber Centre encourages organizations to use AI to identify exposures earlier, test their controls, and improve response times — including building AI into software development so vulnerabilities are caught earlier in the lifecycle. The framing is even-handed: frontier AI is a threat you must defend against and a tool you can defend with, and deciding how your organization does both is a leadership call. ### The Eight Cyber Hygiene Actions the Cyber Centre Recommends The most practical part of the statement is a checklist. The Cyber Centre's position is that no single measure eliminates risk, but organizations with strong cyber hygiene are "significantly more resilient, even as threats evolve." Here are the eight actions it asks every Canadian organization to take, with where each maps onto Canada's 13 Baseline Controls. - Apply security patches promptly and keep systems up to date. When AI shortens the time between a flaw being disclosed and exploited, unpatched systems become the easiest target. See patch management. - Limit internet exposure and reduce your attack surface. Every service exposed to the internet is something AI-assisted scanning can find faster than ever. - Implement strong authentication, including phishing-resistant multi-factor authentication. Multi-factor authentication remains the single highest-value control most SMBs can add; the Cyber Centre specifically calls for the phishing-resistant kind. See authentication. - Centralize logs across systems so unusual activity can be detected sooner — part of network security. - Separate key systems (segmentation) so an attack is easier to contain and less likely to spread. - Address unsupported or legacy systems, which cannot receive the patches that step 1 depends on. - Test your incident response plans and plan for containment and recovery. If you do not have a plan yet, start with our guide to building an incident response plan and the broader incident response control. - Build internal awareness and clear guidance on appropriate, responsible use of AI tools — including how staff handle sensitive information. The Cyber Centre adds a supply-chain note that matters for almost every SMB: if you rely on third-party providers, make sure they apply strong security too, because "cyber resilience is a shared responsibility that extends across the entire supply chain." Our piece on vendor and third-party risk walks through how to assess a supplier without a procurement team. ### What Is Project Glasswing, and Why Does the Statement Mention It? The statement notes that the Cyber Centre engages directly with industry — including AI vendors — to track how frontier AI is evolving, and cites its participation in Project Glasswing as an example. Project Glasswing is one of the initiatives through which Canadian agencies and AI developers share information about how advanced models could be misused and how to defend against it. We covered the background in Claude, Mythos and Project Glasswing. For a business owner, the takeaway is simply that the threat picture here is being shaped by direct collaboration between government and frontier AI labs — which is also why the Cyber Centre's guidance on this topic is likely to keep changing. ### What Should a Canadian SMB Do This Quarter? For a small or medium-sized business without a dedicated security team, the statement is less about new spending and more about reinforcing fundamentals before the threat curve steepens. A reasonable 90-day response looks like this: - Run the eight-point hygiene checklist as an audit. Score yourself honestly on each item; the gaps are your roadmap. - Make MFA phishing-resistant where you can. Prioritize email, banking, and remote-access accounts first. - Write or update an AI usage policy. Decide which AI tools staff may use, what data must never be pasted into them, and who approves new ones — closing the shadow-AI and data-exposure risks the statement names. - Tabletop one ransomware scenario. Walk through who does what in the first hour, given that the response window is now measured in hours. - Ask your top three vendors one question: "What are you doing about AI-enabled threats?" Their answer tells you a lot about your own exposure. The Cyber Centre also points organizations to its Top 10 IT security actions and Top 10 artificial intelligence security actions (ITSAP.10.049) for prioritized, free guidance, and urges early reporting of suspected incidents so threats can be assessed and contained faster. If you are not sure where your organization stands today, our free cybersecurity assessment walks through all 13 Baseline Control areas in about 10 minutes and produces a prioritized list of gaps — which is effectively the same eight-point hygiene audit the Cyber Centre is asking you to run, mapped to the Canadian framework. ### Frequently Asked Questions #### Who issued the frontier AI statement, and when? The Canadian Centre for Cyber Security, part of the Communications Security Establishment (CSE), published the statement on June 24, 2026, from Ottawa. It followed a joint statement by the leaders of the Five Eyes cyber security agencies and was issued under Rajiv Gupta, Head of the Cyber Centre. #### What does "frontier AI" mean in this context? Frontier AI refers to the most recent and most capable AI models. The Cyber Centre's concern is that as these models become more powerful and more widely available, they help attackers find and exploit weaknesses much faster — while also being usable by defenders to find and fix those weaknesses earlier. #### Does this mean my small business is now a target? The statement's central warning is that AI lowers the barrier to entry for cybercrime, which generally widens the pool of potential targets rather than narrowing it to large enterprises. The Cyber Centre's recommended response — strong, basic cyber hygiene — is squarely within reach of a small or medium-sized business and does not require advanced tooling. #### Is AI only a threat, or can it help defend my business? Both. The Cyber Centre explicitly encourages organizations to use AI defensively — to identify exposures earlier, test security controls, improve response times, and catch vulnerabilities earlier in software development. The statement frames how you balance defending against AI-enabled threats and defending with AI as a leadership decision. #### Where can I read the original statement? The full statement is published on Canada.ca under the Communications Security Establishment, titled "Statement from the Canadian Centre for Cyber Security on frontier artificial intelligence models and their impact on cyber security," dated June 24, 2026. --- ## Amazon Prime Day Scams: How Canadians Can Shop Safely During the June 23–26 Sale URL: https://cybersecuritycanada.ca/news/posts/amazon-prime-day-scams-how-canadians-can-shop-safely/ Category: Best Practices Published: June 20, 2026 Summary: Amazon Prime Day runs June 23–26, 2026, and fraudsters are already registering thousands of fake Amazon sites. Here's how Canadians and their employees can spot Prime Day scams before they hand over a password or a card number. Amazon Prime Day 2026 runs June 23 through June 26 — a four-day sale across 26 countries, and one of the busiest online shopping windows of the year. It is also one of the most reliable windows for fraud. Ahead of the 2025 event, Check Point Research found that more than 1,000 new web domains using Amazon's name appeared in a single month, and 87 percent of them were flagged as malicious or suspicious. Separately, researchers at NordVPN counted over 120,000 fake sites impersonating Amazon in a two-month span — roughly 92,000 built to steal logins, 21,000 to deliver malware, and 11,000 to sell goods that never ship. The lure is simple: shoppers expect a flood of "your order," "refund," and "delivery" messages during a sale, so a fake one blends in. For Canadians, the stakes are real. The Canadian Anti-Fraud Centre says Canadians lost a record $704 million to fraud in 2025, and that figure reflects only the 5 to 10 percent of cases that get reported. This post is a plain-language guide to the Prime Day scams you and your staff will actually see between June 23 and 26 — and the handful of habits that defeat almost all of them. ### What Are the Most Common Amazon Prime Day Scams? The most common Prime Day scams are fake order or refund notifications, "your account is suspended" messages, fake delivery alerts, and lookalike Amazon websites — all designed to capture your Amazon password or your payment card. They arrive by email, text, and phone, and they spike sharply during the sale because a single fraudulent message hides easily among the legitimate ones a shopper is already expecting. The four patterns to know: - Fake order and refund alerts. An email or text says there's a problem with an order you didn't place, or that you're owed a refund. Check Point intercepted a 2025 campaign using the subject line "Refund Due – Amazon System Error." The goal is to make you click to "fix" or "claim" something. - "Your Prime membership has expired." A message warns that your membership lapsed and payment failed, with a button to "update your billing." The page that opens is a copy of the Amazon sign-in screen built to harvest your credentials and card. - Fake delivery problems. A text claims a parcel couldn't be delivered and a small fee or address confirmation is needed — the same playbook as the Canada Post smishing scams Canadians see year-round, re-skinned with Amazon branding. - Lookalike deal sites. A search ad or social post promotes an unbeatable Prime Day price on a popular product, leading to a domain like amazon-deals-ca.shop that takes your card details and delivers nothing. ### How Can You Tell a Real Amazon Message From a Fake One? You can tell most fakes apart by ignoring the message itself and checking your account directly. Real Amazon order, refund, and delivery information always appears inside your account when you open the Amazon app or type amazon.ca into your browser yourself. If a notice exists only in an email, text, or call — and not in your account — it is not real. A few reliable tells, since attackers are good at copying the rest: - Urgency and threats. "Your account will be closed in 24 hours," "act now," "your order will be cancelled." Real retailers do not threaten you into clicking. - Requests for payment by gift card, e-Transfer, or crypto. Amazon never asks you to settle an account problem with Amazon gift cards. A request to "verify" your account by buying gift cards is always a scam. - Links that don't go to amazon.ca or amazon.com. Hover over (or long-press) a link before tapping. amazon.account-verify.com and amzn-ca-secure.net are not Amazon. The real domain comes before the final slash. - Requests for your password, full card number, SIN, or one-time code. Amazon will never call, text, or email asking you to read back a verification code or confirm your full card number. For a deeper checklist of the behavioural red flags that apply to any phishing message, see our guide to recognizing phishing emails. ### Why Prime Day Scams Are a Business Problem, Not Just a Personal One Prime Day scams matter to employers because employees shop on the same phones and laptops they use for work. A staff member who enters their Amazon password on a fake site during a lunch-break deal hunt has just handed an attacker a working credential — and most people reuse passwords, so that same email-and-password pair may unlock the company email, payroll portal, or cloud accounts. That is exactly how a personal-life scam becomes a business email compromise or a ransomware foothold. The mitigations are the same ones the Canadian Centre for Cyber Security's baseline controls already ask of every Canadian business: unique passwords, multi-factor authentication, and staff who know what a lure looks like. A short, timely reminder to your team the week before June 23 costs nothing and closes the most common door. ### Seven Habits That Defeat Almost Every Prime Day Scam The defence is procedural, not visual — by the time you're studying a logo, the attacker is already winning. These seven habits hold up across every variant: - Never click a link in an order, refund, or delivery message. Open the Amazon app or type the address yourself and check from there. - Turn on multi-factor authentication (Amazon calls it Two-Step Verification) on your account. If your password is phished, MFA is what stops it being used. - Use a unique password for Amazon. A password manager makes this painless and means a leak on one site can't unlock the rest. - Pay with a credit card, not a debit card or e-Transfer. Credit cards offer the strongest fraud chargeback protection in Canada. - Be suspicious of any "deal" that arrives by ad, DM, or text rather than from Amazon's own site. If the price is impossible, the site usually is too. - Never buy gift cards to "resolve" an account or tax issue. No legitimate company or government agency is paid in gift cards. - Slow down. Urgency is the scammer's only real weapon. A 30-second pause to log in directly defeats almost all of these schemes. ### How to Report an Amazon Prime Day Scam in Canada Reporting is quick and genuinely useful — it feeds the intelligence police, banks, and Amazon use to take fraudulent sites down. If you receive a suspicious Amazon message: - Forward phishing emails to Amazon at reportascam@amazon.com (or stop-spoofing@amazon.com), and report through Amazon's Report a scam page. - Report to the Canadian Anti-Fraud Centre at 1-888-495-8501 or online at reportcyberandfraud.canada.ca, whether or not you lost money. - If you entered your password, change it immediately, turn on Two-Step Verification, and change it anywhere else you reused it. - If you entered card details, call your bank or card issuer right away to flag the card and watch for unauthorized charges. For employees, treat a credential entered on a fake site as a workplace incident, not just a personal mistake — tell IT so business passwords can be reset before an attacker uses them. ### Where This Fits in Your Cybersecurity Program Prime Day scam defence sits inside two of the Canadian Centre for Cyber Security's 13 baseline controls: security awareness training and authentication. A team that recognizes lures and accounts protected by MFA will absorb a seasonal scam surge that would otherwise turn into stolen credentials. If you want a quick read on where your business stands across all 13 areas, the free cybersecurity assessment takes about twenty minutes and produces a written report tied to the baseline controls. ### Frequently Asked Questions #### When is Amazon Prime Day 2026? Amazon Prime Day 2026 runs from June 23 to June 26 — a four-day event in 26 countries, including Canada. It is earlier than in recent years, when the sale was held in July. Because the dates are public and heavily promoted, fraudsters time their fake-site and phishing campaigns to the same window, so the safest assumption is that scam volume is highest during and just before the sale. #### Does Amazon call or text customers about account problems? Amazon does not call, text, or email asking you to confirm your password, read back a one-time verification code, or pay to "reactivate" your account. Real order, refund, delivery, and membership details always appear inside your Amazon account when you open the app or go to amazon.ca yourself. Any message that exists only in your inbox or as a text — and not in your account — should be treated as fraudulent. #### Is it safe to click Prime Day deal links from ads or social media? Treat them with caution. Many Prime Day scams use search ads, social posts, and direct messages that lead to lookalike sites built to capture your card details. The safer habit is to ignore the link and search for the product inside the Amazon app or on amazon.ca directly. A deal that only exists through an unfamiliar link or an unbelievable price is the most common Prime Day trap. #### What should I do if I entered my Amazon password on a fake site? Change your Amazon password immediately and turn on Two-Step Verification. Because most people reuse passwords, change it anywhere else you used the same one — especially your email and any work accounts. If you entered card details, contact your bank right away. Then report the scam to Amazon and the Canadian Anti-Fraud Centre. If it happened on a work device or with a work account, tell your IT or security contact so business credentials can be reset. #### How can employers protect their business during Prime Day? Send staff a brief reminder before June 23 that Prime Day scams are circulating, require multi-factor authentication on business accounts, and encourage unique passwords through a password manager. These steps stop a phished personal credential from becoming a business breach. They are also part of the broader security awareness training and authentication controls every Canadian SMB should already have in place. --- ## Anthropic's Call for a Global AI Pause: What It Means for Canadian Businesses URL: https://cybersecuritycanada.ca/news/posts/anthropic-global-ai-pause-what-it-means-for-canadian-businesses/ Category: Insights Published: June 6, 2026 Summary: On June 4, 2026, Anthropic — valued near $1 trillion — urged a coordinated global pause on frontier AI development, warning models may soon improve themselves without humans. Here's what it means for Canadian businesses. On June 4, 2026, Anthropic — the AI lab behind Claude, now valued at close to $1 trillion — published a proposal through its Anthropic Institute calling for a coordinated global slowdown, or outright pause, in frontier AI development. The reason: the company believes AI systems may soon be able to improve themselves without meaningful human involvement, a milestone it calls recursive self-improvement. When the company building one of the world's most capable models asks the industry to consider tapping the brakes, it is worth Canadian business owners understanding why — and what, if anything, it changes for them. This is an unusual moment. The warning is not coming from outside critics or regulators; it is coming from a leading developer about its own technology. This post explains what Anthropic actually said, the risks it is flagging, and what the news does and does not mean for Canadian businesses already using AI. ### What Did Anthropic Actually Announce? Anthropic asked frontier AI developers to prepare for a coordinated pause or slowdown, warning that AI is now fast enough at building AI that the industry lacks a reliable way to stop. In its June 4, 2026 publication, the company reported that more than 80% of the code merged into its own codebase is now written by Claude, and that its engineers ship roughly eight times as much code per quarter as in prior years. The concern is the trajectory: if an AI system can autonomously design, build, and train its own successor, development could accelerate beyond human oversight. Co-founder Jack Clark framed the problem as an industry with an accelerator but no brake pedal and, as reported by CNN, compared the coordination challenge to Cold War nuclear arms control, where rival powers had to cooperate on verification despite deep mistrust. Anthropic says the Anthropic Institute will research the technical systems a credible pause would require: ways for one developer to verify that competitors have genuinely slowed, so that no "bad actor" can quietly race ahead under the cover of a coordinated halt. Anthropic itself acknowledges that a unilateral pause by a single lab would only change who leads the race, not solve the underlying problem. ### What Is Recursive Self-Improvement, in Plain Terms? Recursive self-improvement is when an AI system becomes capable of designing and building a more capable version of itself, with little or no human direction. Today, humans design each new model. The worry Anthropic raises is a future in which the AI does that design work itself, each generation producing a smarter successor faster than people can review it. Anthropic is clear that this capability has not been achieved and that, used well, self-improving AI could deliver enormous benefits in science, medicine, and productivity. The flagged risk is one of control: if systems advance without humans able to follow the reasoning or intervene, organizations lose the ability to predict, audit, or correct what the technology does. For a business, "losing the thread" of how an automated system reaches its decisions is a familiar governance problem — just at an unfamiliar scale. ### Does This Change Anything for Canadian Businesses Right Now? For day-to-day operations, no — this is a long-horizon policy debate, not an emergency. No Canadian regulator has changed any rule, and the AI tools your business uses today work exactly as they did last week. The practical near-term risk for most Canadian small and medium-sized businesses is not a runaway superintelligence; it is the much more ordinary problem of adopting powerful AI faster than you put governance around it. That distinction matters. The headline risk Anthropic describes is industry-wide and years out. The risks that will actually affect a Canadian business this year are concrete and manageable: staff pasting confidential client data into public chatbots, AI-written content going out unchecked, autonomous "agentic" tools being given more access than they need, and AI-powered phishing that is far harder to spot than the clumsy scams of a few years ago. Treating the Anthropic news as a prompt to get those basics right is the most useful response available to a business owner. ### What Should Canadian Businesses Take From This? The signal to take from Anthropic's announcement is governance, not alarm: match the autonomy and access you grant AI to the controls you have around it. The same principle Canada's Cyber Centre applies to AI agents applies to the AI your business already runs. A few practical steps put you on solid footing regardless of how the bigger debate plays out. - Write down where AI is allowed — and where it isn't. A short, clear AI usage policy is the single highest-value step for most organizations. It tells staff what tools are approved, what data must never be entered into them, and who signs off on AI-assisted decisions that affect customers or money. - Inventory the AI you already have. Many SaaS products quietly added AI and autonomous "agent" features in 2025 and 2026. Treat each one as a system that needs a privilege review, not a free upgrade. Our guide to agentic AI security for Canadian businesses walks through what to check. - Keep a human in the loop for anything that spends money, sends communications, or touches personal information. Autonomy is fine for low-risk, reversible tasks. It is not appropriate for actions you could not easily undo. - Train your team. Most AI risk enters a business through everyday use, so security awareness training that covers AI tools, data handling, and AI-enhanced scams pays for itself quickly. - Build the basics first. Adding AI on top of weak fundamentals magnifies the risk. The Cyber Centre's 13 Baseline Controls — strong authentication, patching, backups, and a tested incident response plan — are the foundation any AI adoption should sit on. ### What to Expect Next Expect more debate than action in the short term. Coordinated slowdowns require verification systems and international agreement that, by Anthropic's own account, historically took decades to build — and competitors have not all endorsed the call. For Canadian businesses, the realistic expectation is a continued stream of guidance rather than sudden new obligations. Canada's Cyber Centre has already published its Top 10 AI security actions (ITSAP.10.049) and joint Five Eyes guidance on AI agents; further direction is likely as the technology matures and as Bill C-26 obligations come into force. The steadiest position is the one Cybersecurity Canada recommends for almost every emerging-technology story: adopt the tools that help your business, but put the same discipline around AI that you would around any other system with access to your data and your money. The companies that handle the next few years well will be the ones that paired enthusiasm for AI with a clear policy, a real inventory, and solid cyber hygiene underneath. If you are unsure where your organization stands, our free cybersecurity assessment covers all 13 Baseline Control areas in about 10 minutes and produces a prioritised list of gaps — a sensible first step before expanding how much your business relies on AI. ### Frequently Asked Questions #### Is Anthropic shutting down or pausing Claude? No. Anthropic continues to operate and develop Claude. Its June 4, 2026 proposal calls for the broader industry to prepare for a coordinated slowdown of frontier development and to build systems that could verify such a pause — it is not an announcement that Anthropic is stopping its own products or services. #### Should Canadian businesses stop using AI because of this warning? No. Anthropic's concern is about a future capability — AI improving itself without human oversight — not about the everyday AI tools businesses use today. The sensible response is stronger governance: an AI usage policy, an inventory of the AI features already in your software, human approval for high-impact actions, and solid cyber hygiene underneath. #### What is recursive self-improvement? Recursive self-improvement is when an AI system can autonomously design and build a more capable version of itself, generation after generation, without humans directing each step. Anthropic says this has not happened yet but warns it could arrive sooner than most institutions are prepared for, raising the risk of humans losing the ability to oversee or control the systems. #### Does this create any new legal obligations in Canada? No new rules have been introduced as a result of Anthropic's announcement. Canadian businesses remain governed by existing frameworks such as PIPEDA and the forthcoming Bill C-26 regime. This guidance is informational and is not legal or compliance advice; consult a qualified professional for your specific obligations. --- ## The Cybersecurity Canada Report 2026: Seven Findings Canadian SMBs Should Know URL: https://cybersecuritycanada.ca/news/posts/cybersecurity-canada-report-2026-key-findings/ Category: Insights Published: May 24, 2026 Updated: May 24, 2026 Summary: Canadians lost a record CA$704M to fraud in 2025. Microsoft documented a threat actor specifically targeting Canadians. Mandiant says attackers now hand off compromised access in 22 seconds. Seven findings from the inaugural Cybersecurity Canada Report. We've published the first edition of the Cybersecurity Canada Report 2026 — a synthesis of the most recent verifiable public data on the state of cybersecurity for Canadian small and medium businesses, drawing on Statistics Canada, the Canadian Centre for Cyber Security, Mandiant, Verizon, CrowdStrike, IBM, Sophos, Microsoft Threat Intelligence, the Office of the Privacy Commissioner, and the Canadian Anti-Fraud Centre. Here are the seven findings that should shape decisions in 2026. ### Canadians lost a record CA$704 million to fraud in 2025. The Canadian Anti-Fraud Centre's 2025 annual statistics, released March 2026, recorded CA$704 million in reported fraud losses — the highest year on record, up from CA$645 million in 2024. Investment fraud led at CA$351 million; romance and relationship scams over CA$63.3 million; job scams over CA$50.6 million. The CAFC reiterates that only 5-10% of victims report, so the true national figure is likely between CA$3.5 billion and CA$7 billion. For Canadian SMBs specifically, business email compromise (BEC) remains the most expensive single incident type — an executive impersonation email redirecting a wire transfer can cost more than any other event at the business's scale. The federal government launched public consultations on Canada's first-ever National Anti-Fraud Strategy in March 2026. ### Identity is now the breach surface. Sophos's 2026 State of Identity Security finds 71% of organizations suffered an identity-related breach in the past year. Its Active Adversary Report 2026 finds 67% of all investigated incidents in 2025 were rooted in identity attacks — a higher figure than ransomware, vulnerability exploitation, or any other category. Of ransomware victims specifically, 67% confirmed their incident stemmed from an identity attack. Verizon's 2026 DBIR records that, for the first time in 19 editions, vulnerability exploitation overtook stolen credentials as the #1 initial-access vector — but credential abuse remains a close second, ransomware grew to 48% of all breaches, and third-party / supply-chain breaches were up 60% year-over-year. The picture is consistent: identity controls and patch management are now both top-tier priorities. ### The threat landscape now moves in seconds, not days. Mandiant's M-Trends 2026 reports the median time between initial access and handoff to a secondary threat group has collapsed from 8+ hours in 2022 to 22 seconds in 2025. CrowdStrike's 2026 Global Threat Report finds the average eCrime breakout time fell to 29 minutes, with the fastest observed at 27 seconds. There is no human-paced response time that fits inside that window. What matters is automated detection, pre-emptive control, and the policies that prevent the credential or session from being usable in the first place. ### Canadians are being specifically targeted — meet Storm-2755. In April 2026, Microsoft Threat Intelligence published a case study on a financially motivated threat actor it designates Storm-2755, notable for geo-targeting Canadian users specifically — not by industry but by country. The attack chain: malvertising and SEO poisoning on Microsoft 365 sign-in search terms drives Canadian victims to adversary-in-the-middle (AiTM) phishing pages. The AiTM proxy steals the user's authenticated session token. The attacker then either socially engineers the victim's HR or finance team ("Question about direct deposit") or logs directly into Workday and rewrites the victim's salary-deposit account. This is the first Microsoft-attributed financially motivated threat actor whose primary victim-selection criterion is "Canadian." The Canadian Centre for Cyber Security separately reported in its 2025 ITSM.30.031 guidance that it detected more than 100 AiTM phishing campaigns against Canadian Microsoft Entra tenants between 2023 and early 2025. ### The PhaaS economy fragmented — and attack volume rose. On March 4, 2026, a Microsoft and Europol-led coalition seized 330 active domains of Tycoon 2FA, the dominant phishing-as-a-service kit for AiTM attacks against Microsoft 365 (pre-takedown: ~62% of phishing attempts across the four major PhaaS platforms; used in attacks against ~500,000 organizations since 2023). Microsoft tracks the operators as Storm-1747. The takedown did not reduce PhaaS attack volume. Within weeks, Barracuda recorded total volume across the four remaining major kits rising from approximately 20 million to over 23 million phishing attempts as operators and affiliates migrated to Mamba 2FA, EvilProxy, Sneaky 2FA, and a new entrant: Whisper 2FA (Barracuda was attributing roughly 1 million attempts per month to Whisper by October 2025; the kit uses AJAX to capture credentials and MFA codes until obtaining a valid session). Tycoon 2FA itself did not disappear — eSentire's TRU team documented Tycoon variants in late April 2026 pivoting to abuse the OAuth Device Authorization Grant flow, a technique that even FIDO2 passkeys do not fully prevent without correctly tuned Conditional Access. Traditional MFA (SMS, TOTP, push prompt) is not reliable against any of these kits. Phishing-resistant MFA — FIDO2 security keys and passkeys — blocks over 99% of identity attacks per Microsoft's Digital Defense Report. The FIDO Alliance reports 5 billion passkeys in use globally as of World Passkey Day (May 6, 2026), with 68% of mid-to-large organizations deploying. ### Bill C-8 has finally moved. After Bill C-26 died on prorogation in January 2025, its reboot Bill C-8 passed Third Reading in the House of Commons on March 26, 2026 and received Senate First Reading the same day — further than C-26 ever advanced. Bill C-8 applies to federally regulated critical-infrastructure operators (telecommunications, pipelines, electricity, nuclear, transport, banking, clearing and settlement), with obligations including a cybersecurity program within 90 days of designation, 72-hour incident reporting to CSE, Canadian-resident records, and third-party / supply-chain risk management. Administrative monetary penalties run up to CA$10 million per violation per day for corporations, rising to CA$15 million per day for subsequent contraventions. For most SMBs, Bill C-8 will not apply directly — but SMBs supplying designated operators (managed service providers, contractors, professional services firms) will inherit obligations through their contracts. Given that the bill has advanced further than C-26 did, supply-chain readiness should no longer be treated as hypothetical. Bill C-27 (containing CPPA and AIDA) remains dead. PIPEDA continues to govern federal private-sector privacy; Quebec's Law 25 is the de facto stricter national standard. On January 30, 2026, Quebec's Commission d'accès à l'information published new guidance on the prevention of confidentiality incidents — a Guide and Checklist for Law 25-regulated entities, with increased scrutiny signalled on AI deployments processing Quebec-resident personal information. ### Canadian buyers are reconsidering U.S. cybersecurity vendors. The 2025 CIRA Cybersecurity Survey captured a structural sentiment shift: - 69% of Canadian organizations now cite data sovereignty as the most important sourcing factor (up from 60% in 2024) - 56% have specifically reconsidered U.S. vendors in light of cross-border trade and political uncertainty - 70% are worried about new AI cyber threats; 54% specifically cite AI-powered cyber attacks - 65% have integrated AI tools into workflows in 2025, up from 44% in 2023 Combined with the IBM finding that AI-augmented security operations correlate with CA$3.34 million lower breach costs, the 2026 Canadian SMB cybersecurity buyer profile looks distinctly different than at any point in the last decade — more Canada-first, more AI-augmented, and less tolerant of opaque cross-border data flows. ### Read the full report The full Cybersecurity Canada Report 2026 goes deeper on each of these findings with primary-source URLs for every figure, plus a dedicated section on token theft and adversary-in-the-middle phishing. The report will be updated annually; aggregate de-identified findings from the free Cybersecurity Canada assessment will be incorporated in the 2027 edition. To benchmark your organization against the Canadian Centre for Cyber Security's 13 Baseline Controls, the free assessment takes under 30 minutes, runs entirely in your browser, and produces a score and prioritized recommendations across every control area. The single highest-leverage move for most Canadian SMBs in 2026 is the one in finding #5 above: deploy phishing-resistant MFA on administrative and finance-team accounts. It costs nothing on Microsoft 365 Business Premium or Google Workspace Business, and it is the only defence that reliably stops the Storm-2755-class attacks that are now specifically targeting Canadians. --- ## Claude Mythos and Project Glasswing: What 10,000 AI-Discovered Zero-Days Mean for Canadian Businesses URL: https://cybersecuritycanada.ca/news/posts/claude-mythos-and-project-glasswing-what-canadian-businesses-need-to-know/ Category: Insights Published: May 23, 2026 Summary: Anthropic's Claude Mythos Preview model has autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities under Project Glasswing. Here is what Canadian businesses should do while the patches catch up. In its first month of operation under Anthropic's Project Glasswing, the unreleased Claude Mythos Preview model autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities across major operating systems, browsers, and widely used open-source software. The figure was published by Anthropic in its mid-May 2026 program update and analysed by mainstream outlets including Bloomberg and consulting firm Bain & Company. The model is not publicly available — Anthropic is holding it back specifically because of its offensive cybersecurity capabilities — but the disclosures from Glasswing are already pushing patches into the software Canadian businesses run every day. The headline number is dramatic. The more important number for Canadian small and medium-sized businesses is the one underneath it: as of Anthropic's first program update, roughly 827 confirmed high- or critical-severity vulnerabilities are still awaiting disclosure, and the open-source maintainers receiving them have asked Anthropic to slow down because they cannot patch quickly enough. That backlog — not the AI itself — is the immediate risk for Canadian SMBs. ### What is Claude Mythos, and what did Project Glasswing find? Claude Mythos Preview is an unreleased frontier model from Anthropic that can autonomously identify, validate, and exploit software vulnerabilities with minimal human guidance. Project Glasswing is the invitation-only partner program Anthropic launched in April 2026 to give about a dozen founding organizations — including Amazon Web Services, Apple, Google, Microsoft, Cisco, NVIDIA, CrowdStrike, JPMorgan Chase, and the Linux Foundation — controlled access to Mythos, along with roughly 40 additional critical-infrastructure operators and $100 million in Claude usage credits. Among the disclosed findings is CVE-2026-4747, a 17-year-old remote-code-execution flaw in FreeBSD's NFS server that Mythos identified and fully exploited end-to-end with no human steering after the initial prompt. The program has also flagged long-standing flaws in OpenBSD, FFmpeg, and the Linux kernel that remain under embargo while patches are written. Independent CVE trackers, including VulnCheck and The Register, note that only a small fraction of the 10,000+ findings have been publicly attributed so far — the rest sit inside a 90-day coordinated-disclosure window. ### Why this matters even though Mythos is not publicly available Anthropic's decision to gate Mythos behind Glasswing has been described as the "responsible" path by Canada's Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, after an April 14, 2026 meeting with the company, reported by Bloomberg and Global News. Restricting access gives defenders a head start, but it does not buy them a permanent advantage. Three things follow from that, and all three matter for Canadian businesses: - Patches will arrive in bursts. As Glasswing maintainers ship fixes, Canadian businesses will see unusually large security updates for FreeBSD, Linux distributions, browsers, media libraries, and other foundational software. The volume is the point — not any single CVE. - The window between patch release and exploitation is collapsing. Exploit-intelligence groups now report a median time from CVE disclosure to working exploit of roughly 10 hours in 2026, down from 56 days in 2024. Attackers do not need their own Mythos to weaponise a public advisory — current open models are already enough to read a fix and reverse-engineer the bug. - Maintainer capacity, not detection, is the bottleneck. Anthropic has reported that high- or critical-severity findings take an average of two weeks to patch, and that some maintainers have asked the company to slow disclosure. For software that depends on volunteer maintainers, "more findings" does not translate cleanly into "more fixes." ### What changes for Canadian businesses right now The practical risk for Canadian businesses is not that Claude Mythos itself will be turned against them. It is that monthly patch cycles no longer match the speed of the threat. A small business that batches Windows, macOS, browser, and router updates into a once-a-month maintenance window was already exposed; in the Mythos era, that delay is likely to be the difference between patched and compromised. Three specific Canadian risk concentrations are worth naming: - Edge devices and routers. Many Canadian SMBs rely on consumer-grade or end-of-life networking equipment whose vendors patch slowly, if at all. Glasswing-style disclosures will surface long-standing flaws in this category. - Open-source dependencies in custom software. If your business runs custom web applications, an internal portal, or vendor software built on FFmpeg, OpenSSL, or Linux components, you may inherit a Glasswing-related advisory through a supplier rather than directly. This is the same pattern we covered in our analysis of the Notepad++ supply-chain attack. - Unpatched legacy systems. Devices still on Windows 10, end-of-life network appliances, or unmaintained line-of-business applications will not receive Glasswing fixes at all. The Canadian Centre for Cyber Security has long flagged this category as the most attractive to opportunistic attackers; AI-assisted exploitation makes the gap worse. ### How Canadian SMBs should respond to the Mythos disclosures The right response is not specialised AI security tooling. It is faster, more disciplined execution of the controls the Canadian Centre for Cyber Security has been recommending since 2022. Five practical moves, in priority order: - Move patch management from monthly to weekly — or automatic. For workstations and browsers, turn on automatic updates and verify they are landing. For servers, shorten your patch window for high- and critical-severity CVEs to seven days or less. Our pillar on patch management lays out the checklist. - Inventory what you actually run. You cannot patch what you do not know about. Maintain a simple list of operating systems, key applications, network devices, and the open-source components your custom software depends on. Vendors that cannot provide a software bill of materials are now a vendor and third-party risk finding. - Make multi-factor authentication mandatory. A working exploit still usually needs an initial foothold. MFA on email, remote access, cloud admin consoles, and any internet-facing service remains the single highest-leverage control available to a Canadian SMB. See multi-factor authentication for the rollout pattern. - Test your backups against a ransomware scenario, not a tidy "files deleted" scenario. Glasswing-class disclosures lower the cost of opportunistic intrusion; ransomware operators will be the first commercial users. Offline, immutable, and tested backups are the floor. - Rehearse the first 24 hours. If a Mythos-disclosed flaw is exploited against a Canadian SMB before it is patched, the first hour of the response will determine the outcome. Our piece on what to do in the first 24 hours after a cyber attack is the starting script; pair it with the incident response pillar. This is also the moment to be honest about why cybercriminals target small businesses — not because they are valuable, but because they are reachable. AI lowers the cost per target, which makes "we are too small to attack" a worse assumption in 2026 than it was a year ago. ### How Project Glasswing maps to Canada's Baseline Cyber Security Controls Most of what the Mythos disclosures require from Canadian SMBs is already in the Cyber Centre's 13 Baseline Controls. The mapping is direct: - Faster patching of operating systems and applications → Patch management (BC.2), shortened to weekly cadence for critical CVEs. - Hardening of internet-facing services and edge devices → Secure configuration (BC.4) and network security (BC.9). - MFA on admin and remote access → Authentication (BC.5) with phishing-resistant factors where possible. - Backups that survive ransomware → Backup and recovery (BC.7) with offline copies and restoration tests. - A tested response plan → Incident response (BC.1), updated to assume short patch windows and AI-accelerated attacker tooling. If you are not sure where your organization sits against these controls today, our free cybersecurity assessment walks through all 13 in about ten minutes and produces a prioritised list of gaps — the same gaps a Glasswing-class advisory would be most likely to exploit. The companion piece on agentic AI security for Canadian businesses covers the other half of the AI-cyber picture: what happens when your own business starts deploying AI agents inside its systems. ### Frequently asked questions #### What is Claude Mythos in plain terms? Claude Mythos is an unreleased AI model from Anthropic with strong autonomous cybersecurity capabilities. Unlike publicly available models, it can plan, run, and verify a vulnerability-discovery process end-to-end with minimal human input. Anthropic has chosen not to release it publicly and is instead giving controlled access to about a dozen partner organizations under Project Glasswing. #### Did Claude Mythos really find 10,000 zero-days? Anthropic reports that Claude Mythos Preview identified more than 10,000 high- or critical-severity findings during its first month under Project Glasswing. Independent CVE trackers note that only a handful — including the FreeBSD NFS flaw CVE-2026-4747 — have been publicly attributed so far. The remainder are inside a 90-day coordinated-disclosure window, and the total assumes Anthropic's own validation methodology. Treat the 10,000+ figure as Anthropic's claim, not yet an independently audited count. #### Should Canadian businesses be worried about Mythos itself? Not directly. Mythos is gated behind Glasswing partners and is not available to the public, and Canada's federal AI minister has characterised that gating as a responsible approach. The realistic risk is the disclosure pipeline that Glasswing is producing: Canadian businesses will need to patch high- and critical-severity flaws faster than they did in previous years, because attackers using current open AI models can reverse-engineer fixes into exploits in hours rather than weeks. #### What should we do this week? Turn on automatic updates everywhere they are available, shorten your patch window for critical CVEs, verify that MFA is enforced on every internet-facing account, confirm you have an offline backup tested within the last 90 days, and re-read your incident response plan. None of this is new — Mythos has changed the urgency, not the playbook. #### Where can I read the primary sources? Anthropic's Project Glasswing page is at anthropic.com/glasswing, and the technical write-up of Claude Mythos Preview is at red.anthropic.com. The Canadian Centre for Cyber Security publishes ongoing guidance at cyber.gc.ca. --- ## CRA, Interac, and Canada Post: The Canadian Brand Phishing Playbook for SMBs URL: https://cybersecuritycanada.ca/news/posts/cra-interac-canada-post-canadian-brand-phishing-playbook-for-smbs/ Category: Best Practices Published: May 14, 2026 Summary: Canadian SMB employees see CRA refund texts, fake Interac e-Transfer notifications, and Canada Post 'missed delivery' SMS every week. Here's how to train your team to spot the Canadian brand phishing patterns generic training misses. Generic phishing training tells your employees to watch for "IRS scams" and "FedEx delivery emails." Canadian employees don't get those. They get a text claiming to be the Canada Revenue Agency about a refund, an email that looks exactly like an Interac e-Transfer notification, and an SMS saying Canada Post couldn't deliver a parcel because the address was incomplete. The brands are different, the lures are different, and the cues your staff are watching for are the wrong ones. The Canadian Anti-Fraud Centre reported a record $638 million lost to fraud in Canada in 2024 — up from $578 million the year before — and the CAFC estimates this represents only 5 to 10 percent of total losses, because most victims never report. For a small or medium business, a single employee clicking the wrong link on a CRA-themed text on their work phone can lead to credential theft, business email compromise, or ransomware. This is the playbook of the Canadian brand lures your team will actually see — and what to train them to do about it. ### Why Canadian Brand Phishing Works So Well on SMB Employees Brand phishing succeeds because the recipient already trusts the sender. Canadians interact with the CRA every spring, receive Interac e-Transfers as a normal part of doing business, and check Canada Post tracking pages weekly. Attackers don't need to invent a reason for the message to exist — they just need to time it right and copy the look. The Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security have both flagged impersonation of trusted Canadian brands as one of the most consistent attack vectors against individuals and small businesses. For SMB owners, the risk is not only the personal accounts of staff. Employees who fall for a personal-life lure on a work device often expose business credentials, business banking, or the email account attackers use to launch business email compromise against your customers and suppliers. ### The CRA Refund and "Tax Owing" Pattern The most common Canadian brand-phishing pattern is a text or email impersonating the Canada Revenue Agency, usually claiming the recipient is owed a refund payable by Interac e-Transfer, or that tax is owed and a warrant will be issued if not paid immediately. The message typically links to a convincing copy of a major Canadian bank's sign-in page. The CRA's own Recognize a scam page is explicit about what the agency will and will not do. Train employees to remember three rules: - The CRA does not send refunds by Interac e-Transfer. Refunds arrive by direct deposit or cheque. Any text or email offering one through e-Transfer is fraudulent. - The CRA does not demand immediate payment by gift card, cryptocurrency, or wire. Any "pay now or be arrested" message is a scam. - The CRA does not send links to sign-in pages by SMS. If a CRA notice is real, it will appear in the recipient's My Account or My Business Account when they log in directly at canada.ca — never via a link they were sent. If staff use personal CRA accounts on work devices, the compromise of those personal accounts can give attackers access to T4 information, payroll details, and corporate tax filings. ### The Interac e-Transfer Notification Pattern Fake Interac e-Transfer notifications are designed to look identical to the real thing, with the same yellow-and-black branding, the sender's "name," and a "Deposit your money" button that leads to a phishing copy of a Canadian bank login page. Interac's own email fraud guidance identifies several reliable tells employees should learn: - Real Interac notifications never include attachments. A "Transfer details.pdf" or HTML attachment is always fraudulent. - Real notifications use proper currency formatting. Phishing copies frequently put the dollar sign after the amount (100$ instead of $100.00) or use unusual decimal separators. - Generic greetings are a red flag. Real Interac notifications include the sender's name and message; phishing copies often default to "Hi" or "Dear Customer." - Hover the link before clicking. Legitimate deposit links are hosted on the recipient's bank's domain, not a lookalike like interac-deposit.com or etransfer-secure.ca. For businesses that actually receive customer payments by e-Transfer, the safer default is to turn on Autodeposit in your business banking. Autodeposit removes the security-question-and-answer step entirely, which is the step phishing copies exploit — funds are credited directly into the recipient's account with no link to click. The Interac fraud reporting address is phishing@interac.ca for any suspicious message that reaches a staff inbox. ### The Canada Post "Missed Delivery" Pattern The Canada Post smishing pattern is the most prolific in the country. An SMS arrives saying a parcel could not be delivered because the address is incomplete or a small redelivery fee — usually between $3 and $10 — is required. The low dollar amount is intentional: it feels harmless enough to enter a credit card without thinking. Canada Post's fraud guidance is unambiguous on the key point: Canada Post does not send unsolicited text messages, and never asks for fees or personal information by SMS. Legitimate tracking notifications are only sent if you have opted in through a Canada Post account, and they come from the short codes 272727 or 55555 — not from a regular ten-digit phone number, and never with a "pay this fee" link. The reason this matters for SMBs: shipping-and-receiving staff, e-commerce business owners, and anyone expecting a parcel for work are conditioned to act on delivery messages. Train every staff member who handles shipments to verify any "delivery problem" by logging in to the Canada Post tracking page directly using the tracking number from the original order — never the link in the SMS. ### Three Other Canadian Brands Worth Naming in Training Beyond the big three, the same pattern repeats with a handful of other distinctly Canadian targets your training material should mention by name: - Service Canada / Service Ontario impersonation. Calls or texts claiming the recipient's Social Insurance Number has been "compromised" and will be "suspended" unless they confirm details. SINs are not suspended; the entire premise is fraudulent. - Big-bank login pages. Phishing pages impersonating RBC, TD, Scotiabank, BMO, CIBC, and National Bank often follow a CRA or Interac lure as the destination. The domain in the address bar is the only reliable check — not the logo or layout. - Telecom billing scams. Fake Rogers, Bell, or Telus "overdue bill" SMS or emails that link to a payment page asking for credit card details. Each of these targets a Canadian-specific behaviour — bilingual government correspondence, our concentration of six major banks, and our three dominant telecoms — that generic American training material simply doesn't cover. ### What to Train Employees to Do — Five Rules That Hold Up The defence against brand phishing is procedural, not visual. By the time staff are squinting at logos, the attacker has already won. Five rules to bake into security awareness training: - Never act on an unexpected link in a message. Open a new browser tab and log in to the service directly — canada.ca, the bank's app, the Canada Post site — and check from there. - Treat urgency as a red flag, not a reason to hurry. Real institutions do not threaten arrest, account suspension, or fee deadlines by text. - Verify any request involving money or credentials through a second channel. A phone call to a known number breaks every variant of business email compromise and brand phishing. - Turn on multi-factor authentication on every business account. If credentials are phished, MFA is what stops the attacker from using them. - Report it, don't just delete it. A reported phishing attempt lets IT warn the rest of the team before someone else clicks. For a deeper checklist of behavioural indicators, see our guide to recognizing phishing emails. ### How to Report a Canadian Brand Phishing Attempt Reporting is fast and worthwhile. Suspicious messages should be sent to the brand being impersonated and to the Canadian Anti-Fraud Centre: - CRA-themed: Forward emails to phishing@cra-arc.gc.ca and report at the CRA's Recognize a scam page. - Interac-themed: Forward to phishing@interac.ca. - Canada Post-themed: Forward to the address on Canada Post's fraud reporting page. - Any of the above: Report to the Canadian Anti-Fraud Centre at 1-888-495-8501 or online at reportcyberandfraud.canada.ca. If credentials were entered or money was sent, treat it as an incident immediately. Reset the affected password, revoke active sessions, contact your bank, and follow your incident response plan. ### Where This Fits in Your Cybersecurity Program Brand phishing defence sits inside two of the Canadian Centre for Cyber Security's 13 baseline controls: security awareness training and authentication. If those two areas are weak — no recurring training, no MFA, no documented reporting path — the rest of your security program cannot compensate. If you want a quick read on where your business currently stands across all 13 areas, the free cybersecurity assessment takes about twenty minutes and produces a written report tied to the baseline controls. ### Frequently Asked Questions #### Does the CRA ever send text messages to Canadians? The CRA does not use text messages or instant messages to start a conversation with you about your taxes, benefits, refund, or account. It never sends links to sign-in pages by SMS, never asks for personal or banking information by SMS, and never issues tax refunds through Interac e-Transfer. Any text containing a link, a payment request, or a threat of arrest is fraudulent. The authoritative source is the CRA's own Recognize a scam page. #### How can I tell a real Interac e-Transfer notification from a fake one? Real Interac notifications never include attachments, never use generic greetings like "Dear Customer," and always link to your actual bank's domain. Phishing copies frequently misformat currency (placing the $ after the number), use lookalike domains, or include HTML and PDF attachments. When in doubt, ignore the link in the email and log in to your bank directly to check for the deposit. #### Is Canada Post phishing illegal, and does reporting it actually help? Yes — phishing fraud is a criminal offence in Canada, prosecuted under the Criminal Code's fraud (s.380) and identity-fraud (s.403) provisions, regardless of which brand is being impersonated. Reports to the Canadian Anti-Fraud Centre feed an intelligence database used by police, banks, and telecoms to disrupt campaigns and warn the public. The CAFC estimates its data captures only 5 to 10 percent of actual losses, so each report has outsized value. #### What should I do if an employee already entered credentials on a phishing site? Treat it as a credential compromise. Reset the password immediately, revoke active sessions, enable MFA if it wasn't already on, and review account activity for unauthorized access. If banking or payment information was entered, contact the bank within hours, not days. Document the incident and follow your incident response plan — and if customer or employee personal information may have been exposed, you may have breach-reporting obligations under PIPEDA. #### Should we block all CRA, Interac, and Canada Post emails to be safe? No. The volume of legitimate correspondence from these organizations — particularly during tax season and the holiday shipping period — makes outright blocking impractical and counterproductive. The correct defences are layered: email authentication (SPF, DMARC, DKIM), modern email filtering, MFA on every account, employee training focused on behavioural red flags rather than logos, and a documented path for staff to report anything suspicious. --- ## Canvas Data Breach 2026: What the Instructure Hack Means for Canadian Universities and Businesses URL: https://cybersecuritycanada.ca/news/posts/canvas-data-breach-what-canadian-universities-and-businesses-need-to-know/ Category: Threats Published: May 8, 2026 Summary: The Canvas data breach has hit UBC, SFU, the University of Toronto, OCAD, Western's Ivey, Mohawk College and Ontario Tech, with ShinyHunters claiming 275 million records across 9,000 schools. Here's what happened and what to do. The Canvas data breach disclosed by Instructure on May 1, 2026 — and followed by a mass login-page defacement on May 7 that Instructure has tied to the same intrusion — has pulled in at least seven Canadian post-secondary institutions, including the University of British Columbia (UBC), Simon Fraser University (SFU), the University of Toronto, OCAD University, Western's Ivey Business School, Mohawk College and Ontario Tech University. The cyber-extortion group ShinyHunters has claimed it stole 3.65 terabytes of data covering roughly 275 million users across nearly 9,000 schools worldwide, with a public-leak deadline of May 12, 2026 unless Instructure negotiates. Instructure has confirmed a narrower set of facts: an unauthorized actor exploited "an issue related to our Free-for-Teacher accounts," accessed certain identifying information — names, email addresses, student ID numbers and messages between Canvas users — and was detected and cut off in late April. The company says it has "found no evidence that passwords, dates of birth, government identifiers, or financial information were involved." The 275-million figure remains the attacker's unverified claim and should be read as an upper-bound marketing number, not a confirmed exposure count. For Canadian students, the immediate worry is targeted phishing. For Canadian businesses watching from the sidelines, the more uncomfortable question is the same one raised by the Canada Life breach two weeks earlier: how a publicly exposed web application — wired into thousands of organizations — can be picked apart by a single criminal group, and what defensive playbook actually keeps you out of the next one. ### What Happened in the Canvas Data Breach According to Instructure, the company detected unauthorized activity in its Canvas environment on April 29, 2026 and revoked the intruder's access the same day. The incident was disclosed publicly on May 1. ShinyHunters posted a public leak threat naming Instructure in early May (sources cite dates between May 2 and May 5), and on May 7 the same actor defaced thousands of Canvas login portals — replacing institutional sign-in pages with a ransom note demanding Instructure "negotiate a settlement" before May 12. Instructure has stated the May 7 activity was tied to the same April 29 incident. Canvas, Canvas Beta and Canvas Test were placed into maintenance mode while the company investigated; service was restored later that day. The verified facts, as of May 8, 2026: - Vector: an issue tied to Instructure's Free-for-Teacher accounts (a free, self-serve tier of Canvas separate from the licensed instances most universities run). Free-for-Teacher accounts have been temporarily shut down. - Detection date: April 29, 2026. - Public disclosure: May 1, 2026. - Confirmed data accessed: names, email addresses, student ID numbers, and Canvas messages between users at affected institutions. - Confirmed not accessed (per Instructure): passwords, dates of birth, government identifiers, financial information. - Threat actor: ShinyHunters — the same financially motivated extortion group linked to the Canada Life intrusion and a September 2025 social-engineering compromise of Instructure's Salesforce environment (which, per Instructure at the time, exposed business contact data rather than Canvas customer or product data). - Attacker claims (unverified): ~275 million users and 3.65 TB of data across ~9,000 schools. - Ransom deadline: end of day, May 12, 2026. - Status: vulnerability remediated, third-party forensic firm engaged, law-enforcement notified, Canvas restored. Attribution should be hedged in any active investigation, but ShinyHunters has publicly claimed the breach, named victim institutions on its leak infrastructure, and the pattern is consistent with the group's prior activity. ### Which Canadian Universities Are Affected At least seven Canadian post-secondary institutions have publicly confirmed they are in scope of the Canvas breach, and the list may grow as more schools complete their reviews. Confirmed so far: - University of British Columbia (UBC) - Simon Fraser University (SFU) - University of Toronto (Quercus, U of T's Canvas-based learning platform, was taken offline) - OCAD University - Ontario Tech University - Mohawk College - Western University's Ivey Business School U of T, OCAD and Ontario Tech have noted that winter terms were already complete, so coursework was not disrupted — but exposed account information is a year-round problem, not a term-end one. UBC and SFU advised students still logged in to log out and wait for an all-clear notice. Because Canvas is the learning management system (LMS) of choice for a large share of Canadian universities and colleges, additional institutional disclosures are likely in the days ahead. If you are a Canadian student or employee at any school that uses Canvas, assume your name, school email and student ID may have been touched and act accordingly. ### What Was Exposed and What It Means for Canadians The data accessed in the Canvas breach is not, on its own, the kind that empties a bank account — but it is enough to fuel highly convincing phishing aimed at students, parents paying tuition, and faculty. Names tied to verified school email addresses and student ID numbers, plus the contents of in-platform messages, give attackers everything they need to impersonate registrars, financial-aid offices, professors, and student-services staff. The realistic Canadian risks over the next several months include: - Targeted "tuition" and "financial aid" phishing that references your real school, real student ID and real course context. - Account-takeover attempts on services that share your school email, especially where students reuse passwords across personal accounts. - Resume and job-offer scams aimed at students whose addresses have been confirmed at known institutions. - Scholarship and grant fraud using real names, IDs and messages to add credibility. - Smishing (text-message phishing) if mobile numbers were collected by attackers from previous breaches and matched to Canvas profiles. Under PIPEDA and provincial privacy laws, affected institutions are expected to notify individuals where there is a real risk of significant harm. Watch for an official notice from your school — not from "Canvas," "Instructure," or a third party — and verify any communication by going to the school's website directly rather than clicking links in email. ### What Affected Students and Staff Should Do This Week If you have a Canvas account at one of the named Canadian institutions — or any school that uses Canvas — take these five steps now. They are quick, free, and they materially reduce the value of the stolen data to whoever ends up holding it. - Change your school account password and any password that reuses the same string elsewhere. Use a unique password for every account; a password manager makes this practical. - Turn on multi-factor authentication (MFA) on your school account and your personal email. If your institution offers a phishing-resistant option (passkey, security key), pick that. See our guide on multi-factor authentication. - Be skeptical of any message referencing your school, course, professor, or student ID for the next several months — even when the details look legitimate. Verify by phoning the school directly or going to the official portal. - Do not click links or attachments in unsolicited "Canvas," "Instructure," "Quercus," or registrar emails. Type the URL yourself. - Watch for notices from your institution. They will use their own domain — not a free webmail address, not a .com lookalike. The patterns to recognize are covered in how to recognize phishing emails. ### Why This Matters for Canadian Businesses The Canvas breach is not just an education story. It is a clean illustration of a pattern Canadian businesses should expect to see repeatedly: a publicly accessible web application, used by thousands of organizations, picked at by a sophisticated extortion group until something gives way. The same pattern produced the Canada Life intrusion in April, the Instructure Salesforce compromise last September, and a long line of incidents before that. Two structural realities make this worse, not better, in 2026: - Anything reachable from the public internet will be probed. Login pages, API endpoints, file uploaders, password-reset flows, free or trial tiers — all of it. Free or low-friction account tiers (like Canvas's Free-for-Teacher) are particularly attractive because attackers can sign up themselves, study the platform from the inside, and look for issues that affect the paid product. - Generative AI has lowered the cost of finding flaws. The same large language models defenders use are now being used by criminals to read source code, infer authentication logic, generate exploit prototypes, and write convincing phishing at scale. The reconnaissance and exploit-development work that used to take a skilled team a month can be done by one person in days. This is the same dynamic we wrote about in AI-powered phishing — except now it applies to web vulnerabilities, not just emails. Put bluntly: if your business runs an internet-facing application, or relies on a vendor that does, it is being looked at. The defenders' job is to find the issues first. #### Use the Same AI Tooling Attackers Are Using — Defensively Canadian businesses can flip the AI advantage by adopting continuous, AI-assisted penetration testing and vulnerability assessment instead of the once-a-year audit model many SMBs still rely on. Modern AI-augmented security tooling can: - Continuously scan public-facing assets for new exposures as code and configuration change. - Re-test the same applications against newly disclosed vulnerability classes within days of publication. - Generate proof-of-concept exploits in safe, scoped environments to confirm whether a finding is actually exploitable, rather than theoretical. - Triage the resulting findings against your real architecture, prioritising the ones that map to a realistic attack path. The objective is straightforward: find and patch the issue before an external attacker — increasingly one assisted by the same kind of AI — finds and exploits it. This is consistent with the 13 Baseline Cyber Security Controls published by the Canadian Centre for Cyber Security, particularly the controls covering patch management and web application security. It is also where federal critical-infrastructure obligations under Bill C-26 are heading: regulators will increasingly expect ongoing assurance, not annual snapshots. A separate, equally important point: any AI tooling your business uses for security testing — or anything else — should sit inside a written AI usage policy that defines what data may and may not be sent to which models. #### Treat Third-Party Code and Vendors as Part of Your Attack Surface The Canvas incident also reinforces a point we made in our pieces on vendor and third-party risk and the Notepad++ supply-chain attack: your security perimeter now extends through every SaaS platform, open-source library, browser extension, and third-party script your business depends on. A vulnerability in any of them — including ones you didn't know you were running — can be the back door into your environment. Practical actions for the next 30 days: - Maintain an inventory of every SaaS platform and third-party library your business depends on, including transitive dependencies in any internally developed software. - Subscribe to vendor security advisories and a CVE feed for the libraries on that list. Free options include cyber.gc.ca alerts and the U.S. CISA known exploited vulnerabilities catalog. - Continuously scan dependencies for known vulnerabilities (software composition analysis), not just at release time. - Question free or trial tiers of platforms that share infrastructure with your paid environment — confirm with the vendor that an issue in the free tier cannot reach your data. - Rehearse a SaaS-vendor compromise scenario as part of your incident response plan — Canvas is a useful tabletop exercise this month. ### What Could Have Prevented This — and What Should Happen Next No public reporting yet describes the precise technical flaw in the Free-for-Teacher tier. What we can say from the disclosed facts is that the controls most likely to have changed the outcome are well-understood and well-documented: - Continuous web application security testing of every internet-facing surface, including free or trial tiers, with a particular focus on authentication, multi-tenancy boundaries, and bulk-data endpoints. - Strict tenancy isolation so that a vulnerability in a free or self-serve tier cannot reach licensed-customer data. - Anomaly detection on bulk reads so that exfiltration of millions of records does not look like normal traffic to a monitoring system. - Phishing-resistant MFA and help-desk hardening to defeat the social-engineering playbook ShinyHunters has used against Instructure's Salesforce environment in September 2025 and against many other SaaS customers since. - Faster, more transparent disclosure timelines so that downstream institutions — including Canadian universities — can act on attacker claims before login pages are publicly defaced. These are not exotic controls. They are the same items Canadian regulators, the Canadian Centre for Cyber Security, and frameworks like the CCCS Baseline reference repeatedly. The hard part is keeping them current against an attacker pool that now uses AI to find the gaps faster than human defenders can. ### The Bigger Picture Public-facing applications will keep getting probed. ShinyHunters and groups like it are not going away. AI is amplifying the attacker side of the equation, and any business that waits for an annual penetration test to find out how it stands is, in practical terms, hoping nothing changes between January and December. That is not a strategy. The realistic posture for Canadian businesses in 2026 is continuous: continuous monitoring, continuous testing, continuous third-party assessment, and a written incident response plan that assumes a SaaS vendor — not your own server — will be the one in the headlines. The Canvas breach will not be the last of its kind this year. If you are not sure where your business stands on web-application security, third-party risk, or incident readiness, our free Canadian cybersecurity assessment walks through the 13 Baseline Controls and gives you a clear, prioritised view of which gaps to close first — without collecting your data, and without a sales call attached. ### Frequently Asked Questions — Canvas Data Breach 2026: What the Instructure Hack Means for Canadian Universities and Businesses Q: Which Canadian universities were affected by the Canvas data breach? A: At least seven Canadian post-secondary institutions have publicly confirmed they are in scope: the University of British Columbia, Simon Fraser University, the University of Toronto (whose Canvas-based Quercus platform was taken offline), OCAD University, Ontario Tech University, Mohawk College, and Western University's Ivey Business School. Because Canvas is the learning management system used by a large share of Canadian universities and colleges, additional institutional disclosures are possible. Q: What data was exposed in the Canvas data breach? A: Instructure has confirmed that an unauthorized actor accessed names, email addresses, student ID numbers, and messages between Canvas users. The company has stated it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. Names tied to verified school email addresses and student IDs are still enough to fuel convincing phishing that impersonates registrars, financial-aid offices, and faculty. Q: Were 275 million Canvas users really affected? A: The 275 million user figure — along with claims of 3.65 terabytes of data across roughly 9,000 schools — comes from the extortion group ShinyHunters and remains unverified. It should be read as an attacker's upper-bound claim, not a confirmed exposure count. Instructure has confirmed a narrower set of facts: an issue related to its Free-for-Teacher accounts allowed access to certain identifying information. Q: When did the Canvas data breach happen? A: Instructure detected unauthorized activity in its Canvas environment on April 29, 2026 and revoked the intruder's access the same day. The incident was disclosed publicly on May 1, 2026. On May 7, the same actor defaced thousands of Canvas login portals with a ransom note demanding Instructure negotiate before May 12, 2026; Instructure has stated the May 7 activity was tied to the same April 29 incident. Canvas was briefly placed in maintenance mode and restored later that day. Q: How did attackers get into Canvas? A: Instructure has attributed the intrusion to an issue related to its Free-for-Teacher accounts — a free, self-serve tier of Canvas separate from the licensed instances most universities run. Free-for-Teacher accounts were temporarily shut down in response. The company says the vulnerability has been remediated, a third-party forensic firm has been engaged, and law enforcement has been notified. Q: What should students and staff at affected schools do? A: Assume your name, school email address, and student ID may have been touched, and treat any message referencing your school, student ID, or course context with suspicion for the next several months. The realistic risks are targeted tuition and financial-aid phishing, account-takeover attempts on services sharing your school email, resume and job-offer scams, scholarship fraud, and text-message phishing. Use a unique password for your school account and enable multi-factor authentication wherever your institution offers it. --- ## Agentic AI Security for Canadian Businesses: What the New Cyber Centre Guidance Means URL: https://cybersecuritycanada.ca/news/posts/agentic-ai-security-for-canadian-businesses-cyber-centre-guidance/ Category: Insights Published: May 3, 2026 Summary: Canada's Cyber Centre and four allied agencies published Careful Adoption of Agentic AI Services on May 1, 2026. Here's what the new agentic AI security guidance means for Canadian businesses considering AI agents. On May 1, 2026, the Canadian Centre for Cyber Security joined the United States Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), Australia's ASD-ACSC, the United Kingdom's NCSC, and New Zealand's NCSC-NZ to publish Careful Adoption of Agentic AI Services — a 28-page joint guide that tells organizations how to deploy AI agents without breaking their security model. For Canadian businesses now experimenting with agentic AI in customer support, procurement, IT operations, or finance, this is the first piece of Five Eyes guidance written specifically for the technology. The guide's core message is blunt: agentic AI inherits every weakness of large language models (LLMs), then adds a wider attack surface, more autonomy, and harder-to-trace accountability. The authoring agencies recommend organizations "never grant [agentic AI] broad or unrestricted access" and "only use agentic AI for low-risk and non-sensitive tasks" until oversight, evaluation methods, and standards mature. This post translates the guidance for Canadian small and medium-sized business decision-makers — what's actually new, what risks matter most, and what to do before letting an AI agent touch your business systems. ### What Is Agentic AI, and Why Does the Cyber Centre Want You to Be Careful? Agentic AI is software that uses an LLM to interpret goals, plan steps, and take actions on its own — calling tools, querying data sources, sending emails, modifying records — without a human approving each move. A generative AI chatbot writes a draft for you. An AI agent submits the purchase order, replies to the supplier, and updates the accounting system. The Cyber Centre and its partners flag this autonomy as the central security problem. Where traditional software does only what it was coded to do, an agentic AI system makes decisions based on probabilistic reasoning, reads untrusted data from the web or email, and chains tools together in ways its designers did not anticipate. The guidance identifies four risk categories that Canadian businesses should understand before deploying AI agents. #### Privilege Risks Agents are often granted broad access on day one to "reduce friction." The guidance warns this creates a confused deputy pattern: when a malicious actor compromises any tool or input feeding into the agent, they inherit every privilege the agent holds. A procurement agent given access to financial systems, email, and contract repositories effectively becomes a single key to all of them. #### Behaviour Risks LLM-based agents can engage in specification gaming — technically completing the goal in unsafe ways. The guidance gives a memorable example: an agent told to "maximise system uptime" disables security updates because patches require reboots. The document also catalogues deceptive behaviour, prompt injection, and emergent capabilities the original developers did not program. #### Structural Risks Multi-agent systems amplify problems. A single hallucination from one agent can be accepted as truth by a second agent, which then takes a destructive action. The guidance highlights tool-squatting (malicious tools published under legitimate-looking names), insecure agent-to-agent communication, and rogue agents that propagate harmful instructions across an enterprise. #### Accountability Risks When several agents collaborate on a decision and something goes wrong, fragmented logs and opaque reasoning chains make it nearly impossible to determine which component caused the error. For Canadian businesses, this is also a PIPEDA and Bill C-26 problem: regulators expect organizations to explain how a decision involving personal data was made. ### What Canadian Businesses Should Do Before Deploying AI Agents The guidance is explicit that agentic AI security must sit inside an organization's existing cyber security framework, not beside it. For Canadian SMBs, that means the 13 Baseline Controls published by the Cyber Centre are the starting point, with agent-specific additions layered on top. The authoring agencies recommend these practical steps, which translate well for smaller organizations. #### 1. Start with Low-Risk, Reversible Tasks The guidance recommends a phased deployment model: begin with use cases where errors are recoverable and the data is non-sensitive. Drafting internal documents, summarising public information, or organising a calendar are appropriate starting points. Approving payments, modifying customer records, or accessing personal information are not — at least not until you have monitoring and rollback procedures in place. #### 2. Apply Least Privilege, Per Action Static permissions granted at deployment ("the agent can read all email") are flagged as one of the most common mistakes. The guidance recommends evaluating entitlements at each invocation, using ephemeral credentials that expire when the task finishes, and dynamically scoping privileges to the specific sub-task. For most Canadian SMBs, this maps onto existing authentication and access control practices — apply the same principle of least privilege you already use for human accounts to AI agents. #### 3. Keep a Human in the Loop for High-Impact Actions The Cyber Centre and partners are direct: "Prevent agents from autonomously executing high impact actions or outputs without prior human approval." Specifically called out — system resets, network egress, deletion of critical records, and any request to delete logs or audit records — should require human review. This is also where your incident response plan needs an agentic AI scenario added. #### 4. Treat Tools and Third-Party Components as Supply Chain Risk Agents typically use tools — APIs, plugins, third-party services — to act on the world. The guidance warns these can be tool-squatted (malicious clones with similar names) or quietly compromised. The recommended response is the same supply chain discipline Canadian businesses should already apply to software dependencies: a verified allow-list, regular review, and a software bill of materials. See our piece on vendor and third-party risk for the underlying playbook. #### 5. Log Everything, Then Monitor What You Logged Continuous monitoring of agent behaviour — inputs, tool calls, internal reasoning, decisions, outputs — is repeated throughout the document. The guidance specifically recommends quarantining any request from an agent to delete logs until a human approves it. Comprehensive logging also feeds the breach-investigation obligations Canadian organizations carry under PIPEDA and the forthcoming Bill C-26 regime. #### 6. Threat-Model the Agent, Not Just the App The authoring agencies recommend using updated risk taxonomies — the OWASP 2026 Top 10 for Agentic Applications and the MITRE ATLAS™ matrix — to threat-model any agent before deployment. For Canadian SMBs without a dedicated security team, this can be as simple as walking through "what happens if this agent is given a malicious prompt?" and "what happens if the tool it depends on is compromised?" before the system goes live. ### How the Five Eyes Guidance Maps to the Canadian Baseline Controls Most of the agentic AI controls in the guidance are extensions of work Canadian SMBs are already expected to do under the Cyber Centre's Baseline framework. The mapping is roughly: - Identity for agents → Authentication (BC.5) extended to non-human principals, with cryptographically anchored agent identities and mutual TLS for agent-to-service calls. - Tool allow-lists and SBOM → Secure configuration (BC.4) plus the supply chain hygiene already required for software. - Human-in-the-loop checkpoints → Incident response (BC.1) and existing change-control processes, applied to agent decisions. - Continuous monitoring of agent behaviour → Network security (BC.9) logging extended to agent inputs, reasoning, and tool calls. - AI literacy and human oversight → Security awareness training (BC.6), updated to cover prompt injection and agent misuse scenarios. If your business has not implemented those baseline controls for traditional IT, the guidance is clear that adding agentic AI on top is a higher-risk move. Appendix A of the document lists "cyber security prerequisites before implementation of AI agents," and most of them are baseline cyber hygiene — strong authentication, secure-by-design principles, zero trust, secure development, and tested incident response — rather than AI-specific tooling. ### A Realistic Starting Point for Canadian SMBs For Canadian small and medium-sized businesses, the practical takeaway is not "don't use agentic AI." It is "match the autonomy you grant the agent to the maturity of the controls you have around it." A reasonable starting position looks like this: - Inventory the agents already in use. Many SaaS products quietly added agentic features in 2025 and 2026 — meeting summarisers, autonomous email assistants, AI-driven scheduling. Treat each as a system that needs a privilege review. - Limit each agent to one well-defined, low-risk job. Avoid the procurement-agent-with-access-to-everything pattern described in the guidance. - Require human approval for anything destructive or financial. Send-money, delete-data, change-permission actions should never be fully autonomous, even if the vendor says it is safe. - Verify the vendor. Ask whether the agent meets the practices in Careful Adoption of Agentic AI Services — particularly around least-privilege scopes, audit logging, and tool allow-lists. If the vendor cannot answer, treat that as a finding. - Update your incident response plan. Add a scenario for "the agent did something unauthorised" — what gets disabled, who reviews logs, how customers and regulators are notified. The Cyber Centre's existing Top 10 AI security actions (ITSAP.10.049) is a useful companion document for organizations earlier in their AI journey. Combined with the new agentic-specific guidance, it gives Canadian businesses a concrete checklist for the next 12 months. If you are unsure where your organization sits today, our free cybersecurity assessment walks through all 13 Baseline Control areas in roughly 10 minutes and produces a prioritised list of gaps. The same assessment is also a reasonable proxy for whether you are ready to safely adopt agentic AI: most of the prerequisites in Appendix A of the guidance are graded by it. ### Frequently Asked Questions #### Who issued the new agentic AI security guidance? Careful Adoption of Agentic AI Services was co-authored by the Canadian Centre for Cyber Security, CISA, the NSA, Australia's ASD-ACSC, the UK's NCSC, and New Zealand's NCSC-NZ — the Five Eyes cyber agencies. CISA and the Cyber Centre published it on May 1, 2026, with the document itself dated April 30, 2026. #### Does this guidance apply to small Canadian businesses, or only large enterprises? The document is written for "government, critical infrastructure and industry stakeholders," but the recommended best practices scale down to small and medium-sized businesses. Canadian SMBs that already use AI agents — even built into off-the-shelf SaaS products — are in scope of the privilege, behaviour, structural, and accountability risks the guide describes. #### Is agentic AI the same as ChatGPT or Microsoft Copilot? Not exactly. Generative AI tools like ChatGPT or Copilot produce content for a human to review and act on. Agentic AI uses the same underlying language models but adds tools, memory, and planning so the system can take actions independently — sending emails, modifying files, calling APIs. Many vendors are now layering agentic features on top of generative AI products, which is why the guidance recommends an inventory. #### What is prompt injection, and why does the Cyber Centre keep mentioning it? Prompt injection is an attack where malicious instructions are hidden inside data the agent reads — a phishing email, a web page, a calendar invite — that cause the agent to ignore its original instructions and do something harmful. Because agentic AI systems pull data from many sources and act on it autonomously, the guidance treats prompt injection as one of the most important risks to design against. Our guide on AI-powered phishing covers a related angle. #### Where can I read the full document? CISA hosts the guidance at cisa.gov, and Australia's ASD-ACSC hosts a parallel copy at cyber.gov.au. The PDF is 28 pages and is freely available under a Creative Commons licence. --- ## Canada Life Data Breach: What Canadians and Canadian Businesses Need to Know URL: https://cybersecuritycanada.ca/news/posts/canada-life-data-breach-what-canadians-need-to-know/ Category: Threats Published: April 26, 2026 Summary: The Canada Life data breach exposed personal information for up to 70,000 people after attackers used one employee's account to reach a Salesforce environment. Here's what happened and what to do. The Canada Life data breach disclosed publicly on April 23, 2026 exposed the personal information of up to 70,000 people — most of them customers of one large corporate group plan — after the criminal extortion group ShinyHunters used a single Canada Life employee's account to reach the insurer's Salesforce environment. Canada Life says the incident has been contained and is offering free credit monitoring to affected individuals. The two numbers circulating in coverage do not contradict each other, but they answer different questions. 70,000 is Canada Life's verified count of individuals whose personal data was actually accessed. 5.6 million is the figure ShinyHunters has claimed for the records it could reach in the broader Salesforce environment — a number Canada Life has not confirmed and that should be treated as the attacker's unverified claim, not a confirmed exposure count. The verified figure is what affected Canadians and regulators will work from; the larger figure matters because it suggests how much one compromised account could potentially touch. For Canadians, the practical question is: what was exposed, and what should you do? For Canadian businesses, the more uncomfortable question is how a single set of compromised credentials gave attackers that kind of reach into a customer database — and whether the same path exists in your own environment. ### What Happened in the Canada Life Data Breach Canada Life — one of the country's largest life and health insurers — identified a cyber incident in mid-April 2026 and disclosed it publicly on April 23. The company says attackers gained access through a single employee account and used it to query data held in Canada Life's Salesforce customer relationship management (CRM) system. ShinyHunters set a ransom deadline of April 21, 2026 with a "pay or leak" demand before public disclosure. Key facts confirmed by Canada Life and reported across major Canadian news outlets: - Up to 70,000 individuals had personal information accessed - Less than 0.5% of Canada Life's total customer base - The majority of affected accounts belong to one large corporate group customer - Threat actor: ShinyHunters, a financially motivated extortion group - Attack vector: a single compromised employee account used to access Salesforce - ShinyHunters has claimed access to 5.6 million records; Canada Life's verified count is approximately 70,000 - The incident has been contained; operations and services continue normally ### What Information Was Exposed The data accessed in the Canada Life breach is the kind used to underwrite group benefits, not the kind that lets a criminal directly empty a bank account — but it is more than enough to support targeted phishing, identity verification fraud, and benefits-related social engineering. According to Canada Life's disclosure, the exposed fields include: - Full name - Date of birth - Mailing address - Gender - Annual income level Canada Life has stated that Social Insurance Numbers, banking details, and medical information were not part of the accessed data. That is meaningful — but a name, date of birth, address, and income level is still a strong starting point for identity fraud or impersonation, especially when paired with information that may already be available from previous unrelated breaches. ### Who Is ShinyHunters and Why Salesforce ShinyHunters is a long-running cybercriminal extortion group that has been linked to a series of 2025–2026 intrusions targeting cloud-hosted CRM and customer data platforms — Salesforce in particular. The group's pattern, reported across multiple incidents this spring, is to compromise an employee's credentials (commonly through phishing, credential reuse, or social engineering of help desks), authenticate to the company's Salesforce tenant, and bulk-export customer records before issuing a ransom demand. This is not a flaw in Salesforce itself. The platform performs as designed when a legitimate user logs in with valid credentials. The weak point is the human account in front of it — and the absence of controls that would catch an unusual bulk export from one user's session. Attribution should always be hedged in active investigations, but ShinyHunters has publicly claimed the Canada Life intrusion and posted the company on its leak-threat infrastructure with the April 21 deadline. Multiple security outlets have corroborated the claim. ### What Canadians Affected by the Breach Should Do If you are a Canada Life customer — particularly through a workplace group benefits or retirement plan — assume you may be in scope until you hear otherwise. Canada Life has said affected individuals will be contacted directly and offered free credit monitoring. While you wait, take these steps: - Watch for the official notification. Canada Life is contacting affected people directly. Do not click links in emails claiming to be the breach notice — go to canadalife.com directly or call the number on a document you already have. - Enrol in the offered credit monitoring. It is free and covers the kinds of fraud most likely to follow an income-and-address leak. - Place a fraud alert with Equifax Canada and TransUnion Canada. Both bureaus offer free fraud alerts that require lenders to take extra steps to verify your identity. - Be sceptical of "Canada Life" calls and emails for the next several months. Attackers know who was breached and what data they have. Expect targeted phishing that references your real address, birthday, or employer. - Never give out a password, MFA code, or banking detail in response to an inbound call, even if the caller knows personal details about you. Hang up and call back on a verified number. If you want a deeper checklist, our guide on how to recognize phishing emails covers the patterns most commonly used after a breach like this one. ### Why This Matters for Canadian Businesses The Canada Life breach is not just a consumer story. It is the same pattern that has hit a string of other large organizations through their Salesforce, Workday, and similar SaaS environments over the last twelve months. The lesson for Canadian businesses — particularly small and medium-sized ones that often assume they are too small to be of interest — is that the identity of one employee is now frequently the entire perimeter. #### One Account Should Not Be Able to Export 5.6 Million Records Even if ShinyHunters' figure is inflated, the structural point stands: the attackers were able to query and pull a substantial volume of customer data using credentials belonging to a single user. That suggests the account had broad data access, no anomaly-based limits on bulk export, and no step-up authentication on sensitive operations. Most SaaS platforms — including Salesforce — offer controls to limit these exact behaviours, but they have to be configured. #### Multi-Factor Authentication Is the Floor, Not the Ceiling The Canadian Centre for Cyber Security's 13 Baseline Cyber Security Controls list multi-factor authentication (MFA) as a foundational requirement — and for good reason. ShinyHunters' typical playbook involves bypassing or stealing through MFA fatigue, phishing-resistant push prompts, or session token theft. Phishing-resistant MFA (such as FIDO2 security keys or platform passkeys) materially raises the bar. We covered this in detail in our piece on multi-factor authentication. #### Your SaaS Vendors Are Your Attack Surface If your business uses Salesforce, HubSpot, Microsoft 365, Google Workspace, or any SaaS platform that holds customer data, those platforms are part of your attack surface — even though you do not run them. This is the heart of what we wrote about in vendor and third-party risk. Your responsibility is not to operate the platform, but to configure access, identity, and monitoring within it as if it were your own data centre — because, for the data inside, it is. ### What Canadian Businesses Should Do This Week If the Canada Life breach has prompted a "could this happen to us?" question at your leadership table, these are the most practical steps to take in the next seven days. #### 1. Audit Who Can Bulk-Export from Your CRM Run a report of which user accounts have permission to export, query, or download large volumes of customer records from your CRM and other SaaS systems. The list should be short, named, and reviewed quarterly. Most organizations are surprised by how long this list actually is. #### 2. Turn On Phishing-Resistant MFA for Privileged Accounts For any account that can access sensitive customer data, push notifications and SMS codes are no longer adequate. Move privileged accounts to FIDO2 security keys or platform passkeys. Most SaaS platforms support this natively at no extra cost. #### 3. Enable Anomaly Alerts on Bulk Data Access Salesforce, Microsoft 365, Google Workspace, and most major SaaS platforms can alert administrators when a user logs in from a new country, downloads an unusually large number of records, or behaves outside their normal pattern. Turn these on. Route them somewhere a human will read them. #### 4. Train the Help Desk Against Social Engineering A common ShinyHunters technique is calling the help desk pretending to be a locked-out employee and asking for a password or MFA reset. Help-desk staff should require a verified callback or video confirmation before resetting credentials for any account with sensitive access. This belongs in your security awareness training program. #### 5. Confirm Your Incident Response Plan Covers SaaS Compromise If the compromised system is a SaaS platform you do not host, your incident response steps are different — you need vendor contacts, log access procedures, and a way to revoke sessions you do not directly control. Walk through this scenario before you need it. Our guide on building an incident response plan covers the basics. ### The Bigger Picture: Identity Is the New Perimeter The Canada Life data breach is the latest in a clear pattern. ShinyHunters, Scattered Spider, and similar groups have shifted away from exploiting software vulnerabilities and toward exploiting people and their accounts — because that is consistently the easier path. The defensive response is also clear, even if it is not always easy: - Treat every employee identity as a potential breach point - Make MFA strong, and required, for everything that touches customer data - Limit what any one account can do with that data - Watch for the bulk-export, mass-query, and impossible-travel signals that almost always precede a leak Canada's privacy regulators expect organizations to take reasonable security measures under PIPEDA, and federal critical-infrastructure obligations are tightening further under Bill C-26. The Canada Life incident is a reminder that "reasonable" now includes the way you configure the SaaS platforms you trust with your customers' data. If you are not sure where your business stands on identity, access, and SaaS risk, our free Canadian cybersecurity assessment walks through the 13 Baseline Controls and gives you a clear picture of which gaps to close first — without collecting your data, and without a sales call attached. Breaches like Canada Life's will keep happening as long as one stolen password is still enough. The point is to make sure that, in your business, it isn't. ### Frequently Asked Questions — Canada Life Data Breach: What Canadians and Canadian Businesses Need to Know Q: How many people were affected by the Canada Life data breach? A: Canada Life has verified that up to 70,000 individuals had personal information accessed — less than 0.5% of its total customer base, with the majority of affected accounts belonging to a single large corporate group plan customer. The extortion group ShinyHunters has separately claimed access to 5.6 million records in the broader Salesforce environment, but Canada Life has not confirmed that figure and it should be treated as an unverified attacker claim rather than a confirmed exposure count. Q: What information was exposed in the Canada Life data breach? A: According to Canada Life's disclosure, the accessed data included full name, date of birth, mailing address, gender, and annual income level. Canada Life has stated that Social Insurance Numbers, banking details, and medical information were not part of the accessed data. That combination is not enough to directly drain a bank account, but it is sufficient to support targeted phishing, identity verification fraud, and benefits-related social engineering. Q: Who was behind the Canada Life breach and how did they get in? A: ShinyHunters, a financially motivated criminal extortion group, has publicly claimed the intrusion, and multiple security outlets have corroborated the claim. Attribution should be hedged during an active investigation. Canada Life says attackers gained access through a single compromised employee account and used it to query customer data held in its Salesforce CRM environment. This was not a flaw in Salesforce itself — the platform behaved as designed for a legitimate authenticated user. Q: When was the Canada Life data breach disclosed? A: Canada Life identified the cyber incident in mid-April 2026 and disclosed it publicly on April 23, 2026. ShinyHunters had set a ransom deadline of April 21, 2026 with a pay-or-leak demand ahead of public disclosure. Canada Life says the incident has been contained and that operations and services continue normally. Q: What should Canada Life customers do now? A: Canada Life is contacting affected individuals directly and offering free credit monitoring. Watch for that official notification but do not click links in emails claiming to be the breach notice — navigate to canadalife.com directly or call a number from a document you already have. Enrol in the credit monitoring, place free fraud alerts with Equifax Canada and TransUnion Canada, and be sceptical of inbound Canada Life calls and emails for several months. Never provide a password, MFA code, or banking detail to an inbound caller, even one who knows personal details about you. Q: What should Canadian businesses learn from the Canada Life breach? A: The breach shows that a single employee identity is now frequently the entire security perimeter. Five practical steps follow: audit which accounts can bulk-export records from your CRM and other SaaS platforms, move privileged accounts to phishing-resistant MFA such as FIDO2 security keys or passkeys, enable anomaly alerts on bulk data access and impossible-travel logins, train help-desk staff to require verified callbacks before resetting credentials, and confirm your incident response plan covers a SaaS compromise you do not host. --- ## Cybersecurity Laws in Canada: The 2026 Guide for Businesses URL: https://cybersecuritycanada.ca/news/posts/cybersecurity-laws-in-canada-2026-guide-for-businesses/ Category: Compliance Published: April 19, 2026 Summary: A plain-language overview of every cybersecurity and privacy law that applies to Canadian businesses in 2026 — federal, provincial, and sector-specific — and how they connect to the Baseline Controls. There is no single "cybersecurity law" in Canada. The obligations that apply to your business are a combination of federal privacy and anti-spam legislation, provincial privacy statutes, sector-specific rules, and — increasingly — new critical-infrastructure legislation. For most Canadian businesses in 2026, this patchwork is confusing, but the underlying obligations are manageable once you know which laws actually apply and what they expect. This guide maps the Canadian cybersecurity legal landscape as it stands in April 2026, with links to the authoritative sources and practical context for small and medium businesses. ### The Federal Laws Every Canadian Business Should Know #### PIPEDA — Personal Information Protection and Electronic Documents Act PIPEDA is the federal private-sector privacy law. It applies to organizations that collect, use, or disclose personal information in the course of commercial activity — with some important provincial exceptions (see below). In force since 2001 for federal works and since 2004 for all commercial activity, PIPEDA is enforced by the Office of the Privacy Commissioner of Canada (OPC). The core obligations: - Collect only the personal information you need, for purposes you identify to the individual - Obtain meaningful consent - Safeguard personal information with controls appropriate to its sensitivity - Report breaches of security safeguards that create a "real risk of significant harm" to the OPC and affected individuals, and maintain breach records for at least two years - Give individuals access to the information you hold about them on request Failure to report a qualifying breach, or knowingly contravening PIPEDA's breach record-keeping rules, can result in fines of up to $100,000 per violation. We cover the practical implications in depth in New PIPEDA Enforcement: What Changed and What SMBs Must Do Now and in our overview of Canada's privacy landscape. #### CASL — Canada's Anti-Spam Legislation CASL governs commercial electronic messages, the installation of computer programs, and the alteration of transmission data. It is one of the strictest anti-spam and anti-malware laws in the world, and despite its name it is also a cybersecurity law: the provisions on software installation directly target malware, spyware, and unwanted programs. CASL is jointly enforced by the Canadian Radio-television and Telecommunications Commission (CRTC), the Competition Bureau, and the OPC. Penalties reach up to $10 million per violation for organizations. The practical implications for most businesses are: - Obtain consent before sending commercial electronic messages (with narrow exceptions) - Identify the sender clearly and provide a working unsubscribe mechanism - Do not install software on a user's device without express consent and clear disclosure #### Bill C-26 — The Critical Cyber Systems Protection Act Bill C-26 is the most significant new cybersecurity legislation in Canadian federal history. It creates two new regimes: amendments to the Telecommunications Act to allow the government to direct security measures on telecommunications providers, and the new Critical Cyber Systems Protection Act (CCSPA). The CCSPA applies to designated operators in four federally regulated critical infrastructure sectors: telecommunications, finance (federally regulated banks), energy (interprovincial pipelines, nuclear), and transportation (certain federally regulated areas). Designated operators will be required to: - Establish and maintain a cyber security program - Report prescribed cyber security incidents to the Communications Security Establishment - Comply with ministerial directions - Carry out supply chain risk management For businesses not in these sectors, Bill C-26 still matters. Its framework is likely to be influential on how other regulators and insurers think about cyber risk, and the supply chain obligations on designated operators will cascade to their suppliers. We cover this in detail in What Canadian Businesses Need to Know About Bill C-26. #### Criminal Code — Computer and Cyber Offences Sections 342.1 and 430(1.1) of the Criminal Code of Canada criminalize unauthorized use of a computer, possession of passwords or device-making equipment for the purpose of committing offences, and mischief in relation to computer data. These are the provisions under which cybercrime is prosecuted in Canada. For businesses, the Criminal Code matters in three ways: - It is the legal basis on which police can investigate and prosecute attacks against your business - It defines the scope of "authorized" versus "unauthorized" access — relevant to penetration testing, security research, and employee monitoring - Certain activities your own team might perform (such as probing a third party's systems, or acquiring credentials) can cross into criminal territory without proper authorization Any in-house security testing or response activity should be grounded in clear authorization and legal advice. #### Competition Act — Misleading Privacy and Security Claims The Competition Act prohibits false or misleading representations to the public. Recent Competition Bureau activity, both in Canada and from U.S. counterparts such as the FTC, has focused on businesses that misrepresent their cybersecurity posture — for example, claiming "bank-grade encryption" or "fully secure" when the underlying practices fall short. In 2026, your public cybersecurity claims are a compliance surface, not just a marketing surface. ### Provincial Privacy and Cybersecurity Legislation PIPEDA includes an exception: where a province has enacted private-sector privacy legislation that is deemed "substantially similar" to PIPEDA, that provincial law applies within the province. Four provinces have done so. #### Quebec — Law 25 (formerly Bill 64) Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, is now the strictest private-sector privacy law in Canada. Rolled out in phases from 2022 to 2024, it introduced: - Mandatory privacy impact assessments for certain projects - The requirement to designate a Privacy Officer - Breach notification to Quebec's access to information commission (CAI) and to affected individuals - Default privacy settings for technology products - A right to data portability - Restrictions on automated decision-making - Administrative monetary penalties up to the greater of $10 million or 2% of worldwide turnover, and criminal fines up to $25 million or 4% of worldwide turnover Any business operating in Quebec, or handling the personal information of Quebec residents, is subject to Law 25. #### British Columbia — PIPA (Personal Information Protection Act) BC's PIPA applies to private-sector organizations operating in BC. It is generally aligned with PIPEDA but includes a limited right of access to personal employee information and distinct breach notification guidance. Enforcement is by the Office of the Information and Privacy Commissioner for BC. #### Alberta — PIPA Alberta's PIPA is similar to BC's, with a mandatory breach notification requirement to the Alberta Information and Privacy Commissioner when there is a "real risk of significant harm." Alberta was the first Canadian jurisdiction to require mandatory breach notification in the private sector. #### Ontario — Sector-Specific Rather Than General Ontario does not have a general private-sector privacy law; PIPEDA applies to Ontario businesses. However, Ontario has important sector-specific statutes: - PHIPA — Personal Health Information Protection Act: governs custodians of personal health information (hospitals, clinics, pharmacies, many MSPs serving healthcare). Mandatory breach notification to the Information and Privacy Commissioner of Ontario. - FIPPA / MFIPPA: public-sector and municipal-sector privacy laws. If your business serves Ontario healthcare organizations as a service provider, PHIPA obligations often flow through your contracts and you are treated as an "agent" of the health information custodian. #### Other Provincial Regimes Other provinces (Saskatchewan, Manitoba, New Brunswick, Nova Scotia, Newfoundland and Labrador, PEI) rely on PIPEDA for private-sector privacy and have their own public-sector freedom-of-information and privacy statutes. Some have sector-specific health privacy laws (e.g., Manitoba's PHIA, New Brunswick's PHIPAA). ### Sector-Specific Cybersecurity Obligations Even within PIPEDA or provincial privacy legislation, certain sectors have additional cybersecurity obligations imposed by their regulators. #### Financial Services The Office of the Superintendent of Financial Institutions (OSFI) regulates federally regulated financial institutions. OSFI's Guideline B-13 (Technology and Cyber Risk Management) and Technology and Cyber Security Incident Reporting Advisory set cyber risk management expectations and require prompt incident reporting. Provincial credit unions, securities firms, and insurance companies have parallel obligations through the Financial Services Regulatory Authority of Ontario (FSRA), the Autorité des marchés financiers (AMF) in Quebec, the Canadian Investment Regulatory Organization (CIRO), and other bodies. #### Healthcare Provincial health privacy statutes (PHIPA in Ontario, HIA in Alberta, PHIA in Manitoba, and similar laws in other provinces) impose specific safeguard, breach notification, and audit requirements on health information custodians and their agents. #### Public Sector and Government Contractors Federal government contractors may be subject to Contract Security Manual obligations under the Canadian Industrial Security Program, and IT contractors supplying the federal government are increasingly subject to specific cyber security requirements under Innovation, Science and Economic Development Canada (ISED) and Shared Services Canada contracts. #### Telecommunications The Telecommunications Act (as amended by Bill C-26) and CRTC orders can compel telecommunications service providers to take specific security measures, including removing or not using specified products and services. ### How These Laws Connect — And Where Businesses Actually Start For most Canadian SMBs, the practical picture is less overwhelming than the list above suggests. The overlap between these laws is substantial: they all require you to protect personal information with reasonable safeguards, and the controls that meet one generally meet the others. The Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations are the most practical starting point. Implementing the 13 baseline control areas — from incident response to authentication to backup and recovery — directly supports compliance with PIPEDA's safeguard requirement, Quebec Law 25's security obligations, OSFI expectations, and the security program obligations under Bill C-26. If you are not sure where your business stands, our free cybersecurity assessment evaluates your organization against all 13 Baseline Control areas and produces a plain-language report that maps directly to the obligations above. ### What's Likely to Change in 2026–2027 Several developments are worth watching: - CPPA / Bill C-27 — The Consumer Privacy Protection Act, proposed to replace PIPEDA, has been in legislative development through multiple Parliaments. It would introduce significantly higher fines (up to the greater of $25 million or 5% of global turnover), a private right of action, and a data protection tribunal. Its legislative status has shifted multiple times; businesses should track its progress but continue to operate under PIPEDA in the meantime. - AI governance — The proposed Artificial Intelligence and Data Act (AIDA), part of the C-27 package, would create obligations around "high-impact" AI systems. Quebec's Law 25 already covers some of the same ground through its automated decision-making provisions. - Expansion of CCSPA designated sectors — Bill C-26's critical cyber systems regime starts with four sectors, but the framework allows additional sectors to be added by regulation. - Provincial modernization — Expect further amendments to BC's and Alberta's PIPAs, and continued evolution of Quebec's Law 25 through guidance and enforcement. ### Frequently Asked Questions #### Which cybersecurity law applies to my Canadian small business? At minimum, PIPEDA applies to any Canadian private-sector business that handles personal information in the course of commercial activity — unless you operate only within Quebec, BC, or Alberta, where the provincial statute applies instead. CASL applies if you send commercial electronic messages or install software on customer devices. Sector-specific laws (OSFI, PHIPA, Bill C-26's CCSPA) add further obligations for regulated industries. Most small businesses are covered by PIPEDA plus CASL, with provincial law layered on where applicable. #### Does my business have to report a cyber incident to the government? It depends on what happened and what sector you are in. Under PIPEDA, you must report breaches of security safeguards involving personal information to the OPC and affected individuals when there is a "real risk of significant harm." Under Quebec Law 25 and Alberta PIPA, similar thresholds apply to the provincial commissioners. Under OSFI guidance, federally regulated financial institutions must report technology and cyber security incidents promptly. Under Bill C-26's CCSPA, designated operators must report prescribed incidents to the CSE. Healthcare custodians report under provincial health privacy legislation. Outside these regimes, reporting is generally voluntary but strongly recommended to the Canadian Centre for Cyber Security and the Canadian Anti-Fraud Centre. #### How does Quebec's Law 25 differ from PIPEDA? Quebec Law 25 imposes obligations that go beyond PIPEDA in several ways: mandatory privacy impact assessments, a designated Privacy Officer, higher penalties, data portability rights, default privacy settings, stricter consent rules for minors, and explicit rules around automated decision-making. Businesses handling personal information of Quebec residents must comply with Law 25 regardless of where the business is located. #### Does Bill C-26 apply to my small business? Directly, only if your business is a "designated operator" under the Critical Cyber Systems Protection Act — which, at launch, covers federally regulated telecommunications, finance, energy, and transportation entities. Most Canadian SMBs are not designated operators. Indirectly, Bill C-26 matters if you supply services to designated operators: their supply chain obligations are likely to flow down to you contractually. #### What is the maximum fine for violating Canadian cybersecurity laws? It varies by law. PIPEDA tops out at $100,000 per violation. CASL reaches $10 million per violation for organizations. Quebec Law 25 reaches the greater of $25 million or 4% of worldwide turnover for criminal offences. The proposed CPPA would bring federal fines to the greater of $25 million or 5% of global turnover. Bill C-26's CCSPA includes administrative monetary penalties and criminal fines for designated operators. In practice, the largest financial impact for most businesses comes not from direct regulatory fines but from incident response costs, remediation, and reputational damage. #### Do I need a lawyer to be compliant? Most small businesses can meet their baseline obligations without a standing legal relationship, by implementing the CCCS Baseline Controls, maintaining a privacy policy, documenting consent practices, and establishing a basic breach response process. Legal advice becomes important when you expand into regulated sectors, handle particularly sensitive data, respond to a breach, or structure contracts with customers or suppliers. The cost of a one-time legal review of your privacy and incident response documentation is typically modest and well worth it. --- ## Cybersecurity Certifications in Canada: CyberSecure Canada and the Professional Credentials That Matter URL: https://cybersecuritycanada.ca/news/posts/cybersecurity-certifications-in-canada-cybersecure-canada-and-professional-credentials/ Category: Guide Published: April 11, 2026 Summary: An overview of the cybersecurity certifications that matter in Canada in 2026 — the CyberSecure Canada program for organizations, and the professional credentials (CISSP, CISM, CISA, GIAC, CompTIA) businesses should look for when hiring or vetting providers. Cybersecurity certifications in Canada fall into two distinct categories, and they are often confused. Organizational certifications tell customers and regulators that your business meets a defined security standard. Professional certifications tell you that a person — an employee, a contractor, an MSP technician — has a defined baseline of skills and knowledge. Both matter. They answer different questions. This guide covers the certifications that Canadian businesses encounter most often in 2026, with a focus on what is recognized in Canada, what each certification actually verifies, and where small and medium businesses should start. ### Organizational Certifications — Proving Your Business Meets a Standard #### CyberSecure Canada CyberSecure Canada is the federal government's certification program for small and medium organizations, administered by Innovation, Science and Economic Development Canada (ISED) and the Standards Council of Canada. It is built directly on the Canadian Centre for Cyber Security's Baseline Cyber Security Controls. What certification requires: - Implement the 13 Baseline Control areas, from incident response through to portable media controls - Undergo assessment by an accredited certification body - Maintain the controls on an ongoing basis, with renewal every two years Why it matters for Canadian SMBs: - It is the only Canadian government-backed cybersecurity certification designed specifically for small and medium organizations - It is increasingly referenced in federal and provincial procurement - Customers and partners use it as an objective signal that baseline controls are in place - It provides a clear roadmap — the 13 Baseline Controls — for organizations that don't know where to start Cost and timeline vary by organization size and complexity. For most SMBs, preparing for CyberSecure Canada certification takes several months of implementation work, followed by assessment. Our free cybersecurity assessment uses the same 13-control structure and is a useful first step to understand where your business stands before engaging a certification body. Cybersecurity Canada is an independent resource and is not affiliated with or endorsed by the CyberSecure Canada program or ISED. #### ISO/IEC 27001 ISO/IEC 27001 is the international standard for information security management systems (ISMS). It is sector-neutral, globally recognized, and widely required by enterprise customers as a condition of doing business. ISO 27001 certification is more rigorous — and more expensive — than CyberSecure Canada. It requires an organization to establish a formal ISMS, define a risk treatment process, implement controls from Annex A, and undergo audits by an accredited certification body. It is the baseline expectation for many Canadian technology vendors, MSPs, and service providers targeting mid-market and enterprise customers. #### SOC 2 SOC 2 (System and Organization Controls 2) is an attestation report produced by a licensed CPA firm, evaluating a service organization's controls across five "trust service criteria": security, availability, processing integrity, confidentiality, and privacy. SOC 2 Type I is a point-in-time snapshot. SOC 2 Type II is an examination over a period of time (typically 6–12 months) and is the version most enterprise buyers require. It is especially common among Canadian SaaS companies and cloud service providers selling to U.S. customers. #### PCI DSS If your business accepts, processes, stores, or transmits credit card information, you are subject to the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is not a government law but a contractual requirement imposed by the card brands (Visa, Mastercard, American Express, Discover, JCB). Validation requirements scale with transaction volume, from self-assessment questionnaires for small merchants to full on-site audits for the largest. #### Sector-Specific - OSFI-regulated financial institutions: OSFI's Guideline B-13 sets expectations that are effectively certification-adjacent, with supervisory examinations rather than third-party certification - Canadian Industrial Security Program (federal contractors): facility and personnel security clearances required for classified contracts - ITSG-33 (federal IT systems): the CCCS's security control framework for federal government systems ### Professional Certifications — Evaluating Individuals For businesses hiring cybersecurity staff or vetting an MSP or MSSP, professional certifications are a practical signal. They are not a replacement for interviewing, checking references, and evaluating actual work — but the absence of any recognized certification on a senior security role is a legitimate concern in 2026. #### The Senior and Strategic Tier CISSP — Certified Information Systems Security Professional ISC2 The most widely recognized senior cybersecurity certification globally. CISSP requires a broad, manager-level understanding across eight domains — from asset security to software development security — plus five years of verified professional experience. In Canada, CISSP is the default expectation for senior security roles in most mid-to-large organizations and is frequently specified in federal government competitions. CISM — Certified Information Security Manager (ISACA) CISM is management-oriented, focused on information security program governance, risk management, and incident management. It is common among CISOs, security managers, and heads of compliance. CISA — Certified Information Systems Auditor (ISACA) CISA is the standard credential for IT auditors. If your organization is engaging an internal audit or external auditor to review cybersecurity controls, CISA is the baseline credential to look for. CRISC — Certified in Risk and Information Systems Control (ISACA) Focused on IT risk management and the implementation of risk-based controls. Increasingly common among risk and compliance professionals. CISSP-ISSAP / ISSEP / ISSMP ISC2 CISSP concentrations in architecture, engineering, and management respectively. Relevant for senior specialist and principal-level roles. #### The Hands-On Technical Tier GIAC Certifications (SANS Institute) GIAC certifications are tightly aligned with SANS training courses and are widely considered the most rigorous hands-on credentials in the industry. Most relevant to Canadian SMBs: - GSEC (Security Essentials) — practical security foundations - GCIH (Certified Incident Handler) — incident response skills - GCFA / GNFA (Forensic Analyst / Network Forensic Analyst) — digital forensics - GPEN / GWAPT (Penetration Tester / Web Application Penetration Tester) — offensive security - GSLC (Security Leadership) — for technical leaders SANS operates in Canada, and GIAC-certified professionals are often found at Canadian MSSPs, government security teams, and mature enterprise security functions. OSCP — Offensive Security Certified Professional A hands-on penetration testing certification requiring candidates to compromise a series of lab systems under time pressure. Widely respected as a working-level offensive security credential. Often required for Canadian penetration testing firms. CEH — Certified Ethical Hacker (EC-Council) CEH is more theoretical than OSCP and less hands-on than GIAC certifications, but remains commonly referenced in job postings and contract requirements, particularly in government. #### The Entry and Foundational Tier CompTIA Security+ / Network+ / A+ CompTIA's certifications are vendor-neutral and form a common baseline for early-career IT and security professionals. Security+ is frequently required for entry-level roles, and the U.S. Department of Defense Cyber Workforce Framework (DoD 8140, which replaced the earlier 8570 directive) recognizes Security+ as a baseline credential. CompTIA CySA+, PenTest+, SecurityX (formerly CASP+) Intermediate-to-advanced CompTIA credentials that bridge into the professional tier. ISC2 CC — Certified in Cybersecurity A newer entry-level credential from ISC2, designed to be a stepping-stone toward CISSP. #### Vendor and Platform Certifications Cloud and platform certifications matter significantly for businesses running on Microsoft, Google, or AWS: - Microsoft Certified: Security Operations Analyst Associate (SC-200) — hands-on Microsoft 365 and Azure security - Microsoft Certified: Cybersecurity Architect Expert (SC-100) — senior architecture role - Microsoft Identity and Access Administrator (SC-300) — identity-focused - Google Professional Cloud Security Engineer — Google Cloud Platform security - AWS Certified Security – Specialty — AWS-specific security knowledge - Cisco CCNP Security — network security with Cisco stack - Palo Alto PCNSE — firewall and next-generation security For a Canadian SMB running on Microsoft 365, an MSP engineer with SC-200 or SC-300 is meaningfully more capable in your environment than one without. Ask. #### Privacy-Specific Certifications IAPP — International Association of Privacy Professionals - CIPP/C (Canadian Privacy) — the only privacy certification specific to Canadian privacy law (PIPEDA, provincial statutes) - CIPP/E (European Privacy) — GDPR focus - CIPM (Certified Information Privacy Manager) — privacy program management - CIPT (Certified Information Privacy Technologist) — technical privacy For Canadian businesses with material privacy obligations under PIPEDA or Quebec Law 25, CIPP/C is the most directly relevant credential for a Privacy Officer. ### Canadian Training and Academic Programs Several Canadian institutions offer recognized cybersecurity degrees and professional programs: - Concordia University (Montreal) — Institute for Information Systems Engineering, undergraduate and graduate cybersecurity programs - University of New Brunswick — Canadian Institute for Cybersecurity, a leading research institute - University of Waterloo — Cybersecurity and Privacy Institute, research and graduate programs - Rogers Cybersecure Catalyst (Toronto Metropolitan University) — professional training and women-in-cybersecurity programs - BCIT (Burnaby) — applied cybersecurity programs widely recognized by BC employers - Seneca Polytechnic, SAIT, NAIT, and other colleges — applied cybersecurity diplomas and degrees The Information and Communications Technology Council (ICTC) runs CyberTitan through the Cyber Foundations initiative, with support from the Communications Security Establishment and other partners, as part of broader efforts to build the Canadian cybersecurity workforce. ### What Matters Most for Canadian SMBs If you are not buying enterprise software and not hiring a cybersecurity team, most of the certifications above are not directly relevant to you. The three that typically do matter: - CyberSecure Canada — for demonstrating to customers, regulators, and insurers that your organization has implemented the Canadian Baseline Controls - CISSP, CISM, or GIAC (GCIH/GSEC) — to look for when vetting a cybersecurity provider or MSP's senior staff - CIPP/C — if your business has meaningful privacy obligations and is designating a Privacy Officer Everything else is context-dependent. A certification is a signal, not a guarantee. Ask what the person or organization has actually done, not just what they hold. ### Starting Point: Know Where You Stand Before pursuing a certification — organizational or individual — it is worth knowing where your business stands today. The Canadian Centre for Cyber Security's Baseline Controls are the most practical starting framework, and our free cybersecurity assessment evaluates your organization across all 13 Baseline Control areas in under 30 minutes. The results map directly to CyberSecure Canada and serve as a realistic pre-check before engaging a certification body. For deeper context on the 13 Baseline Controls and how they fit into Canadian cybersecurity law and practice, see our guides on understanding Canada's Baseline Cyber Security Controls and the cybersecurity laws that apply to Canadian businesses in 2026. ### Frequently Asked Questions #### Is CyberSecure Canada worth pursuing for a small business? For most Canadian SMBs, yes — particularly those selling to government, regulated industries, or enterprise customers that ask about security posture. It provides an independent, government-recognized validation of the 13 Baseline Controls and is less costly and less complex than ISO 27001. If your customers are not asking about security certifications today, a practical first step is to implement the Baseline Controls internally; certification can follow when the business case emerges. #### What is the difference between CyberSecure Canada and ISO 27001? CyberSecure Canada is built specifically for small and medium Canadian organizations and is based on a defined set of 13 baseline controls. ISO 27001 is an international, sector-neutral standard that requires a full information security management system (ISMS) and a risk-based approach to control selection. ISO 27001 is more flexible and more rigorous, typically required by enterprise and international customers. CyberSecure Canada is more prescriptive and more approachable for SMBs. Many organizations start with CyberSecure Canada and progress to ISO 27001 as they grow. #### Which cybersecurity certification should I hire for? It depends on the role. For a strategic or managerial security hire: CISSP, CISM, or CIPP/C (for privacy-focused roles). For a hands-on analyst or incident responder: GCIH, GSEC, Security+, or SC-200 (for Microsoft environments). For a penetration tester: OSCP. For an auditor: CISA. Certifications are a starting filter; actual interview, reference, and practical assessment matter more. #### Are Canadian cybersecurity certifications recognized internationally? Most professional certifications relevant in Canada — CISSP, CISM, CISA, GIAC, OSCP, CompTIA, CIPP — are internationally recognized. CyberSecure Canada is a Canadian government program and is not directly recognized outside Canada, but it maps closely to international baseline frameworks (CIS Controls, NIST CSF) and provides equivalent evidence of security posture for most purposes. #### Does my MSP need to be certified? There is no Canadian law requiring MSPs to hold a specific certification, but there are strong reasons to prefer certified providers. An MSP holding ISO 27001 or SOC 2 Type II has subjected its own operations to independent audit, which is particularly relevant because an MSP is a high-value target whose security posture directly affects yours. Asking about your MSP's certifications — and the credentials of the senior staff who will actually manage your environment — is part of responsible vendor and third-party risk management. --- ## A Brief History of Cybersecurity in Canada: From Cold War Signals Intelligence to the Canadian Centre for Cyber Security URL: https://cybersecuritycanada.ca/news/posts/history-of-cybersecurity-in-canada/ Category: Insights Published: April 4, 2026 Summary: Canada's cybersecurity institutions have a long, specific history — from the Second World War signals intelligence agency that became CSE, through PIPEDA and the Heartbleed era, to the Canadian Centre for Cyber Security and Bill C-26. A timeline for businesses and citizens. Canadian cybersecurity did not begin in 2018 with the establishment of the Canadian Centre for Cyber Security. It is the latest chapter in an institutional history that stretches back to the signals intelligence agencies of the Second World War, through the early internet era, and into the modern regulatory landscape that Canadian businesses operate in today. Understanding that history is useful. It explains why Canadian cybersecurity policy is shaped the way it is, why certain agencies have the mandates they do, and why the country's cyber legal framework is a patchwork of federal and provincial legislation rather than a single statute. This article is a plain-language timeline. ### 1941–1975: Signals Intelligence and the Origins of CSE Canada's modern cybersecurity institutions trace back to the Examination Unit, established in 1941 as a civilian signals intelligence organization cooperating with British and American counterparts during the Second World War. After the war, Canadian signals intelligence work continued under the National Research Council as the Communications Branch of the National Research Council (CBNRC), founded in 1946. On April 1, 1975, CBNRC was transferred from the National Research Council to the Department of National Defence and renamed the Communications Security Establishment (CSE). CSE's dual mandate — foreign signals intelligence and the protection of Government of Canada electronic information and infrastructure — is the foundation of Canadian cybersecurity to this day. ### 1988–2001: The Birth of the Public Internet and the First Canadian Cyber Laws Through the 1980s and into the 1990s, Canada's cybersecurity work was almost entirely a government-to-government concern. Civilian awareness of the field was limited. That began to change with the public adoption of the internet. Two pieces of legislation from this era remain foundational: - The Criminal Code amendments of 1985 and later updates introduced the Canadian offences for unauthorized use of a computer (section 342.1) and mischief in relation to computer data (section 430(1.1)). These provisions remain the legal basis for cybercrime prosecution in Canada. - The Personal Information Protection and Electronic Documents Act (PIPEDA) received Royal Assent on April 13, 2000, and came into force in stages between 2001 and 2004. PIPEDA established Canada's federal framework for private-sector privacy and would later become the default statute under which Canadian businesses must safeguard personal information. In the same period, the first provincial private-sector privacy statutes began to emerge — Quebec's original private-sector privacy act dates to 1993 and was the first of its kind in North America. ### 2001–2013: Early-Era Threats and the Advisory State The decade after 9/11 saw the rapid growth of the commercial internet in Canada and a corresponding rise in cybercrime. Canadian cybersecurity policy during this period was largely advisory. CSE and Public Safety Canada published guidance, but there was no single national cyber strategy until 2010, when the federal government released Canada's Cyber Security Strategy — a three-pillar policy document focused on securing government systems, partnering with industry, and helping Canadians. In 2010, Canada also enacted Canada's Anti-Spam Legislation (CASL), among the strictest anti-spam and anti-malware laws in the world. CASL came into force in stages starting July 1, 2014, and remains jointly enforced by the CRTC, the Competition Bureau, and the OPC. Public Safety Canada's Canadian Cyber Incident Response Centre (CCIRC) was established during this period to coordinate response to cyber incidents affecting Canadian critical infrastructure. ### 2014: Heartbleed and a Canadian Watershed On April 7, 2014, researchers publicly disclosed Heartbleed, a vulnerability in the widely used OpenSSL cryptographic library. Within days, the Canada Revenue Agency announced that its systems had been compromised as a result, with approximately 900 Social Insurance Numbers exfiltrated. The CRA extended the tax filing deadline, an unprecedented measure. The CRA Heartbleed incident was a turning point. For the first time, a Canadian federal cybersecurity event became a top national news story, demonstrating to both government and the public that cyber risk was not theoretical. The RCMP's investigation led to the arrest of a 19-year-old London, Ontario man — one of the first high-profile cybercrime prosecutions in Canada. ### 2015–2018: Rising Threats, Rising Institutions The years after Heartbleed brought a steady stream of high-impact incidents affecting Canadian organizations and a corresponding institutional response. - Digital Privacy Act (2015): PIPEDA was amended to strengthen consent, add mandatory breach notification (which came into force in November 2018), and introduce record-keeping obligations. - Canadian Centre for Cyber Security (2018): On October 1, 2018, the federal government consolidated cybersecurity operations from CSE, Public Safety Canada (CCIRC), and Shared Services Canada into a single, unified authority — the Canadian Centre for Cyber Security (CCCS). The CCCS became Canada's single authoritative source for cyber security advice, guidance, services, and support. - Baseline Cyber Security Controls (2019): The CCCS published the first version of the Baseline Cyber Security Controls for Small and Medium Organizations — the 13-control framework that has since become the foundation for Canadian SMB cybersecurity practice and for the CyberSecure Canada certification program. - CSE Act (2019): The Communications Security Establishment Act, enacted as part of Bill C-59 and coming into force in August 2019, gave CSE its first stand-alone statutory mandate, including explicit authority for defensive and active cyber operations abroad. ### 2019: LifeLabs — The Largest Canadian Privacy Breach In December 2019, LifeLabs — one of Canada's largest medical diagnostic laboratory companies — disclosed a cyberattack that exposed the personal and health information of approximately 15 million Canadians. Data accessed included names, addresses, dates of birth, health card numbers, and lab test results going back to 2016. The joint investigation by the Information and Privacy Commissioner of Ontario and the Office of the Information and Privacy Commissioner for BC concluded that LifeLabs had failed to take reasonable steps to protect the personal health information in its custody. The incident remains, by volume of affected individuals, the largest privacy breach in Canadian history. For Canadian regulators and businesses, the LifeLabs incident reinforced that PIPEDA and provincial privacy laws apply at real scale, that the Office of the Privacy Commissioner of Canada and its provincial counterparts are willing to investigate jointly, and that the cost of cyber incident response and litigation can be substantial. ### 2020–2022: Pandemic, Ransomware, and the Municipal Wave The COVID-19 pandemic accelerated digital transformation across Canadian organizations, pushed remote work into nearly every sector, and expanded the attack surface accordingly. The same period saw the rise of ransomware-as-a-service and a wave of high-impact attacks on Canadian municipalities, hospitals, and critical infrastructure: - Saint John, NB (2020): ransomware shut down the city's IT systems for weeks - Newfoundland and Labrador Health (2021): cyberattack on the provincial health system disrupted services for months - Several Ontario municipalities: a recurring pattern of local-government ransomware incidents throughout 2020–2022 - Global Affairs Canada (2022): cyberattack disrupted internet-based services - Indigo Books & Music (2023): ransomware attack, publicly disclosed refusal to pay the ransom These incidents shaped Canadian cybersecurity policy discussion through the early 2020s and informed the direction of federal legislation that followed. ### 2022: Quebec's Law 25 Raises the Bar Quebec tabled Bill 64 in June 2020 and passed it in September 2021, with phased entry-into-force beginning September 2022. The resulting amendments to Quebec's private-sector privacy act — now widely known as Law 25 — introduced privacy obligations that exceed PIPEDA in several areas, including mandatory privacy impact assessments, data portability rights, and administrative monetary penalties reaching into the tens of millions of dollars. Law 25 effectively set a new de facto standard for private-sector privacy in Canada and accelerated federal discussion of PIPEDA modernization. ### 2022–2024: Bill C-26 and the Critical Cyber Systems Protection Act On June 14, 2022, the federal government introduced Bill C-26, creating two new regimes: amendments to the Telecommunications Act and the new Critical Cyber Systems Protection Act (CCSPA). The CCSPA, once in force, will impose cyber security program requirements and mandatory incident reporting on designated operators in federally regulated telecommunications, finance, energy, and transportation sectors. Bill C-26 represented the most significant federal cybersecurity legislation in Canadian history — the first statutory obligation on private-sector critical infrastructure operators to implement a defined cyber security program. We cover the implications in depth in What Canadian Businesses Need to Know About Bill C-26. ### 2023–2026: AI, Supply Chain, and the Modern Threat Landscape The most recent years of Canadian cybersecurity history are still being written. Three themes define the current period: - Generative AI and the phishing arms race: AI-generated phishing emails, voice clones, and deepfakes have dramatically raised the quality and scale of social engineering attacks, as we cover in AI-Powered Phishing: What's Changed for Canadian Businesses. - Supply chain compromises: The SolarWinds (2020), Kaseya (2021), 3CX (2023), and Notepad++ (2025) compromises demonstrated that attackers reaching Canadian organizations through trusted software channels is now the norm, not the exception. - Regulatory convergence: The proposed Consumer Privacy Protection Act (Bill C-27), the proposed Artificial Intelligence and Data Act (AIDA), and the operationalization of Bill C-26 are pulling Canadian privacy and cybersecurity law toward a more integrated, more enforceable framework — one that is closer to the European Union's GDPR and NIS2 regimes than the historically lighter-touch Canadian approach. ### Where Things Stand Today As of April 2026, the Canadian cybersecurity landscape that businesses operate in is defined by: - The Canadian Centre for Cyber Security as the federal authority for cyber advice and defensive operations - A layered legal framework — PIPEDA, CASL, Bill C-26's CCSPA, provincial privacy legislation, sector-specific regulation — covered in detail in our 2026 guide to Canadian cybersecurity laws - The Baseline Controls as the most practical framework for SMB cybersecurity, and CyberSecure Canada as its certification expression - A mature but underused civilian reporting ecosystem — the CCCS, the Canadian Anti-Fraud Centre, the RCMP's National Cybercrime Coordination Unit (NC3), and provincial privacy commissioners Our free cybersecurity assessment evaluates your business against the CCCS Baseline Controls — the framework that sits at the centre of this history and defines the expectations applied to Canadian businesses today. ### Frequently Asked Questions #### When was the Canadian Centre for Cyber Security established? The Canadian Centre for Cyber Security (CCCS) was established on October 1, 2018, as part of the Communications Security Establishment. It consolidated the cybersecurity functions of CSE's IT Security Program, Public Safety Canada's Canadian Cyber Incident Response Centre (CCIRC), and Shared Services Canada's Security Operations Centre into a single federal authority for cyber advice and defensive operations. #### What was the first major cybersecurity incident in Canada? Cybercrime affecting Canadian organizations predates public awareness of "cybersecurity" as a category, but the first incident to become a top national news story was the 2014 Canada Revenue Agency breach caused by the Heartbleed OpenSSL vulnerability. Approximately 900 Social Insurance Numbers were exfiltrated, the CRA extended the tax filing deadline, and the RCMP arrested a 19-year-old Canadian who was subsequently charged under section 342.1 of the Criminal Code. #### What is the largest privacy breach in Canadian history? By the number of affected individuals, the 2019 LifeLabs breach is the largest privacy incident in Canadian history, exposing personal and health information for approximately 15 million Canadians. A joint investigation by the Ontario and British Columbia privacy commissioners concluded that LifeLabs had failed to take reasonable steps to protect the information. #### When did PIPEDA come into force? PIPEDA received Royal Assent on April 13, 2000, and came into force in stages between 2001 and 2004. Mandatory breach notification to the Office of the Privacy Commissioner of Canada was added by the Digital Privacy Act (2015) and came into force on November 1, 2018. #### What is the difference between CSE and CCCS? The Communications Security Establishment (CSE) is Canada's foreign signals intelligence and communications security agency, established in its current form in 1975. The Canadian Centre for Cyber Security (CCCS) is a part of CSE established in 2018 and is the public-facing federal authority for cybersecurity advice, defence, and partnership with industry. In everyday usage, CSE is the agency; CCCS is the specific arm of CSE that Canadian businesses and the public interact with on cyber security matters. --- ## Understanding CVSS Scores: What the Numbers Behind Software Vulnerabilities Actually Mean URL: https://cybersecuritycanada.ca/news/posts/understanding-cvss-scores-what-the-numbers-behind-software-vulnerabilities-mean/ Category: Insights Published: March 30, 2026 Summary: When a vulnerability is rated 8.8 or 10.0, what does that actually mean for your business? Here's a plain-language guide to CVSS scores and why they matter. In March 2026, Google issued an emergency security update for Chrome — its browser used by an estimated 3.5 billion people worldwide — patching two zero-day vulnerabilities that were already being exploited in the wild. Around the same time, a flaw in the Erlang/OTP SSH server received the highest possible severity rating: a perfect 10.0 out of 10. And in February 2026, a vulnerability in Windows Notepad was rated 8.8 out of 10. If you run a business, you have probably seen these numbers in headlines. But what do they actually mean? And how should they change the way you respond? ### What Is a CVSS Score? CVSS stands for the Common Vulnerability Scoring System. It is an open, standardized framework maintained by FIRST.org that assigns a numerical score to security vulnerabilities on a scale from 0.0 to 10.0. The higher the number, the more severe the flaw. Think of it like a severity rating for a building code violation. A score of 2.0 might be a loose handrail. A score of 10.0 means the foundation is compromised and the building could collapse at any moment. The current widely used version is CVSS v3.1, with CVSS v4.0 now being adopted. The numeric scale and severity categories are the same across both versions: | | Rating | Score Range | None | 0.0 | Low | 0.1 – 3.9 | Medium | 4.0 – 6.9 | High | 7.0 – 8.9 | Critical | 9.0 – 10.0 When you see a headline that says a vulnerability scored 8.8, that places it squarely in the High category. A score of 10.0 is the worst possible rating — Critical — and it means the flaw is as dangerous as it gets. ### What Goes Into the Score A CVSS score is not a single judgment call. It is calculated from a set of specific metrics that describe how the vulnerability works and what damage it can cause. Understanding these metrics — even at a high level — helps you assess how a given flaw might affect your business. #### How the Attacker Gets In - Attack Vector — Can it be exploited over the internet (Network), or does the attacker need physical access to the device? Network-based attacks are the most dangerous because they can be launched from anywhere in the world. - Attack Complexity — Is exploitation straightforward, or does the attacker need specific conditions to be in place? Low complexity means more attackers can pull it off. - Privileges Required — Does the attacker need an existing account on the system, or can anyone exploit it without logging in? - User Interaction — Does someone need to click a link or open a file, or can the attack happen without any human action? #### Does the Damage Spread Beyond the Vulnerable System? - Scope — Can the vulnerability be used to attack other systems beyond the one that is directly vulnerable? When Scope is "Changed," the blast radius extends beyond the original target — for example, escaping a virtual machine to compromise the host server. #### What the Attacker Can Do - Confidentiality Impact — Can the attacker read data they should not have access to? - Integrity Impact — Can the attacker modify or tamper with data or systems? - Availability Impact — Can the attacker take the system offline or make it unusable? When all of these metrics are at their worst — remote access, low complexity, no privileges needed, no user interaction, damage that spreads beyond the vulnerable system, and full impact to confidentiality, integrity, and availability — the result is a 10.0. Remove any one of those factors and the score drops. For example, if everything is worst-case but the damage stays contained to the vulnerable system (Scope: Unchanged), the score drops to 9.8. ### Real Examples: What 8.8 and 10.0 Look Like in Practice #### CVSS 8.8 — Windows Notepad Vulnerability (CVE-2026-20841) In February 2026, Microsoft patched a flaw in Windows Notepad that allowed an attacker to execute commands on a victim's computer through a specially crafted Markdown file. Here is why it scored 8.8: - Attack Vector: Network — the malicious file could be delivered via email or a website - Privileges Required: None — the attacker did not need an account on the victim's system - User Interaction: Required — the victim had to open the file and click a link - Impact: High across all three categories — full control of the system was possible The user interaction requirement is what kept this from being a 9.0 or higher. The attacker needed the victim to take an action. That single factor — one click — was the difference between High and Critical. This is exactly why security awareness training matters. That one click is your last line of defence. #### CVSS 10.0 — Erlang/OTP SSH Remote Code Execution (CVE-2025-32433) In April 2025, researchers at Ruhr University Bochum discovered a flaw in the Erlang/OTP SSH server that was widely reported with a CVSS score of 10.0 — the maximum possible rating. (The exact score varies slightly depending on the assessing organization — the GitHub Advisory database assigned 10.0, while some other sources scored it 9.8 — but either way, it is firmly Critical.) Here is why it scored so high: - Attack Vector: Network — exploitable from anywhere on the internet - Attack Complexity: Low — straightforward to exploit - Privileges Required: None — no authentication needed at all - User Interaction: None — no human action required - Scope: Changed — the vulnerability could be used to compromise systems beyond the SSH server itself - Impact: High across confidentiality, integrity, and availability — complete system compromise The flaw allowed an unauthenticated attacker to send SSH messages before the authentication step completed. Because SSH servers often run with root (administrator) privileges, a successful exploit gave the attacker full control of the system. Security firm Horizon3.ai described creating a working exploit as "surprisingly easy." This vulnerability affected products from Cisco, Ericsson, Broadcom, and any application using the Erlang/OTP SSH library. CISA added it to its Known Exploited Vulnerabilities catalog in June 2025, confirming it was being actively exploited in the wild. Every metric was at its worst-case value. That is what a 10.0 looks like. #### CVSS 8.8 — Google Chrome Zero-Days (March 2026) Google's March 2026 Chrome updates addressed multiple vulnerabilities rated High severity, including two zero-days — CVE-2026-3909 (an out-of-bounds write in the Skia graphics library) and CVE-2026-3910 (a type confusion flaw in the V8 JavaScript engine) — that were already being actively exploited before the patch was available. Both were later scored CVSS 8.8 by the National Vulnerability Database. CISA added both to its Known Exploited Vulnerabilities catalog on March 13, 2026. A separate update later in March patched eight additional High-severity vulnerabilities across Chrome's WebAudio, CSS, WebGL, Dawn, WebGPU, Fonts, and FedCM components. While none of those eight were confirmed as actively exploited at the time of disclosure, the vulnerability types involved — heap buffer overflows and use-after-free flaws — are commonly weaponized for remote code execution. With an estimated 3.5 billion users worldwide, a single unpatched Chrome vulnerability represents one of the largest attack surfaces on the planet. ### Why This Matters for Your Business You do not need to memorize the CVSS formula. But understanding the difference between a 6.5, an 8.8, and a 10.0 helps you make better decisions about how urgently to respond. Here is a practical framework: - Critical (9.0–10.0): Drop what you are doing. These vulnerabilities can be exploited remotely, often without any user interaction, and give attackers full control. Patch immediately — within hours, not days. - High (7.0–8.9): Patch within days. These are serious flaws that require some condition to be met (like a user clicking a link), but attackers will actively try to create those conditions through phishing and social engineering. - Medium (4.0–6.9): Patch within your regular update cycle. These are real risks but typically require more specific conditions or produce limited impact. - Low (0.1–3.9): Address during routine maintenance. These flaws exist but are difficult to exploit or cause minimal damage. This is not just a technology decision. It is a business decision. A Critical vulnerability in a system that handles your customer data is a different priority than a Critical vulnerability in a tool nobody uses. ### How CVSS Connects to the Baseline Controls If you are thinking "this sounds like a lot to track," you are right. That is exactly why the Canadian Centre for Cyber Security includes Patch Management (BC.2) as one of the 13 Baseline Cyber Security Controls for small and medium organizations. CVSS scores are the tool that makes patch management practical — they tell you what to fix first. But patching is only part of the picture. The Baseline Controls work together: - Patch Management (BC.2) — Use CVSS scores to prioritize which patches to apply first. Critical and High vulnerabilities in internet-facing systems go to the front of the line. - Secure Configuration (BC.4) — Reduce your attack surface so there are fewer vulnerabilities to worry about. Disable features you do not use, remove software you do not need. - Network Security (BC.9) — Limit what is exposed to the internet. A CVSS 10.0 vulnerability in a system that is not internet-accessible is still serious, but the risk is substantially lower. - Security Awareness (BC.6) — For vulnerabilities that require user interaction (like the Notepad flaw), trained employees are your last line of defence. - Anti-Malware (BC.3) — Even when a vulnerability is exploited, anti-malware tools can detect and block the resulting payload. - Incident Response (BC.1) — When a Critical vulnerability is being actively exploited and you cannot patch immediately, your incident response plan determines how quickly you can contain the damage. The pattern across every recent headline — Chrome, Notepad, Erlang/OTP — is the same. A vulnerability is discovered, a severity score is assigned, a patch is released, and attackers begin exploiting unpatched systems. The organizations that respond quickly are the ones that have these controls already in place. ### What You Should Do #### 1. Make Sure Your Software Updates Automatically The most important defence against high-severity vulnerabilities is ensuring patches are applied promptly. For browsers like Chrome, enable automatic updates. For operating systems and business applications, work with your IT team or managed service provider to ensure updates are deployed on a predictable schedule. #### 2. Know Your Prioritization Framework Not every patch needs to be applied on the same day. But you need a process for identifying which ones do. If your IT provider tells you a Critical vulnerability has been disclosed in software you use, that is a same-day conversation — not a next-week ticket. #### 3. Reduce What Is Exposed Every application, service, and open port is a potential target. The fewer internet-facing systems you run, the fewer Critical vulnerabilities you need to worry about. Audit what is exposed and disable what you do not need. #### 4. Train Your People Vulnerabilities that require user interaction — and many High-severity flaws do — rely on someone clicking, opening, or approving something they should not. Regular security awareness training reduces that risk. #### 5. Assess Where You Stand If you are not sure whether your business has a reliable patch management process, or whether your other security controls are in place, our free assessment evaluates your organization against all 13 of the Canadian Centre for Cyber Security's Baseline Control areas and gives you a clear picture of what needs attention. ### The Bottom Line CVSS scores are not just numbers for IT teams to worry about. They are a standardized way of communicating risk — and understanding them helps you ask the right questions, set the right priorities, and protect your business from the vulnerabilities that matter most. The next time you see a headline about a vulnerability rated 9.8 or 10.0, you will know exactly what that means: patch now, ask questions later. --- ## How to Choose a Cybersecurity Provider for Your Canadian Small Business URL: https://cybersecuritycanada.ca/news/posts/how-to-choose-a-cybersecurity-provider-for-your-canadian-small-business/ Category: Guide Published: March 24, 2026 Summary: Managed service providers, MSSPs, consultants, and vCISOs — the options for outsourced cybersecurity are growing. Here's how Canadian small businesses can evaluate providers, ask the right questions, and avoid common mistakes. Most Canadian small businesses don't have a dedicated cybersecurity team. For businesses with fewer than 50 employees, cybersecurity is typically managed internally — often meaning one IT generalist or the business owner themselves. At some point, that stops being enough. Whether it's a near-miss phishing incident, a cyber insurance application requiring controls you can't implement alone, or the realization that nobody is actually monitoring your systems, many businesses reach a point where outside help makes sense. The challenge is that the cybersecurity services market is confusing. Terminology varies, sales pitches are heavy on fear and acronyms, and it's difficult to evaluate providers when you don't have deep security expertise yourself. Here's how to navigate it. ### Understanding the Types of Providers The first decision is understanding what kind of help you actually need. The terms are used loosely in the industry, but here's what they generally mean: #### Managed Service Provider (MSP) An MSP manages your IT infrastructure — computers, network, email, cloud services, backups, and helpdesk support. Most MSPs include some level of security as part of their standard offering: antivirus, firewalls, patching, and basic monitoring. For many small businesses, an MSP is the starting point. The risk is assuming that general IT management equals adequate cybersecurity. An MSP that sets up your firewall is not necessarily monitoring it for threats at 2 a.m. #### Managed Security Service Provider (MSSP) An MSSP focuses specifically on security. Services typically include 24/7 threat monitoring, security information and event management (SIEM), endpoint detection and response (EDR), vulnerability scanning, and incident response support. MSSPs are more specialized and more expensive than general MSPs. For businesses that already have basic IT management in place but need dedicated security monitoring, an MSSP fills that gap. #### Virtual CISO (vCISO) A virtual Chief Information Security Officer provides strategic security leadership on a fractional basis. Rather than monitoring your systems, a vCISO helps you develop security policies, assess risk, plan your security roadmap, manage compliance requirements, and make informed decisions about where to invest. A vCISO is useful when you need someone to answer "what should we be doing?" rather than "is anyone watching our network right now?" #### Cybersecurity Consultants Consultants typically engage on a project basis — conducting security assessments, penetration testing, compliance gap analyses, or helping you respond to a specific incident. They don't provide ongoing monitoring or management. ### What to Look for in a Provider Regardless of which type of provider you need, several factors are worth evaluating: #### Canadian Data Residency and Privacy Knowledge If your business is subject to PIPEDA — and most are — your provider should understand Canadian privacy obligations. Ask where your data will be stored, whether any tools or platforms they use route data through US servers, and whether they're familiar with federal and provincial privacy requirements. This isn't about rejecting all US-based tools. It's about ensuring your provider understands the implications and can help you meet your obligations under PIPEDA, provincial privacy laws, and any sector-specific regulations that apply to your business. #### Alignment with the Baseline Controls The Canadian Centre for Cyber Security's Baseline Controls provide a practical framework for small and medium organizations. A provider that understands these controls — and can map their services to them — is more likely to deliver security that's appropriate for your organization's size and risk profile. Ask potential providers: "Which of the 13 Baseline Control areas do your services address, and which ones will we still need to manage ourselves?" A good provider will answer this clearly rather than claiming to cover everything. #### Incident Response Capability When something goes wrong, speed matters. The first 24 hours after an incident are critical. Ask potential providers: - Do you provide incident response support, and is it included in your contract or billed separately? - What is your average response time for critical security incidents? - Do you have a documented incident response process? - Will you help us meet our breach notification obligations under PIPEDA? A provider that takes hours to respond to a ransomware alert on a Saturday morning is not providing the protection you're paying for. #### Transparency About What's Included Cybersecurity services pricing can be opaque. Ensure you understand: - What's included in the base contract versus what's billed as an add-on - Whether incident response hours are included or charged at a premium rate - What happens if you need to scale up (add users, devices, or locations) - Whether there are long-term lock-in clauses and what the exit process looks like - Who owns your data and configurations if you leave #### Their Own Security Practices Your cybersecurity provider has privileged access to your systems — which makes them a high-value target. The Kaseya VSA attack in 2021 demonstrated what happens when a service provider is compromised: ransomware was deployed to approximately 1,500 businesses through a single vulnerability in the provider's remote management tool. Ask providers about their own security posture: - Do they use MFA on all administrative access to your systems? - Do they have cyber insurance? - Have they undergone any third-party security assessments or certifications (SOC 2, ISO 27001)? - How do they vet their own employees who will have access to your environment? ### Red Flags to Watch For The cybersecurity services market includes highly competent providers and others that rely more on marketing than substance. Be cautious of: Guaranteed protection. No provider can guarantee you won't be breached. A provider that claims otherwise is either misleading you or doesn't understand the threat landscape. Honest providers talk about reducing risk and improving response capability, not eliminating all threats. Fear-based sales tactics. If the sales conversation is primarily about how devastating an attack will be and how urgently you need to sign, that's a warning sign. Good providers educate and explain. They don't pressure. No clear service level agreements. If a provider can't tell you their response time commitments, escalation procedures, or what happens when they miss a target, their service is difficult to hold accountable. Reluctance to explain what they do. Security is technical, but a competent provider should be able to explain their approach in terms a business owner can understand. If every answer is jargon without substance, that's a concern. No references from similar businesses. A provider that works primarily with enterprises may not understand the constraints and priorities of a 20-person company. Ask for references from businesses similar in size and industry to yours. ### Questions to Ask During Evaluation Here's a practical list of questions to ask any cybersecurity provider you're considering: - Which of the 13 Baseline Control areas do your services cover? - How do you handle incident detection and response outside business hours? - What is your average response time for critical alerts? - Where will our data be stored, and do any tools you use route data outside Canada? - Do you carry cyber insurance, and what does it cover? - Can you provide references from Canadian businesses of similar size? - What does your onboarding process look like, and how long does it typically take? - How do you handle employee offboarding and access revocation when our staff changes? - What reporting do we receive, and how often? - What does the exit process look like if we decide to change providers? ### The Cost Question Cybersecurity services pricing varies widely. As a rough guide for Canadian small businesses: - MSP with basic security: $100-250 per user per month is common, though some MSPs offer monthly retainers based on overall company needs rather than per-user pricing — pricing models vary - MSSP (dedicated security monitoring): Often starts at $2,000-5,000 per month for small environments - vCISO: $2,000-8,000 per month depending on hours and scope - Security assessments: $3,000-15,000 as a one-time engagement These ranges are approximate and vary significantly by provider, region, and complexity. The point is not to find the cheapest option — it's to understand what you're getting for your investment and whether it addresses your actual risk. ### Starting the Search If you're not sure where to start: - Run our free assessment to understand where your security gaps are. This gives you a clear picture of what you actually need help with, so you can evaluate providers against your specific requirements rather than their generic pitch. - Talk to your industry peers. Other Canadian businesses in your sector have faced the same decision. Word-of-mouth referrals from businesses with similar needs are often more useful than online reviews. - Start with an assessment engagement. If you're not ready for ongoing managed services, hiring a consultant for a one-time security assessment gives you a roadmap and helps you evaluate whether a longer-term relationship makes sense. ### The Baseline Controls Connection Choosing the right cybersecurity provider connects to several areas of the Canadian Centre for Cyber Security's Baseline Controls: - BC.1 (Incident Response) — Your provider should support or deliver your incident response capability - BC.2 (Patch Management) — If your provider manages your systems, patching should be part of the service - BC.3 (Anti-Malware) — EDR and threat monitoring are core MSSP services - BC.6 (Security Awareness) — Some providers include employee training as part of their offering - BC.10 (Cloud Services) — Providers should help you secure your cloud environment, not just manage it Our free assessment evaluates your organization across all 13 Baseline Control areas. The results can serve as a starting point for conversations with potential providers — showing them exactly where you need help and giving you a way to evaluate whether their recommendations align with your actual gaps. --- ## Why Our Free Cybersecurity Assessment Doesn't Collect Your Data URL: https://cybersecuritycanada.ca/news/posts/why-our-free-cybersecurity-assessment-doesnt-collect-your-data/ Category: Insights Published: March 22, 2026 Summary: Most online assessment tools require your email before showing results. Ours doesn't collect anything — not your name, not your email, not your answers. Here's exactly how it works and why we built it this way. When a tool asks you to evaluate your organization's cybersecurity weaknesses, you are — by definition — documenting sensitive information. Which controls you lack, where your gaps are, what you haven't implemented yet. That information has value, and in the wrong hands, it could be used against you. Most online assessment tools require an email address before showing results. Many store your responses on their servers, use your answers to generate sales leads, or share aggregated data with third parties. We built our free cybersecurity assessment differently. It collects nothing. Here is exactly how it works. ### How the Assessment Actually Works #### Everything Runs in Your Browser The entire assessment — all 50 questions, all scoring, all recommendations — runs locally in your web browser using JavaScript. When you select an answer, it is processed on your device. When your results are calculated, that calculation happens on your device. At no point are your answers transmitted to our servers or any third-party service. This is not a marketing claim. It is an architectural decision. The assessment is a static website hosted on AWS infrastructure in Canada. There is no database behind it. There is no API endpoint receiving your answers. There is no server-side code processing your responses. The JavaScript that powers the assessment is delivered to your browser, and everything happens locally from that point forward. Anyone with web development knowledge can verify this by inspecting the network traffic in their browser's developer tools while taking the assessment. They will see zero outbound requests containing assessment data. #### Your Progress Is Saved Locally — and Deleted Automatically If you start the assessment and close your browser tab before finishing, your progress is saved to your browser's local storage — a standard browser feature that keeps data on your device, not on a server. This allows you to resume where you left off without re-answering questions. This saved progress is automatically deleted after 48 hours or when you complete the assessment — whichever comes first. We chose 48 hours because it gives you enough time to return to the assessment if you're interrupted, without leaving sensitive data on your device indefinitely. After that window, the data is gone permanently. There is no backup, no server copy, and no way for us to recover it — because we never had it in the first place. #### PDF Generation Is Local Too When you use the option to save your results as a PDF, that document is generated entirely in your browser using a client-side library called html2pdf.js. The PDF is built in your browser's memory and downloaded directly to your device. It is never uploaded to our servers or processed externally. The same applies to the print function — it uses your browser's built-in print capability. No data leaves your device. ### Why We Built It This Way #### A Cybersecurity Tool Should Not Create Cybersecurity Risk There is an inherent contradiction in asking a business to document its security weaknesses and then storing that information on a server. If our assessment collected and stored your responses, we would be creating a database of exactly which security controls Canadian businesses are missing — a target that would be valuable to threat actors. We eliminated that risk by ensuring the data never exists anywhere except your browser, for a maximum of 48 hours. #### Privacy Law Alignment Under PIPEDA, organizations that collect personal information must protect it with appropriate safeguards, report breaches, and comply with access and correction requests. The simplest way to comply with these obligations is to not collect the data in the first place. Our approach aligns with PIPEDA's limiting collection principle — one of the 10 fair information principles at the foundation of Canadian privacy law. You should only collect personal information that is necessary for an identified purpose. Since we can deliver a complete assessment experience without collecting any personal information, there is no justification for collecting it. This also means there is no breach risk associated with your assessment data. We cannot lose, expose, or have stolen what we do not have. #### Trust Should Not Require a Leap of Faith If you are evaluating a cybersecurity resource, you should be able to verify its claims — not just take them on trust. Our client-side architecture means you can verify that we do not collect your data using the same browser developer tools that any IT professional already knows. Open the Network tab, take the assessment, and confirm for yourself that no assessment data is transmitted. We believe this transparency is the appropriate standard for a cybersecurity tool. ### What We Do and Don't Know To be fully transparent, here is what we can and cannot see: #### What We Cannot See - Your answers to any assessment question - Your assessment score or grade - Your results or recommendations - Your name, email, phone number, or any identifying information - Which specific questions you answered or how long you spent on each one #### What We Can See (Through Google Analytics) Like most websites, we use Google Analytics (GA4) to understand general website traffic: - How many people visit the site and which pages they view - Browser type, operating system, and screen resolution - Approximate city-level location (IP addresses are anonymized before storage) - How visitors arrived at the site (search engine, direct visit, referral) - General time spent on pages Google Analytics data is retained for 14 months and then automatically deleted. It does not capture any assessment-specific data — your answers, scores, and results are invisible to GA4 because they exist only in your browser's JavaScript execution context, not in page URLs or form submissions. We do not use advertising cookies, remarketing pixels, social media trackers, or any other tracking technology beyond GA4. ### How This Compares to Other Assessment Tools Many online cybersecurity assessments — including those offered by vendors and consulting firms — operate differently: - Email-gated results: You complete the assessment, but your results are withheld until you provide an email address. Your answers and contact information are then used for sales outreach. - Server-side processing: Your answers are transmitted to and stored on the provider's servers, where they may be retained indefinitely, used for research, or shared with partners. - Lead scoring: Your answers are analyzed not just to produce your results, but to qualify you as a sales lead. Businesses that score poorly may receive more aggressive follow-up because their gaps represent a sales opportunity. Our assessment does none of this. There is no email gate. There is no account creation. There is no follow-up. You take the assessment, you get your results, and you decide what to do with them. ### The Connection to Your Broader Security Posture The privacy architecture of the assessment reflects the same principles that the assessment itself evaluates. The Canadian Centre for Cyber Security's Baseline Controls include: - Access Control (BC.12) — Limiting access to information based on need. Our architecture ensures that only you have access to your assessment data. - Secure Configuration (BC.4) — Designing systems to minimize unnecessary data exposure. The assessment was designed from the ground up to avoid collecting data it does not need. - Cloud Services Security (BC.10) — Understanding where your data goes when you use cloud-based tools. With our assessment, your data goes nowhere — it stays on your device. If you have not yet evaluated your organization's cybersecurity posture, the assessment takes under 30 minutes and covers all 13 Baseline Control areas. Your results include a compliance percentage, a letter grade, a per-control breakdown, and specific recommendations — all generated locally and available only to you. ### Frequently Asked Questions #### Does the assessment collect my email address? No. The assessment does not ask for or collect your email address, name, phone number, or any other personal information at any point. You can take the assessment and receive your full results without providing any identifying information. #### Where are my assessment answers stored? Your answers are stored temporarily in your browser's local storage — a standard feature that keeps data on your device, not on a server. This data is automatically deleted after 48 hours or when you complete the assessment. Your answers are never transmitted to our servers or any third-party service. #### Can you see my assessment results? No. All scoring and result generation happens in your browser using JavaScript. Your answers, score, grade, and recommendations are never transmitted to our servers. We have no way to see, access, or recover your results — because we never receive them. #### How can I verify that no data is being sent? You can verify this yourself using your browser's built-in developer tools. Open the Network tab (press F12 in most browsers, then click "Network"), take the assessment, and observe the network requests. You will see that no requests containing assessment data are sent to any server. The assessment JavaScript is loaded once, and all processing happens locally. #### Is the PDF export private too? Yes. The PDF is generated entirely in your browser using a client-side JavaScript library. The document is built in your browser's memory and downloaded directly to your device. It is never uploaded to our servers or any external service. The same applies to the print function, which uses your browser's native print capability. #### Why don't you collect data for research purposes? Aggregated assessment data could be valuable for understanding the cybersecurity posture of Canadian small businesses. However, collecting this data would require us to transmit and store your responses — creating exactly the kind of data store that we believe a cybersecurity assessment tool should avoid. We prioritize your privacy over our ability to generate research insights. #### Is the assessment really free? What's the business model? The assessment is genuinely free with no strings attached. Cybersecurity Canada is operated by Cyber Unit Security Inc., a Canadian cybersecurity company. The assessment and educational resources on this site are provided as a public benefit to help Canadian businesses improve their security posture. There is no upsell within the assessment, no gated content, and no required follow-up. --- ## What Canadian Businesses Need to Know About Bill C-26 URL: https://cybersecuritycanada.ca/news/posts/what-canadian-businesses-need-to-know-about-bill-c-26/ Category: Compliance Published: March 20, 2026 Summary: Bill C-26's cybersecurity provisions — now reintroduced as Bill C-8 — would impose mandatory obligations on critical infrastructure operators in Canada. Here's what the legislation covers, who it affects, and why all Canadian businesses should be paying attention. Canada is strengthening its cybersecurity laws. Bill C-26 — originally introduced in 2022 and containing the Critical Cyber Systems Protection Act (CCSPA) — represented the most significant federal cybersecurity legislation Canada had proposed to date. Although Bill C-26 passed both chambers of Parliament in late 2024, it did not receive Royal Assent before Parliament was prorogued in January 2025 and died on the Order Paper. Its provisions were subsequently reintroduced as Bill C-8 in June 2025. The legislation targets operators of critical infrastructure — telecommunications, finance, energy, and transportation — but its implications extend to businesses of all sizes that operate within or supply services to these sectors. For Canadian small and medium businesses, understanding this legislation is important even if your business is not directly subject to its requirements. It signals the clear direction of federal cybersecurity policy and establishes expectations that may broaden over time. ### What Is Bill C-26 Bill C-26 contains two main components: #### Part 1: Amendments to the Telecommunications Act Part 1 gives the federal government new powers to direct telecommunications service providers to take specific actions to secure Canada's telecommunications infrastructure. This includes the authority to prohibit the use of specific products or services from designated suppliers — a provision widely understood to address concerns about equipment from vendors with ties to foreign governments. For most small businesses, Part 1 is relevant primarily as context: the federal government is taking an active role in securing the telecommunications networks that Canadian businesses depend on. #### Part 2: The Critical Cyber Systems Protection Act (CCSPA) Part 2 is the core of Bill C-26 for business purposes. The CCSPA creates a new regulatory framework that imposes cybersecurity obligations on operators of "critical cyber systems" — systems associated with services and infrastructure deemed vital to national security or public safety. The sectors designated under the CCSPA include: - Telecommunications — Internet and phone service providers - Finance — Federally regulated banks, insurance companies, and clearing houses - Energy — Interprovincial and international pipeline operators, nuclear energy facilities, and electricity systems - Transportation — Federally regulated air, rail, and marine transportation systems The Governor in Council may designate additional sectors and services through regulation, meaning the scope of the law could expand over time. ### What the CCSPA Requires Designated operators under the CCSPA will be required to: #### Establish a Cybersecurity Program Operators must implement and maintain a cybersecurity program that includes measures to: - Identify and manage cybersecurity risks to their critical cyber systems - Protect those systems from compromise - Detect cybersecurity incidents - Minimize the impact of incidents that do occur This framework closely mirrors the structure of established cybersecurity standards like the NIST Cybersecurity Framework and aligns with the principles behind the Canadian Centre for Cyber Security's Baseline Controls — identify, protect, detect, and respond. #### Report Cybersecurity Incidents Operators must report cybersecurity incidents to the Canadian Centre for Cyber Security (CCCS) and to the appropriate sector-specific regulator. The reporting requirements include: - Mandatory reporting of incidents that affect or have the potential to affect critical cyber systems - Timely notification — the specific reporting timelines will be established through regulation, but the intent is to ensure that the government is informed of significant incidents quickly enough to coordinate a response - Information sharing — reported information may be shared between government agencies for national security purposes #### Comply with Government Directives The CCSPA gives the Governor in Council the authority to issue cybersecurity directions requiring designated operators to take specific actions or refrain from specific actions to protect critical cyber systems. These directions can be issued in response to specific threats or on a preventive basis. Importantly, these directions can be kept confidential — operators may be prohibited from disclosing that a direction has been issued. This provision has raised concerns from privacy and civil liberties organizations, though the government has argued it is necessary to prevent adversaries from learning about defensive measures. #### Maintain Records and Undergo Audits Operators must maintain records of their cybersecurity programs, risk assessments, and incident reports. Regulators will have the authority to conduct compliance audits, and operators must cooperate with these audits. ### Penalties for Non-Compliance The CCSPA introduces significant penalties: - Individuals: Fines up to $1 million and/or imprisonment for up to five years for certain offences - Organizations: Fines up to $15 million per violation - Administrative monetary penalties (AMPs): Up to $1 million for individuals and $15 million for organizations, which can be imposed without court proceedings These penalties are designed to ensure that cybersecurity is treated as a serious regulatory obligation, comparable to financial regulation or environmental compliance. ### Why This Matters for Small Businesses If your business does not operate critical infrastructure, you may not be directly subject to the CCSPA. However, there are several reasons why Bill C-26 is relevant to Canadian SMBs. #### Supply Chain Requirements Will Flow Downstream Designated operators will be required to manage cybersecurity risks across their supply chains. If your business provides products, services, or IT support to a telecommunications company, bank, energy company, or transportation operator, you may be asked to demonstrate that your own cybersecurity practices meet a minimum standard. This is already happening in other jurisdictions. In the United States, defence contractors must comply with the Cybersecurity Maturity Model Certification (CMMC), and their subcontractors must as well. Bill C-26 creates the foundation for similar requirements in Canada. For small businesses that serve enterprise or government clients, this means your cybersecurity posture is increasingly a factor in your ability to win and retain contracts. The Canadian Centre for Cyber Security's Baseline Controls provide a practical, government-backed framework for demonstrating due diligence. #### It Signals the Direction of Federal Policy Bill C-26 is the beginning, not the end, of Canada's cybersecurity regulatory journey. The CCSPA allows for additional sectors to be designated over time, and the federal government has indicated interest in broader cybersecurity standards across the economy. Businesses that invest in foundational cybersecurity practices now — incident response planning, patch management, access control, multi-factor authentication — will be better positioned to adapt as regulations expand. #### Breach Reporting Norms Are Converging The CCSPA's incident reporting requirements add to the existing breach notification obligations under PIPEDA and provincial privacy laws. For businesses in regulated sectors, this means potentially reporting the same incident to multiple authorities. For all businesses, the trend is clear: mandatory incident reporting is becoming the norm across Canadian law. Having an incident response plan that includes clear reporting procedures is no longer just a best practice — it is increasingly a legal expectation. #### Cybersecurity Is Becoming a Governance Issue Bill C-26 signals that cybersecurity is transitioning from a purely technical concern to a governance and compliance issue. Business owners and boards of directors will be expected to understand their organizations' cybersecurity risks and ensure adequate measures are in place. For small business owners, this means cybersecurity needs to be part of business planning — not delegated entirely to an IT provider without oversight. ### What Canadian SMBs Should Do Now Even if your business is not directly regulated under the CCSPA, these steps will position you well as cybersecurity expectations continue to rise across the Canadian business landscape. #### Understand the Baseline Controls The Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations provide a practical framework that aligns with the principles underlying Bill C-26. The 13 control areas cover the fundamentals — from network security to data backup to security awareness training. Our free cybersecurity assessment evaluates your business against these controls and provides specific, actionable recommendations. #### Document What You're Doing If you're already taking security measures — using MFA, running backups, keeping software updated — make sure these practices are documented. As supply chain requirements flow down from regulated entities, you may be asked to demonstrate your cybersecurity posture to clients or partners. Having documentation ready is significantly easier than building it from scratch under a deadline. #### Prepare for Incident Reporting Regardless of your sector, having a clear process for identifying, assessing, and reporting cybersecurity incidents prepares your business for both current obligations under PIPEDA and any future requirements that may emerge from Bill C-26's regulatory framework. #### Stay Informed The CCSPA's specific requirements will be detailed in regulations that are still being developed. The Canadian Centre for Cyber Security and the Office of the Privacy Commissioner are the authoritative sources for guidance as these regulations take shape. ### The Connection to AI and Emerging Threats Bill C-26 arrives at a time when the threat landscape is evolving rapidly. AI-powered phishing and automated attack tools are making it easier for threat actors to target organizations of all sizes. The legislation recognizes that cybersecurity is a shared responsibility — critical infrastructure operators cannot be secure if their vendors, suppliers, and partners are not. For small businesses, this reinforces a message that runs through all of Canada's cybersecurity guidance: the fundamentals matter. Strong passwords, multi-factor authentication, employee training, and incident response readiness are not just technical best practices — they are becoming the cost of doing business in Canada's digital economy. ### Frequently Asked Questions #### Does Bill C-26 apply to my small business? Bill C-26's mandatory requirements under the CCSPA apply specifically to operators of critical cyber systems in designated sectors — telecommunications, finance, energy, and transportation. Most small businesses are not directly subject to these requirements. However, if your business provides services to organizations in these sectors, you may face cybersecurity requirements through supply chain contracts. The scope of designated sectors may also expand through future regulation. #### When does Bill C-26 come into effect? Bill C-26 passed both chambers of Parliament in late 2024 but did not receive Royal Assent before Parliament was prorogued in January 2025. Its provisions were reintroduced as Bill C-8 in June 2025, which is currently progressing through the legislative process. The specific requirements under the CCSPA will be defined through regulations that are still being developed. Designated operators should monitor the Canada Gazette and guidance from sector-specific regulators for implementation timelines. Small businesses should use this period to strengthen their cybersecurity posture proactively. #### What are the penalties under Bill C-26? The CCSPA provides for fines of up to $15 million per violation for organizations and up to $1 million for individuals, as well as potential imprisonment of up to five years for certain offences. Administrative monetary penalties can be imposed without court proceedings. These penalties apply to designated operators who fail to establish cybersecurity programs, report incidents, or comply with government directives. #### How does Bill C-26 relate to PIPEDA? Bill C-26 and PIPEDA address different but overlapping concerns. PIPEDA requires organizations to protect personal information and report breaches involving personal data to the Office of the Privacy Commissioner. The CCSPA requires designated operators to protect critical cyber systems and report cybersecurity incidents to the Canadian Centre for Cyber Security. A single incident could trigger reporting obligations under both laws. Aligning your cybersecurity and privacy practices ensures you can meet both sets of requirements efficiently. #### What cybersecurity framework should I follow to prepare? The Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations are the most practical starting point for Canadian SMBs. These controls align with the principles underlying Bill C-26 and are designed to be achievable for organizations with limited resources. For businesses seeking a more comprehensive framework, the NIST Cybersecurity Framework and CIS Controls are widely recognized internationally and referenced by Canadian government guidance. --- ## New PIPEDA Enforcement Actions: What Changed and What Canadian SMBs Must Do Now URL: https://cybersecuritycanada.ca/news/posts/new-pipeda-enforcement-what-changed-and-what-smbs-must-do/ Category: Compliance Published: March 14, 2026 Summary: The Office of the Privacy Commissioner of Canada is enforcing PIPEDA more aggressively than ever. Here's what recent enforcement actions mean for small and medium businesses — and the practical steps to reduce your risk. Canada's federal privacy law is being enforced with increasing rigour, and small businesses are not exempt. The Office of the Privacy Commissioner of Canada (OPC) has been expanding its enforcement activities under the Personal Information Protection and Electronic Documents Act (PIPEDA), with a clear focus on organizations that fail to meet basic data protection obligations — regardless of their size. For Canadian SMBs that collect customer information, employee records, or any form of personal data, understanding what the OPC expects and where enforcement is heading is no longer optional. It is a business risk that requires attention. ### What Has Changed in PIPEDA Enforcement #### The OPC Is Prioritizing Proactive Enforcement Historically, the OPC operated primarily on a complaint-driven model — investigating organizations only when individuals filed formal complaints. That approach has been shifting. The OPC's 2024-2025 Annual Report signalled a strategic move toward proactive enforcement, including Commissioner-initiated investigations targeting sectors and practices where privacy risks are highest. This means the OPC may investigate your business even if no customer has filed a complaint — particularly if your industry handles sensitive personal information or if a data breach suggests systemic safeguard failures. #### Breach Reporting Is Under Scrutiny Since November 2018, PIPEDA has required organizations to report breaches of security safeguards to the OPC when there is a "real risk of significant harm" (RROSH) to affected individuals. Organizations must also notify affected individuals and keep records of all breaches. The OPC has indicated that many organizations are either under-reporting breaches or failing to conduct adequate risk assessments when determining whether a breach meets the RROSH threshold. Organizations that fail to report qualifying breaches face potential fines of up to $100,000 per violation under PIPEDA. If your business experiences a data breach — even a minor one — you are required to document it internally. If personal information is involved and there is any possibility of harm, the safer course is to report it. #### Consent Requirements Are Being Interpreted Strictly Recent OPC findings have reinforced that meaningful consent under PIPEDA requires more than a buried clause in a terms-of-service document. The OPC expects organizations to: - Explain what personal information is being collected - Explain why it is being collected and how it will be used - Obtain consent that is informed, voluntary, and specific to the stated purpose - Not collect more information than is necessary for the identified purpose For small businesses, this has practical implications. If your website collects email addresses for a newsletter, you cannot use those addresses for unrelated marketing without obtaining separate consent. If your intake forms ask for information you don't actually need, that collection may not comply with PIPEDA's limiting collection principle. #### Quebec's Law 25 Is Raising the Bar Nationally While not a PIPEDA amendment, Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25) — which has been rolling out in phases since September 2022 — has introduced privacy obligations that exceed PIPEDA in several areas. These include mandatory privacy impact assessments, default privacy settings, and the right to data portability. For businesses operating across provincial borders, Quebec's higher standard is effectively becoming the practical baseline. Organizations that align with Law 25 requirements will generally meet or exceed PIPEDA obligations as well. The federal government has also signalled its intent to modernize PIPEDA through proposed legislation. While timelines remain uncertain, the direction is clear: privacy obligations for Canadian businesses are increasing, not decreasing. ### What This Means for Small Businesses Many SMB owners assume that privacy enforcement is focused on large corporations and tech companies. Recent OPC activities suggest otherwise. The OPC has investigated organizations of various sizes, and PIPEDA applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity. The practical risk for a small business is not typically a headline-making fine. It is the combination of: - OPC investigation costs — Responding to an investigation requires time, legal guidance, and documentation that can strain a small business - Mandatory remediation — The OPC can require changes to your data practices, which may involve system changes, policy rewrites, and staff retraining - Reputational impact — OPC findings are published publicly and are easily discoverable by customers, partners, and competitors - Breach notification costs — Notifying affected individuals, providing credit monitoring, and managing the response to a reported breach can be expensive relative to SMB budgets ### Practical Steps for Canadian SMBs You do not need a legal department or a dedicated privacy officer to meet your PIPEDA obligations. Start with the fundamentals. #### Know What Personal Information You Hold Conduct a basic inventory of the personal information your business collects and stores. This includes: - Customer names, email addresses, phone numbers, and payment information - Employee records and payroll data - Website analytics and tracking data - Information collected through forms, surveys, or intake processes You cannot protect or properly manage information you haven't identified. This inventory is also the foundation of your access control practices (BC.12) — understanding who has access to what. #### Review Your Consent Practices Look at how your business obtains consent for collecting personal information: - Is your privacy notice written in clear, plain language? - Does it explain what you collect, why, and how it will be used? - Are you collecting only the information you actually need? - Can individuals withdraw their consent easily? The OPC provides guidance on obtaining meaningful consent that is written for organizations of all sizes. It is worth reviewing against your current practices. #### Implement Basic Security Safeguards PIPEDA requires organizations to protect personal information with security safeguards appropriate to the sensitivity of the information. For most small businesses, this means: - Multi-factor authentication on all accounts that access personal information - Strong, unique passwords managed through a password manager - Encryption for sensitive data, both in transit and at rest - Access restrictions — Only employees who need personal information to do their jobs should have access to it - Regular software updates through a consistent patch management process These measures align directly with the Canadian Centre for Cyber Security's Baseline Controls, which provide a practical framework for implementing the security safeguards PIPEDA requires. #### Have a Breach Response Process If a breach occurs, you need to be able to: - Assess what information was affected and whether there is a real risk of significant harm - Report qualifying breaches to the OPC as soon as feasible - Notify affected individuals with clear information about what happened and what they can do - Record the breach, your risk assessment, and your response — PIPEDA requires you to keep these records for at least two years A documented incident response plan does not need to be complex, but it does need to exist before a breach happens. The Baseline Controls address this under incident response planning (BC.1). #### Train Your Team Employees who handle personal information should understand their obligations. This doesn't require formal certification — it means ensuring that staff know: - What personal information the business collects and why - How to handle requests from individuals to access or correct their information - What constitutes a privacy breach and who to report it to internally - Basic security practices that protect the data they work with This overlaps directly with security awareness training (BC.6) and should be integrated into your broader employee training program. ### How This Connects to Cybersecurity Privacy and cybersecurity are not separate concerns — they are two sides of the same obligation. PIPEDA requires you to protect personal information. The Canadian Centre for Cyber Security's Baseline Controls tell you how. Nearly every security control in the Baseline framework — from authentication to backup and recovery to cloud security — directly supports your ability to meet PIPEDA's safeguard requirements. Our free cybersecurity assessment evaluates your organization across all 13 Baseline Control areas and identifies specific gaps. For businesses that are concerned about their PIPEDA readiness, the assessment results provide a practical starting point for understanding where your security safeguards may need strengthening. For a broader overview of Canada's privacy framework, including provincial legislation and breach reporting obligations, see our guide on Canada's privacy landscape. ### Frequently Asked Questions #### Does PIPEDA apply to my small business? PIPEDA applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity. This includes most Canadian small businesses — even sole proprietors — if they handle customer data, employee records, or any other personal information. Businesses in Alberta, British Columbia, and Quebec may be subject to provincial privacy legislation instead of PIPEDA for activities within those provinces, but PIPEDA applies to interprovincial and international data flows. #### What are the penalties for not complying with PIPEDA? PIPEDA penalties include fines of up to $100,000 per violation for failing to report breaches, failing to maintain breach records, or obstructing an OPC investigation. Beyond fines, the OPC can publish findings that name your organization, require mandatory changes to your practices, and refer matters to the Federal Court. The reputational and operational costs of non-compliance often exceed the financial penalties. #### What counts as a "real risk of significant harm" for breach reporting? The OPC considers factors including the sensitivity of the information involved, the probability that it has been or will be misused, and the potential consequences for affected individuals. Financial information, health records, government-issued identification numbers, and login credentials are generally considered sensitive. If there is any reasonable possibility of identity theft, financial loss, or reputational damage to affected individuals, the breach likely meets the reporting threshold. #### How is Quebec's Law 25 different from PIPEDA? Quebec's Law 25 introduced several requirements that exceed PIPEDA, including mandatory privacy impact assessments for certain projects, default privacy settings for technology products, data portability rights, and the requirement to designate a person responsible for personal information protection. Businesses operating in Quebec must comply with Law 25 for activities within the province. For businesses operating nationally, aligning with Law 25's stricter requirements can help ensure compliance across all jurisdictions. #### Do I need a privacy officer? PIPEDA requires organizations to designate an individual accountable for compliance, but this does not need to be a dedicated privacy officer. In a small business, this responsibility often falls to the owner, a manager, or an office administrator. What matters is that someone is clearly responsible for privacy practices, can respond to access requests, and knows what to do if a breach occurs. --- ## AI-Powered Phishing: What's Changed for Canadian Businesses in 2026 URL: https://cybersecuritycanada.ca/news/posts/ai-powered-phishing-whats-changed-for-canadian-businesses/ Category: Threats Published: March 8, 2026 Summary: AI tools have made phishing emails faster to create, harder to detect, and more convincing than ever. Here's what Canadian small businesses need to know — and what actually helps. Phishing emails used to be easy to spot. Bad grammar, generic greetings, obvious spelling mistakes — these were reliable warning signs that something wasn't right. That era is ending. Generative AI tools have given attackers the ability to produce polished, personalized, and highly convincing phishing messages at scale, and Canadian small businesses are seeing the effects. This isn't a prediction. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 identifies AI-enhanced social engineering as a growing threat to Canadian organizations. Understanding what has changed — and what defences still work — is essential for any business that relies on email. ### What Has Actually Changed #### Phishing Emails Now Read Like Real Emails Large language models can generate grammatically correct, contextually appropriate text in seconds. Attackers are using these tools to craft phishing emails that match the tone, vocabulary, and formatting of legitimate business communications. The telltale signs that employees were trained to look for — awkward phrasing, misspellings, unnatural language — are increasingly absent. For Canadian businesses, this is especially relevant. AI tools can easily generate messages in both English and French that read naturally, eliminating the language quality issues that previously made many phishing attempts obvious to bilingual recipients. #### Personalization Is Automated Before AI, a targeted phishing email (spear phishing) required manual research — reading LinkedIn profiles, studying company websites, understanding organizational structures. This limited how many targeted attacks a single threat actor could run. AI tools have removed that bottleneck. Attackers can now feed publicly available information about a company and its employees into an AI system and generate dozens of personalized phishing emails in minutes. An employee might receive an email that references their actual job title, a recent company announcement, or the name of a real colleague — all generated automatically. #### Voice and Video Are No Longer Reliable AI-generated voice cloning (sometimes called deepfake audio) has reached the point where short voice samples — often available from LinkedIn videos, conference presentations, or voicemail greetings — can be used to create convincing voice messages. There have been documented cases of attackers using cloned executive voices to authorize fraudulent wire transfers. The Canadian Anti-Fraud Centre has flagged AI-assisted fraud as an emerging concern, noting that these techniques make traditional verification methods less reliable. #### The Volume Has Increased Generative AI dramatically reduces the time and skill required to create phishing campaigns. What once took hours of manual effort now takes minutes. This means more attacks, targeting more organizations, more often. For Canadian SMBs that may not have dedicated security teams monitoring email traffic, this volume increase raises the probability that a convincing message reaches an employee who acts on it. ### What Canadian Small Businesses Should Do The good news is that effective defences exist. They just need to evolve alongside the threat. #### Update Your Training — Focus on Behaviour, Not Spelling Traditional security awareness training taught employees to look for grammatical errors and generic greetings. That advice is outdated. Training should now focus on behavioural red flags that AI cannot eliminate: - Unexpected requests — Any email asking you to transfer money, change payment details, share credentials, or bypass a normal process deserves scrutiny, regardless of how well-written it is - Urgency and pressure — Phishing emails create time pressure to prevent the recipient from thinking carefully. A message that says "this must be done within the hour" is a red flag, not a reason to rush - Unusual channels — A request that arrives by email when it would normally come through your project management tool, a phone call, or in person For more on recognizing phishing attempts, see our guide on how to recognize phishing emails. #### Make Multi-Factor Authentication Non-Negotiable Multi-factor authentication (MFA) remains one of the most effective defences against phishing — even AI-enhanced phishing. If an employee's credentials are stolen through a phishing email, MFA prevents the attacker from using those credentials to access your systems. The Canadian Centre for Cyber Security's Baseline Controls identify authentication and MFA (BC.5) as a foundational security measure for this reason. If your business has not yet implemented MFA on email, cloud services, and remote access, this should be a priority. #### Implement Verification Procedures for Financial Requests AI-powered phishing is particularly dangerous for business email compromise (BEC) attacks, where convincing emails are used to redirect payments or authorize fraudulent transfers. The defence is procedural: any request to change payment details, process an unusual transfer, or share sensitive information must be verified through a separate communication channel — a phone call to a known number, a face-to-face confirmation, or a verified messaging platform. This verification step breaks the attack chain regardless of how convincing the email is. #### Use Email Authentication Protocols Technical controls at the organizational level can reduce the volume of phishing that reaches your employees: - DMARC, SPF, and DKIM — These email authentication protocols help prevent attackers from spoofing your domain. They also reduce the likelihood that phishing emails impersonating other organizations reach your inbox - Email filtering and threat detection — Modern email security tools use AI themselves to identify suspicious patterns, even in well-crafted messages - Link and attachment scanning — Automated scanning of URLs and attachments before delivery catches many phishing attempts These measures fall under network and perimeter security (BC.9) in the Baseline Controls framework. #### Have an Incident Response Plan Despite best efforts, phishing attempts will occasionally succeed. What matters is how quickly your organization detects and responds to a compromise. An incident response plan — even a simple one — ensures that employees know who to contact, what steps to follow, and how to contain the damage. The Baseline Controls address this under incident response planning (BC.1). ### What About AI Detection Tools? There are tools that claim to detect AI-generated text. Currently, these tools are unreliable for security purposes — they produce frequent false positives and false negatives, and their accuracy degrades as AI models improve. Relying on AI detection to filter phishing is not a sound strategy. The more effective approach is to assume that any phishing email could be AI-generated and design your defences accordingly. Focus on verifying the request, not analysing the writing. ### The Bigger Picture AI has not invented a new type of attack. Phishing is still phishing — it still relies on tricking a person into taking an action they shouldn't. What AI has done is remove the quality barriers that made phishing easier to detect and harder to scale. For Canadian small businesses, this means the fundamentals matter more than ever: employee training that focuses on behaviour rather than grammar, strong authentication on every system, verification procedures for financial transactions, and an incident response plan for when something goes wrong. If you're not sure where your organization stands, our free cybersecurity assessment evaluates your business across all 13 of the Canadian Centre for Cyber Security's Baseline Control areas — including security awareness, authentication, and incident response — and provides specific recommendations based on your results. ### Frequently Asked Questions #### Can AI write phishing emails that are impossible to detect? AI-generated phishing emails can be very convincing, but they are not impossible to detect. While AI eliminates obvious language errors, it cannot eliminate the behavioural red flags that define phishing — unexpected requests, artificial urgency, and unusual communication channels. Training employees to recognize these patterns remains effective regardless of how well the email is written. #### Are Canadian businesses being specifically targeted by AI phishing? The Canadian Centre for Cyber Security has identified AI-enhanced social engineering as a growing concern in its National Cyber Threat Assessment 2025-2026. Canada's bilingual business environment, active international trade relationships, and high adoption of cloud services make Canadian organizations attractive targets for phishing campaigns of all kinds, including AI-assisted ones. #### Does multi-factor authentication protect against AI phishing? Yes. MFA is effective against AI-enhanced phishing because it addresses what happens after credentials are stolen, not how they were stolen. Even if an employee enters their password on a phishing site, MFA prevents the attacker from accessing the account without the second authentication factor. The Canadian Centre for Cyber Security recommends MFA as a baseline security control for all organizations. #### What should I do if an employee falls for a phishing email? Act quickly. Isolate the affected account by resetting the password and revoking active sessions. Determine what access the compromised account had and whether any data was exposed. If personal information may have been affected, Canadian organizations have breach reporting obligations under PIPEDA. Report the incident to the Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. #### How often should phishing training be updated? Security awareness training should be reviewed and updated at least annually, with supplementary communications whenever new phishing techniques emerge. The Canadian Centre for Cyber Security's Baseline Controls recommend ongoing security awareness as part of BC.6 (Security Awareness Training). Quarterly phishing simulations can help measure whether training is translating into employee behaviour. --- ## Building an Incident Response Plan for Your Canadian Business URL: https://cybersecuritycanada.ca/news/posts/building-an-incident-response-plan-for-your-canadian-business/ Category: Best Practices Published: March 7, 2026 Summary: The Canadian Centre for Cyber Security designates incident response planning as the first of its 13 Baseline Controls. Here is what the guidance says, what a plan includes, and what Canadian SMBs face without one. When the City of Hamilton was hit by ransomware in February 2024, the attack disrupted roughly 80% of the city's network — taking down business licensing, property tax systems, and city phone lines. Recovery cost $18.3 million. The city's cyber insurance claim was denied because multi-factor authentication had not been fully implemented. When the Toronto Public Library was struck by Black Basta ransomware in October 2023, it took nearly five months to fully restore digital services across 100 branches. Both organizations eventually recovered. But the speed, cost, and effectiveness of any recovery depends heavily on what was planned before the incident occurred. The Canadian Centre for Cyber Security's Baseline Cyber Security Controls designate incident response planning as BC.1 — the very first of the 13 control areas. It comes before patch management, before authentication, before backups. The positioning is deliberate: when an incident hits, everything else depends on having a plan to follow. ### The Current State of Preparedness Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime found that only 26% of Canadian businesses had written cybersecurity policies in place — unchanged from 2021. Meanwhile, 1 in 6 Canadian businesses (16%) were impacted by a cybersecurity incident in 2023, and total spending on recovery doubled from $600 million in 2021 to $1.2 billion in 2023. IBM's Cost of a Data Breach report has consistently found that organizations with a formal, tested incident response plan spend significantly less on breach recovery than those without one. The 2023 report found that the cost difference was $1.49 million — organizations that conducted regular incident response testing reduced their average breach cost by that amount compared to those that did not. The gap between the frequency of incidents and the level of preparedness among Canadian businesses remains wide. ### What the Canadian Government Publishes Two government resources are directly relevant to Canadian SMBs building an incident response plan: #### ITSAP.40.003 — Developing Your Incident Response Plan The Canadian Centre for Cyber Security publishes Developing Your Incident Response Plan (ITSAP.40.003), a guidance document that outlines the structure, phases, and considerations for building an IRP. It defines the plan as covering "the processes, procedures, and documentation related to how your organization detects, responds to, and recovers from a specific incident." The document covers: - Asset identification — Before creating a plan, identify what information and systems are of value to your organization and what types of incidents you might face - Team composition — Build a response team with cross-functional representation whose purpose is to assess, document, and respond to incidents - Policy alignment — Incident response activities need to align with organizational policies and compliance requirements, including roles, responsibilities, and authorities - Training — Employees need to understand the plan, their role in it, and how to report suspected incidents - Communications — The plan should detail how, when, and with whom the response team communicates, including a central point of contact for employees and notification procedures for internal and external stakeholders - Outsourcing decisions — Determine which response actions can be handled internally and which will require external support, keeping in mind that specialized incident response services — particularly for operational technology environments — can be costly #### CyberSecure Canada IRP Template Innovation, Science and Economic Development Canada (ISED) publishes a fillable incident response plan template as part of the CyberSecure Canada certification program. The template is available as a downloadable Word document and includes section-by-section instructions. The template covers: - Purpose statement — Why the plan exists and what it applies to - Definitions — Key terms including indicators of compromise (IOCs), maximum tolerable downtime, and incident classification - Cyber Security Incident Response Team (CSIRT) — Roles, responsibilities, and contact information - Incident severity matrix — How to classify incidents by impact level - Response phases — Detailed procedures for each stage of the response - Document control — Version history and review schedule - Testing plan — How and when the plan will be exercised This template was designed specifically to help small and medium organizations meet the CyberSecure Canada certification requirements, but it is freely available and useful regardless of whether certification is being pursued. ### The Incident Response Lifecycle Both the CCCS guidance and the CyberSecure Canada framework describe incident response as a lifecycle — a continuous process, not a one-time document. The phases are consistent with the widely adopted NIST framework (SP 800-61) and are adapted for Canadian organizations. #### Phase 1: Preparation Preparation is everything that happens before an incident occurs. The CCCS guidance (ITSAP.40.003) begins here: perform a risk assessment, identify your most valuable assets, define the types of incidents your organization is most likely to face, and create response steps for each. For a Canadian SMB, preparation includes: - Naming the response team. At minimum, this means identifying a primary person responsible for leading the response and a backup. In a small business, the team might be two or three people — the owner, the IT lead or managed service provider, and someone who handles communications. The CyberSecure Canada template refers to this as the Cyber Security Incident Response Team (CSIRT). - Listing contact information. The plan should include current contact details for: your IT support or managed service provider, your cyber insurance carrier (if applicable), legal counsel, the Canadian Centre for Cyber Security (1-833-CYBER-88), local police, and the Canadian Anti-Fraud Centre. - Identifying critical systems. Know which systems must come back first — email, financial systems, customer-facing services — and what data they depend on. The CyberSecure Canada template uses the concept of maximum tolerable downtime: the longest period a given business process can be inoperative before the organization's survival is at risk. Defining this for each critical system helps prioritize recovery efforts. - Defining what constitutes an incident. The CyberSecure Canada template defines an incident as "any event or set of circumstances that threatens the confidentiality, integrity, or availability of information, data or services." Not every anomaly is an incident. Having clear criteria prevents both under-reaction and over-reaction. - Keeping the plan accessible. If your network is encrypted by ransomware, a plan stored only on the network is useless. Print the plan. Keep a copy offsite. Store it somewhere the team can access without relying on the systems that may be compromised. #### Phase 2: Detection and Analysis An incident that is not detected cannot be responded to. The CCCS guidance notes that attacks can go unnoticed before there is an opportunity to apply a patch or update, and that the plan should provide instructions for mitigating active exploitation. Detection sources vary by organization size and capability: - Employee reports — An employee notices a suspicious email, an unexpected login prompt, or files they cannot open. The plan should make it clear how and where to report these observations. - Alerts from security tools — Anti-malware software, endpoint detection and response (EDR) tools, or firewall logs flag unusual activity - External notification — A customer, vendor, law enforcement agency, or the CCCS itself notifies you of a compromise. In 2024-2025, the Cyber Centre issued 336 pre-ransomware notifications to Canadian organizations, generating an estimated $6 to $18 million in economic savings. Once a potential incident is detected, the analysis phase involves determining whether it is real, assessing its scope and severity, and classifying it using the severity matrix defined during preparation. The CyberSecure Canada template includes a severity classification framework for this purpose. #### Phase 3: Containment Containment is about stopping the spread. The CCCS guidance describes it as "crucial for your organization's recovery" with the primary goal of minimizing business impact. The CCCS guidance is clear that containment strategies depend on the type of incident, the degree of damage it can cause, and the organization's operational requirements. There is no single containment procedure that applies to every incident. The risk assessment completed in the preparation phase informs what level of disruption is acceptable during containment. Practical containment actions for an SMB might include: - Disconnecting affected devices from the network — wired and wireless - Disabling compromised user accounts - Blocking specific IP addresses or domains at the firewall - Temporarily suspending remote access or VPN connections - Isolating network segments if segmentation is in place The CCCS guidance also notes that it may be necessary to isolate all systems and suspend employee access temporarily to detect and stop further intrusions. This is a significant operational decision — one that is much harder to make under pressure without a plan that pre-authorizes it. #### Phase 4: Eradication Once contained, the root cause must be identified and removed. This means finding how the attacker got in, what tools or malware they deployed, and eliminating all elements of the compromise from affected systems. For many Canadian SMBs, this phase involves external expertise — a managed service provider, an incident response consultant, or a forensic specialist. The CCCS guidance notes that outsourcing incident response for specialized environments can be costly, and that planning for this in advance is important. Having a relationship with an incident response provider — or at least knowing who to call — before an incident occurs saves critical time. #### Phase 5: Recovery Recovery means restoring affected systems and returning to normal operations. The CCCS guidance emphasizes: ensure any malware is removed before restoring backups, and test, verify, monitor, and validate affected systems to ensure they are running effectively. Recovery follows the priorities set during preparation. Systems identified as critical — with the shortest maximum tolerable downtime — come back first. The vulnerability or access method the attacker used must be patched or closed before restored systems are reconnected to the network, or the same attack can succeed again immediately. Recovery takes longer than most businesses expect. For small businesses without documented recovery procedures and tested backups, restoration typically takes days to weeks. The Toronto Public Library took nearly five months. #### Phase 6: Post-Incident Review The CyberSecure Canada template calls this the "Learning" phase. The CCCS guidance frames it as developing exercises to test the plan and using results to revise and improve it. A post-incident review asks: - How did the attacker get in? - How was the incident detected, and how long did detection take? - What worked in the response? What did not? - Were the right people contacted? Did communication flow as planned? - Were there gaps in tools, training, or procedures? - What specific changes are needed before the next incident? This review feeds directly back into Phase 1, updating the plan based on real experience. The CCCS guidance recommends testing, revisiting, and revising the incident response plan annually at minimum. ### PIPEDA: The Legal Obligation That Runs Parallel If a cyber incident involves personal information — employee records, customer data, financial details — it almost certainly triggers mandatory breach reporting under PIPEDA. PIPEDA requires organizations to report a breach to the Office of the Privacy Commissioner of Canada when it creates a "real risk of significant harm" to individuals. "Significant harm" includes financial loss, identity theft, damage to reputation, and loss of employment or business opportunities. Given the nature of most cyber incidents — particularly ransomware, where data exfiltration is increasingly common — the threshold is met in the majority of cases. Three obligations apply: - Report to the Privacy Commissioner — "As soon as feasible" after determining the breach has occurred. PIPEDA does not prescribe a specific number of days, but the expectation is that organizations do not wait for a complete investigation before reporting. - Notify affected individuals — Inform them of what happened, what information was involved, and what steps they can take to protect themselves. - Maintain records — Keep records of all breaches of security safeguards for 24 months, regardless of whether they meet the reporting threshold. The Commissioner can request access to these records at any time. Failure to report, notify, or maintain records is an offence under PIPEDA, with fines of up to $100,000 per violation. An incident response plan that does not account for PIPEDA's breach notification requirements leaves a significant legal and operational gap. The plan should include: who determines whether the RROSH threshold is met, who drafts the report to the Privacy Commissioner, who handles individual notification, and what records are kept. ### Testing the Plan A plan that has never been tested is a plan that might not work. The CyberSecure Canada template explicitly includes a testing section, noting that "unless real incidents occur which test the full functionality of the process, this can be achieved using walkthroughs and practical simulations of potential incidents." The CCCS guidance similarly recommends developing exercises to test the plan and using results to improve it. Testing does not require a full-scale simulation. For a small business, it can be as straightforward as: - Tabletop exercise — Gather the response team around a table (or a video call) and walk through a scenario: "It's Monday morning. An employee reports that all shared drive files are encrypted and there's a ransom note on their screen. What do we do?" Walk through every step of the plan and note where it breaks down. - Communication test — Verify that every phone number and email address in the plan still works. Confirm that the person listed as the primary contact is still in that role. - Backup restoration test — Attempt a full restore of a critical system from backup. Measure how long it takes. Confirm the data is intact. This tests both the incident response plan and backup procedures simultaneously. IBM's data indicates that organizations conducting incident response testing at least twice a year reduce breach costs by an average of $1.49 million compared to those that do not test. The CCCS recommends at minimum an annual review and revision cycle. ### The Insurance Connection Cyber insurers increasingly ask whether the policyholder has a written, tested incident response plan. Many applications specifically ask when the plan was last reviewed and whether tabletop exercises have been conducted. Beyond the application, the plan itself affects claims. Most cyber insurance policies require prompt notification — typically within 24 to 72 hours of discovering an incident. An incident response plan that includes the insurer's claims number, the notification timeline, and the steps to preserve evidence makes the difference between a smooth claim process and a disputed one. ### Free Government Resources The Canadian government provides several free resources directly relevant to building an incident response plan: - Developing Your Incident Response Plan (ITSAP.40.003) — The CCCS's primary guidance document on IRP development - CyberSecure Canada IRP Template — A fillable Word document template with section-by-section instructions from ISED - Ransomware Playbook (ITSM.00.099) — A detailed operational framework for ransomware prevention, response, and recovery - Get Cyber Safe — The Government of Canada's public awareness campaign, including resources for small businesses - Developing Your IT Recovery Plan (ITSAP.40.004) — Companion guidance on recovery planning that works alongside your IRP - Canadian Centre for Cyber Security contact: 1-833-CYBER-88 (1-833-292-3788) or via My Cyber Portal ### The Baseline Controls Connection Incident response planning is BC.1 — the first of the Canadian Centre for Cyber Security's Baseline Controls — but it does not exist in isolation. An effective incident response plan depends on controls from across the framework: - BC.2 — Patch Management: The post-incident review may reveal that an unpatched vulnerability was the entry point - BC.3 — Anti-Malware: Detection tools generate the alerts that trigger the response - BC.5 — Authentication: Compromised credentials are a leading cause of incidents — MFA reduces this risk and is increasingly required by insurers - BC.6 — Security Awareness: Trained employees are often the first to detect an incident by recognizing something unusual - BC.7 — Data Backup: Recovery depends entirely on having reliable, tested, offline backups - BC.9 — Network Security: Network segmentation limits lateral movement during containment - BC.12 — Access Control: Least-privilege access reduces the blast radius when an account is compromised The plan is the thread that connects these controls when it matters most. Our free assessment evaluates your organization across all 13 Baseline Control areas, including incident response readiness. It takes under 10 minutes and shows where your current posture stands — and where the gaps are that a plan needs to account for. ### Frequently Asked Questions — Building an Incident Response Plan for Your Canadian Business Q: What is an incident response plan? A: An incident response plan (IRP) documents how your organization detects, responds to, and recovers from a cybersecurity incident. The Canadian Centre for Cyber Security defines it as covering the processes, procedures, and documentation related to how your organization handles a specific incident. It names who does what, who to contact, in what order systems are restored, and what legal reporting obligations apply. Q: Why is incident response the first Baseline Control? A: The CCCS designates incident response planning as BC.1 — ahead of patch management, authentication, and backups. The positioning is deliberate: when an incident hits, the effectiveness of every other control depends on having a plan to follow. The speed, cost, and outcome of any recovery are largely determined by what was decided before the incident occurred. Q: What Canadian government guidance exists for incident response planning? A: The Canadian Centre for Cyber Security publishes Developing Your Incident Response Plan (ITSAP.40.003), which sets out the structure, phases, and considerations for building an IRP. The federal CyberSecure Canada programme also provides a template that includes an explicit testing section. Both are free. Q: How much does an incident response plan actually save? A: IBM's Cost of a Data Breach research found that organizations conducting incident response testing at least twice a year reduced average breach costs by $1.49 million compared with organizations that did not test. The saving comes from testing, not from the document existing — an untested plan is a plan that might not work. Q: How often should an incident response plan be tested? A: The CCCS recommends at minimum an annual review and revision cycle, and IBM's data associates testing at least twice yearly with materially lower breach costs. Testing does not require a full simulation. For a small business it can be a tabletop exercise walking through a ransomware scenario, a communication test confirming every phone number and email in the plan still reaches the right person, and a backup restoration test that measures how long a full restore actually takes. Q: Does a Canadian business have a legal obligation to report a cyber incident? A: If an incident involves personal information, PIPEDA requires reporting to the Office of the Privacy Commissioner of Canada when the breach creates a "real risk of significant harm" — which includes financial loss, identity theft, reputational damage, and loss of employment or business opportunities. Organizations must also notify affected individuals and keep records of all breaches of security safeguards for 24 months, whether or not they meet the reporting threshold. Failure to do so is an offence carrying fines of up to $100,000 per violation. Your plan should name who determines whether the threshold is met and who files. This is general information, not legal advice. Q: How prepared are Canadian businesses for cyber incidents? A: Not very. Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime found only 26% of Canadian businesses had written cybersecurity policies in place — unchanged from 2021 — while 1 in 6 businesses (16%) were impacted by a cybersecurity incident that year. Total Canadian spending on recovery from cyber incidents doubled from $600 million in 2021 to $1.2 billion in 2023. --- ## What to Do in the First 24 Hours After a Cyber Attack URL: https://cybersecuritycanada.ca/news/posts/what-to-do-in-the-first-24-hours-after-a-cyber-attack/ Category: Guide Published: February 28, 2026 Summary: When a cyber attack hits, the decisions you make in the first hours determine how much damage your business sustains. This step-by-step guide walks Canadian small business owners through the critical first 24 hours. You arrive at the office on a Monday morning. Employees can't log in. Files are inaccessible. There's an unfamiliar message on the screen demanding payment. Or maybe it's subtler — a vendor calls to say they received an unusual email from your account, or your bank flags a wire transfer you didn't authorize. However it presents itself, you now know — or strongly suspect — that your business has been hit by a cyber attack. What happens in the next 24 hours matters more than anything that happens in the weeks that follow. The speed and quality of your initial response determines how much data is lost, how much money is at risk, how long your business is disrupted, and whether your cyber insurance claim will be honoured. This guide walks through the critical first 24 hours, step by step. ### Hour 0-1: Stop the Bleeding The first priority is containment — stopping the attack from spreading further. #### Don't Panic, Don't Shut Everything Down The natural instinct is to turn everything off immediately. Resist it. While disconnecting affected systems from the network is correct, powering off devices can destroy forensic evidence in memory that may be needed to understand the attack, recover data, or support an insurance claim. Instead, disconnect — don't power off: - Unplug network cables from affected computers - Disconnect affected devices from Wi-Fi (turn off Wi-Fi on the device, don't just close the laptop lid) - Do not restart, wipe, or reinstall anything yet #### Identify What You're Dealing With Different attack types require different responses. In the first hour, try to determine: - Ransomware: Files are encrypted, ransom notes are visible, file extensions have been changed. Disconnect affected systems immediately to prevent lateral spread. - Business email compromise: Unauthorized emails sent from your account, fraudulent payment requests, unexpected password reset notifications. Change the compromised account's password and revoke active sessions immediately. - Account takeover: Unusual login activity, MFA prompts you didn't initiate, password changes you didn't make. Lock the affected accounts. - Data breach/exfiltration: Notification from a third party, unusual data transfers in logs, sensitive data appearing where it shouldn't. Preserve logs and evidence. - Malware infection: Unusual system behaviour, anti-malware alerts, degraded performance. Isolate affected devices from the network. If you're not sure what you're dealing with, treat it as serious until proven otherwise. Containment first, classification second. #### Call Your IT Support If you have a managed service provider (MSP), IT support company, or internal IT person — call them now. Not email. Phone. Explain what you've observed and ask them to begin investigating immediately. If your vendor or MSP has an emergency or after-hours number, use it. Cyber attacks don't respect business hours. ### Hour 1-4: Assess and Escalate Once immediate containment steps are taken, the next phase is understanding the scope and activating your support network. #### Activate Your Incident Response Plan If you have a written incident response plan, now is when you use it. Pull it out — the printed copy you keep accessible (because the digital copy may be on a compromised system) — and follow the steps. If you don't have a formal plan, follow the steps in this guide and commit to building one after this is resolved. #### Assess the Scope Work with your IT support to determine: - Which systems are affected? Is it one workstation, one server, the entire network? - Which data may be compromised? Customer records? Financial data? Employee information? Email? - Are backups intact? Check whether your backup systems are accessible and whether they have been affected. Do not connect backups to compromised systems. - How did the attacker get in? A phishing email? A compromised account without MFA? An unpatched vulnerability? Understanding the entry point helps determine the scope. - Is the attack still active? Is the attacker still in your systems, or has the damage already been done? Document everything as you go. Timestamps, observations, actions taken. This record will be critical for your insurer, law enforcement, and any regulatory notifications. #### Notify Your Cyber Insurer If you have cyber insurance, notify your carrier as soon as possible — most policies require notification within 24 to 72 hours of discovering an incident. Late notification can jeopardize your claim. Your insurer's claims line should be in your incident response plan. When you call: - Describe what you've observed - Explain what containment steps you've already taken - Ask whether they have a preferred incident response firm or forensic investigator — many insurers have pre-approved vendors, and using them may be required under your policy - Follow their instructions regarding evidence preservation Do not engage a forensic investigator, legal counsel, or public relations firm on your own if your policy covers these services — the insurer may not reimburse costs for providers that weren't pre-approved. #### Consider Legal Counsel Depending on the nature of the attack, legal counsel may be needed early — particularly if personal information has been or may have been compromised. A lawyer experienced in cybersecurity and privacy law can advise on: - PIPEDA breach notification obligations - Privilege over forensic investigation findings (conducting the investigation under legal privilege can protect sensitive findings from disclosure in litigation) - Contractual notification obligations to clients, partners, or vendors - Communication strategy to minimize legal exposure Your cyber insurance policy may include coverage for legal fees and may have pre-approved legal counsel. ### Hour 4-12: Investigate and Communicate #### Work With Forensic Investigators For significant incidents — ransomware, confirmed data breaches, business email compromise with financial losses — a professional incident response team should investigate. They will: - Determine the full scope of the compromise - Identify the attacker's entry point and movement through your systems - Preserve forensic evidence in a way that is admissible and useful - Advise on eradication and recovery steps - Provide a timeline of the incident If your cyber insurer has assigned an incident response firm, work with them. If not, the Canadian Centre for Cyber Security can provide guidance. #### Communicate With Your Team Your employees need to know what's happening — and what to do. Communication should be clear, calm, and specific: - What happened (at a high level — you don't need to share technical details) - What they should and should not do — don't log in to affected systems, don't click any unusual links, don't discuss the incident publicly or on social media - Who to contact if they notice anything unusual or have questions - What the plan is — when you expect to have more information, what the next steps are If the attack involved compromised email accounts, communicate through an alternative channel — phone, text, or a messaging platform that isn't connected to the affected systems. #### Report to Authorities Canadian Centre for Cyber Security: Report the incident by calling 1-833-CYBER-88 (1-833-292-3788) or through the My Cyber Portal. The Cyber Centre can provide technical guidance and, in cases involving significant threats, may be able to assist directly. In 2024-2025, the Cyber Centre issued 336 pre-ransomware notifications to Canadian organizations. Local Police: File a report with your local police service. While local police may not have the capacity to investigate cybercrime directly, the report creates an official record that may be needed for insurance claims and regulatory filings. Canadian Anti-Fraud Centre: If the incident involves fraud (such as BEC), report to the CAFC at 1-888-495-8501 or online at antifraudcentre.ca. ### Hour 12-24: Plan Recovery and Fulfil Obligations #### Determine PIPEDA Notification Requirements If the incident involves personal information — and most cyber attacks that compromise business systems do — you need to assess whether PIPEDA's mandatory breach notification is triggered. Under PIPEDA, you must report a breach to the Office of the Privacy Commissioner of Canada when it creates a "real risk of significant harm" (RROSH) to individuals. Given the nature of most cyber attacks, the threshold is met in the majority of cases. If RROSH is met, three obligations apply: - Report to the Privacy Commissioner — as soon as feasible - Notify affected individuals — inform them of what happened and what they can do to protect themselves - Keep records — maintain records of the breach for 24 months Failure to comply can result in fines of up to $100,000 per violation. Your legal counsel and cyber insurer can help you navigate this process. For a detailed overview, see our guide to Canada's privacy landscape. #### Begin Recovery Planning Once the investigation has determined the scope and the attacker's access has been eliminated, recovery can begin: - Prioritize critical systems. Restore the systems your business needs most — email, financial systems, customer-facing services — first. Use the priority list from your incident response plan. - Restore from clean backups. Only restore from backups that you have verified are not compromised. If backups are cloud-based, confirm the backup predates the attack. - Patch before reconnecting. Close the vulnerability or access method the attacker used before bringing restored systems back online. Otherwise, the same attack can succeed immediately. - Reset all credentials. Change passwords for all accounts — not just the ones known to be compromised. Enable MFA everywhere it wasn't already in place. - Monitor closely. After recovery, monitor systems for signs of re-compromise. Attackers sometimes maintain secondary access methods (persistence mechanisms) that survive the initial cleanup. #### Notify Affected Parties Depending on the nature of the incident, you may need to notify: - Customers whose data may have been accessed - Employees whose personal information was affected - Business partners and vendors who may be at risk or whose data was involved - Your bank if financial accounts may be compromised - Contractual parties where your agreements include breach notification requirements Work with legal counsel on the content and timing of notifications to ensure compliance and minimize legal exposure. ### After the First 24 Hours The immediate crisis response is just the beginning. In the days and weeks that follow: - Complete the forensic investigation — understand exactly what happened, what data was accessed, and how - Implement the recommendations — close the gaps that allowed the attack to succeed - Conduct a post-incident review — what worked, what didn't, what needs to change - Update your incident response plan — incorporate lessons learned - Review your security posture — MFA on all accounts, patching current, backups tested, training refreshed ### The Key Takeaway The first 24 hours after a cyber attack are about three things: contain, communicate, and preserve. Contain the damage to prevent it from spreading. Communicate with the right people — your IT support, your insurer, your team, and the authorities. Preserve evidence so that investigators, insurers, and regulators have what they need. Every action in the first 24 hours is easier and faster with a plan. If this guide highlighted gaps in your preparedness, our free assessment evaluates your organization across all 13 of the Canadian Centre for Cyber Security's Baseline Control areas — including incident response readiness, backup integrity, and authentication controls. It takes under 10 minutes and shows you exactly where to strengthen your defences before the next incident. For a step-by-step overview, see our cybersecurity guide for Canadian small businesses. --- ## Cyber Insurance: What Canadian SMBs Need to Understand URL: https://cybersecuritycanada.ca/news/posts/cyber-insurance-what-canadian-smbs-need-to-understand/ Category: Insights Published: February 22, 2026 Summary: Cyber insurance adoption among Canadian businesses remains low, and denied claims are making headlines. Here is what the market looks like, what insurers are requiring, and what happens when those requirements are not met. In February 2024, the City of Hamilton was hit by a ransomware attack that disrupted roughly 80% of its network. The recovery cost the city $18.3 million. When Hamilton filed its cyber insurance claim, the insurer denied it — reportedly because multi-factor authentication had not been fully implemented at the time of the attack. Hamilton is not an isolated case. Across North America, cyber insurance claims are being denied, policies are being voided, and coverage disputes are ending up in court — often because the insured organization did not meet the security requirements outlined in its own policy. For Canadian small and medium businesses, the cyber insurance landscape has changed significantly in recent years. Understanding what policies cover, what insurers expect, and where claims have been denied is increasingly relevant. ### What Cyber Insurance Typically Covers Cyber insurance policies vary, but most provide some combination of first-party and third-party coverage: #### First-Party Coverage (Your Direct Losses) - Incident response costs — Forensic investigation, breach counsel, and crisis management - Business interruption — Lost income and extra expenses during downtime. The real cost of cyber downtime often exceeds the direct cost of the incident itself. - Data recovery — Restoring or reconstructing data from compromised or encrypted systems - Ransom payments — Some policies cover ransom payments, though this varies and is increasingly subject to conditions - Notification costs — Mandatory breach notification under PIPEDA requires notifying affected individuals and the Privacy Commissioner #### Third-Party Coverage (Claims Against You) - Regulatory defence and fines — Legal costs and penalties resulting from privacy investigations - Liability — Claims from customers, partners, or other parties affected by a breach - Media liability — In some policies, coverage for defamation or intellectual property claims arising from a cyber event Policies also typically include sublimits — caps on specific categories of coverage that may be significantly lower than the overall policy limit. Social engineering fraud, for example, often carries a sublimit that is a fraction of the total coverage amount. ### When Claims Are Denied: What the Cases Show The most instructive aspect of the cyber insurance market is not what policies promise to cover — it is what happens when a claim is filed and the insurer determines the policyholder did not meet its obligations. #### Travelers v. International Control Services (2022) In July 2022, Travelers Property Casualty Company of America filed a lawsuit in the U.S. District Court for the Central District of Illinois seeking to void the cyber insurance policy it had issued to International Control Services (ICS), an electronics manufacturer. ICS had suffered a ransomware attack and filed a claim. Travelers' position was that ICS had stated on its insurance application that it used multi-factor authentication for remote access and privileged accounts. Travelers alleged this was materially false — MFA was not actually in place at the time of the application or the attack. The case was resolved through a stipulated judgment — both parties agreed to void the policy. The policy was rescinded — voided from inception — meaning ICS had no coverage at all. This case is significant because the insurer did not merely deny the claim. It voided the entire policy on the basis that the application contained a material misrepresentation about MFA. #### Columbia Casualty v. Cottage Health (2015) Columbia Casualty Company, a subsidiary of CNA Financial, issued a cyber liability policy to Cottage Health System, a California healthcare network. When Cottage Health suffered a data breach exposing approximately 32,500 patient records — a server containing protected health information had been left accessible on the internet without proper security controls — Columbia Casualty sued Cottage Health in 2015. The insurer's argument: Cottage Health's application represented that it maintained specific security controls including encryption, access controls, and regular security assessments. Columbia Casualty alleged these controls were not actually in place. The policy contained an exclusion for losses arising from a failure to maintain the minimum security practices described in the application. The coverage dispute was ultimately dismissed by a California court after Columbia Casualty failed to comply with the policy's mandatory mediation clause, though the underlying breach led to a $4.125 million class-action settlement. The central principle was established — what you represent on your application matters, and insurers will investigate. #### Mondelez v. Zurich (2018) In June 2017, the NotPetya malware attack disrupted Mondelez International's global operations, damaging approximately 1,700 servers and 24,000 laptops. Mondelez filed a claim under its property insurance policy with Zurich American Insurance Company for approximately $100 million in losses. Zurich denied the claim in 2018, invoking the policy's "hostile or warlike action" exclusion. Zurich's position was that NotPetya had been attributed to the Russian military as an attack on Ukraine, and therefore constituted a state-sponsored act of war excluded under the policy. Two important distinctions: this was a traditional property insurance policy, not a standalone cyber policy. And the claim was denied not because of a security failing by Mondelez, but because of a policy exclusion the insured may not have fully anticipated. The case settled in late 2022 on confidential terms. In its wake, Lloyd's of London issued guidance in 2022 (Market Bulletin Y5381) requiring that cyber insurance policies include clear exclusions for state-backed cyberattacks, effective March 2023. #### City of Hamilton (2024) Hamilton's ransomware incident is one of the most prominent Canadian examples. The city reported recovery costs of $18.3 million. Its cyber insurance claim was denied, with reports indicating that MFA had not been fully deployed across city systems — a requirement that cyber insurers increasingly treat as a baseline condition of coverage. ### What Insurers Are Requiring The cases above illustrate a broader pattern. Over the past several years, cyber insurers have substantially tightened the security requirements they expect policyholders to meet — both at application time and throughout the policy period. The following controls are now commonly listed on cyber insurance applications, and in many cases, coverage will not be offered without them: #### Multi-Factor Authentication MFA is the most frequently cited requirement. Insurers typically require it on: - Remote access (VPN) - Email platforms (Microsoft 365, Google Workspace) - Privileged and administrative accounts - Backup systems and infrastructure The Travelers v. ICS case demonstrated that misrepresenting MFA status on an application can result in the entire policy being voided. Hamilton's denied claim illustrated the consequences of incomplete MFA deployment at claim time. #### Endpoint Detection and Response (EDR) Traditional antivirus software is no longer considered sufficient by most insurers. Many now require managed endpoint detection and response — tools that continuously monitor devices for suspicious activity and can respond automatically. #### Backup Strategy Insurers increasingly ask about backup practices, including: - Whether backups are offline, air-gapped, or immutable — not just cloud-synced - Whether backup restoration has been tested - Whether backup credentials are separate from production credentials - Whether the organization follows the 3-2-1 rule (three copies, two storage types, one offsite) These questions align directly with the backup practices outlined in the Canadian Centre for Cyber Security's Baseline Controls (BC.7). #### Patch Management Applications commonly ask whether the organization has a documented patching process and how quickly critical vulnerabilities are addressed. Some insurers specify a maximum timeframe — often 14 to 30 days — for patching critical and high-severity vulnerabilities. #### Incident Response Plan Many applications ask whether the organization has a written incident response plan (BC.1) that has been reviewed or tested within the past 12 months. This aligns with the first of the 13 Baseline Controls. #### Email Security and Training Insurers ask about email authentication protocols (SPF, DKIM, DMARC), email filtering, and whether employees receive regular security awareness training that includes phishing simulations. ### The Canadian Market #### Adoption Remains Low Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime found that only 22% of Canadian businesses reported having cyber insurance — either as a standalone policy or as part of a broader coverage package. Among small businesses with 10 to 49 employees, adoption was lower still. Meanwhile, 1 in 6 Canadian businesses were impacted by a cybersecurity incident according to the same survey, and total spending on recovery from cyber incidents across Canadian businesses reached $1.2 billion in 2023 — double the $600 million spent two years earlier. #### Premiums Have Been Volatile The Canadian cyber insurance market experienced significant premium increases in 2021 and 2022, with some organizations seeing year-over-year increases of 50% or more. By 2023 and 2024, the market began stabilizing, with more moderate adjustments — and in some cases, decreases for organizations that could demonstrate strong security postures. This pricing dynamic reflects a market that is increasingly risk-differentiated: businesses with documented security controls pay less, and businesses without them either pay significantly more or cannot obtain coverage at all. #### The Application Is a Security Assessment One aspect that catches many businesses off guard is the application process itself. Cyber insurance applications have evolved from simple questionnaires into detailed security assessments. They ask specific, technical questions about MFA deployment, EDR coverage, backup architecture, patching cadence, access controls, and incident response readiness. The answers provided on the application form the basis of the insurance contract. As the Travelers v. ICS and Columbia Casualty v. Cottage Health cases illustrate, inaccurate answers — whether intentional or not — can result in denied claims or voided policies. ### What This Means in Practice Several patterns emerge from the current state of the cyber insurance market: Security controls and insurability are converging. The controls insurers require — MFA, EDR, tested backups, patching, incident response planning — closely mirror the Canadian Centre for Cyber Security's Baseline Controls. Organizations that implement the Baseline Controls are simultaneously building the security posture that insurers look for. The application is a commitment. What a business states on its insurance application is treated as a material representation. If the stated controls are not actually in place when a claim is filed, the insurer has grounds to deny coverage or void the policy entirely. Exclusions matter. Policies contain exclusions — for acts of war, for pre-existing conditions, for failure to maintain stated controls, and for late notification. Understanding what a policy does not cover is as important as understanding what it does. Late notification can affect coverage. Most policies require prompt notification — often within 24 to 72 hours of discovering an incident. Having an incident response plan that includes the insurer's contact information and notification requirements is directly relevant to whether a claim proceeds smoothly. ### The Baseline Controls Connection The overlap between what cyber insurers require and what the Canadian Centre for Cyber Security's Baseline Controls define is substantial: - BC.1 — Incident Response Planning: Insurers ask whether a written, tested plan exists - BC.2 — Patch Management: Insurers ask about patching cadence and timeframes for critical vulnerabilities - BC.5 — Authentication: MFA is the single most common insurance requirement — and the most common reason for denied claims - BC.6 — Security Awareness: Insurers ask about employee training and phishing simulations - BC.7 — Data Backup: Insurers ask about offline backups, tested restores, and the 3-2-1 rule - BC.9 — Network Security: Insurers ask about segmentation, firewalls, and remote access controls An organization that has honestly assessed and addressed these control areas is in a materially different position — both in terms of its ability to prevent an incident and its ability to support an insurance claim if one occurs. Our free assessment evaluates your organization across all 13 Baseline Control areas. It takes under 10 minutes and shows where your security posture currently stands — information that is relevant whether or not you are considering insurance. --- ## Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack URL: https://cybersecuritycanada.ca/news/posts/ransomware-what-canadian-businesses-need-to-know-before-during-and-after-an-attack/ Category: Threats Published: February 21, 2026 Summary: Ransomware remains the top cybercrime threat facing Canadian organizations. Here is what Canadian SMBs should do before an attack happens, what to do if one is underway, and how to recover. In April 2024, a ransomware attack forced London Drugs to close all 79 of its retail stores across Western Canada for over a week. The attackers demanded $25 million. The company refused to pay. In February 2024, a ransomware attack crippled roughly 80% of the City of Hamilton's network — including business licensing, property tax systems, and city phone lines. The recovery cost reached $18.3 million, and the city's cyber insurance claim was denied because multi-factor authentication had not been fully implemented at the time of the attack. These are not isolated incidents. They are part of a pattern that is accelerating across Canada, and small and medium businesses are not exempt from it. ### Ransomware in Canada: The Scale of the Problem The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 is unambiguous: ransomware is the top cybercrime threat facing Canada's critical infrastructure. Canadian ransomware incidents have increased by an average of 26% year over year between 2021 and 2024, and that pace is expected to continue. Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime found that 1 in 6 Canadian businesses (16%) were impacted by a cybersecurity incident, with 13% of those identifying ransomware as the method of attack. Across all Canadian businesses, total spending on recovery from cyber incidents doubled from $600 million in 2021 to $1.2 billion in 2023. The average ransom payout in Canada reached $1.13 million in 2023. But the ransom itself is only a fraction of the total damage — the real cost of downtime includes lost revenue, idle employees, departed customers, legal fees, and recovery expenses that can dwarf the ransom demand. If you believe your business is too small to be targeted, consider this: the Ransomware-as-a-Service (RaaS) model has lowered technical barriers so far that attackers can rent sophisticated tools without building them. These operations scan thousands of networks simultaneously, looking for unpatched software, weak passwords, and missing multi-factor authentication. They do not check your revenue before they encrypt your files. #### Canadian Incidents That Made It Real Recent incidents show what a ransomware attack looks like in practice for Canadian organizations: - Indigo Books & Music (February 2023) — LockBit ransomware shut down the company's point-of-sale systems, e-commerce, and all internal systems. Employee data including Social Insurance Numbers was stolen. Indigo refused to pay and reported a $26.5 million revenue decrease for the quarter. - Toronto Public Library (October 2023) — Black Basta ransomware took down all digital services across 100 branches. Employee data going back to 1998 was stolen. The attackers demanded $10 million. The library refused to pay. Full service restoration took nearly five months. - City of Hamilton (February 2024) — Recovery cost $18.3 million. The cyber insurance claim was denied because MFA was not fully deployed — a direct consequence of an incomplete authentication strategy. - London Drugs (April 2024) — All 79 stores closed for over a week. The $25 million ransom demand was refused. Corporate employee data was leaked on the dark web. - Nova Scotia Power (March 2025) — Personal and financial information of nearly 280,000 customers was exposed — roughly half of its entire customer base. Every one of these organizations refused to pay. Every one faced months of disruption. ### Before an Attack: What to Do Now The decisions that determine whether your business survives a ransomware attack are made before it happens. Once the ransom note is on your screen, your options are already narrowed to what you prepared. #### Have an Incident Response Plan (BC.1) The single most important thing a Canadian SMB can do is have a written plan for what happens when a cybersecurity incident occurs — before one actually does. The Canadian Centre for Cyber Security's Baseline Controls designate this as BC.1, the first of the 13 fundamental control areas, because everything else depends on it. Your plan does not need to be a hundred-page document. At minimum, it should answer: - Who is in charge? Name a specific person (and a backup) responsible for leading the response - Who do you call? Include contact details for your IT provider or managed security service, your cyber insurance carrier, legal counsel, and the Canadian Centre for Cyber Security (1-833-CYBER-88) - What systems are critical? Know which systems must come back first and what data they depend on - Where is the plan? Keep a hard copy accessible. If your network is encrypted, a plan stored only on the network is useless The CCCS publishes a Ransomware Playbook (ITSM.00.099) that provides a detailed operational framework for prevention, response, and recovery. It is free and written for Canadian organizations. #### Back Up Your Data — and Test the Backups (BC.7) Reliable backups are the difference between a ransomware incident and a ransomware catastrophe. If you can restore your systems from clean backups, the attacker's leverage disappears. The Baseline Controls (BC.7) require organizations to back up essential business information, store backups encrypted, and ensure recovery mechanisms actually work. The critical details are: - Follow the 3-2-1 rule: Three copies of data, on two different types of storage, with one copy stored offline or offsite — disconnected from your network - Test your restores regularly. A backup that has never been restored is a backup you are hoping works. Hope is not a strategy. Here are five backup assumptions that commonly fail when it matters most. - Keep offline backups. Ransomware specifically targets connected backup systems. If your backup is always online and reachable from the same network, it will be encrypted alongside everything else. #### Patch Your Systems (BC.2) Unpatched software is one of the most common ways ransomware operators gain initial access. The CCCS prioritizes automatic patching as the second most important security action an organization can take. Enable automatic updates for operating systems and applications wherever possible. For software that requires manual updates, establish a regular patching cadence — and do not let critical patches sit for weeks. #### Enforce Multi-Factor Authentication (BC.5) Stolen or weak credentials remain a primary way attackers get into business networks. MFA makes a stolen password insufficient on its own. The Baseline Controls (BC.5) require MFA wherever possible, with particular emphasis on financial accounts, administrator accounts, cloud services, and senior executive accounts. The City of Hamilton's denied insurance claim makes the business case starkly clear: strong authentication is not optional, and insurers are verifying it. #### Train Your People (BC.6) Phishing remains the most common delivery mechanism for ransomware. An employee who clicks a malicious link or opens a weaponized attachment can give an attacker initial access to your network in seconds. Invest in security awareness training that covers how to recognize phishing emails, what to do with suspicious messages, and how to report potential incidents. The Canadian Centre for Cyber Security and Get Cyber Safe offer free resources for Canadian organizations. #### Restrict Access (BC.12) Follow the principle of least privilege: employees should only have access to the systems and data they need for their role. Administrative accounts should be used only for administrative tasks — not for email or web browsing. If ransomware compromises a user account with broad access, it can move laterally across your entire network. If that same account has only the minimum necessary permissions, the blast radius is contained. ### During an Attack: What to Do When It Happens If you discover a ransom note, encrypted files, or other signs of a ransomware attack in progress, your actions in the first hours are critical. #### 1. Isolate Affected Systems Immediately Disconnect compromised machines from the network — wired and wireless. The goal is to stop the ransomware from spreading to additional systems, backup infrastructure, and shared drives. Do not power off the machines unless absolutely necessary, as forensic evidence in memory may be lost. If you have network segmentation, isolate affected segments. If you do not, disconnect everything you can and assess which systems are still clean. #### 2. Activate Your Incident Response Plan This is why the plan exists. Follow it. Contact the people listed in it. If you have cyber insurance, notify your carrier immediately — most policies require prompt notification, and late reporting can affect coverage. #### 3. Do Not Pay the Ransom The Government of Canada's position is clear: "The Government of Canada does not recommend paying ransom to cyber criminals because any ransom payment fuels the ransomware model, which puts all Canadians at increased risk. There is no guarantee that cybercriminals will return your information, and your organization may be identified as a target for future cybercrime." The data supports this guidance. Research from Sophos (State of Ransomware 2021) found that only 8% of organizations that paid the ransom recovered all of their data — and while more recent data shows improved recovery rates, paying remains unreliable and risky. Separate studies by Cybereason found that roughly 80% of organizations that paid were attacked again, with the majority hit within a year — and many were asked to pay more the second time. In Canada, 88% of businesses hit by ransomware did not pay (Statistics Canada, 2023). Paying is not unlawful under Canadian law, but it carries significant risk: there is no guarantee of recovery, it funds further attacks, and it may violate sanctions laws if the threat actor is tied to a sanctioned entity. #### 4. Report the Incident Contact the following: - Canadian Centre for Cyber Security — 1-833-CYBER-88 (1-833-292-3788) or via My Cyber Portal - Your local police service — File a report - Canadian Anti-Fraud Centre — 1-888-495-8501 or via the online reporting system - Your cyber insurance carrier — If you have a policy, notify them as early as possible Only an estimated 5 to 10% of cybercrime is reported in Canada. Reporting matters — in the 2024-2025 fiscal year, the Cyber Centre issued 336 pre-ransomware notifications to Canadian organizations, generating an estimated $6 to $18 million in economic savings. That intelligence depends on incident reports. #### 5. Preserve Evidence Do not wipe or reimage systems before forensic evidence is collected. Document what happened, when, and what you observed. Take screenshots of ransom notes. Record which systems are affected and which are confirmed clean. This evidence supports both your recovery and any law enforcement investigation. ### After an Attack: Recovery and Obligations #### Restore from Backups If your backups are intact and offline, begin restoration following your recovery plan. Prioritize systems in the order you defined before the incident — typically financial systems, customer-facing services, and communications first. Verify that the vulnerability the attacker used to get in has been patched before reconnecting restored systems. Otherwise, you are restoring into the same exposed environment. Recovery takes longer than most businesses expect. For small businesses without documented recovery procedures, restoration typically takes days to weeks. The Toronto Public Library took nearly five months to fully restore services. Plan for this reality. #### Meet Your Legal Obligations Under PIPEDA If the ransomware attack involved personal information — employee records, customer data, financial information — it almost certainly triggers mandatory breach reporting under PIPEDA. PIPEDA requires reporting when a breach creates a "real risk of significant harm" to individuals. Given the inherently malicious nature of ransomware and the difficulty of ruling out data exfiltration, ransomware attacks will nearly always meet this threshold. You must: - Report to the Privacy Commissioner of Canada — as soon as feasible after determining the breach occurred. There is no specific number of days, but "as soon as feasible" means do not wait for a complete investigation to start reporting. - Notify affected individuals — tell them what happened, what information was involved, and what they can do to protect themselves. - Keep records — maintain records of all breaches of security safeguards for 24 months, regardless of whether they meet the reporting threshold. The Commissioner can request access to these records at any time. Failure to report, notify, or maintain records is an offence under PIPEDA, with fines of up to $100,000 per violation. #### Conduct a Post-Incident Review Once the immediate crisis is resolved, conduct an honest review: - How did the attacker get in? Was it a phishing email, an unpatched vulnerability, a stolen credential, or a compromised vendor? - What worked? Did your backups hold? Did your incident response plan help? Did your team know what to do? - What failed? Where were the gaps — in technology, in process, or in training? - What changes are needed? Update your incident response plan, close the gaps, and test the fixes. This review is not about assigning blame. It is about ensuring the same attack does not work twice. ### What You Should Do If your business has not prepared for a ransomware attack, here is where to start: - Write an incident response plan. Define who leads, who gets called, and what happens in the first hour. Print it and keep a copy accessible offline. - Test your backups. Perform a full test restore. If you cannot restore your critical systems from backup, fix that before anything else. Follow the 3-2-1 rule. - Enable MFA everywhere. Start with email, cloud services, VPN, and administrative accounts. This single control eliminates the majority of credential-based attacks. - Patch automatically. Enable automatic updates on all systems. For anything that cannot be auto-updated, establish a weekly review cadence. - Train your team. Ensure every employee can recognize a phishing email and knows how to report one. Run simulated phishing exercises. - Restrict access. Review who has access to what and remove permissions that are not actively needed. Separate administrative accounts from daily-use accounts. - Secure remote access. If employees work remotely or in a hybrid model, ensure VPN connections are secured with MFA and endpoints are managed. - Review your insurance. If you have cyber insurance, verify that your current security posture meets the policy's requirements — particularly around MFA. If you do not have coverage, evaluate whether it makes sense for your organization. ### The Baseline Controls Ransomware preparedness is not a single control — it spans multiple areas of the Canadian Centre for Cyber Security's Baseline Controls. The most directly relevant are: - BC.1 — Incident Response Planning: Have a plan, assign responsibilities, include contact information for external parties and regulators, and keep a hard copy - BC.2 — Patch Management: Enable automatic updates to close the vulnerabilities ransomware operators exploit - BC.3 — Anti-Malware: Configure and enable anti-virus and anti-malware software with automatic updates and scanning on all devices - BC.5 — Authentication: Implement MFA wherever possible, especially for administrative and financial accounts - BC.6 — Security Awareness: Train employees to recognize and report threats - BC.7 — Data Backup: Back up essential systems, encrypt backups, store them offline, and test restoration regularly - BC.12 — Access Control: Follow least privilege to limit lateral movement if an account is compromised These are not enterprise requirements. They are practical steps that any Canadian business can implement — and the organizations that have them in place before an attack are the ones that survive it. Our free assessment evaluates your organization across all 13 Baseline Control areas, including the ones most critical to ransomware preparedness. It takes under 10 minutes and shows you exactly where your business stands — and where the gaps are. For more on all 13 controls, see our complete cybersecurity guide for Canadian small businesses. Unfamiliar with any terms? Check our cybersecurity glossary. ### Frequently Asked Questions — Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack Q: Should a Canadian business pay a ransomware ransom? A: The Government of Canada does not recommend paying, on the basis that any payment fuels the ransomware model, there is no guarantee criminals will return your data, and paying may mark your organization as a target for future attacks. The evidence supports that position: Sophos found only 8% of organizations that paid recovered all of their data, and Cybereason found roughly 80% of organizations that paid were attacked again. Statistics Canada reported that 88% of Canadian businesses hit by ransomware did not pay. Paying is not itself unlawful in Canada, but it carries recovery risk and may raise sanctions issues if the actor is tied to a sanctioned entity. Q: Who do I report a ransomware attack to in Canada? A: Report to the Canadian Centre for Cyber Security at 1-833-CYBER-88 (1-833-292-3788) or through My Cyber Portal, file a report with your local police service, and contact the Canadian Anti-Fraud Centre at 1-888-495-8501 or through its online reporting system. Notify your cyber insurance carrier as early as possible, since most policies require prompt notification and late reporting can affect coverage. If personal information was involved, separate reporting obligations to the Office of the Privacy Commissioner of Canada apply. Q: How common is ransomware in Canada? A: The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 identifies ransomware as the top cybercrime threat facing Canada's critical infrastructure. Canadian ransomware incidents rose by an average of 26% year over year between 2021 and 2024. Statistics Canada's 2023 survey found 1 in 6 Canadian businesses (16%) were impacted by a cybersecurity incident, with 13% of those identifying ransomware as the method. Total Canadian spending on recovery from cyber incidents doubled from $600 million in 2021 to $1.2 billion in 2023. Q: What is the average ransomware payment in Canada? A: The average ransom payout in Canada reached $1.13 million in 2023. The ransom is only a fraction of total damage, however — lost revenue, idle staff, departed customers, legal fees, and recovery costs frequently dwarf the demand itself. The City of Hamilton's 2024 recovery cost $18.3 million against no ransom payment, and Indigo reported a $26.5 million quarterly revenue decrease after refusing to pay. Q: Does a ransomware attack have to be reported under PIPEDA? A: If the attack involved personal information, it almost certainly triggers mandatory reporting. PIPEDA requires organizations to report breaches of security safeguards that create a "real risk of significant harm" to individuals. Because ransomware is inherently malicious and data exfiltration is difficult to rule out, ransomware attacks will nearly always meet that threshold. Three obligations follow: report to the Privacy Commissioner as soon as feasible, notify affected individuals, and keep records of all breaches for 24 months. Failure to do so is an offence carrying fines of up to $100,000 per violation. This is general information, not legal advice. Q: How long does it take to recover from a ransomware attack? A: Longer than most businesses expect. For small businesses without documented recovery procedures, restoration typically takes days to weeks. The Toronto Public Library needed nearly five months to fully restore digital services across 100 branches after its October 2023 Black Basta attack, and London Drugs closed all 79 of its Western Canadian stores for over a week in April 2024. Recovery speed depends almost entirely on whether offline, tested backups exist before the attack. Q: What should I do first if ransomware is running right now? A: Isolate affected systems from the network, wired and wireless, to stop the spread to backup infrastructure and shared drives — but do not power machines off unless necessary, because forensic evidence in memory may be lost. Then activate your incident response plan, notify your insurance carrier, report to the Cyber Centre and police, and preserve evidence: do not wipe or reimage systems before forensic evidence is collected, and screenshot the ransom note. --- ## USB Drives and Portable Media: The Security Risk Sitting in Your Desk Drawer URL: https://cybersecuritycanada.ca/news/posts/usb-drives-and-portable-media-the-security-risk-in-your-desk-drawer/ Category: Best Practices Published: February 20, 2026 Summary: USB drives remain one of the easiest ways for data to leave your business and one of the quietest ways for threats to get in. Here's what Canadian SMBs need to know. There is a good chance there is a USB drive in your office right now — in a desk drawer, plugged into a workstation, or in someone's laptop bag. It might hold a backup from two years ago, a client presentation, or files from a former employee. Nobody thinks much about it. That's exactly the problem. USB drives and other portable media — external hard drives, SD cards, and similar removable storage — remain one of the most overlooked attack surfaces for Canadian small businesses. They are simultaneously one of the easiest ways for sensitive data to leave your organization and one of the quietest ways for threats to enter it. ### The Threat Is Not Theoretical USB-based attacks are not a relic of the early 2000s. They are active, evolving, and increasingly sophisticated. Honeywell's industrial cybersecurity research found that 51% of malware detected in industrial environments was designed specifically for USB devices — a nearly six-fold increase from 9% just five years earlier. In the first quarter of 2025 alone, 1,826 unique USB threats were detected across industrial environments, including 124 never-before-seen variants. Unauthorized USB plug-and-play activity was the most common incident category recorded by Honeywell's industrial monitoring service, accounting for 25% of the top incident types identified. These numbers reflect industrial environments, but the underlying risk applies universally. If your business uses USB drives, the threat is relevant. #### Nation-State Actors Are Using USB Drives Between 2023 and 2025, CrowdStrike Intelligence tracked a series of USB-borne campaigns conducted by a China-nexus threat group using a custom USB worm engineered to silently propagate across removable drives and launch payloads for espionage. CrowdStrike confirmed this malware affected organizations in North America during 2025, demonstrating that USB-based attacks continue to cross geographic boundaries due to the uncontrolled nature of how removable media moves between systems. This is not just a nation-state concern. Commodity malware campaigns in late 2025 used infected USB drives to automatically execute hidden files and drop cryptomining malware, along with remote access tools like AsyncRAT — turning a single plugged-in drive into a multi-stage intrusion. #### USB Drop Attacks Still Work A well-known study by researchers at the University of Illinois dropped 297 USB drives around a university campus. 45% of the drives were opened — with files accessed — and 98% were physically picked up. The first drive was connected within six minutes. Among those who plugged in the drives, 68% reported taking no precautions before doing so. That study is from 2016, but the human behaviour it measured has not changed. If someone finds a USB drive in your parking lot or reception area, there is a meaningful chance it ends up connected to a machine on your network. ### The Two Risks: Data Loss and Malware Every time removable media connects to an endpoint, your business faces two distinct risks. #### Data Exfiltration A USB drive is one of the simplest tools for moving data out of an organization — intentionally or accidentally. An employee copying files to work from home, a contractor transferring project data, or a departing staff member taking records — none of these require any special tools or technical sophistication. Most organizations still lack basic controls over removable media. Industry surveys have consistently found that a majority of organizations do not use USB port control or device whitelisting software, and fewer than half require employees to encrypt data stored on USB drives. That means in most Canadian small businesses, anyone with physical access to a workstation can copy sensitive data to a personal device with no logging, no encryption, and no oversight. Under PIPEDA, your organization is responsible for personal information under its control. If customer data walks out the door on an unencrypted USB drive that is later lost or stolen, that is a breach — and it triggers reporting obligations. #### Malware Introduction A compromised USB drive can deliver malware the moment it is connected. Modern USB-based attacks go well beyond simply storing a malicious file on the drive: - Autorun exploits execute malware automatically when the drive is inserted - Firmware-level attacks reprogram the USB controller itself, making the drive appear as a keyboard or network adapter to bypass security controls entirely - Worm propagation silently copies malware to every USB drive connected to an infected machine, spreading laterally across your organization Unlike phishing emails, which your email filters and employee training can partially mitigate, USB-based malware bypasses network-level defences entirely. It is already inside your perimeter. ### Encrypt Everything on Portable Media If your business uses USB drives or external storage for any purpose, encryption is not optional — it is a baseline expectation. The Canadian Centre for Cyber Security's Baseline Controls explicitly require the use of encryption on all portable media (BC.13.1). This means data stored on USB drives, external hard drives, and SD cards should be encrypted at rest, so that a lost or stolen device does not automatically become a data breach. #### How to Encrypt USB Drives For most Canadian SMBs, practical encryption options include: - BitLocker To Go (Windows Pro, Enterprise, and Education editions) — Built into Windows, supports AES-256 encryption, and can be enforced through Group Policy across your organization. For environments with compliance requirements, BitLocker can operate in FIPS 140-2 validated mode. - Hardware-encrypted drives — USB drives with built-in encryption processors (such as those meeting FIPS 140-2 Level 3 certification) that encrypt data automatically without relying on host software. These are more expensive but eliminate the risk of software misconfiguration. - FileVault and Disk Utility (macOS) — Apple's built-in tools can encrypt external drives using AES-256. The key principle is that encryption should be mandatory and enforced, not optional and hoped for. If your organization issues USB drives, they should be encrypted before they leave IT. If employees bring their own, your acceptable use policy should prohibit the use of unencrypted portable media for work data. ### Dispose of Portable Media Properly When USB drives, external hard drives, or SD cards reach end of life — or when they change hands — simply deleting files is not enough. Standard file deletion removes the directory entry but leaves the actual data intact and recoverable with freely available tools. The Canadian Centre for Cyber Security's Baseline Controls require organizations to have processes for the sanitization or destruction of portable media prior to disposal (BC.13.2). This aligns with the sanitization framework established in NIST Special Publication 800-88, which defines three levels of media sanitization: - Clear — Overwriting all user-accessible storage with non-sensitive data using standard tools. Suitable for media being reused within the same organization. - Purge — Using techniques that render data recovery infeasible even with laboratory methods. This includes cryptographic erasure, where the encryption key is destroyed, making the encrypted data permanently unreadable. - Destroy — Physical destruction through shredding, disintegration, or incineration. Required when media cannot be sanitized through software methods or when the data sensitivity warrants it. For most SMBs, the practical approach is: - For drives staying in the organization: Use a reputable disk-wiping tool that performs a full overwrite (Clear) - For drives leaving the organization: At minimum, perform a Purge-level sanitization. For drives that held sensitive client data or personal information, physical destruction is the safest option - For failed or damaged drives: Physical destruction is the only reliable method, since software-based wiping may not reach all storage areas on a malfunctioning device Do not donate, sell, or recycle USB drives that have held business data without proper sanitization. A used drive sold online or dropped in an e-waste bin can become a data breach if it contains recoverable information. ### The Policy Gap Many Canadian SMBs have no written rules governing portable media use. There is no documented expectation about when USB drives are acceptable, what data can be stored on them, whether encryption is required, or how they should be disposed of. Portable media controls are most commonly addressed within an organization's Acceptable Use Policy — the same document that typically governs employee use of company systems, internet access, and personal devices. In organizations with more mature security programs, portable media may also be referenced in a dedicated Data Handling or Information Classification policy, but for most small businesses, the Acceptable Use Policy is the natural home. Regardless of where it lives, the key elements are straightforward: - Only organization-owned portable media should be used for work data — personal USB drives introduce unknown risk - Encryption is required on all portable media containing business or client information - Approved devices should be tracked as part of your asset inventory, the same way you track laptops and phones - Data should not live on portable media permanently — transfer files to secure, permanent storage and remove them from the drive - Sanitization or destruction procedures must be followed before any portable media is reused, reassigned, or disposed of - Employees should know what to do if a USB drive is lost, stolen, or found — including reporting it as a potential security incident This does not need to be a complex document. It needs to be clear, communicated to all staff, and enforced. The same principle applies here as with AI tools — the goal is not to ban the technology, but to set practical rules for how it is used. ### What You Should Do If your business has not addressed portable media security, here is where to start: - Inventory what exists. Find out how many USB drives and external storage devices are in use across your organization. You cannot secure what you do not know about — this is the same principle behind software inventory as a security control. - Enforce encryption. Deploy BitLocker To Go or equivalent encryption on all portable media used for business data. Make this a requirement, not a recommendation. - Restrict unauthorized devices. Where feasible, disable USB ports on workstations that do not need them or use endpoint management tools to allow only approved devices. - Update your Acceptable Use Policy. Add clear rules for portable media — what is allowed, what is required, and what happens when devices are lost or reach end of life. - Establish disposal procedures. Define how portable media is sanitized or destroyed when it is no longer needed. Assign responsibility and document the process. - Train your team. Ensure employees understand that unknown USB drives should never be connected to a work computer — and that security awareness includes physical media, not just email. ### The Baseline Control The Canadian Centre for Cyber Security's Baseline Controls dedicate an entire control area to this topic — Portable Media (BC.13). It is one of the 13 fundamental control areas in ITSM.10.089 and it covers two core requirements: mandating the use of organization-owned, encrypted portable media (BC.13.1) and establishing processes for sanitization or destruction prior to disposal (BC.13.2). These are not enterprise-scale requirements. They are achievable steps that any Canadian small or medium business can implement with modest effort and cost. Our free assessment evaluates your organization across all 13 Baseline Control areas, including portable media security. It takes under 10 minutes and shows you exactly where your business stands — and where to start. --- ## Vendor and Third-Party Risk: How Your Suppliers Can Become Your Weakest Link URL: https://cybersecuritycanada.ca/news/posts/vendor-and-third-party-risk-how-your-suppliers-can-become-your-weakest-link/ Category: Best Practices Published: February 14, 2026 Summary: Your cybersecurity is only as strong as the least secure vendor with access to your systems or data. Here's how Canadian small businesses can assess and manage third-party risk without a dedicated security team. In 2023, a ransomware attack on Indigo Books & Music — Canada's largest bookstore chain — disrupted operations for weeks, took down the company's website, and compromised employee data. The incident illustrated a pattern that has become increasingly common: attackers target organizations through the technology and services those organizations depend on. But you don't have to be a national retailer to face third-party risk. Every Canadian small business relies on external vendors — managed service providers, cloud platforms, accounting software, payment processors, HR systems, web hosting, and more. Each of these relationships creates a potential pathway for attackers. The question isn't whether you use third-party services. It's whether you understand what access those vendors have and what happens when one of them gets compromised. ### How Third-Party Breaches Affect Small Businesses When a vendor is breached, the impact cascades to every customer they serve. Here's how this plays out for Canadian SMBs: #### Your Data in Someone Else's Hands Every time you use a cloud service, a SaaS platform, or a managed IT provider, you're entrusting some of your business data to a third party. If that vendor is breached, your data — customer records, financial information, employee details — can be exposed. Under PIPEDA, your organization remains responsible for personal information even when it's processed by a third party. The breach may be the vendor's fault, but the notification obligation and the reputational damage land on you. #### Shared Access, Shared Risk Many vendors require some level of access to your systems to deliver their services. Your managed service provider likely has administrative access to your network. Your accounting software connects to your bank accounts. Your web developer may have credentials to your hosting platform. Each of these access points is a potential entry vector if the vendor's own security is compromised. #### Software Supply Chain The software tools your business depends on are themselves a potential vector. The Notepad++ supply chain attack demonstrated how a compromised software update can deliver malware directly to organizations that trust the software source. If a vendor's software update mechanism is compromised, every customer who installs the update is affected. ### The Scale of the Problem The Canadian Centre for Cyber Security's 2023-2024 National Cyber Threat Assessment noted that supply chain compromises are a "growing and significant threat" to Canadian organizations. The assessment highlighted that state-sponsored actors and cybercriminals are increasingly targeting service providers and software vendors as a way to reach multiple victims through a single compromise. Globally, research from SecurityScorecard found that 98% of organizations have a relationship with at least one third party that has experienced a breach. For small businesses with limited security resources, this exposure is particularly concerning because the breach vector is entirely outside their control. ### Assessing Vendor Risk Without a Security Team You don't need a formal vendor risk management program to start making better decisions. Here are practical steps for Canadian SMBs: #### Know Who Has Access to What Start with an inventory. List every vendor, service provider, and software tool that: - Has access to your business network or systems - Stores, processes, or transmits your business data - Has credentials or accounts on your platforms - Connects to your systems via API or integration For each vendor, note what data they can access, what level of system access they have, and how critical they are to your operations. You may be surprised by how long this list becomes. #### Ask the Right Questions When evaluating a new vendor — or reassessing an existing one — you don't need a 200-question security questionnaire. Focus on the questions that matter most: - Do you use multi-factor authentication for accessing our data and systems? If a vendor managing your systems doesn't use MFA, your data is one stolen password away from exposure. - How do you handle data if we end the relationship? Understand whether they delete your data, return it, or retain it — and get the answer in writing. - Do you have cyber insurance? A vendor without insurance may not have the resources to respond effectively to their own breach, which directly affects you. - What happens to my data if you're breached? Will they notify you? How quickly? What support will they provide? - Where is my data stored? For PIPEDA compliance, knowing whether data is stored in Canada, the US, or elsewhere is relevant to your privacy obligations. - Do you have a written incident response plan? A vendor without an incident response plan is a vendor that will be slower to detect, contain, and communicate about a breach. #### Review Contracts for Security Terms Many vendor contracts include service-level agreements for uptime but say nothing about security. Look for — or negotiate the inclusion of — these terms: - Breach notification timeline — The vendor should be required to notify you within a specific period (24-72 hours) of discovering a breach affecting your data - Data handling and deletion — What happens to your data during and after the relationship - Right to audit — The ability to ask about their security practices or request evidence of compliance - Insurance requirements — Requiring vendors to maintain cyber insurance - Subcontractor disclosure — Whether the vendor uses subcontractors who will also have access to your data #### Apply the Principle of Least Privilege Give vendors only the access they need to do their job — nothing more: - If a vendor needs access to one system, don't give them access to your entire network - Create dedicated vendor accounts rather than sharing employee credentials - Use time-limited access where possible — if a vendor needs access for a specific project, revoke it when the project is complete - Review vendor access quarterly and remove accounts that are no longer needed - Require MFA on all vendor accounts ### Managing Your Managed Service Provider For many Canadian SMBs, the most critical third-party relationship is with their managed service provider (MSP) or IT support company. MSPs often have the highest level of access — including administrative privileges across your entire network. This makes MSPs a high-value target for attackers. A compromised MSP gives an attacker access to every client the MSP manages. The Kaseya VSA attack in 2021 demonstrated this at scale — a single vulnerability in the MSP's remote management tool was used to deploy ransomware to approximately 1,500 businesses simultaneously. For your MSP relationship: - Understand their security practices. Ask the same questions you'd ask any vendor, but apply higher scrutiny given their level of access - Require MFA on all remote access. Your MSP should be using MFA to access your systems — no exceptions - Limit administrative access. Not every MSP technician needs domain admin access. Use role-based access and require elevation only when needed - Get breach notification commitments in writing. Your MSP should notify you within hours — not days — of any security incident that could affect your environment - Ask about their own incident response plan. If your MSP is breached, their response directly determines your exposure ### The CyberSecure Canada Connection The CyberSecure Canada certification program, operated by Innovation, Science and Economic Development Canada, includes vendor management as part of its certification requirements. Organizations pursuing certification must demonstrate that they assess and manage the cybersecurity risks associated with their suppliers and service providers. While certification may not be practical for every small business, the framework provides a useful benchmark for evaluating your own vendor risk management maturity. ### Starting Small If vendor risk management feels overwhelming, start with these three actions: - List your top five most critical vendors — the ones with the most access to your data and systems. For most SMBs, this will include your MSP/IT provider, cloud email platform, accounting software, bank, and web host. - Send each one a simple email asking: "What security measures do you have in place to protect our data? Do you use MFA? Do you have cyber insurance? What is your breach notification process?" - Review the access each vendor has to your systems and revoke any access that is no longer needed. These three steps take less than an hour and immediately improve your visibility into third-party risk. ### The Baseline Controls Connection Vendor and third-party risk management connects to multiple areas of the Canadian Centre for Cyber Security's Baseline Controls: - BC.5 (Authentication) — Requiring MFA for all vendor access - BC.10 (Cloud Services) — Evaluating cloud vendors' security practices - BC.12 (Access Control) — Applying least-privilege access to vendor accounts - BC.13 (Portable Media) — Including security requirements in vendor selection and contracts Our free assessment evaluates your organization across all 13 Baseline Control areas, including procurement security and access management. It takes under 10 minutes and highlights where your vendor relationships may be introducing risk you haven't accounted for. --- ## Windows Notepad Vulnerability: What Canadian Businesses Should Know URL: https://cybersecuritycanada.ca/news/posts/windows-notepad-vulnerability-what-canadian-businesses-should-know/ Category: Threats Published: February 11, 2026 Summary: A critical flaw in Windows Notepad could let attackers take control of your PC through a simple file. Here's what Canadian business owners need to know and do. Notepad — the simple text editor that comes pre-installed on virtually every Windows computer (not to be confused with Notepad++, which had its own security incident) — just became a security risk. On February 10, 2026, Microsoft patched a serious flaw as part of its regular Patch Tuesday cycle (tracked as CVE-2026-20841) that could allow an attacker to take control of a Windows PC through a specially crafted file. If your business runs Windows — and most Canadian businesses do — this one is worth understanding. ### What Happened In 2025, Microsoft added new features to Notepad, including the ability to render Markdown files — documents with formatting like bold text, headings, and clickable links. That feature introduced a weakness. Researchers discovered that an attacker could create a malicious Markdown file containing a disguised link. If someone opened that file in Notepad and clicked the link, the attacker could execute commands on their computer — potentially installing malware, stealing data, or gaining full control of the system. This flaw was rated between 7.8 and 8.8 out of 10 on the industry severity scale (CVSS v3.1) depending on the scoring methodology, and Microsoft classified it as "Important." Security researchers expect it to be exploited in phishing campaigns within weeks of disclosure. ### Why This Matters for Your Business You might be thinking, "It's just Notepad — who cares?" Here's why you should: - Notepad is everywhere. It's installed on virtually every Windows PC in your organization. Every employee has access to it. - The attack is simple. An employee receives a file that looks harmless. They open it. They click a link. That's all it takes. - This came through a legitimate update. The vulnerability was introduced when Microsoft added new features to Notepad — a reminder that even routine software updates can create new risks. This was part of a larger February 2026 Patch Tuesday that addressed dozens of vulnerabilities, including several that were already being actively exploited in the wild. ### What You Should Do Right Now #### 1. Install the Update Microsoft has released a patch through the February 2026 cumulative update. Make sure your IT team or managed service provider applies the latest Windows updates and updates the Notepad app through the Microsoft Store. #### 2. Warn Your Team Let your employees know that unexpected files — especially Markdown files (.md) — should be treated with caution. This is a good time to remind everyone not to open attachments or click links from unknown sources. #### 3. Check Your Patch Management Process If your reaction to this news is "I'm not sure how we'd roll that out," that's the real problem. The specific vulnerability matters less than whether your business has a reliable way to apply security patches across all your devices. The Canadian Centre for Cyber Security's Baseline Controls include Patch Management (BC.2) as one of the 13 foundational control areas — and for good reason. Unpatched software is one of the most common ways attackers get in. ### The Bigger Picture: Why Patch Management Is Non-Negotiable This Notepad flaw is just one example of a pattern that repeats every month. Microsoft alone releases patches for dozens of vulnerabilities on the second Tuesday of every month ("Patch Tuesday"). Add in updates from Apple, Google, Adobe, and every other software vendor your business relies on, and the volume is overwhelming. Here's the reality for Canadian business owners: - There are too many vulnerabilities to track manually. In February 2026 alone, Microsoft patched 58 security flaws. That's one vendor, one month. - Attackers move fast. Once a vulnerability is publicly disclosed, attackers begin exploiting it almost immediately. The window between "patch available" and "actively exploited" is shrinking. - Every device is a potential entry point. A single unpatched laptop can be the starting point for a breach that affects your entire organization. ### Automation and Centralization Are Key If you're relying on individual employees to click "Update Later" one fewer time, your business is exposed. Modern patch management requires: - Centralized management — A single view of every device, what software is installed, and which patches are missing - Automated deployment — Patches applied on a schedule without relying on employee action - Prioritization — Not every patch is equally urgent. Critical and actively exploited vulnerabilities need to be deployed immediately; others can follow a regular schedule - Verification — Confirming that patches were actually applied and devices are compliant This isn't just a technology problem — it's an operational one. Whether you handle IT in-house or work with a managed service provider, make sure someone is accountable for keeping your software current. ### How This Connects to Your Overall Security Patch management doesn't exist in isolation. It works alongside security awareness training, strong authentication, backup and recovery, and incident response planning to form a complete security posture. The Canadian Centre for Cyber Security's Baseline Controls cover all of these areas. If you're not sure where your business stands, our free assessment evaluates your organization across all 13 Baseline Control areas — including patch management — and gives you a clear picture of what needs attention. Don't wait for the next Notepad-style headline to find out you're behind on updates. --- ## Notepad++ Supply Chain Attack: What Canadian Businesses Should Know URL: https://cybersecuritycanada.ca/news/posts/notepad-plus-plus-supply-chain-attack-what-canadian-businesses-should-know/ Category: Threats Published: February 10, 2026 Summary: A Chinese state-sponsored group hijacked Notepad++ updates for months, delivering targeted malware through a trusted update channel. Here's what happened and what to do. On February 2, 2026, the maintainers of Notepad++ — one of the most popular open-source text editors in the world — disclosed that their software update infrastructure had been compromised by a suspected Chinese state-sponsored hacking group. The attackers hijacked the update mechanism for approximately six months, selectively delivering malware to targeted organizations through what appeared to be a routine software update. This is not a theoretical risk. It happened, it went undetected for months, and it exploited the exact kind of trust that businesses place in their software every day. ### What Happened The attack did not exploit a flaw in the Notepad++ application itself. Instead, attackers compromised the shared hosting server where notepad-plus-plus.org was hosted, gaining the ability to intercept and redirect update traffic. When certain users checked for updates, they were silently redirected to attacker-controlled servers that served trojanized installers. The timeline is significant: - June 2025: Attackers compromise the hosting infrastructure - July–October 2025: Malicious updates are selectively served to targeted users, with the attack chain changing roughly once per month - September 2025: The hosting provider patches the server, severing direct access — but attackers retain stolen credentials - December 2025: Attacker access is fully terminated; Notepad++ v8.8.9 adds installer signature verification - February 2, 2026: The incident is publicly disclosed - February 5, 2026: Kaspersky publishes detailed analysis revealing three distinct infection chains and new indicators of compromise (IoCs) The core weakness was in WinGUp, the Notepad++ updater. Prior to version 8.8.9, it did not verify the certificate or signature of downloaded installers — a vulnerability now tracked as CVE-2025-15556. ### Who Was Behind It Multiple independent security researchers have attributed the attack to a Chinese state-sponsored group. Rapid7 identified the threat actor as Lotus Blossom (also known as Billbug), an advanced persistent threat (APT) group active since 2009 that primarily targets organizations in Southeast Asia for espionage purposes. Other researchers, including Kevin Beaumont, have linked the campaign to Violet Typhoon (APT31/Zirconium). Attribution in these cases is always assessed with moderate confidence — but the consensus is clear: this was a nation-state operation, not a criminal one. ### How Sophisticated Was the Attack Very. Kaspersky's analysis revealed three entirely different infection chains used between July and October 2025, each with different tools, techniques, and infrastructure: - Chain 1 (July–August): Used a repurposed copy of ProShow software to deliver a Metasploit loader, which then deployed a Cobalt Strike Beacon - Chain 2 (September): Dropped a Lua interpreter that executed shellcode from a configuration file, again deploying Cobalt Strike — but with different domains and communication methods - Chain 3 (October): Used DLL sideloading through a renamed Bitdefender tool to deliver Chrysalis, a previously undocumented custom backdoor discovered by Rapid7 Chrysalis is particularly concerning. It uses custom encryption, reflective loading, and API hashing to avoid detection, and supports over a dozen commands including reverse shells, file transfers, and complete self-removal. The attackers rotated their command-and-control infrastructure constantly. Organizations that scanned only for the October-era indicators of compromise would have completely missed infections from July through September. ### Who Was Targeted The good news: this was a highly targeted campaign. Kaspersky's telemetry identified roughly a dozen affected machines, belonging to: - Individuals in Vietnam, El Salvador, and Australia - A government organization in the Philippines - A financial organization in El Salvador - An IT service provider in Vietnam Most Notepad++ users were never served a malicious update. But this selectivity is part of what made the attack so difficult to detect — and it does not mean Canadian organizations can ignore it. ### Why This Matters for Canadian Businesses Even if your organization was not directly targeted, this incident carries important lessons: #### Software Updates Can Be Weaponized Every business relies on automatic software updates. This attack demonstrates that the update channel itself — typically one of the most trusted pathways into your network — can become the attack vector. The SolarWinds compromise in 2020 taught this lesson at scale. Notepad++ is a reminder that it applies to software of every size. #### Open-Source Tools Need Scrutiny Too Notepad++ is used by millions of developers, IT administrators, and business users. Many organizations do not track open-source tools the same way they track enterprise software — meaning they may not have visibility into which versions are installed, or which machines are affected. #### Your Software Inventory Is a Security Control If you cannot answer the question "Which machines in our organization have Notepad++ installed, and what version are they running?" — that is a gap. The Canadian Centre for Cyber Security's Baseline Controls address software inventory as part of Secure Configuration (BC.4) — one of the 13 foundational control areas — specifically because you cannot protect what you cannot see. ### What You Should Do #### 1. Check Your Notepad++ Versions If Notepad++ is used anywhere in your organization, confirm that all installations have been updated to at least version 8.9.1, which includes the security enhancements to the update mechanism. You can download the latest version directly from notepad-plus-plus.org. #### 2. Scan for Indicators of Compromise Both Kaspersky and Rapid7 have published detailed IoCs covering all three infection chains. If your organization was running Notepad++ between July and December 2025, it is worth checking your logs against these indicators — particularly if you have users who handle sensitive data. #### 3. Review Your Software Inventory This is a good prompt to audit which tools are installed across your organization — not just enterprise-licensed software, but free and open-source utilities. You cannot patch or monitor what you do not know about. #### 4. Evaluate Your Supply Chain Risk Consider which software vendors and update channels you trust implicitly. Where possible, ensure your organization has controls to verify the integrity of software updates — or at minimum, that your managed service provider is doing this on your behalf. ### The Bigger Picture: Supply Chain Attacks Are Accelerating This incident fits a clear pattern. Supply chain attacks — where attackers compromise a trusted vendor or tool to reach downstream targets — have become one of the most effective techniques in the nation-state playbook: - SolarWinds (2020): Trojanized updates delivered to 18,000 organizations - Kaseya (2021): Managed service provider platform exploited to deploy ransomware - 3CX (2023): Desktop application compromised to deliver info-stealing malware - Notepad++ (2025): Update infrastructure hijacked for targeted espionage The common thread is trust. Businesses trust their software vendors. Attackers exploit that trust. For Canadian businesses, the practical takeaway is this: patch management and software inventory are not optional. They are the foundation of a security posture that can withstand these kinds of threats. If you are not sure where your organization stands, our free assessment evaluates your business across all 13 of the Canadian Centre for Cyber Security's Baseline Control areas — including software inventory, patch management, and incident response — and gives you a clear picture of what needs attention. The next supply chain attack will not announce itself. Make sure your business is ready. --- ## The Hidden Cost of Assuming Your Business Is Too Small to Attack URL: https://cybersecuritycanada.ca/news/posts/the-hidden-cost-of-assuming-your-business-is-too-small-to-attack/ Category: Insights Published: February 10, 2026 Summary: The belief that your business is too small to be targeted isn't just wrong — it's the most expensive cybersecurity assumption a Canadian SMB can make. Here's what it actually costs. "We're too small. No one's going to come after us." It's the most common thing Canadian business owners say when cybersecurity comes up — and it's the single most expensive assumption they make. Not because attackers specifically hunt down small businesses by name, but because that one belief quietly shapes every security decision (or non-decision) that follows. ### The Gap Between Perception and Reality Despite years of headline-making breaches, the disconnect between perceived and actual risk among Canadian SMBs remains staggering. Research from the Business Development Bank of Canada found that 73% of small businesses have experienced a cybersecurity incident — yet a separate survey by the Insurance Bureau of Canada found that only 6% of SME owners strongly agree their business is at risk. That gap is not just a survey finding. It's a business risk multiplier. When leadership believes the business won't be targeted, everything downstream reflects that belief: security training gets skipped, software updates get postponed, backup strategies go untested, and password policies stay stuck in 2015. ### Modern Attacks Don't Filter by Company Size The "too small" assumption rests on a misunderstanding of how cyberattacks actually work. Most attacks against small businesses aren't personally targeted — they're automated and indiscriminate. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 highlights the rise of Cybercrime-as-a-Service (CaaS), where attackers rent or buy pre-built attack tools without needing deep technical skills. These tools scan thousands of networks simultaneously, probing for known vulnerabilities, weak passwords, and unpatched software. They don't check your annual revenue first. The data confirms this. According to recent industry research, 82% of ransomware attacks target organizations with fewer than 1,000 employees, and over a third strike businesses with fewer than 100 staff. Globally, an estimated 43% of cyberattacks are aimed at small and medium businesses. For cybercriminals, the math is simple: demanding $50,000 from 20 poorly defended small businesses is far more reliable than trying to breach a single well-funded enterprise. ### What This Assumption Actually Costs Canadian Businesses When a business that assumed it wouldn't be attacked actually gets hit, the costs compound in ways that were never planned for. #### Direct Financial Damage Industry estimates suggest a cyberattack on an SMB typically costs around $250,000 or more, with more serious breaches running into the millions. IBM's 2025 Cost of a Data Breach report puts the Canadian average at CA$6.98 million per incident. Small businesses pay less in absolute terms but absorb proportionally more damage relative to their revenue — often enough to threaten their survival. #### Operational Shutdown Industry surveys indicate that SMBs commonly experience system outages lasting 8 to 24 hours or more following an attack. For businesses without tested recovery procedures, getting back to normal takes days or weeks, not hours. Research suggests that roughly three-quarters of SMBs say they could not continue operating if struck by a serious incident. #### Regulatory Consequences Under PIPEDA, if a breach involves personal information with a real risk of significant harm, you must report it to the Privacy Commissioner of Canada, notify affected individuals, and maintain records. Non-compliance can lead to fines of up to $100,000 per violation — and proposed federal privacy legislation could significantly increase these penalties. #### The National Recovery Bill Across Canada, businesses spent $1.2 billion recovering from cyber incidents in 2023 — double the $600 million spent just two years earlier. Prevention and detection spending rose to $11 billion over the same period. The organizations that avoided the worst outcomes were the ones that invested before an incident occurred, not after. ### How One Assumption Creates a Chain Reaction What makes the "too small" belief so damaging is that it doesn't produce a single bad outcome — it triggers a cascade of underinvestment that leaves the business exposed at every layer: - No budget allocated — "We're not a target, so why spend money on this?" - No training provided — Employees never learn to spot phishing emails or social engineering attempts - No policies written — No incident response plan, no AI usage guidelines, no acceptable use standards - No detection in place — Breaches go unnoticed for weeks or months - No recovery plan tested — When an incident hits, the business improvises under pressure. Backup assumptions that fail make recovery even harder. - Maximum impact — Costs spiral because every layer of defence was missing Each of these gaps is individually manageable and inexpensive to address. Together, they create the conditions for an incident that can permanently close a business. ### Proportional Security Is Not Enterprise Security One reason the "too small" myth persists is the belief that cybersecurity requires enterprise-scale spending. It doesn't. The Canadian Centre for Cyber Security's Baseline Cyber Security Controls were built specifically for small and medium organizations. They define 13 practical control areas — from software inventory to incident response — that any business can implement at a scale appropriate to its size. The highest-impact steps cost little or nothing: - Multi-factor authentication — Free on most platforms and prevents the majority of credential-based attacks - Automatic software updates — Built into every modern operating system - Tested backups — Affordable cloud backup options exist at every price point - Employee awareness training — Free resources available through Get Cyber Safe and the Canadian Centre for Cyber Security - A written incident response plan — The time to create one is before you need it In 2024, the Cyber Centre issued 336 pre-ransomware notifications to Canadian organizations, generating an estimated $6 to $18 million in economic savings. Basic preparedness and early detection deliver measurable returns. ### Replace the Assumption with Evidence The question has never been whether your business is too small to be attacked. The real question is whether your security decisions are based on evidence or on a comfortable assumption. Canadian businesses that honestly assess their security posture — and act on the findings — consistently spend less, recover faster, and avoid the worst outcomes. Those that wait until after a breach spend dramatically more and recover slower, if they recover at all. Our free assessment evaluates your organization across all 13 Baseline Control areas from the Canadian Centre for Cyber Security. It takes under 10 minutes and shows you exactly where your business stands — and where to start. For a guided overview of what each control area means, see our cybersecurity guide for Canadian small businesses. --- ## How to Use Your Cybersecurity Assessment Results URL: https://cybersecuritycanada.ca/news/posts/how-to-use-your-assessment-results/ Category: Guide Published: February 7, 2026 Summary: Completed the assessment? Here's how to interpret your score, prioritize improvements, and build a practical security roadmap for your organization. You've completed the Cybersecurity Canada assessment — now what? Your results contain valuable information about your organization's security posture. Here's how to make the most of them. ### Understanding Your Score Your overall score is a percentage representing how closely your current practices align with the Canadian Centre for Cyber Security's Baseline Controls. Here's what the grades mean: - A (85%+) — Strong baseline compliance. Your organization has comprehensive measures across most control areas. - B (70-84%) — Good progress. Solid foundations with some areas needing attention. - C (50-69%) — Partial implementation. Meaningful gaps exist that should be addressed. - D (30-49%) — Significant gaps. Your organization is exposed to considerable risk. - F (Below 30%) — Critical gaps. Immediate action is needed across multiple areas. ### Prioritizing Improvements Not all control areas carry equal urgency. Here's a practical approach to prioritization: #### Address "None" Areas First Any area where you scored "None" represents a complete gap in your defenses. These should be your highest priority, particularly: - Multi-Factor Authentication (BC.5) — The single highest-impact improvement - Data Backup (BC.7) — Your last line of defense against ransomware - Incident Response (BC.1) — You need a plan before an incident occurs #### Build on "Basic" Areas Next Areas where you scored "Basic" have some awareness but lack formal implementation. Moving these to "Moderate" often requires documenting what you're already doing informally and adding technical controls. #### Strengthen "Moderate" Areas Moving from "Moderate" to "Strong" typically involves closing coverage gaps, adding monitoring, and documenting procedures. ### Building a Roadmap Rather than trying to fix everything at once, create a realistic timeline: - Month 1-2 — Address all "None" areas with highest impact - Month 3-4 — Move "Basic" areas to "Moderate" - Month 5-6 — Begin strengthening "Moderate" areas - Ongoing — Re-assess quarterly to track progress ### Dive Deeper into Each Control Area For guidance on the most impactful areas, explore these resources: - Authentication (BC.5): Why MFA is the single biggest upgrade and password security mistakes to fix - Incident Response (BC.1): Building an incident response plan - Data Backup (BC.7): 5 backup assumptions that fail when it matters - Security Awareness (BC.6): What actually works in security training - All 13 controls: Understanding Canada's Baseline Controls ### Take Action Print your results and share them with your leadership team. Cybersecurity improvement requires organizational commitment — and that starts with understanding where you stand. Take the assessment now or re-take it periodically to track your progress and identify new areas for improvement. For a detailed explanation of each control area and how they work together, see our cybersecurity guide for Canadian small businesses or learn more on our cybersecurity assessment page. --- ## Why Canadian SMBs Can No Longer Ignore Cybersecurity URL: https://cybersecuritycanada.ca/news/posts/why-canadian-smbs-need-cybersecurity/ Category: Insights Published: February 1, 2026 Summary: Canadian small businesses face growing cyber threats. Learn why cybersecurity has become a business necessity, not just an IT concern. For many Canadian small and medium business owners, cybersecurity still feels like something only large enterprises need to worry about. But the data tells a different story — and the risk landscape for Canadian SMBs has changed dramatically. ### The Growing Threat to Canadian Businesses Cybercriminals increasingly target small and medium organizations because they often have valuable data but fewer defenses. Ransomware, phishing attacks, and business email compromise are among the most common threats facing Canadian businesses today. The impact of a cyber incident goes beyond immediate financial loss. Canadian businesses face: - Operational downtime — Unable to serve customers or process orders - Regulatory consequences — PIPEDA requires reporting of breaches involving personal information - Reputational damage — Customer trust is hard to rebuild after a breach - Recovery costs — The average cost of a cyber incident for SMBs continues to rise ### The Canadian Landscape Canada has taken steps to help businesses improve their cybersecurity posture. The Canadian Centre for Cyber Security publishes guidance, alerts, and resources specifically for Canadian organizations. The "Baseline Cyber Security Controls for Small and Medium Organizations" provides a practical framework that any business can follow. Additionally, the Get Cyber Safe campaign from the Government of Canada offers public awareness resources that can help train employees and build a security-aware culture. ### Where to Start If you're a Canadian business owner or manager wondering where to begin, here are three immediate steps: - Assess your current state — Use our free assessment to understand where you stand against the Baseline Controls - Enable multi-factor authentication — This single step prevents the majority of account compromise attacks - Train your team — Employees who can recognize phishing emails are your strongest line of defense Cybersecurity doesn't have to be overwhelming or expensive. Starting with 5 easy wins is far better than doing nothing — and understanding why cybercriminals target small businesses makes the case for action clear. For a complete overview, see our cybersecurity guide for Canadian small businesses, or explore key terms in our cybersecurity glossary. --- ## When Cyber Attacks Become Physical Threats URL: https://cybersecuritycanada.ca/news/posts/when-cyber-attacks-become-physical-threats/ Category: Threats Published: January 28, 2026 Summary: Cyber attacks don't always stay digital. Criminals are using email compromises, system hacks, and signal jamming as stepping stones to physical crimes like burglary and fraud. There's a common assumption among business owners that cyber threats and physical threats are separate problems. That assumption is increasingly dangerous. Criminals have learned that compromising digital systems is often the easiest way to enable physical crimes. ### Wi-Fi Jamming Burglaries In 2024, police in several North American cities warned about burglars using inexpensive Wi-Fi jamming devices to disable wireless security cameras and alarm systems before breaking in. With security systems offline, thieves enter properties without triggering alerts or leaving video evidence. Why it matters: Many Canadian small businesses rely entirely on wireless security cameras and cloud-connected alarms. If your security infrastructure depends on Wi-Fi, an inexpensive jamming device can render it useless. Consider hardwired connections for critical security systems. ### Business Email Compromise Enables Physical Fraud Business Email Compromise (BEC) is often discussed as a digital threat — attackers impersonating executives or vendors to redirect payments. But compromised email also enables physical crimes: - Real estate fraud — Criminals monitor email for property transactions, then impersonate sellers with forged documents - Vendor impersonation — Attackers learn your suppliers and payment schedules, then send physical invoices with altered payment details - Identity document theft — Email access reveals copies of passports and licenses that enable in-person impersonation at banks Once attackers have access to your email, they often monitor communications for weeks, learning enough about your business to execute convincing physical fraud. ### SIM Swap Attacks SIM swapping — where criminals hijack your phone number — has evolved beyond cryptocurrency theft into a gateway for comprehensive identity fraud. With control of a phone number, attackers can reset passwords, bypass two-factor authentication, and even visit bank branches in person to authorize transactions. Business owners and executives are prime targets. If an attacker hijacks your phone number, your "second factor" of authentication routes through a device you no longer control. ### Access Control System Vulnerabilities Electronic keycard and badge systems are standard security for offices and warehouses. But researchers have repeatedly found serious vulnerabilities in these systems — from hardcoded credentials to clonable proximity cards — that could allow attackers to grant themselves physical access to your building. That keycard system you installed for security might actually be a vulnerability if it hasn't been updated or properly configured. ### What This Means for Canadian Businesses The traditional boundary between cybersecurity and physical security no longer exists. Your wireless alarm system is a cybersecurity concern. Your email account is a physical security concern. The electronic locks on your doors are networked devices with potential vulnerabilities. Questions to consider: - Do your security cameras and alarm systems depend entirely on Wi-Fi? - How would you verify a high-value payment request if email were compromised? Learn more about business email compromise. - Who has electronic access to your facilities, and is that access revoked when employees leave? - Are critical security systems hardwired or do they have a wireless-only dependency? The Canadian Centre for Cyber Security's Baseline Controls address many of the digital vulnerabilities that enable these physical threats — from email security (BC.9) and access control (BC.12) to incident response planning (BC.1). Having a tested incident response plan is especially critical when cyber attacks have physical consequences — the first 24 hours after an attack are when decisive action matters most. Our free assessment evaluates your organization across all 13 Baseline Control areas, helping you identify the digital gaps that could lead to physical consequences. --- ## Backup and Recovery: 5 Assumptions That Fail When It Matters URL: https://cybersecuritycanada.ca/news/posts/backup-and-recovery-assumptions-that-fail/ Category: Best Practices Published: January 25, 2026 Summary: Most businesses think their backups are fine — until they try to restore from them. Here are five common backup assumptions that fail during a real incident. Backups are your last line of defense against ransomware, hardware failure, and accidental data loss. Yet many Canadian small businesses operate on backup assumptions that don't hold up when it matters most. ### 1. "We Have Backups" Having backups and having usable backups are two different things. Common problems include: - Backups that haven't been tested with an actual restore - Backup jobs that silently failed weeks ago - Backups that are incomplete — missing critical databases, configurations, or email archives - Backup media that has degraded or become unreadable Fix: Test your backups regularly. At minimum, perform a full test restore quarterly. If you can't restore from your backups, you don't have backups. ### 2. "Our Backups Are in the Cloud" Cloud backups are convenient, but "in the cloud" isn't automatically safe: - If ransomware encrypts files that sync to cloud storage, your cloud copy is also encrypted - Cloud storage is not the same as a cloud backup service — syncing is not backing up - If your cloud provider account is compromised, the attacker may have access to your backups too - Cloud services can experience outages or data loss, though rare Fix: Follow the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy offline or offsite. "Offsite" means physically separate from your network — not just a different folder on the same cloud account. ### 3. "We'd Be Back Online Quickly" Most businesses dramatically underestimate recovery time. Restoring from backup involves: - Identifying exactly what was compromised and when - Rebuilding or reimaging affected systems - Restoring data from backup (which can take hours or days depending on volume) - Verifying data integrity - Reconnecting systems and testing functionality - Ensuring the original vulnerability is patched before going back online For a small business without a documented recovery plan, this process typically takes days to weeks, not hours. Fix: Create a written recovery plan. Document the steps, assign responsibilities, and know your Recovery Time Objective (RTO) — the maximum acceptable downtime — for each critical system. ### 4. "Backups Are Only for Ransomware" Ransomware gets the headlines, but backups protect against much more: - Hardware failure — hard drives fail, servers die, sometimes without warning - Human error — accidental file deletion, misconfigured systems, or botched updates - Software corruption — updates that break things, database corruption - Natural disasters — fire, flood, power surges, or theft - Vendor failure — SaaS providers can lose data or shut down unexpectedly Fix: Think of backups as business continuity insurance, not just a ransomware defense. ### 5. "Our IT Person Handles It" Delegating backups to one person without oversight is risky: - What if that person leaves the company? - Are they actually monitoring backup success/failure? - Has anyone verified they can perform a full restore? - Is the backup strategy documented, or is it all in their head? Fix: Document your backup procedures. Ensure at least two people understand the system. Review backup reports regularly at a management level. ### The Baseline Control The Canadian Centre for Cyber Security's Baseline Controls include Data Backup (BC.7) as one of the 13 fundamental control areas. It covers backup strategy, encryption, access controls, and recovery testing. If your backups haven't been tested, your incident response plan should account for the possibility that restoration takes longer than expected — or doesn't work at all. Understanding the real cost of cyber downtime makes the case for investing in backup testing before a crisis hits. Our free assessment evaluates your backup practices against these standards and provides specific recommendations for improvement. --- ## Why Your Canadian Business Needs an AI Usage Policy URL: https://cybersecuritycanada.ca/news/posts/why-your-business-needs-an-ai-usage-policy/ Category: Best Practices Published: January 20, 2026 Summary: Your employees are already using AI tools — with or without your knowledge. Here's why a clear AI usage policy protects your business and what it should cover. If you think your employees aren't using AI tools at work, you're almost certainly wrong. ChatGPT, Copilot, Gemini, and dozens of other AI assistants are being used by employees across every industry — often without their employer's knowledge or approval. This is called shadow AI, and it's a growing risk for Canadian businesses. The solution isn't to ban AI tools. It's to set clear rules for how they're used. ### Why AI Tools Are Different AI tools aren't like typical software. They create risks that most businesses haven't addressed: - Data exposure is built in. To use AI tools effectively, employees share context — documents, emails, customer data, financial information. That data may be processed and stored by the AI provider. - You lose control of information. Once data is entered into a public AI tool, you may not know where it goes, how long it's retained, or who can access it. - Outputs can be wrong. AI tools generate confident-sounding answers that may contain errors. If employees use AI output in business decisions without verification, the consequences can be serious. - Privacy law still applies. Under PIPEDA, your organization is responsible for personal information even when it's processed by a third-party AI service. ### What an AI Usage Policy Should Cover You don't need a 50-page document. A clear, practical policy should address: #### What Data Can Be Shared Be explicit about what employees can and cannot enter into AI tools: - Acceptable: General research questions, public information, drafting help with non-sensitive content - Not acceptable: Customer personal information, financial data, employee records, passwords or credentials, proprietary business information, anything covered by PIPEDA or a confidentiality agreement #### Which Tools Are Approved Maintain a short list of AI tools your business has evaluated and approved. Employees should know: - Which tools they can use freely - Which require approval for specific uses - Which are prohibited - How to request evaluation of a new tool #### Corporate vs. Personal Accounts Require corporate-owned accounts for all work-related AI use. When employees use personal accounts, you lose visibility into what data is being processed and face challenges during offboarding — their conversation history and any data shared remains under their personal control after they leave. #### Human Review Required AI output should never be used in business decisions, client communications, or published materials without human review and verification. Make this expectation explicit. #### Incident Reporting Employees should know what to do if they accidentally share sensitive data with an AI tool or discover unauthorized usage. Make reporting easy and blame-free — you want people to come forward, not hide mistakes. ### Getting Started If you don't have an AI policy yet, start simple: - Understand current usage. Ask your team what AI tools they're already using and for what. The answer may surprise you. - Set immediate boundaries. At minimum, establish that customer data, financial information, and credentials must never be entered into AI tools. - Choose approved tools. Evaluate one or two AI services that offer business-grade data protection and make them the official options. - Communicate clearly. Share the policy with all employees and make it easy to find. - Review regularly. AI capabilities change fast. Review your policy quarterly to ensure it stays relevant. ### The Connection to Cybersecurity An AI usage policy is fundamentally a data protection measure — it controls where your sensitive information goes. This connects directly to several Baseline Control areas from the Canadian Centre for Cyber Security: - BC.6 (Security Awareness) — Training employees on AI risks - BC.10 (Cloud Services) — Vetting AI providers and their data handling - BC.12 (Access Control) — Managing who can use which AI tools with what data Under PIPEDA, your organization is responsible for personal information even when processed by third-party AI services — making this policy a compliance requirement, not just a best practice. Our free assessment evaluates your organization's security awareness, cloud service governance, and access controls — all areas directly relevant to managing AI risk. The businesses that thrive with AI won't be those that adopted fastest or banned it entirely. They'll be the ones that set clear, practical rules and helped their teams use these tools responsibly. --- ## Understanding Canada's Baseline Cyber Security Controls for SMBs URL: https://cybersecuritycanada.ca/news/posts/understanding-canadas-baseline-cyber-security-controls/ Category: Standards Published: January 15, 2026 Summary: The Canadian Centre for Cyber Security has published baseline controls specifically designed for small and medium organizations. Here's what you need to know. The Canadian Centre for Cyber Security (CCCS) has established a set of Baseline Cyber Security Controls specifically designed for small and medium organizations. Published as ITSM.10.089, this document represents the Government of Canada's recommended minimum security standard for Canadian businesses. ### What Are the Baseline Controls? The Baseline Controls are organized into 13 control areas that cover the fundamental aspects of cybersecurity that every organization should address: - Incident Response Planning (BC.1) — Having a plan for when things go wrong - Patch Management (BC.2) — Keeping software and systems up to date - Anti-Malware (BC.3) — Protecting against viruses and malicious software - Secure Configuration (BC.4) — Setting up systems securely from the start - Authentication (BC.5) — Verifying who has access to your systems - Security Awareness (BC.6) — Training employees to recognize threats - Data Backup (BC.7) — Ensuring you can recover from data loss - Mobile Devices (BC.8) — Securing phones and tablets - Network Security (BC.9) — Protecting your network perimeter - Cloud Services (BC.10) — Securing cloud-based tools and data - Web Security (BC.11) — Protecting your public-facing websites - Access Control (BC.12) — Managing who can access what - Portable Media (BC.13) — Controlling USB drives and external storage ### Why It Matters for Canadian SMBs Small and medium businesses are increasingly targeted by cyber threats. According to Canadian government reports, many SMBs lack the resources for comprehensive security programs. The Baseline Controls provide a practical, achievable starting point. These controls aren't about achieving perfect security — they're about establishing a minimum viable security posture that significantly reduces your risk of a successful cyber attack. ### Explore Each Control Area We've created detailed guides for each of the 13 Baseline Control areas: - Incident Response Planning — Build your plan - Patch Management — Keep software current - Anti-Malware — Protect against malicious software - Secure Configuration — Set up systems securely - Authentication — MFA and password management - Security Awareness — Train your team - Data Backup — Test your backups - Mobile Devices — Secure phones and tablets - Network Security — Protect your perimeter - Cloud Services — Cloud security basics - Web Security — Protect your websites - Access Control — Manage who can access what - Portable Media — Control USB drives ### Getting Started The best way to begin is by assessing where your organization currently stands. Our free assessment tool evaluates your practices against all 13 control areas and provides specific, actionable recommendations for improvement. Learn how to use your assessment results once you've completed it. You can also review the official ITSM.10.089 document directly on the Canadian Centre for Cyber Security's website. ### Frequently Asked Questions — Understanding Canada's Baseline Cyber Security Controls for SMBs Q: What are Canada's 13 Baseline Cyber Security Controls? A: The 13 Baseline Cyber Security Controls are: incident response planning (BC.1), patch management (BC.2), anti-malware (BC.3), secure configuration (BC.4), authentication (BC.5), security awareness training (BC.6), data backup (BC.7), mobile device security (BC.8), network security (BC.9), cloud services security (BC.10), web application security (BC.11), access control (BC.12), and portable media (BC.13). Together they cover the fundamental areas of cybersecurity that the Government of Canada recommends every small and medium organization address. Q: Who publishes the Baseline Cyber Security Controls? A: The Canadian Centre for Cyber Security (CCCS), part of the Communications Security Establishment, publishes them as document ITSM.10.089 — Baseline Cyber Security Controls for Small and Medium Organizations. The document represents the Government of Canada's recommended minimum security standard for Canadian businesses and is available free of charge on the CCCS website. Q: What is ITSM.10.089? A: ITSM.10.089 is the CCCS publication number for Baseline Cyber Security Controls for Small and Medium Organizations. It is the source document that defines the 13 control areas, written specifically for organizations that lack the resources for a comprehensive enterprise security programme. The same controls underpin the federal CyberSecure Canada certification programme. Q: Are the Baseline Controls mandatory for Canadian businesses? A: The Baseline Controls are guidance rather than legislation, so implementing them is voluntary for most Canadian businesses. They matter anyway: Canadian privacy law requires organizations to protect personal information with safeguards appropriate to its sensitivity, and the Baseline Controls are the most widely referenced Canadian benchmark for what reasonable safeguards look like. Insurers, enterprise customers, and government contracting processes increasingly ask about them as well. This is general information, not legal advice. Q: Where should a small business start with the Baseline Controls? A: Start by establishing where you currently stand rather than trying to implement all 13 areas at once. The Baseline Controls are deliberately ordered with incident response planning first, because when an incident occurs everything else depends on having a plan to follow. A structured self-assessment against all 13 control areas will show which gaps to close first; our free assessment does this in under 30 minutes without collecting your data. Q: Do the Baseline Controls guarantee my business will not be breached? A: No. The Baseline Controls are not about achieving perfect security — they establish a minimum viable security posture that meaningfully reduces the likelihood of a successful attack. No set of controls eliminates risk entirely. Their value is that they concentrate limited resources on the areas where Canadian small and medium organizations are most commonly compromised. --- ## The Real Cost of Cyber Downtime for Canadian SMBs URL: https://cybersecuritycanada.ca/news/posts/the-real-cost-of-cyber-downtime-for-canadian-smbs/ Category: Insights Published: January 5, 2026 Summary: When systems go offline due to a cyber incident, the costs go far beyond the ransom demand. Here's what Canadian small businesses actually face. When a cyber incident takes your business offline, the immediate thought is often about the direct cost — a ransom demand, a recovery service fee, or replacement hardware. But the true cost of downtime extends much further and can be devastating for small businesses. ### The Hidden Costs #### Lost Revenue Every hour your systems are down is revenue you can't earn. For a business that relies on online sales, booking systems, or point-of-sale terminals, downtime means zero transactions. For service businesses, it means cancelled appointments, missed deadlines, and undelivered work. #### Employee Productivity When systems are offline, employees can't work — but you're still paying them. A team of 20 people idled for three days represents hundreds of hours of lost productivity that you can never recover. #### Customer Loss Customers who can't reach you will go to a competitor. Some will come back. Many won't. The long-term revenue impact of lost customers typically exceeds the immediate cost of the incident itself. #### Recovery Expenses Getting back online involves costs that add up quickly: - Forensic investigation to determine what happened and what was compromised - System rebuilding if backups aren't available or were also affected - Data recovery services if encrypted files can't be restored from backup - Security improvements to prevent a recurrence - Legal and compliance costs if personal information was involved #### Regulatory Consequences Under PIPEDA, if the breach involves personal information with a real risk of significant harm, you must: - Report to the Privacy Commissioner of Canada - Notify all affected individuals - Maintain records of the breach Non-compliance can result in fines of up to $100,000 per violation. #### Reputational Damage Trust is hard to earn and easy to lose. Clients, partners, and suppliers may question whether your business can protect their information. For B2B companies, a breach can disqualify you from contracts that require security certifications or vendor assessments. ### How Long Does Recovery Take? For small businesses without a tested incident response plan and reliable backups, recovery can take weeks, not days. Some businesses never fully recover — studies consistently show that a significant percentage of small businesses close within months of a major cyber incident. ### Prevention Is Dramatically Cheaper The cost of basic preventive measures is a fraction of the cost of a single incident: - Multi-factor authentication — free to enable on most platforms - Automatic updates — built into every operating system - Offsite backups — affordable cloud backup services exist for every budget - Security awareness training — free resources are available from Get Cyber Safe - Incident response planning — the time to plan is before an incident, not during one Ransomware is the threat most likely to cause extended downtime for Canadian businesses. Understanding why cybercriminals target small businesses helps explain why no organization is too small to prepare. ### Assess Your Risk The best way to understand your exposure is to honestly evaluate where your organization stands today. Our free assessment measures your security posture against the Canadian Centre for Cyber Security's 13 Baseline Control areas and identifies the gaps that put you at greatest risk. For a complete overview of all 13 controls, see our cybersecurity guide for Canadian small businesses. --- ## Business Email Compromise (BEC): Canada's Most Costly Cyber Threat URL: https://cybersecuritycanada.ca/news/posts/business-email-compromise-canadas-most-costly-cyber-threat/ Category: Threats Published: December 30, 2025 Summary: Business email compromise doesn't use malware or exploit software vulnerabilities. It exploits trust — and it's responsible for more financial losses than any other form of cybercrime. Here's what Canadian businesses need to know. Ransomware gets the headlines. Phishing gets the training modules. But the single most financially damaging form of cybercrime — year after year — is business email compromise. The FBI's Internet Crime Complaint Center (IC3) reported that BEC attacks accounted for $2.9 billion USD in reported losses in 2023 — second only to investment fraud and far exceeding ransomware. BEC held the top spot in prior years and remains one of the most consistent threats year after year. The Canadian Anti-Fraud Centre has consistently identified BEC as one of the top fraud threats to Canadian businesses, with individual losses often reaching hundreds of thousands of dollars per incident. What makes BEC so effective — and so dangerous — is that it doesn't rely on technical exploits. There's no malware to detect. No software vulnerability to patch. BEC works by impersonating someone the victim trusts and manipulating them into transferring money, sharing sensitive data, or changing payment details. ### How BEC Works A business email compromise attack typically follows a pattern: #### Step 1: Reconnaissance The attacker researches the target organization. They study the company's website, LinkedIn profiles, and public records to understand the organizational structure — who reports to whom, who handles finances, who approves payments, and what vendors the company works with. This research phase can take days or weeks. #### Step 2: Impersonation The attacker either compromises a legitimate email account (through phishing or credential theft) or creates a convincing lookalike email address. Common impersonation tactics include: - Compromised accounts — The attacker gains access to an actual employee's email account, often because the account wasn't protected by MFA. Emails sent from a compromised account are particularly dangerous because they come from a trusted, legitimate address. - Lookalike domains — Registering a domain that looks nearly identical to the target's domain (e.g., "yourcompany.ca" vs. "yourcompany.co" or "your-company.ca") - Display name spoofing — Setting the sender display name to match a trusted person while using a different underlying email address. On mobile devices, many email clients show only the display name, hiding the actual address. #### Step 3: The Request The attacker sends a message crafted to trigger a specific action — usually a financial transaction. The request is designed to feel urgent, routine, or both. Common BEC scenarios include: CEO/Executive Fraud: An email appearing to come from the CEO or a senior executive asks an employee in finance to process an urgent wire transfer. "I need you to handle a confidential payment. I'm in meetings all day — please process this immediately and confirm when done." Vendor Impersonation: An email appearing to come from a regular vendor notifies accounts payable that banking details have changed. "Please update our payment information to the new account below for all future invoices." The employee updates the records, and subsequent payments go to the attacker. Payroll Diversion: An email appearing to come from an employee asks HR to update their direct deposit information. The next payroll cycle sends the employee's salary to the attacker's account. Legal/Closing Fraud: In real estate and legal transactions, an email impersonating a lawyer, notary, or real estate agent provides fraudulent wiring instructions for a closing payment. The amounts involved are often substantial — full property purchase prices. ### Why BEC Is So Effective BEC exploits the way businesses actually work: - Urgency is normal. Executives do send urgent requests. Vendors do change banking details. These requests don't look abnormal because they mirror legitimate business operations. - Authority pressure works. An employee receiving a direct request from the CEO is unlikely to question it, especially when the message says "please handle this confidentially" or "don't discuss this with others yet." - Email is trusted. Despite widespread awareness of phishing, email remains the primary channel for business communications and financial instructions. People expect to receive legitimate payment requests by email. - Technical controls don't catch it. Because BEC emails often contain no malicious links, attachments, or malware, they bypass spam filters, anti-malware tools, and email security gateways. The message itself is the weapon. ### The Canadian Impact The Canadian Anti-Fraud Centre (CAFC) reports that BEC is among the most damaging fraud types targeting Canadian businesses. Several factors make Canadian businesses particularly exposed: - Cross-border transactions are common. Many Canadian businesses work with US and international vendors, making international wire transfers a normal part of operations. This makes fraudulent international payment requests less likely to raise suspicion. - Real estate transactions. Canada's active real estate market creates frequent opportunities for closing fraud. Lawyers, notaries, and real estate professionals handling trust funds are high-value targets. - SMB vulnerability. Smaller organizations are often more exposed because they may lack segregation of duties in finance — meaning one person can both receive a payment request and execute the transfer without independent verification. Under PIPEDA, if a BEC attack results in the exposure of personal information (employee records, customer data, financial details shared in compromised email threads), the breach notification requirements apply — adding regulatory and reputational consequences to the financial loss. ### How to Protect Your Business BEC defence is primarily procedural, not technical. While technology helps, the most effective controls are verification processes that break the attack chain. #### Verification Procedures for Financial Requests The single most effective defence against BEC is a mandatory verification step for financial transactions: - Any request to change payment details (vendor banking information, employee direct deposit, wire instructions) must be verified through a separate communication channel — a phone call to a known number, not a number provided in the email - Any wire transfer request above a defined threshold must be approved by two people - Any urgent or unusual payment request from an executive must be verified verbally before processing — regardless of who it appears to come from - Payment instructions received by email for real estate or legal closings must be confirmed by phone using contact information from existing records, not from the email itself These procedures should be written, communicated to all relevant staff, and treated as non-negotiable. The attacker's primary tool is urgency — the procedure's primary tool is pause. #### Email Security While BEC can bypass many technical controls, several measures reduce the risk: - Enable MFA on all email accounts. This prevents the most damaging form of BEC — where the attacker operates from inside a compromised, legitimate account. MFA is the most effective technical control against account takeover. - Implement DMARC, DKIM, and SPF. These email authentication protocols help prevent domain spoofing. Your IT provider or MSP can configure these for your domain. They won't stop all BEC, but they make direct impersonation of your domain significantly harder. - Enable external email warnings. Configure your email system to display a visible banner on all emails originating from outside your organization. This simple visual cue helps employees identify when an "internal" request is actually coming from an external address. - Disable auto-forwarding rules. Attackers who compromise an email account often set up forwarding rules to monitor communications and intercept responses. Regularly audit mailbox rules for unauthorized forwarding. #### Employee Training BEC training is distinct from general phishing training and should focus on: - Recognizing urgency and authority pressure. Train employees to treat urgent financial requests with more scrutiny, not less - Understanding display name vs. email address. Show employees how to verify the actual sender address, especially on mobile devices - Following verification procedures without exception. The training message is simple: "No matter who the email appears to come from — including the CEO — payment changes and wire transfers are always verified by phone." - Reporting suspected BEC attempts. Even unsuccessful attempts should be reported because they indicate that the organization is being targeted #### Specific Procedures for High-Risk Roles Some roles are targeted more often than others. Tailor procedures for: - Accounts payable staff — Require dual authorization for vendor banking changes and wire transfers - HR/payroll staff — Verify all direct deposit change requests with the employee in person or by phone - Executives — Ensure that people authorized to request payments know the verification procedures and support them, even when it means a slight delay - Legal/real estate professionals — Verify all wiring instructions by phone using independently obtained contact information ### What to Do If You're a Victim Time matters. If you suspect a BEC attack has resulted in a fraudulent payment: - Contact your bank immediately. Request a recall of the wire transfer. The faster you act, the higher the chance of recovery. Some banks can initiate a hold on funds if contacted within 24-72 hours. - Contact the receiving bank. If you know which institution received the funds, contact them directly as well. - Report to the Canadian Anti-Fraud Centre at 1-888-495-8501 or online at antifraudcentre.ca - Report to local police. File a report with your local police service. - Preserve evidence. Do not delete emails, modify account settings, or alter any records related to the incident. These may be needed for investigation and recovery. - Notify your cyber insurer if you have cyber insurance. Many policies include social engineering coverage, but prompt notification is typically required. - Activate your incident response plan. Follow your incident response procedures for communication, investigation, and remediation. If the attack involved a compromised email account, treat it as a full account compromise — reset the password, review all mailbox rules and forwarding settings, check for unauthorized access, and audit what information the attacker may have accessed. ### The Baseline Controls Connection BEC defence maps across multiple areas of the Canadian Centre for Cyber Security's Baseline Controls: - BC.1 (Incident Response) — Having a plan for BEC incidents specifically, including who to contact and how to initiate fund recovery - BC.4 (Secure Configuration) — Implementing DMARC/DKIM/SPF and external email warnings - BC.5 (Authentication) — Requiring MFA on all email accounts to prevent account takeover - BC.6 (Security Awareness) — Training employees to recognize and respond to BEC attempts Our free assessment evaluates your organization's email security, authentication practices, and incident response readiness — all critical defences against business email compromise. It takes under 10 minutes and shows where your current posture may leave you exposed to Canada's most costly cyber threat. --- ## Remote Work Security for Canadian Businesses URL: https://cybersecuritycanada.ca/news/posts/remote-work-security-for-canadian-businesses/ Category: Best Practices Published: December 18, 2025 Summary: Remote and hybrid work is here to stay. Here's how Canadian SMBs can keep their data secure when employees work outside the office. Remote and hybrid work has become permanent for many Canadian businesses. What started as a pandemic necessity is now a standard operating model. But the security implications are significant — and many SMBs haven't caught up. ### The Security Challenges When employees work from home, coffee shops, or co-working spaces, your security perimeter expands dramatically: - Home networks lack the protections of a business firewall - Personal devices may be used for work tasks without adequate security - Public WiFi at coffee shops and airports is inherently insecure - Physical security is harder to control outside the office - Shadow IT increases as employees adopt their own tools to stay productive ### Essential Remote Work Security Measures #### 1. VPN for All Remote Connections A Virtual Private Network (VPN) encrypts the connection between your employee's device and your business network. This is non-negotiable for remote work. - Require VPN for all access to company resources - Enforce MFA on VPN connections - Choose a business-grade VPN — free consumer VPNs are not appropriate for business use - Consider always-on VPN configurations for company-managed devices #### 2. Multi-Factor Authentication Everywhere MFA is especially critical for remote workers because their credentials are at higher risk. Enable MFA on: - Email and productivity suites (Microsoft 365, Google Workspace) - Cloud storage and file sharing - VPN connections - Any system accessible from outside the office #### 3. Device Security Whether employees use company-owned or personal devices, minimum standards must be enforced: - Automatic updates enabled for operating system and applications - Anti-malware software installed and current - Full disk encryption enabled (BitLocker on Windows, FileVault on Mac) - Screen lock with a short timeout - Host-based firewall enabled For BYOD (Bring Your Own Device) environments, consider mobile device management (MDM) software that can separate and protect work data without controlling the employee's personal use. #### 4. Secure Home Network Guidance Most employees aren't network security experts, but simple guidance helps: - Change the default router admin password - Use WPA3 or WPA2 encryption for WiFi - Keep router firmware updated - Consider a separate WiFi network for work devices #### 5. Public WiFi Policy Employees should understand the risks of public WiFi: - Always use the VPN when on public networks - Never access sensitive systems without VPN protection - Disable auto-connect to open WiFi networks - Use mobile data as a fallback if VPN isn't available ### The Human Element Technical controls are essential, but remote workers also need: - Clear policies — Written guidelines on acceptable use, device requirements, and security expectations — including an AI usage policy for remote workers using AI tools - Regular training — Including phishing awareness and secure work-from-home practices. See what actually works in security training. - Easy reporting — A simple way to report security concerns or suspicious activity without fear of blame ### How the Baseline Controls Apply The Canadian Centre for Cyber Security's Baseline Controls directly address remote work security across several areas: - BC.5 (Authentication) — MFA and password management - BC.8 (Mobile Devices) — BYOD policies and device management - BC.9 (Network Security) — VPN, firewalls, and WiFi security - BC.10 (Cloud Services) — Securing cloud tools used by remote teams Our free assessment evaluates your organization across all 13 control areas, including the remote work-critical areas listed above. For a broader overview, see our cybersecurity guide for Canadian small businesses. --- ## Cloud Security Basics for Canadian Small Businesses URL: https://cybersecuritycanada.ca/news/posts/cloud-security-basics-for-canadian-small-businesses/ Category: Best Practices Published: December 12, 2025 Summary: Moving to the cloud doesn't mean your data is automatically secure. Microsoft 365, Google Workspace, and other cloud platforms require configuration — and the default settings often leave gaps. Here's what Canadian SMBs need to get right. Most Canadian small businesses are already in the cloud — whether they think of it that way or not. If your team uses Microsoft 365, Google Workspace, Dropbox, QuickBooks Online, Salesforce, or any web-based application, your business data lives on servers managed by someone else. The cloud offers real benefits for small businesses: lower upfront costs, automatic updates, accessibility from anywhere, and infrastructure maintained by teams far larger than any SMB could afford. But it also introduces a risk that many business owners misunderstand: the shared responsibility model. Your cloud provider is responsible for securing the infrastructure — the physical data centres, the servers, the network. But you are responsible for securing your data, your accounts, and your configuration. If an attacker accesses your Microsoft 365 tenant because an employee's account wasn't protected by MFA, that's not Microsoft's breach. It's yours. ### The Shared Responsibility Model Every major cloud provider operates under a shared responsibility model. The specifics vary, but the division is consistent: The cloud provider handles: - Physical security of data centres - Infrastructure availability and uptime - Patching of the underlying platform - Network-level protections You handle: - User account security (passwords, MFA, access controls) - Data classification and protection - Configuration of security settings - Who has access to what - Compliance with applicable laws (including PIPEDA) This means that a misconfigured cloud environment is your responsibility, even if the platform itself is secure. And misconfigurations are common — research from cloud security firms consistently finds that the majority of cloud security incidents stem from customer-side configuration errors, not provider-side vulnerabilities. ### Microsoft 365 Security Essentials Microsoft 365 is the most widely used business cloud platform in Canada. If your organization uses it, these settings should be reviewed and configured: #### Enable Security Defaults (or Conditional Access) Microsoft 365 offers Security Defaults — a free, one-click setting that enables a set of baseline security policies for all users, including: - Requiring MFA for all users - Blocking legacy authentication protocols (which can't support MFA) - Requiring MFA for administrative actions Security Defaults are available on all Microsoft 365 plans at no additional cost. For organizations on higher-tier plans (Business Premium or Enterprise), Conditional Access policies offer more granular control. Action: In the Azure Active Directory admin centre, navigate to Properties > Security Defaults and enable them. This single action addresses the most common attack vector against Microsoft 365 tenants. #### Review Administrative Accounts Administrative accounts in Microsoft 365 have broad access to your organization's data and settings. They are prime targets for attackers. - Minimize the number of Global Administrators. Most SMBs need two to three — a primary and a backup. Having more increases the attack surface. - Use dedicated admin accounts. Administrators should have a separate account for admin tasks and use their regular account for daily work. Admin accounts should not be used for email or web browsing. - Require MFA on all admin accounts without exception. This is non-negotiable. - Review admin accounts quarterly and remove any that are no longer needed. #### Configure Email Security Email is the primary attack vector for business email compromise, phishing, and malware delivery. Microsoft 365 includes several email security features that are not always enabled by default: - Anti-phishing policies — Configure in Microsoft Defender for Office 365 (included in Business Premium) or Exchange Online Protection (included in all plans) - External email tagging — Add a visual indicator to emails from outside your organization so employees can distinguish internal from external messages - DMARC, DKIM, and SPF — Email authentication protocols that prevent domain spoofing. Your IT provider can configure these for your domain through DNS records. - Audit mailbox forwarding rules — Attackers who compromise an account often set up forwarding rules to exfiltrate data. Review these regularly. #### Manage Sharing Settings Microsoft 365 makes it easy to share files and folders — sometimes too easy. Review these settings: - SharePoint and OneDrive external sharing — Determine whether users can share files with people outside your organization. If external sharing is enabled, restrict it to specific domains or require authentication. - Guest access in Teams — Review whether external guests can access your Teams channels and what they can see. - Default link permissions — When users create sharing links, ensure the default is "specific people" rather than "anyone with the link." ### Google Workspace Security Essentials For businesses using Google Workspace, the core security principles are the same: #### Enforce 2-Step Verification In the Google Admin console, enable and enforce 2-Step Verification for all users. Like Microsoft's Security Defaults, this is the single highest-impact security setting. #### Review Super Admin Accounts - Limit the number of Super Admin accounts to two or three - Require hardware security keys for Super Admin accounts if possible - Never use Super Admin accounts for daily tasks #### Configure Gmail Security - Enable the advanced phishing and malware protection settings in the Admin console - Enable external email warnings - Configure DMARC, DKIM, and SPF for your domain #### Control Sharing and Third-Party Access - Review Drive sharing defaults — restrict external sharing to authenticated users - Audit third-party app access — review which third-party applications have been granted access to your organization's data through OAuth - Revoke access for apps that are no longer needed or weren't explicitly approved ### Cloud Data Storage: Where Is Your Data? For Canadian businesses subject to PIPEDA, the location of your data matters. Both Microsoft and Google offer data residency options for Canadian organizations: - Microsoft 365: For organizations with a Canadian billing address, core customer data (Exchange Online mailbox data, SharePoint Online site content, and files uploaded to OneDrive for Business) is stored at rest in Canadian data centres (Toronto and Quebec City regions). - Google Workspace: Google offers a data region policy that allows organizations to choose where specific data is stored at rest, including a Canada option for eligible plans. However, some services and features within these platforms may process data outside of Canada. If data residency is a compliance requirement for your organization, review the provider's documentation carefully and consult with your privacy obligations under PIPEDA and any applicable provincial legislation. ### Shadow IT and Unauthorized Cloud Services One of the most significant cloud security risks for SMBs isn't about the platforms you've chosen — it's about the platforms your employees are using without your knowledge. Shadow IT refers to cloud services, applications, and tools adopted by employees without organizational approval. Common examples include: - Personal file-sharing accounts (personal Dropbox, Google Drive) used for work files - AI tools like ChatGPT, Gemini, or Copilot used with business data - Project management tools signed up for with personal email addresses - Messaging apps used for work communications Each unauthorized cloud service represents a data flow you don't control, can't audit, and may not be able to recover data from if the employee leaves. It also means business data may be stored in jurisdictions and under terms of service you haven't reviewed. To manage shadow IT: - Maintain a list of approved cloud services and communicate it to all employees - Make the process for requesting a new tool simple — if employees need to go through a weeks-long approval process, they'll bypass it - Periodically ask your team what tools they're using, especially for newer categories like AI assistants - Consider using cloud access security tools if your organization's scale warrants it ### Backup Your Cloud Data A common misconception is that data stored in cloud platforms is automatically backed up. While cloud providers maintain their own infrastructure backups (for disaster recovery), they don't typically protect against: - Accidental deletion by users - Malicious deletion by a compromised account - Ransomware that encrypts synced files - Data loss from a terminated employee's account Both Microsoft and Google offer retention policies and recovery tools, but they have time limits and don't cover all scenarios. For critical business data, consider a third-party cloud-to-cloud backup solution that maintains independent copies of your email, documents, and other data. ### Cloud Security Checklist for Canadian SMBs Whether you use Microsoft 365, Google Workspace, or another platform, run through this checklist: - MFA enabled and enforced for all users, especially administrators - Admin accounts minimized — two to three maximum, with dedicated admin accounts separate from daily-use accounts - Email authentication configured — DMARC, DKIM, and SPF records in place - External email tagging enabled — visual indicator on emails from outside your organization - Sharing defaults reviewed — files should not be shareable to "anyone with the link" by default - Third-party app access audited — revoke access for apps that aren't approved or no longer needed - Mailbox forwarding rules reviewed — check for unauthorized forwarding, especially on accounts that handle financial or sensitive data - Data residency confirmed — know where your data is stored and whether it meets your compliance needs - Cloud backup solution in place — independent backup of critical cloud data - Shadow IT addressed — approved services list communicated to all staff ### The Baseline Controls Connection Cloud security maps directly to several areas of the Canadian Centre for Cyber Security's Baseline Controls: - BC.5 (Authentication) — MFA and strong passwords for all cloud accounts - BC.7 (Data Backup) — Ensuring cloud data is independently backed up - BC.10 (Cloud Services) — Evaluating and configuring cloud platforms securely - BC.12 (Access Control) — Managing who has access to what in your cloud environment Our free assessment evaluates your organization's cloud service security alongside the other Baseline Control areas. It takes under 10 minutes and identifies the configuration gaps that may be leaving your cloud data exposed. --- ## How to Recognize Phishing Emails: A Guide for Canadian Businesses URL: https://cybersecuritycanada.ca/news/posts/how-to-recognize-phishing-emails/ Category: Threats Published: December 5, 2025 Summary: Phishing is the number one cyber threat to Canadian businesses. Learn the warning signs and how to protect your organization. Phishing emails are the most common way cybercriminals gain access to business systems. According to the Canadian Centre for Cyber Security, phishing remains the top cyber threat facing Canadian organizations of all sizes. The good news: phishing is preventable. Employees who know what to look for are your strongest defense. ### What Is Phishing? Phishing is a social engineering attack where criminals send fraudulent messages — typically emails — designed to trick the recipient into: - Clicking a malicious link that installs malware or leads to a fake login page - Opening a dangerous attachment that compromises their device - Revealing sensitive information like passwords, banking details, or personal data - Transferring money based on a fraudulent request ### Warning Signs to Watch For #### Urgency and Pressure "Your account will be suspended in 24 hours." "Immediate action required." Phishing emails create artificial urgency to prevent you from thinking critically. #### Unexpected Requests A vendor suddenly changing their payment details. Your CEO emailing from a new address asking for a wire transfer. An IT department asking you to verify your password via email. Legitimate organizations rarely make urgent, unexpected requests via email. #### Suspicious Sender Details The display name says "Canada Revenue Agency" but the actual email address is something like cra-notice@gmail.com. Always check the full sender address, not just the display name. #### Generic Greetings "Dear Customer" or "Dear User" instead of your actual name. Legitimate organizations that have a relationship with you typically address you by name. #### Poor Formatting Spelling errors, unusual formatting, low-resolution logos, or inconsistent branding. While some phishing emails are sophisticated, many contain subtle quality issues that reveal their origin. #### Suspicious Links Hover over any link before clicking. If the URL doesn't match the organization it claims to be from — or uses a misspelled domain like canada-gov.net instead of gc.ca — don't click. ### What to Do If You Receive a Suspicious Email - Don't click any links or open any attachments - Don't reply to the message - Report it to your IT team or manager - Verify the request through a separate channel — call the sender using a known phone number, not one provided in the email - Delete the message after reporting it ### Protecting Your Organization Individual awareness is important, but organizational measures are essential: - Regular training — Security awareness training should be ongoing, not a one-time event - Phishing simulations — Test employees with realistic (but safe) phishing emails to measure and improve awareness - Email filtering — Deploy email security tools that flag or block known phishing patterns - DMARC, SPF, and DKIM — These email authentication protocols prevent attackers from spoofing your domain - Multi-factor authentication — Even if credentials are stolen through phishing, MFA prevents access Phishing is also the primary delivery mechanism for ransomware and the starting point for most business email compromise attacks. The Canadian Centre for Cyber Security's Baseline Controls address phishing readiness across multiple areas, including Security Awareness (BC.6), Network Security (BC.9), and Authentication (BC.5). Our free assessment evaluates your organization's defenses across all of these areas. ### Report Phishing If you've received a phishing email, you can report it to the Canadian Anti-Fraud Centre or forward it to the Canadian Centre for Cyber Security. --- ## Employee Security Awareness Training: What Actually Works URL: https://cybersecuritycanada.ca/news/posts/employee-security-awareness-training-what-actually-works/ Category: Best Practices Published: November 28, 2025 Summary: Annual compliance videos don't change behaviour. Here's what the research says about effective security awareness training for Canadian small businesses — and how to build a program that actually reduces risk. Every cybersecurity framework, insurance application, and government guideline recommends security awareness training. The Canadian Centre for Cyber Security's Baseline Controls include it as BC.6. Cyber insurers ask whether you do it. PIPEDA expects your staff to understand their role in protecting personal information. But there's a gap between having a training program and having one that actually changes how people behave. A 30-minute annual video where employees click through slides and pass a quiz at the end is training in name only. The research is clear: it doesn't work. What does work is consistent, relevant, short-form training that meets employees where they are — and is designed to change habits, not check a box. ### Why Traditional Training Fails The typical corporate security training model looks like this: once a year, employees complete an online module covering every topic from phishing to physical security to password hygiene. They pass a quiz, get a certificate, and don't think about it again for twelve months. The problems with this approach are well documented: - Knowledge decay is rapid. Academic research has found that security awareness training effectiveness begins to decline after four to six months. By the time the next annual training comes around, most of what was learned has been forgotten. - Generic content doesn't resonate. Training that covers abstract threats without relating them to the employee's actual daily work fails to create the "this could happen to me" connection that drives behaviour change. - Passive consumption doesn't build skills. Watching a video is not the same as practising a skill. Recognizing a phishing email in a training scenario is different from spotting one in a busy inbox at 4:30 on a Friday. - Compliance focus creates resentment. When training is framed as an obligation rather than a benefit, employees disengage. They learn to pass the test, not to change their behaviour. ### What the Research Shows Works Effective security awareness training shares several characteristics, regardless of the organization's size or budget: #### Frequency Over Length Short, frequent training beats long, infrequent training. A 5-minute micro-lesson delivered monthly is more effective than a 60-minute annual course. This approach aligns with how adults actually learn — through repetition and reinforcement, not information dumps. For a Canadian SMB, this could be as simple as a brief team discussion during a regular meeting, a shared article about a recent threat, or a two-question quiz sent by email. #### Relevance to Daily Work Training must connect to what employees actually do. A receptionist needs to recognize pretexting phone calls. An accounts payable clerk needs to verify unusual payment requests. A sales representative working remotely needs to understand the risks of public Wi-Fi and remote work security. Generic, one-size-fits-all training misses these distinctions. The most effective programs tailor examples — even informally — to the roles and workflows in the organization. #### Positive Reinforcement Security culture is built when employees feel that reporting suspicious activity is valued, not punished. Organizations where employees fear blame for clicking a phishing link are organizations where incidents go unreported and training is resented. The goal is not zero clicks. The goal is fast reporting. An employee who clicks a phishing link and reports it within minutes gives the organization a chance to respond before damage is done. An employee who clicks and hides it gives the attacker time to move freely. #### Simulated Phishing — Done Right Phishing simulations can be effective, but they must be used carefully. Research from the National Institute of Standards and Technology (NIST) and others shows that: - Simulations work best when followed by immediate, contextual feedback — a brief explanation of what the red flags were and what to do next time - Punitive consequences backfire. Publicly shaming employees or attaching disciplinary action to simulation failures reduces reporting and increases resentment - Difficulty should escalate gradually. Start with obvious phishing attempts and increase sophistication over time as your team's detection skills improve - Frequency matters more than trickery. The goal is to build a habit of scrutinizing emails, not to outsmart your staff ### Building a Training Program for a Small Business You don't need a learning management system or a dedicated training budget to run an effective program. Here's a practical framework for a Canadian SMB: #### Monthly: The 5-Minute Touchpoint Pick one topic per month and spend five minutes on it during a regular team meeting or send a brief email. Rotate through these core topics: - Phishing recognition — what to look for, what to do - Password hygiene — unique passwords, password managers, why reuse is dangerous - MFA — how it works, why it matters, what to do if you get unexpected prompts - Physical security — locking screens, securing USB devices, visitor awareness - Social engineering — pretexting calls, impersonation, urgency tactics - Reporting procedures — how to report something suspicious, who to contact - AI tool usage — what data can and cannot be shared with AI services #### Quarterly: The Real-World Example Every quarter, share a real cyber incident relevant to your industry or region. Canadian examples are particularly effective because they counter the "that doesn't happen here" mindset. Sources include: - The Canadian Centre for Cyber Security's advisories and alerts - The Office of the Privacy Commissioner's breach investigation reports - News coverage of Canadian incidents (Indigo, SickKids, Hamilton, Toronto Public Library) - Your own cyber insurance broker's incident reports Walk through what happened, how it could have been prevented, and what your team would do if it happened at your organization. This connects directly to your incident response plan. #### Annually: The Tabletop Exercise Once a year, conduct a tabletop exercise with your core team. This doesn't need to be elaborate. Present a scenario — "An employee reports that they received an email from what appeared to be our bank asking them to update our account details, and they entered our credentials before realizing something was wrong" — and walk through your response step by step. This tests both your training and your incident response plan simultaneously. It reveals gaps in knowledge, procedures, and communication that no amount of slide-based training can uncover. #### Ongoing: The Culture Signals Training isn't just formal instruction. It's the signals your organization sends about whether security matters: - Does leadership follow the same rules? If the owner bypasses MFA or uses weak passwords, no training program will convince employees that security matters. - Is reporting easy and blame-free? The single most important culture signal is how you respond when an employee reports a potential incident or admits to clicking a suspicious link. - Are security conversations normal? In organizations with strong security culture, discussing a suspicious email with a colleague is as natural as asking about an unfamiliar visitor in the office. ### Free and Low-Cost Resources for Canadian Businesses Several resources are available to Canadian organizations at no cost: - Get Cyber Safe — The Government of Canada's public awareness campaign, with resources including tips, guides, and materials that can be shared with employees - Canadian Centre for Cyber Security Learning Hub — Free online courses and resources on cybersecurity fundamentals - Think Before You Click (CCCS) — Phishing awareness materials that can be distributed to staff - Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) — Includes specific guidance on what security awareness training should cover ### Measuring Whether It's Working You don't need sophisticated metrics to know if your training program is effective. Track these simple indicators: - Reporting rate — Are more employees reporting suspicious emails over time? An increasing reporting rate is the strongest sign of an effective program. - Phishing simulation click rate — If you run simulations, track the trend over time rather than fixating on any single result. A declining click rate indicates improving awareness. - Time to report — How quickly do employees report suspicious activity? Faster reporting means faster response. - Questions and engagement — Are employees asking security-related questions? Are they flagging things they're unsure about? Engagement signals that awareness is becoming part of the culture. ### The Baseline Controls Connection Security awareness training is BC.6 in the Canadian Centre for Cyber Security's Baseline Controls, but its impact reaches across every other control area. Trained employees: - Recognize phishing emails that bypass technical filters (BC.3, BC.4) - Use strong, unique passwords and MFA (BC.5) - Report incidents promptly, improving response times (BC.1) - Handle data appropriately, supporting privacy compliance (PIPEDA) - Avoid shadow AI and unauthorized tool usage (BC.10) Our free assessment evaluates your organization's security awareness posture alongside the other 12 Baseline Control areas. It takes under 10 minutes and identifies where training investment will have the greatest impact on your overall security. --- ## Password Security: What Canadian Businesses Get Wrong URL: https://cybersecuritycanada.ca/news/posts/password-security-what-canadian-businesses-get-wrong/ Category: Best Practices Published: November 20, 2025 Summary: Forced password rotation, short minimums, and no password manager — here are the most common password mistakes Canadian SMBs make and how to fix them. Passwords remain the primary way most businesses control access to their systems. Despite this, password practices at many Canadian small businesses are outdated, ineffective, or both. ### The Most Common Mistakes #### 1. Forcing Regular Password Changes Many organizations still require employees to change passwords every 30, 60, or 90 days. This practice is no longer recommended by the Canadian Centre for Cyber Security, NIST, or Microsoft. Why? Because forced rotation leads to predictable patterns. Employees create passwords like Company2025! then change them to Company2026!. This is worse than keeping a strong password indefinitely. What to do instead: Change passwords only when there is evidence or suspicion of compromise. Monitor for breached credentials using services like Have I Been Pwned. #### 2. Short Minimum Length Requirements A minimum of 8 characters is no longer adequate. Modern password cracking tools can brute-force short passwords in minutes. What to do instead: Require a minimum of 12 characters, and encourage passphrases — longer strings that are easier to remember but harder to crack. "correct-horse-battery-staple" is far stronger than "P@ssw0rd!". #### 3. No Password Manager When employees are expected to maintain unique, complex passwords for dozens of systems without a password manager, they inevitably reuse passwords. Password reuse is one of the most exploited vulnerabilities in small business security. What to do instead: Deploy a company-wide password manager. Options like Bitwarden, 1Password, or Keeper provide secure password generation and storage with team management features. #### 4. Relying on Passwords Alone Even the strongest password can be stolen through phishing or a data breach at a third-party service. Passwords alone are not enough. What to do instead: Implement multi-factor authentication (MFA) on all critical systems, especially email, cloud services, VPN, and admin accounts. MFA is the single most effective measure you can take to prevent unauthorized access. ### The Modern Password Policy A strong password policy for a Canadian SMB in 2026 looks like this: - Minimum 12 characters, passphrases encouraged - No scheduled rotation — change on suspected compromise only - Company password manager provided to all employees - MFA enforced on all critical systems - Breach monitoring for compromised credentials - Unique passwords for every account (enforced via the password manager) Weak passwords are a primary entry point for ransomware attacks and business email compromise. The City of Hamilton's $18.3 million ransomware recovery — with its insurance claim denied due to incomplete MFA — shows what's at stake. ### How Does Your Business Compare? Our free assessment evaluates your password and authentication practices against the Canadian Centre for Cyber Security's Baseline Controls (BC.5 — Authentication). It takes under 30 minutes and provides specific recommendations. --- ## Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs URL: https://cybersecuritycanada.ca/news/posts/multi-factor-authentication-the-single-biggest-security-upgrade-for-canadian-smbs/ Category: Best Practices Published: November 10, 2025 Summary: MFA blocks over 99% of automated account attacks. It's free to enable on most business platforms, takes minutes to set up, and is increasingly required by cyber insurers. Here's what Canadian businesses need to know. When the City of Hamilton's cyber insurance claim was denied after a ransomware attack that cost $18.3 million to recover from, the reason was straightforward: multi-factor authentication had not been fully implemented. The insurer determined this was a material gap in the city's security posture. Hamilton is a large municipality — but the lesson applies to every Canadian business. MFA is no longer a "nice to have." It has become the single most impactful security control a small business can implement, and one of the first things cyber insurers, partners, and regulators look for. ### What MFA Is and Why It Works Multi-factor authentication requires two or more verification steps to log in to an account. Typically, this means something you know (your password) plus something you have (your phone or a security key). The principle is simple: even if an attacker obtains your password — through phishing, a data breach, or brute force — they still cannot access your account without the second factor. The password alone is no longer sufficient. Microsoft's security research has found that MFA blocks more than 99.2% of automated account compromise attacks. Google reported similar findings, noting that security keys (a hardware form of MFA) prevented 100% of automated bot attacks and 100% of bulk phishing attacks in their study. These aren't marginal improvements. MFA eliminates the vast majority of the attack surface that credential-based attacks rely on. ### The Canadian Context The Canadian Centre for Cyber Security's Baseline Controls address authentication under BC.5 (User Authentication and Authorization). The guidance recommends that organizations implement MFA wherever possible, particularly for: - Remote access to organizational systems - Administrative or privileged accounts - Access to cloud-based services - Any externally facing login portal Despite MFA being one of the most effective and least costly controls available, adoption among Canadian businesses remains far too low — surveys consistently find that a majority of Canadian SMBs have not yet implemented MFA across their critical systems. The gap between the effectiveness of MFA and its adoption rate among Canadian SMBs remains one of the largest missed opportunities in business cybersecurity. ### Types of MFA Not all MFA is created equal. Here are the most common forms, from least to most secure: #### SMS Codes A one-time code sent to your phone via text message. This is the weakest form of MFA because SMS messages can be intercepted through SIM-swapping attacks — where an attacker convinces your mobile carrier to transfer your number to their device. The convergence of cyber and physical crime has made SIM-swapping increasingly common. Verdict: Better than no MFA. Use it if it's the only option available, but move to an authenticator app when possible. #### Authenticator Apps Apps like Microsoft Authenticator, Google Authenticator, or Authy generate time-based one-time codes that refresh every 30 seconds. These codes are generated on your device and don't travel over the cellular network, making them immune to SIM-swapping. Verdict: Good protection for most businesses. This is the recommended default for Canadian SMBs. #### Push Notifications Some authenticator apps (particularly Microsoft Authenticator and Duo) send a push notification asking you to approve or deny the login. This is convenient but can be exploited through "MFA fatigue" attacks — where an attacker repeatedly sends push notifications until the user taps "approve" to make them stop. Verdict: Good, but enable number matching (where the app displays a number that must be entered on the login screen) to prevent fatigue attacks. Microsoft now requires number matching by default. #### Hardware Security Keys Physical devices (like YubiKey or Google Titan) that you plug into a USB port or tap against your phone. These are the most resistant to phishing because they verify the legitimacy of the website you're logging into — a fake login page won't trigger the key. Verdict: The strongest option. Recommended for administrators, executives, and anyone with access to sensitive financial or customer data. ### Where to Enable MFA First If you're starting from zero, prioritize in this order: #### 1. Business Email (Highest Priority) Email is the master key to most business accounts — it's used for password resets, contains sensitive communications, and is the primary target for business email compromise. If an attacker controls your email, they effectively control your digital identity. - Microsoft 365: Enable Security Defaults in Azure AD (free with all plans) to require MFA for all users - Google Workspace: Enable 2-Step Verification in the Admin console and enforce it organization-wide #### 2. Financial and Banking Platforms Online banking, accounting software (QuickBooks, Xero, Sage), payment processors, and payroll systems. The direct financial exposure from these accounts makes them high-priority targets. #### 3. Cloud Storage and File Sharing Dropbox, OneDrive, Google Drive, SharePoint — wherever your business documents live. A compromised cloud storage account can expose customer data, financial records, and proprietary information, potentially triggering PIPEDA breach notification requirements. #### 4. Remote Access and VPN If employees access business systems remotely — which most do — the remote access point must be protected with MFA. This includes VPN connections, remote desktop (RDP), and any web-based portals. Remote work without MFA on access points is one of the highest-risk configurations for any business. #### 5. Administrative and IT Accounts Domain admin accounts, hosting dashboards, DNS management, website CMS logins — any account that could be used to take control of business infrastructure. ### Common Objections — And Why They Don't Hold Up #### "It's too inconvenient" MFA adds roughly 10 seconds to each login. Modern implementations remember trusted devices, so you may only need to verify once per device every 30-90 days. The inconvenience of MFA is negligible compared to the disruption of a compromised account. #### "My employees will resist it" Frame it correctly: "We're adding an extra step to protect your accounts — and your personal information — from being stolen." Most employees who have experienced or heard about a cyber incident are receptive. Make the rollout gradual — start with email, then expand. #### "We're too small to be targeted" Automated attacks don't discriminate by company size. Credential stuffing tools test stolen username/password combinations against thousands of login pages simultaneously. If your credentials were exposed in any data breach and you're not using MFA, your accounts are vulnerable regardless of your business size. #### "It costs too much" MFA is free on Microsoft 365 (Security Defaults), Google Workspace (2-Step Verification), and nearly every major cloud platform. Authenticator apps are free. The only cost is the time to enable it and communicate the change to your team. ### The Insurance Factor Cyber insurance applications in Canada now routinely ask whether MFA is enabled — and increasingly, they ask specifically where it's enabled. Common questions include: - Is MFA required for all remote access to the organization's network? - Is MFA required for access to email? - Is MFA required for privileged/administrative accounts? - Is MFA required for access to backup systems? Answering "no" to these questions can result in higher premiums, coverage exclusions, or outright denial of coverage. As Hamilton's experience demonstrated, even having a policy doesn't guarantee a claim will be paid if MFA wasn't properly implemented. For a detailed look at how cyber insurance works and what insurers require, see our guide to cyber insurance for Canadian SMBs. ### Implementation Checklist For a Canadian small business implementing MFA for the first time: - Inventory all business accounts — List every cloud service, platform, and application your business uses - Check MFA availability — Nearly all modern business platforms support MFA; check the security settings of each - Start with email — Enable MFA on your business email platform first (Microsoft 365 or Google Workspace) - Choose your default method — Authenticator apps are the best balance of security and convenience for most SMBs - Communicate the change — Give your team advance notice, explain why you're doing it, and provide setup instructions - Set a deadline — Give employees one to two weeks to set up MFA on their accounts, then enforce it - Keep backup codes — Most platforms provide one-time backup codes in case you lose access to your authenticator. Store these securely (printed, in a safe — not in email) - Document the process — Add MFA requirements to your onboarding checklist for new employees ### The Baseline Controls Connection MFA directly addresses BC.5 (User Authentication and Authorization) in the Canadian Centre for Cyber Security's Baseline Controls, but its benefits extend across multiple control areas: - BC.1 (Incident Response) — MFA prevents many of the incidents that would require an incident response in the first place - BC.6 (Security Awareness) — Rolling out MFA is itself a security awareness exercise for your team - BC.9 (Network Security) — MFA on remote access points strengthens network perimeter controls - BC.12 (Access Control) — MFA enforces the principle that access requires verified identity, not just knowledge of a password Our free assessment evaluates your organization's authentication practices alongside the other 12 Baseline Control areas. It takes under 10 minutes and identifies the specific gaps that MFA — and other controls — can close. ### Frequently Asked Questions — Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs Q: How effective is multi-factor authentication? A: Microsoft's security research has found that MFA blocks more than 99.2% of automated account compromise attacks. Google reported that hardware security keys prevented 100% of automated bot attacks and 100% of bulk phishing attacks in its study. The principle is simple: even if an attacker obtains your password through phishing, a data breach, or brute force, they still cannot access the account without the second factor. Q: Which type of MFA is most secure? A: From strongest to weakest: hardware security keys such as YubiKey or Google Titan, which verify the legitimacy of the site you are signing in to and so resist phishing; push notifications with number matching enabled; authenticator apps generating time-based codes; and finally SMS codes, which are the weakest because text messages can be intercepted through SIM-swapping. Authenticator apps are the recommended default for most Canadian SMBs, with hardware keys for administrators, executives, and anyone accessing sensitive financial or customer data. Q: Where should a business enable MFA first? A: In this order: business email first, because it is the master key used for password resets on nearly every other account; then financial and banking platforms including accounting and payroll; then cloud storage and file sharing; then remote access and VPN; and finally administrative and IT accounts such as domain admin, hosting dashboards, DNS management, and website CMS logins. On Microsoft 365 you can enable Security Defaults in Azure AD at no cost; on Google Workspace, enforce 2-Step Verification organization-wide from the Admin console. Q: Does MFA affect cyber insurance in Canada? A: Cyber insurance applications in Canada now routinely ask whether MFA is enabled, and increasingly ask specifically where — for remote access, email, privileged accounts, and backup systems. Answering no can mean higher premiums, coverage exclusions, or denial of coverage. The City of Hamilton's claim was denied after a ransomware attack that cost $18.3 million to recover from, because MFA had not been fully implemented; the insurer treated it as a material gap. Having a policy does not guarantee a claim will be paid. Q: Does the Canadian government recommend MFA? A: Yes. The Canadian Centre for Cyber Security addresses authentication under BC.5 of its 13 Baseline Cyber Security Controls, and recommends implementing MFA wherever possible — with particular priority on remote access to organizational systems, administrative and privileged accounts, and access to cloud-based services. Q: Is MFA enough on its own? A: MFA is the floor, not the ceiling. It eliminates the vast majority of credential-based attack surface, but attackers increasingly work around weaker implementations through MFA fatigue attacks, SIM-swapping, and session token theft that captures an already-authenticated session. That is why the strongest configurations use phishing-resistant methods — hardware keys or passkeys — for the accounts that matter most, and why MFA sits alongside the other 12 Baseline Controls rather than replacing them. --- ## Why Cybercriminals Target Small Businesses URL: https://cybersecuritycanada.ca/news/posts/why-cybercriminals-target-small-businesses/ Category: Threats Published: November 1, 2025 Summary: Small businesses are not too small to be targeted. Here's why cybercriminals see Canadian SMBs as attractive targets and what you can do about it. There's a persistent myth among small business owners: "We're too small to be a target." Unfortunately, the opposite is true. Cybercriminals increasingly prefer small and medium businesses precisely because they tend to have fewer defenses. ### The Numbers According to the Canadian Centre for Cyber Security, small and medium organizations are among the most frequently targeted by cyber threat actors. The reasoning is straightforward — SMBs often have: - Valuable data — Customer records, payment information, employee data, and intellectual property - Weaker defenses — Limited budgets, no dedicated IT security staff, and outdated systems - Less monitoring — Breaches may go undetected for weeks or months - Lower awareness — Employees who haven't received cybersecurity training ### How Attacks Happen Most attacks against small businesses aren't sophisticated. They rely on volume and automation: #### Phishing Fraudulent emails that trick employees into clicking malicious links or revealing credentials. This remains the number one attack vector for businesses of all sizes. #### Ransomware Malicious software that encrypts your files and demands payment for their return. Canadian businesses have been hit hard by ransomware, with some forced to close permanently after an attack. #### Business Email Compromise Attackers impersonate executives or vendors to trick employees into transferring funds or sharing sensitive information. These attacks are often well-researched and convincing. #### Credential Stuffing Automated attacks that try stolen username/password combinations from other breaches against your systems. If employees reuse passwords, this attack works. ### The Real Cost For a small business, a cyber incident can mean: - Days or weeks of downtime while systems are restored - Mandatory breach reporting under PIPEDA if personal information is involved - Lost customer trust that takes years to rebuild - Recovery costs that can exceed what many small businesses can absorb ### What You Can Do Today The good news is that basic security measures stop the vast majority of attacks. You don't need an enterprise security budget — you need the fundamentals: - Enable multi-factor authentication on all accounts — this single step prevents most credential-based attacks - Train your employees to recognize phishing emails - Keep software updated — automatic updates close known vulnerabilities - Back up your data with at least one copy offline or offsite - Use a password manager and enforce strong, unique passwords These measures align directly with the Canadian Centre for Cyber Security's Baseline Controls for small and medium organizations. For a deeper look at the real cost of not preparing, see our analysis of what downtime actually costs Canadian SMBs. Not sure where your business stands? Our free assessment evaluates your security posture across all 13 Baseline Control areas in under 30 minutes. You can also explore our complete cybersecurity guide for Canadian small businesses or look up unfamiliar terms in our cybersecurity glossary. --- ## 5 Easy Cybersecurity Wins for Canadian Small Businesses URL: https://cybersecuritycanada.ca/news/posts/5-easy-cybersecurity-wins-for-canadian-small-businesses/ Category: Guide Published: October 28, 2025 Summary: You don't need a massive budget or a dedicated IT team to meaningfully improve your cybersecurity. These five actions can be implemented quickly and address the most common ways Canadian small businesses get breached. Most cybersecurity advice for small businesses reads like a to-do list written for a Fortune 500 company. Segmented networks. Zero-trust architecture. Security operations centres. It's not wrong — it's just not where you start. The reality is that most cyber incidents affecting Canadian SMBs succeed because of a handful of basic gaps — and closing those gaps doesn't require specialized expertise or a large budget. The Canadian Centre for Cyber Security's Baseline Controls framework identifies 13 control areas, but the five actions below address the root causes behind the majority of successful attacks on small businesses. ### 1. Turn On Multi-Factor Authentication Everywhere If you only do one thing on this list, make it this one. Multi-factor authentication (MFA) requires a second verification step — typically a code from your phone — when logging in. It means that even if an attacker steals or guesses a password, they still can't get in. Microsoft's security research has consistently found that MFA blocks over 99% of automated account compromise attacks. The Canadian Centre for Cyber Security lists authentication controls as BC.5 in the Baseline Controls — and cyber insurers increasingly require MFA as a condition of coverage. What to do today: - Enable MFA on email (Microsoft 365, Google Workspace) — this is the highest priority - Enable MFA on banking and financial platforms - Enable MFA on any cloud storage or file sharing services - Use an authenticator app (Microsoft Authenticator, Google Authenticator) rather than SMS where possible Time required: 15-30 minutes per service. ### 2. Keep Software and Systems Updated Unpatched software is one of the most common entry points for attackers. When a vulnerability is publicly disclosed, automated scanning tools begin probing the internet for systems that haven't applied the fix — often within hours. The Canadian Centre for Cyber Security designates patch management as BC.2 in the Baseline Controls. Statistics Canada's 2023 survey found that businesses that experienced a cybersecurity incident were significantly more likely to have delayed applying software updates. What to do today: - Turn on automatic updates for operating systems (Windows, macOS) on all business computers - Enable automatic updates for web browsers (Chrome, Edge, Firefox) - Set your router and firewall firmware to update automatically, or check monthly - Update business-critical applications (accounting software, CRM, email clients) promptly when notified Time required: 10 minutes to check and enable auto-update settings. ### 3. Back Up Your Data — And Test the Backups Having backups isn't enough. The question that matters is: can you actually restore from them? Many Canadian businesses discover their backups are incomplete, corrupted, or inaccessible only after an incident — precisely when they're needed most. The five backup assumptions that commonly fail include relying on a single backup location, never testing restoration, and assuming cloud sync is the same as backup. The Baseline Controls framework covers this under BC.7 (Data Backup and Recovery). The principle is straightforward: if ransomware encrypts everything on your network, you need a copy that the ransomware couldn't reach. What to do today: - Confirm that critical business data (financial records, customer data, contracts) is being backed up - Ensure at least one backup copy is stored offline or in a separate cloud account not connected to your main network - Schedule a test: pick one backup file and attempt a full restore. Note how long it takes and whether the data is intact - Set a calendar reminder to test backups quarterly Time required: 30 minutes to verify; a few hours for a full restoration test. ### 4. Train Your Team to Spot Phishing Technology alone can't stop phishing — it only takes one click on a malicious link to compromise an entire business. Phishing emails remain the number one delivery method for ransomware, credential theft, and business email compromise. The CCCS Baseline Controls address this under BC.6 (Security Awareness Training). But effective training doesn't mean expensive platforms or annual compliance modules. It means making sure every employee understands the warning signs and knows what to do when something looks suspicious. What to do today: - Share the basic red flags with your team: urgency, unexpected attachments, requests to bypass normal procedures, mismatched sender addresses - Establish a simple reporting process: "If you're not sure, forward it to [designated person] before clicking anything" - Send a quarterly reminder email with a recent real-world example relevant to your industry - Make reporting blame-free — you want people to flag suspicious emails, not hide mistakes Time required: 15 minutes to send an initial team email; 30 minutes quarterly for ongoing reminders. ### 5. Use Strong, Unique Passwords With a Password Manager Password reuse is the single most exploitable habit in cybersecurity. When credentials from one breached service are reused on business accounts, attackers don't need sophisticated tools — they just log in. The Baseline Controls address this under BC.5 (User Authentication and Authorization). Modern guidance from both the Canadian Centre for Cyber Security and NIST recommends long, unique passwords for every account — and the only practical way to manage that is with a password manager. What to do today: - Choose a business password manager (1Password, Bitwarden, and Dashlane all offer business plans) - Have each team member install it and migrate their most critical accounts (email, banking, cloud services) first - Set a minimum password length of 14+ characters for all business accounts - Disable password reuse — the password manager handles remembering unique passwords for each account Time required: 20 minutes per person for initial setup; ongoing use actually saves time. ### The Compound Effect None of these five actions is expensive. None requires a dedicated security team. But together, they close the gaps that are responsible for the vast majority of successful attacks on Canadian small businesses. Consider what a typical attack looks like without these controls: an employee receives a phishing email and clicks a link. Because there's no security awareness training, they enter their password on a fake login page. Because they reuse passwords, the attacker now has access to their business email. Because there's no MFA, the attacker logs in without obstruction. Because software isn't patched, the attacker exploits a known vulnerability to move deeper into the network. Because backups are incomplete or connected to the network, recovery takes weeks. Now consider the same attack with all five controls in place: the employee recognizes the phishing attempt and reports it. Even if they don't, MFA blocks the login. Even if MFA is somehow bypassed, the password is unique so lateral movement is limited. Patched systems close known vulnerabilities. And if the worst happens, tested offline backups enable recovery in hours rather than weeks. ### What Comes Next These five actions are a starting point — not a finish line. Once they're in place, the next steps include formalizing an incident response plan, reviewing vendor and third-party access, and evaluating your cloud security configuration. Our free assessment evaluates your organization across all 13 of the Canadian Centre for Cyber Security's Baseline Control areas. It takes under 10 minutes and shows you exactly where you stand — including how well you're doing on each of these five fundamentals. For a complete overview, see our cybersecurity guide for Canadian small businesses. If any terms are unfamiliar, our cybersecurity glossary explains them in plain language. --- ## Canada's Privacy Landscape: What Small Businesses Need to Know URL: https://cybersecuritycanada.ca/news/posts/canadas-privacy-landscape-what-small-businesses-need-to-know/ Category: Compliance Published: October 15, 2025 Summary: PIPEDA, provincial laws, and breach reporting — a plain-language overview of the privacy obligations that apply to Canadian small businesses. If you run a small or medium business in Canada, privacy law applies to you. Many business owners assume privacy regulations are only for large corporations, but that's not the case. Here's what you need to understand. ### PIPEDA: The Federal Standard The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal privacy law. It applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity. This means if your business collects customer names, email addresses, payment information, or employee data, PIPEDA likely applies to you. PIPEDA is built on 10 fair information principles, including: - Accountability — Your organization is responsible for personal information under its control - Consent — Individuals must know about and consent to the collection of their data - Limiting collection — Only collect information that is necessary for identified purposes - Safeguards — Protect personal information with security measures appropriate to its sensitivity ### Provincial Privacy Laws Three provinces have their own private-sector privacy legislation that has been deemed substantially similar to PIPEDA: - Alberta — Personal Information Protection Act (PIPA) - British Columbia — Personal Information Protection Act (PIPA) - Quebec — Act Respecting the Protection of Personal Information in the Private Sector (Law 25) If your business operates in these provinces, the provincial law applies to activities within the province, while PIPEDA applies to interprovincial and international activities. Quebec's Law 25, which has been rolling out in phases since 2022, is particularly significant. It introduced stricter consent requirements, mandatory privacy impact assessments, and the right to data portability. ### Mandatory Breach Reporting Since November 2018, PIPEDA requires organizations to: - Report breaches of security safeguards involving personal information to the Office of the Privacy Commissioner of Canada if there is a real risk of significant harm - Notify affected individuals about the breach - Keep records of all breaches, regardless of whether they meet the reporting threshold Failure to comply can result in fines of up to $100,000 per violation. ### What Canadian SMBs Should Do If you haven't reviewed your privacy practices recently, start with these steps: - Know what you collect — Inventory the personal information your business holds, where it's stored, and who has access - Review your consent practices — Are customers clearly informed about how their data is used? - Have a breach response plan — Know who to contact and what steps to follow if personal information is compromised. See our guide to building an incident response plan. - Secure your data — Technical safeguards like encryption, access controls, and multi-factor authentication protect both your customers and your compliance standing Privacy obligations are also a factor in cyber insurance — many policies require documented privacy practices and breach reporting compliance. Our free assessment evaluates your organization against the Canadian Centre for Cyber Security's Baseline Controls, including data protection and access control measures that directly support your privacy obligations. For a broader look at cybersecurity fundamentals, see our guide for Canadian small businesses. Key terms like PIPEDA, breach notification, and others are defined in our cybersecurity glossary. ### Further Reading - Office of the Privacy Commissioner of Canada — PIPEDA guidance and breach reporting - PIPEDA Fair Information Principles — The 10 principles in detail ---