# Cybersecurity Canada > Free, independent cybersecurity guidance and a free self-assessment for Canadian small and medium businesses, organised around the Canadian Centre for Cyber Security's 13 Baseline Cyber Security Controls (ITSM.10.089). Cybersecurity Canada is published by Cyber Unit Security Inc. All content is written for Canadian business owners and executives rather than security practitioners, and is framed against Canadian law and guidance: the CCCS Baseline Controls, PIPEDA, CASL, Quebec Law 25, and Bill C-26 / Bill C-8. Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada. Content is educational and does not constitute legal, compliance, insurance, or professional cybersecurity advice. - Language: en-CA (Canadian English spelling) - Currency in all figures: Canadian dollars unless stated otherwise - Contact: info@cybersecuritycanada.ca - Full text of every page: https://cybersecuritycanada.ca/llms-full.txt ## Primary references - [The Cybersecurity Canada Report 2026](https://cybersecuritycanada.ca/cybersecurity-canada-report-2026/): Annual benchmark of Canadian SMB cybersecurity — verified 2025-2026 statistics on incident rates, breach costs, ransomware, fraud losses, and regulation, sourced from Statistics Canada, CCCS, CIRA, IBM, the OPC, and the Canadian Anti-Fraud Centre. Includes methodology, data vintage, limitations, a full source list, and a suggested citation. - [Canada's 13 Baseline Cyber Security Controls](https://cybersecuritycanada.ca/controls/): Index of the 13 control areas the Government of Canada recommends as the minimum security standard for small and medium organizations. - [Cybersecurity Glossary for Canadian Businesses](https://cybersecuritycanada.ca/glossary/): 71 plain-language definitions of cybersecurity terms, each with a Canadian regulatory or Baseline Control reference and its own page. - [Free Cybersecurity Assessment](https://cybersecuritycanada.ca/assessment/): 50-question self-assessment scored against all 13 Baseline Controls. Runs entirely in the browser; no answers are transmitted or stored. - [Cybersecurity for Canadian SMBs](https://cybersecuritycanada.ca/small-business-cybersecurity/): Starting-point guide on what Canadian small businesses should prioritise and where to begin. - [Canadian Cybersecurity Resources](https://cybersecuritycanada.ca/resources/): Curated Government of Canada guidance, incident reporting channels, and security frameworks. ## The 13 Baseline Controls - [BC.1 — Incident Response](https://cybersecuritycanada.ca/controls/incident-response/): Learn what the Canadian Centre for Cyber Security recommends for incident response planning. Covers IRP templates, PIPEDA breach notification, and ITSAP.40.003 guidance. - [BC.2 — Patch Management](https://cybersecuritycanada.ca/controls/patch-management/): Canadian Centre for Cyber Security guidance on patch management for SMBs. Covers automatic updates, critical patches, asset inventory, and end-of-life software risks. - [BC.3 — Anti-Malware](https://cybersecuritycanada.ca/controls/anti-malware/): CCCS guidance on anti-malware for SMBs. Covers endpoint protection, automatic scanning, email filtering, browser security, and keeping malware signatures updated. - [BC.4 — Secure Configuration](https://cybersecuritycanada.ca/controls/secure-configuration/): CCCS guidance on secure configuration for SMBs. Covers changing defaults, disabling unnecessary services, CIS Benchmarks, and configuration management practices. - [BC.5 — Authentication](https://cybersecuritycanada.ca/controls/authentication/): CCCS guidance on authentication for SMBs. Covers multi-factor authentication, password policies (ITSAP.30.032), password managers, and eliminating shared accounts. - [BC.6 — Security Awareness Training](https://cybersecuritycanada.ca/controls/security-training/): Learn what the Canadian Centre for Cyber Security recommends for cybersecurity training employees in Canada. Covers phishing awareness, social engineering, and training cadence. - [BC.7 — Data Backup & Recovery](https://cybersecuritycanada.ca/controls/backup-recovery/): Learn what the Canadian Centre for Cyber Security recommends for backup strategy for businesses in Canada. Covers the 3-2-1 rule, restore testing, and ransomware resilience. - [BC.8 — Mobile Device Security](https://cybersecuritycanada.ca/controls/mobile-security/): Learn what the Canadian Centre for Cyber Security recommends for mobile device management in Canada. Covers MDM, BYOD policies, encryption, and remote wipe. - [BC.9 — Network & Perimeter Security](https://cybersecuritycanada.ca/controls/network-security/): Learn what the Canadian Centre for Cyber Security recommends for network security for SMBs in Canada. Covers firewalls, segmentation, VPNs, and intrusion detection. - [BC.10 — Cloud Services Security](https://cybersecuritycanada.ca/controls/cloud-security/): Learn what the Canadian Centre for Cyber Security recommends for cloud security for Canadian businesses. Covers shared responsibility, data residency, and secure configuration. - [BC.11 — Web Application Security](https://cybersecuritycanada.ca/controls/web-application-security/): What the Canadian Centre for Cyber Security recommends for web application security. HTTPS, input validation, WAFs, secure development, and OWASP awareness for SMBs. - [BC.12 — Access Control & Authorization](https://cybersecuritycanada.ca/controls/access-control/): What the Canadian Centre for Cyber Security recommends for access control. Least privilege, role-based access, access reviews, and privileged account management for SMBs. - [BC.13 — Portable Media Security](https://cybersecuritycanada.ca/controls/portable-media/): What the Canadian Centre for Cyber Security recommends for portable media security. USB risks, removable media policies, encryption, and secure disposal for SMBs. ## Glossary terms - [Access Control](https://cybersecuritycanada.ca/glossary/access-control/): The practice of restricting who can access which systems, data, and resources within your organization. Good access control means employees only have access to what they need for t... - [Air-Gapped Backup](https://cybersecuritycanada.ca/glossary/air-gapped-backup/): A backup copy of your data that is physically disconnected from your network and the internet. Because it has no network connection, ransomware cannot reach it — making it your mos... - [Anti-Malware](https://cybersecuritycanada.ca/glossary/anti-malware/): Software that detects, prevents, and removes malicious software (malware) from your devices. Modern anti-malware goes beyond traditional antivirus to detect ransomware, spyware, an... - [Attack Surface](https://cybersecuritycanada.ca/glossary/attack-surface/): The total number of points where an attacker could try to enter or extract data from your environment. Every internet-facing system, employee account, cloud service, remote access... - [Adversary-in-the-Middle (AiTM) Phishing](https://cybersecuritycanada.ca/glossary/aitm-phishing/): A phishing attack that places an attacker-controlled reverse proxy between you and the real login page. You enter your password and approve your multi-factor authentication prompt... - [Backdoor](https://cybersecuritycanada.ca/glossary/backdoor/): A hidden method of bypassing normal authentication to gain access to a system. Backdoors can be installed by malware, left behind by attackers after an initial breach, or even buil... - [Baseline Cyber Security Controls](https://cybersecuritycanada.ca/glossary/baseline-cyber-security-controls/): A set of 13 fundamental cybersecurity practices published by the Canadian Centre for Cyber Security (document ITSM.10.089), designed specifically for small and medium organizations... - [Business Email Compromise (BEC)](https://cybersecuritycanada.ca/glossary/bec/): A type of fraud where an attacker impersonates a trusted person — typically a CEO, vendor, or lawyer — via email to trick an employee into transferring money, sharing sensitive dat... - [Brute Force Attack](https://cybersecuritycanada.ca/glossary/brute-force-attack/): An attack method where automated tools systematically try every possible password or key combination until the correct one is found. Short, simple passwords can be cracked in minut... - [Botnet](https://cybersecuritycanada.ca/glossary/botnet/): A network of compromised computers or devices secretly controlled by an attacker. Each infected device (a "bot") can be remotely commanded to send spam, launch denial-of-service at... - [BYOD (Bring Your Own Device)](https://cybersecuritycanada.ca/glossary/byod/): A policy where employees use their personal phones, laptops, or tablets for work. BYOD can reduce hardware costs but introduces security risks — personal devices may lack encryptio... - [Canadian Centre for Cyber Security (CCCS)](https://cybersecuritycanada.ca/glossary/cccs/): Canada's national authority on cybersecurity, part of the Communications Security Establishment (CSE). The CCCS publishes threat assessments, security guidance, and alerts for Cana... - [Credential Stuffing](https://cybersecuritycanada.ca/glossary/credential-stuffing/): An automated attack that uses stolen username and password combinations from previous data breaches to try to log in to other services. It works because people reuse passwords acro... - [Cyber Insurance](https://cybersecuritycanada.ca/glossary/cyber-insurance/): Insurance coverage designed to help organizations manage the financial impact of cyber incidents, including breach response costs, business interruption, regulatory fines, and liab... - [Cloud Security](https://cybersecuritycanada.ca/glossary/cloud-security/): The practices, tools, and policies that protect data, applications, and infrastructure hosted in cloud environments (e.g., Microsoft 365, Google Workspace, AWS). Cloud providers se... - [Cybercrime-as-a-Service (CaaS)](https://cybersecuritycanada.ca/glossary/cybercrime-as-a-service/): A criminal business model where attack tools, infrastructure, and expertise are rented or sold to other criminals — much like legitimate software-as-a-service. CaaS has lowered the... - [CyberSecure Canada](https://cybersecuritycanada.ca/glossary/cybersecure-canada/): A federal cybersecurity certification program operated by Innovation, Science and Economic Development Canada (ISED). It allows small and medium organizations to demonstrate they h... - [Dark Web](https://cybersecuritycanada.ca/glossary/dark-web/): A part of the internet that is not indexed by search engines and requires specialized software (such as the Tor browser) to access. The dark web hosts marketplaces where stolen cre... - [Data Breach](https://cybersecuritycanada.ca/glossary/data-breach/): An incident where personal, confidential, or protected information is accessed, disclosed, or stolen by an unauthorized party. Under PIPEDA, Canadian organizations must report brea... - [DDoS (Distributed Denial of Service)](https://cybersecuritycanada.ca/glossary/ddos/): An attack that floods a website, server, or network with so much traffic that it becomes unavailable to legitimate users. "Distributed" means the traffic comes from thousands of co... - [Defence in Depth](https://cybersecuritycanada.ca/glossary/defence-in-depth/): A security strategy that layers multiple independent defences so that if one control fails, others still protect you. Rather than relying on a single firewall or antivirus, defence... - [DMARC, SPF, and DKIM](https://cybersecuritycanada.ca/glossary/dmarc/): Three email authentication protocols that work together to prevent attackers from sending emails that appear to come from your domain. SPF specifies which servers can send email fo... - [Endpoint Detection and Response (EDR)](https://cybersecuritycanada.ca/glossary/edr/): Security software that continuously monitors devices (endpoints) for suspicious activity and can respond automatically to threats. EDR goes beyond traditional antivirus by detectin... - [Exploit](https://cybersecuritycanada.ca/glossary/exploit/): A piece of code or technique that takes advantage of a specific vulnerability in software or hardware to gain unauthorized access or cause harm. Exploit kits — ready-made toolkits... - [Encryption](https://cybersecuritycanada.ca/glossary/encryption/): The process of converting data into a coded format that can only be read with the correct key. Encryption protects data both in transit (e.g., HTTPS connections) and at rest (e.g.,... - [Firewall](https://cybersecuritycanada.ca/glossary/firewall/): A security device or software that monitors and controls network traffic based on predefined rules, acting as a barrier between your trusted internal network and untrusted external... - [Get Cyber Safe](https://cybersecuritycanada.ca/glossary/get-cyber-safe/): The Government of Canada's public awareness campaign on cybersecurity, operated by the Canadian Centre for Cyber Security. Get Cyber Safe provides free, plain-language tips and res... - [HTTPS](https://cybersecuritycanada.ca/glossary/https/): The secure version of HTTP — the protocol your browser uses to communicate with websites. HTTPS encrypts data in transit using TLS (Transport Layer Security), preventing attackers... - [Identity Theft](https://cybersecuritycanada.ca/glossary/identity-theft/): The fraudulent use of someone's personal information — name, Social Insurance Number, credit card details, or other identifying data — without their consent. When a data breach exp... - [Incident Response Plan](https://cybersecuritycanada.ca/glossary/incident-response-plan/): A written document that defines who is responsible for what when a cybersecurity incident occurs, who to contact, which systems are critical, and what steps to follow. The Canadian... - [Insider Threat](https://cybersecuritycanada.ca/glossary/insider-threat/): A security risk that comes from within your organization — an employee, contractor, or business partner who either intentionally or accidentally compromises your systems. Insider t... - [Keylogger](https://cybersecuritycanada.ca/glossary/keylogger/): Malicious software or hardware that secretly records every keystroke you type — capturing passwords, credit card numbers, emails, and other sensitive information. Keyloggers are ty... - [Lateral Movement](https://cybersecuritycanada.ca/glossary/lateral-movement/): The techniques an attacker uses to move through your network after gaining initial access — jumping from one system to another to find valuable data or gain higher privileges. A ra... - [Least Privilege](https://cybersecuritycanada.ca/glossary/least-privilege/): A security principle that says users should have only the minimum level of access required to do their job — nothing more. If ransomware compromises an account with broad access, i... - [Log Management](https://cybersecuritycanada.ca/glossary/log-management/): The practice of collecting, storing, and reviewing records of activity across your systems — who logged in, what they accessed, what changed, and when. Logs are critical for detect... - [Malware](https://cybersecuritycanada.ca/glossary/malware/): Short for "malicious software." Any software intentionally designed to damage, disrupt, or gain unauthorized access to a computer system. Malware includes viruses, ransomware, spyw... - [Man-in-the-Middle Attack (MitM)](https://cybersecuritycanada.ca/glossary/man-in-the-middle/): An attack where a criminal secretly intercepts and potentially alters communication between two parties who believe they are talking directly to each other. Common examples include... - [Managed Service Provider (MSP)](https://cybersecuritycanada.ca/glossary/managed-service-provider/): A company that remotely manages your IT infrastructure and systems on your behalf. MSPs typically have high-level administrative access to your network, making them both essential... - [Managed Detection and Response (MDR)](https://cybersecuritycanada.ca/glossary/mdr/): A cybersecurity service where a third-party provider monitors your systems around the clock, detects threats, and responds to incidents on your behalf. MDR combines EDR technology... - [Multi-Factor Authentication (MFA)](https://cybersecuritycanada.ca/glossary/mfa/): A security method that requires two or more verification steps to log in — typically something you know (password) plus something you have (phone or security key). MFA blocks over... - [Network Segmentation](https://cybersecuritycanada.ca/glossary/network-segmentation/): The practice of dividing your network into separate zones so that a breach in one area cannot easily spread to others. For example, your point-of-sale system, employee workstations... - [Password Manager](https://cybersecuritycanada.ca/glossary/password-manager/): Software that securely generates, stores, and auto-fills unique, strong passwords for every account. Password managers eliminate the need to remember dozens of passwords and remove... - [Patch Management](https://cybersecuritycanada.ca/glossary/patch-management/): The process of keeping software and operating systems up to date by applying security patches — fixes released by software vendors to close known vulnerabilities. Unpatched softwar... - [Penetration Testing (Pen Test)](https://cybersecuritycanada.ca/glossary/penetration-testing/): An authorized simulated attack on your systems, conducted by security professionals, to find vulnerabilities before real attackers do. A pen test report shows you exactly how an at... - [Phishing](https://cybersecuritycanada.ca/glossary/phishing/): A social engineering attack where criminals send fraudulent messages — typically emails — designed to trick recipients into clicking malicious links, opening dangerous attachments,... - [Phishing-Resistant MFA](https://cybersecuritycanada.ca/glossary/phishing-resistant-mfa/): Multi-factor authentication that cannot be relayed through a fake login page, because the credential is cryptographically bound to the real site's domain. In practice this means FI... - [PIPEDA](https://cybersecuritycanada.ca/glossary/pipeda/): The Personal Information Protection and Electronic Documents Act — Canada's federal privacy law. It applies to any private-sector organization that collects, uses, or discloses per... - [RDP (Remote Desktop Protocol)](https://cybersecuritycanada.ca/glossary/rdp/): A Microsoft protocol that allows users to remotely access and control another computer over a network. RDP is widely used for remote work and IT administration, but exposed RDP por... - [Ransomware](https://cybersecuritycanada.ca/glossary/ransomware/): Malicious software that encrypts your files and demands payment for their return. Modern ransomware often also steals data before encrypting it, threatening to publish it if the ra... - [Ransomware-as-a-Service (RaaS)](https://cybersecuritycanada.ca/glossary/raas/): A criminal business model where ransomware developers lease their tools to other attackers (affiliates) in exchange for a percentage of ransom payments. RaaS has made ransomware at... - [Risk Assessment](https://cybersecuritycanada.ca/glossary/risk-assessment/): A systematic process of identifying what could go wrong (threats), how likely it is (probability), and how bad it would be (impact). A cybersecurity risk assessment helps you prior... - [Recovery Time Objective (RTO)](https://cybersecuritycanada.ca/glossary/rto/): The maximum acceptable amount of time that a system or business process can be offline before the organization's survival is at risk. Defining your RTO for each critical system hel... - [Security Awareness Training](https://cybersecuritycanada.ca/glossary/security-awareness-training/): Ongoing education that teaches employees to recognize and respond to cybersecurity threats — particularly phishing, social engineering, and unsafe data handling. Effective training... - [Shadow IT](https://cybersecuritycanada.ca/glossary/shadow-it/): Technology — cloud services, apps, AI tools, or devices — used by employees for work without organizational approval or oversight. Shadow IT creates data flows you cannot control,... - [SIM Swapping](https://cybersecuritycanada.ca/glossary/sim-swapping/): An attack where a criminal convinces your mobile carrier to transfer your phone number to a device they control. Once they have your number, they can intercept SMS-based two-factor... - [Spear Phishing](https://cybersecuritycanada.ca/glossary/spear-phishing/): A targeted form of phishing directed at a specific individual or organization, using personalized information to make the attack more convincing. Unlike mass phishing campaigns, sp... - [Social Engineering](https://cybersecuritycanada.ca/glossary/social-engineering/): The use of psychological manipulation to trick people into revealing information, granting access, or taking actions that compromise security. Phishing, pretexting (creating a fabr... - [Session Token](https://cybersecuritycanada.ca/glossary/session-token/): The credential your identity provider issues after you sign in successfully, so you are not asked for your password on every click. It is stored as a browser cookie and represents... - [Supply Chain Attack](https://cybersecuritycanada.ca/glossary/supply-chain-attack/): An attack where criminals compromise a trusted vendor, software provider, or service to reach their actual targets downstream. Instead of attacking your business directly, attacker... - [Threat Intelligence](https://cybersecuritycanada.ca/glossary/threat-intelligence/): Information about current and emerging cyber threats — who is attacking, how they operate, what tools they use, and what vulnerabilities they target. The Canadian Centre for Cyber... - [3-2-1 Backup Rule](https://cybersecuritycanada.ca/glossary/3-2-1-backup-rule/): A widely recommended backup strategy: maintain 3 copies of your data, on 2 different types of storage, with 1 copy stored offline or offsite — disconnected from your network. This... - [Two-Factor Authentication (2FA)](https://cybersecuritycanada.ca/glossary/two-factor-authentication/): A specific type of multi-factor authentication that uses exactly two verification steps. In practice, 2FA and MFA are often used interchangeably, though MFA can include three or mo... - [Unauthorized Software](https://cybersecuritycanada.ca/glossary/unauthorized-software/): Any software installed on business systems without organizational approval — including browser extensions, free utilities, cracked applications, and personal tools. Unauthorized so... - [VPN (Virtual Private Network)](https://cybersecuritycanada.ca/glossary/vpn/): A technology that creates an encrypted connection between an employee's device and your business network, protecting data in transit — especially important when working from home,... - [Vishing (Voice Phishing)](https://cybersecuritycanada.ca/glossary/vishing/): A social engineering attack conducted over the phone, where the caller impersonates a trusted entity — such as a bank, government agency, tech support, or a senior executive — to e... - [Vulnerability](https://cybersecuritycanada.ca/glossary/vulnerability/): A weakness in software, hardware, or a process that an attacker can exploit to gain unauthorized access or cause harm. Vulnerabilities are assigned CVE numbers (Common Vulnerabilit... - [Whaling](https://cybersecuritycanada.ca/glossary/whaling/): A highly targeted phishing attack aimed at senior executives, board members, or other high-value individuals within an organization. Whaling emails are carefully crafted to imperso... - [Wi-Fi Security](https://cybersecuritycanada.ca/glossary/wi-fi-security/): The practices and protocols that protect wireless networks from unauthorized access and eavesdropping. Business Wi-Fi should use WPA3 (or at minimum WPA2) encryption, strong passwo... - [XDR (Extended Detection and Response)](https://cybersecuritycanada.ca/glossary/xdr/): A security platform that unifies threat detection and response across multiple layers — endpoints, email, cloud, and network — into a single system. Where EDR monitors individual d... - [Zero Trust](https://cybersecuritycanada.ca/glossary/zero-trust/): A security model built on the principle "never trust, always verify." Instead of assuming that everything inside your network is safe, Zero Trust requires strict verification for e... - [Zero-Day Vulnerability](https://cybersecuritycanada.ca/glossary/zero-day/): A software vulnerability that is unknown to the vendor and has no available patch at the time it is exploited. "Zero-day" refers to the fact that the vendor has had zero days to fi... ## Articles - [Token Theft and AiTM Phishing: Why First-Generation MFA Is Failing Canadian Businesses](https://cybersecuritycanada.ca/news/posts/token-theft-and-aitm-phishing-why-first-generation-mfa-is-failing-canadian-businesses/): Threats, published August 6, 2026. Attackers no longer break multi-factor authentication — they wait for you to complete it and steal the session token instead. In April 2026 Microsoft documented a threat actor targeting Canadian employees specifically, redirecting salary deposits through hijacked Microsoft 365 sessions. - [Frontier AI and Cyber Security: What Canada's Cyber Centre Wants Businesses to Do Now](https://cybersecuritycanada.ca/news/posts/frontier-ai-cyber-security-cyber-centre-statement/): Insights, published June 25, 2026. On June 24, 2026, the Canadian Centre for Cyber Security warned that frontier AI is shrinking the time defenders have to respond — from days or weeks to hours. Here's what the statement means for Canadian businesses. - [Amazon Prime Day Scams: How Canadians Can Shop Safely During the June 23–26 Sale](https://cybersecuritycanada.ca/news/posts/amazon-prime-day-scams-how-canadians-can-shop-safely/): Best Practices, published June 20, 2026. Amazon Prime Day runs June 23–26, 2026, and fraudsters are already registering thousands of fake Amazon sites. Here's how Canadians and their employees can spot Prime Day scams before they hand over a password or a card number. - [Anthropic's Call for a Global AI Pause: What It Means for Canadian Businesses](https://cybersecuritycanada.ca/news/posts/anthropic-global-ai-pause-what-it-means-for-canadian-businesses/): Insights, published June 6, 2026. On June 4, 2026, Anthropic — valued near $1 trillion — urged a coordinated global pause on frontier AI development, warning models may soon improve themselves without humans. Here's what it means for Canadian businesses. - [The Cybersecurity Canada Report 2026: Seven Findings Canadian SMBs Should Know](https://cybersecuritycanada.ca/news/posts/cybersecurity-canada-report-2026-key-findings/): Insights, published May 24, 2026. Canadians lost a record CA$704M to fraud in 2025. Microsoft documented a threat actor specifically targeting Canadians. Mandiant says attackers now hand off compromised access in 22 seconds. Seven findings from the inaugural Cybersecurity Canada Report. - [Claude Mythos and Project Glasswing: What 10,000 AI-Discovered Zero-Days Mean for Canadian Businesses](https://cybersecuritycanada.ca/news/posts/claude-mythos-and-project-glasswing-what-canadian-businesses-need-to-know/): Insights, published May 23, 2026. Anthropic's Claude Mythos Preview model has autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities under Project Glasswing. Here is what Canadian businesses should do while the patches catch up. - [CRA, Interac, and Canada Post: The Canadian Brand Phishing Playbook for SMBs](https://cybersecuritycanada.ca/news/posts/cra-interac-canada-post-canadian-brand-phishing-playbook-for-smbs/): Best Practices, published May 14, 2026. Canadian SMB employees see CRA refund texts, fake Interac e-Transfer notifications, and Canada Post 'missed delivery' SMS every week. Here's how to train your team to spot the Canadian brand phishing patterns generic training misses. - [Canvas Data Breach 2026: What the Instructure Hack Means for Canadian Universities and Businesses](https://cybersecuritycanada.ca/news/posts/canvas-data-breach-what-canadian-universities-and-businesses-need-to-know/): Threats, published May 8, 2026. The Canvas data breach has hit UBC, SFU, the University of Toronto, OCAD, Western's Ivey, Mohawk College and Ontario Tech, with ShinyHunters claiming 275 million records across 9,000 schools. Here's what happened and what to do. - [Agentic AI Security for Canadian Businesses: What the New Cyber Centre Guidance Means](https://cybersecuritycanada.ca/news/posts/agentic-ai-security-for-canadian-businesses-cyber-centre-guidance/): Insights, published May 3, 2026. Canada's Cyber Centre and four allied agencies published Careful Adoption of Agentic AI Services on May 1, 2026. Here's what the new agentic AI security guidance means for Canadian businesses considering AI agents. - [Canada Life Data Breach: What Canadians and Canadian Businesses Need to Know](https://cybersecuritycanada.ca/news/posts/canada-life-data-breach-what-canadians-need-to-know/): Threats, published April 26, 2026. The Canada Life data breach exposed personal information for up to 70,000 people after attackers used one employee's account to reach a Salesforce environment. Here's what happened and what to do. - [Cybersecurity Laws in Canada: The 2026 Guide for Businesses](https://cybersecuritycanada.ca/news/posts/cybersecurity-laws-in-canada-2026-guide-for-businesses/): Compliance, published April 19, 2026. A plain-language overview of every cybersecurity and privacy law that applies to Canadian businesses in 2026 — federal, provincial, and sector-specific — and how they connect to the Baseline Controls. - [Cybersecurity Certifications in Canada: CyberSecure Canada and the Professional Credentials That Matter](https://cybersecuritycanada.ca/news/posts/cybersecurity-certifications-in-canada-cybersecure-canada-and-professional-credentials/): Guide, published April 11, 2026. An overview of the cybersecurity certifications that matter in Canada in 2026 — the CyberSecure Canada program for organizations, and the professional credentials (CISSP, CISM, CISA, GIAC, CompTIA) businesses should look for when hiring or vetting providers. - [A Brief History of Cybersecurity in Canada: From Cold War Signals Intelligence to the Canadian Centre for Cyber Security](https://cybersecuritycanada.ca/news/posts/history-of-cybersecurity-in-canada/): Insights, published April 4, 2026. Canada's cybersecurity institutions have a long, specific history — from the Second World War signals intelligence agency that became CSE, through PIPEDA and the Heartbleed era, to the Canadian Centre for Cyber Security and Bill C-26. A timeline for businesses and citizens. - [Understanding CVSS Scores: What the Numbers Behind Software Vulnerabilities Actually Mean](https://cybersecuritycanada.ca/news/posts/understanding-cvss-scores-what-the-numbers-behind-software-vulnerabilities-mean/): Insights, published March 30, 2026. When a vulnerability is rated 8.8 or 10.0, what does that actually mean for your business? Here's a plain-language guide to CVSS scores and why they matter. - [How to Choose a Cybersecurity Provider for Your Canadian Small Business](https://cybersecuritycanada.ca/news/posts/how-to-choose-a-cybersecurity-provider-for-your-canadian-small-business/): Guide, published March 24, 2026. Managed service providers, MSSPs, consultants, and vCISOs — the options for outsourced cybersecurity are growing. Here's how Canadian small businesses can evaluate providers, ask the right questions, and avoid common mistakes. - [Why Our Free Cybersecurity Assessment Doesn't Collect Your Data](https://cybersecuritycanada.ca/news/posts/why-our-free-cybersecurity-assessment-doesnt-collect-your-data/): Insights, published March 22, 2026. Most online assessment tools require your email before showing results. Ours doesn't collect anything — not your name, not your email, not your answers. Here's exactly how it works and why we built it this way. - [What Canadian Businesses Need to Know About Bill C-26](https://cybersecuritycanada.ca/news/posts/what-canadian-businesses-need-to-know-about-bill-c-26/): Compliance, published March 20, 2026. Bill C-26's cybersecurity provisions — now reintroduced as Bill C-8 — would impose mandatory obligations on critical infrastructure operators in Canada. Here's what the legislation covers, who it affects, and why all Canadian businesses should be paying attention. - [New PIPEDA Enforcement Actions: What Changed and What Canadian SMBs Must Do Now](https://cybersecuritycanada.ca/news/posts/new-pipeda-enforcement-what-changed-and-what-smbs-must-do/): Compliance, published March 14, 2026. The Office of the Privacy Commissioner of Canada is enforcing PIPEDA more aggressively than ever. Here's what recent enforcement actions mean for small and medium businesses — and the practical steps to reduce your risk. - [AI-Powered Phishing: What's Changed for Canadian Businesses in 2026](https://cybersecuritycanada.ca/news/posts/ai-powered-phishing-whats-changed-for-canadian-businesses/): Threats, published March 8, 2026. AI tools have made phishing emails faster to create, harder to detect, and more convincing than ever. Here's what Canadian small businesses need to know — and what actually helps. - [Building an Incident Response Plan for Your Canadian Business](https://cybersecuritycanada.ca/news/posts/building-an-incident-response-plan-for-your-canadian-business/): Best Practices, published March 7, 2026. The Canadian Centre for Cyber Security designates incident response planning as the first of its 13 Baseline Controls. Here is what the guidance says, what a plan includes, and what Canadian SMBs face without one. - [What to Do in the First 24 Hours After a Cyber Attack](https://cybersecuritycanada.ca/news/posts/what-to-do-in-the-first-24-hours-after-a-cyber-attack/): Guide, published February 28, 2026. When a cyber attack hits, the decisions you make in the first hours determine how much damage your business sustains. This step-by-step guide walks Canadian small business owners through the critical first 24 hours. - [Cyber Insurance: What Canadian SMBs Need to Understand](https://cybersecuritycanada.ca/news/posts/cyber-insurance-what-canadian-smbs-need-to-understand/): Insights, published February 22, 2026. Cyber insurance adoption among Canadian businesses remains low, and denied claims are making headlines. Here is what the market looks like, what insurers are requiring, and what happens when those requirements are not met. - [Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack](https://cybersecuritycanada.ca/news/posts/ransomware-what-canadian-businesses-need-to-know-before-during-and-after-an-attack/): Threats, published February 21, 2026. Ransomware remains the top cybercrime threat facing Canadian organizations. Here is what Canadian SMBs should do before an attack happens, what to do if one is underway, and how to recover. - [USB Drives and Portable Media: The Security Risk Sitting in Your Desk Drawer](https://cybersecuritycanada.ca/news/posts/usb-drives-and-portable-media-the-security-risk-in-your-desk-drawer/): Best Practices, published February 20, 2026. USB drives remain one of the easiest ways for data to leave your business and one of the quietest ways for threats to get in. Here's what Canadian SMBs need to know. - [Vendor and Third-Party Risk: How Your Suppliers Can Become Your Weakest Link](https://cybersecuritycanada.ca/news/posts/vendor-and-third-party-risk-how-your-suppliers-can-become-your-weakest-link/): Best Practices, published February 14, 2026. Your cybersecurity is only as strong as the least secure vendor with access to your systems or data. Here's how Canadian small businesses can assess and manage third-party risk without a dedicated security team. - [Windows Notepad Vulnerability: What Canadian Businesses Should Know](https://cybersecuritycanada.ca/news/posts/windows-notepad-vulnerability-what-canadian-businesses-should-know/): Threats, published February 11, 2026. A critical flaw in Windows Notepad could let attackers take control of your PC through a simple file. Here's what Canadian business owners need to know and do. - [Notepad++ Supply Chain Attack: What Canadian Businesses Should Know](https://cybersecuritycanada.ca/news/posts/notepad-plus-plus-supply-chain-attack-what-canadian-businesses-should-know/): Threats, published February 10, 2026. A Chinese state-sponsored group hijacked Notepad++ updates for months, delivering targeted malware through a trusted update channel. Here's what happened and what to do. - [The Hidden Cost of Assuming Your Business Is Too Small to Attack](https://cybersecuritycanada.ca/news/posts/the-hidden-cost-of-assuming-your-business-is-too-small-to-attack/): Insights, published February 10, 2026. The belief that your business is too small to be targeted isn't just wrong — it's the most expensive cybersecurity assumption a Canadian SMB can make. Here's what it actually costs. - [How to Use Your Cybersecurity Assessment Results](https://cybersecuritycanada.ca/news/posts/how-to-use-your-assessment-results/): Guide, published February 7, 2026. Completed the assessment? Here's how to interpret your score, prioritize improvements, and build a practical security roadmap for your organization. - [Why Canadian SMBs Can No Longer Ignore Cybersecurity](https://cybersecuritycanada.ca/news/posts/why-canadian-smbs-need-cybersecurity/): Insights, published February 1, 2026. Canadian small businesses face growing cyber threats. Learn why cybersecurity has become a business necessity, not just an IT concern. - [When Cyber Attacks Become Physical Threats](https://cybersecuritycanada.ca/news/posts/when-cyber-attacks-become-physical-threats/): Threats, published January 28, 2026. Cyber attacks don't always stay digital. Criminals are using email compromises, system hacks, and signal jamming as stepping stones to physical crimes like burglary and fraud. - [Backup and Recovery: 5 Assumptions That Fail When It Matters](https://cybersecuritycanada.ca/news/posts/backup-and-recovery-assumptions-that-fail/): Best Practices, published January 25, 2026. Most businesses think their backups are fine — until they try to restore from them. Here are five common backup assumptions that fail during a real incident. - [Why Your Canadian Business Needs an AI Usage Policy](https://cybersecuritycanada.ca/news/posts/why-your-business-needs-an-ai-usage-policy/): Best Practices, published January 20, 2026. Your employees are already using AI tools — with or without your knowledge. Here's why a clear AI usage policy protects your business and what it should cover. - [Understanding Canada's Baseline Cyber Security Controls for SMBs](https://cybersecuritycanada.ca/news/posts/understanding-canadas-baseline-cyber-security-controls/): Standards, published January 15, 2026. The Canadian Centre for Cyber Security has published baseline controls specifically designed for small and medium organizations. Here's what you need to know. - [The Real Cost of Cyber Downtime for Canadian SMBs](https://cybersecuritycanada.ca/news/posts/the-real-cost-of-cyber-downtime-for-canadian-smbs/): Insights, published January 5, 2026. When systems go offline due to a cyber incident, the costs go far beyond the ransom demand. Here's what Canadian small businesses actually face. - [Business Email Compromise (BEC): Canada's Most Costly Cyber Threat](https://cybersecuritycanada.ca/news/posts/business-email-compromise-canadas-most-costly-cyber-threat/): Threats, published December 30, 2025. Business email compromise doesn't use malware or exploit software vulnerabilities. It exploits trust — and it's responsible for more financial losses than any other form of cybercrime. Here's what Canadian businesses need to know. - [Remote Work Security for Canadian Businesses](https://cybersecuritycanada.ca/news/posts/remote-work-security-for-canadian-businesses/): Best Practices, published December 18, 2025. Remote and hybrid work is here to stay. Here's how Canadian SMBs can keep their data secure when employees work outside the office. - [Cloud Security Basics for Canadian Small Businesses](https://cybersecuritycanada.ca/news/posts/cloud-security-basics-for-canadian-small-businesses/): Best Practices, published December 12, 2025. Moving to the cloud doesn't mean your data is automatically secure. Microsoft 365, Google Workspace, and other cloud platforms require configuration — and the default settings often leave gaps. Here's what Canadian SMBs need to get right. - [How to Recognize Phishing Emails: A Guide for Canadian Businesses](https://cybersecuritycanada.ca/news/posts/how-to-recognize-phishing-emails/): Threats, published December 5, 2025. Phishing is the number one cyber threat to Canadian businesses. Learn the warning signs and how to protect your organization. - [Employee Security Awareness Training: What Actually Works](https://cybersecuritycanada.ca/news/posts/employee-security-awareness-training-what-actually-works/): Best Practices, published November 28, 2025. Annual compliance videos don't change behaviour. Here's what the research says about effective security awareness training for Canadian small businesses — and how to build a program that actually reduces risk. - [Password Security: What Canadian Businesses Get Wrong](https://cybersecuritycanada.ca/news/posts/password-security-what-canadian-businesses-get-wrong/): Best Practices, published November 20, 2025. Forced password rotation, short minimums, and no password manager — here are the most common password mistakes Canadian SMBs make and how to fix them. - [Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs](https://cybersecuritycanada.ca/news/posts/multi-factor-authentication-the-single-biggest-security-upgrade-for-canadian-smbs/): Best Practices, published November 10, 2025. MFA blocks over 99% of automated account attacks. It's free to enable on most business platforms, takes minutes to set up, and is increasingly required by cyber insurers. Here's what Canadian businesses need to know. - [Why Cybercriminals Target Small Businesses](https://cybersecuritycanada.ca/news/posts/why-cybercriminals-target-small-businesses/): Threats, published November 1, 2025. Small businesses are not too small to be targeted. Here's why cybercriminals see Canadian SMBs as attractive targets and what you can do about it. - [5 Easy Cybersecurity Wins for Canadian Small Businesses](https://cybersecuritycanada.ca/news/posts/5-easy-cybersecurity-wins-for-canadian-small-businesses/): Guide, published October 28, 2025. You don't need a massive budget or a dedicated IT team to meaningfully improve your cybersecurity. These five actions can be implemented quickly and address the most common ways Canadian small businesses get breached. - [Canada's Privacy Landscape: What Small Businesses Need to Know](https://cybersecuritycanada.ca/news/posts/canadas-privacy-landscape-what-small-businesses-need-to-know/): Compliance, published October 15, 2025. PIPEDA, provincial laws, and breach reporting — a plain-language overview of the privacy obligations that apply to Canadian small businesses. ## About - [About Cybersecurity Canada](https://cybersecuritycanada.ca/about/): Who publishes this site, editorial approach, and independence statement. - [Privacy Policy](https://cybersecuritycanada.ca/privacy/) - [Terms of Use](https://cybersecuritycanada.ca/terms/) ## Citation Cite pages using the suggested citation printed on each page, or in this form: Cybersecurity Canada (2026). *Page title*. Retrieved from https://cybersecuritycanada.ca/path/