Baseline Controls News Resources Glossary About

Cybersecurity News

Stay informed about cybersecurity threats, best practices, and Government of Canada guidance for businesses.

Government of Canada standards
News & Insights Key Topics
Threats
Insights
Best Practices
Guide
Standards
Compliance
Agentic AI Security for Canadian Businesses: What the New Cyber Centre Guidance Means
May 3, 2026 Insights

Agentic AI Security for Canadian Businesses: What the New Cyber Centre Guidance Means

Canada's Cyber Centre and four allied agencies published Careful Adoption of Agentic AI Services on May 1, 2026. Here's what the new agentic AI securi...

Read more
Canada Life Data Breach: What Canadians and Canadian Businesses Need to Know
April 26, 2026 Threats

Canada Life Data Breach: What Canadians and Canadian Businesses Need to Know

The Canada Life data breach exposed personal information for up to 70,000 people after attackers used one employee's account to reach a Salesforce env...

Read more
Cybersecurity Laws in Canada: The 2026 Guide for Businesses
April 19, 2026 Compliance

Cybersecurity Laws in Canada: The 2026 Guide for Businesses

A plain-language overview of every cybersecurity and privacy law that applies to Canadian businesses in 2026 — federal, provincial, and sector-specifi...

Read more
Cybersecurity Certifications in Canada: CyberSecure Canada and the Professional Credentials That Matter
April 11, 2026 Guide

Cybersecurity Certifications in Canada: CyberSecure Canada and the Professional Credentials That Matter

An overview of the cybersecurity certifications that matter in Canada in 2026 — the CyberSecure Canada program for organizations, and the professional...

Read more
A Brief History of Cybersecurity in Canada: From Cold War Signals Intelligence to the Canadian Centre for Cyber Security
April 4, 2026 Insights

A Brief History of Cybersecurity in Canada: From Cold War Signals Intelligence to the Canadian Centre for Cyber Security

Canada's cybersecurity institutions have a long, specific history — from the Second World War signals intelligence agency that became CSE, through PIP...

Read more
Understanding CVSS Scores: What the Numbers Behind Software Vulnerabilities Actually Mean
March 30, 2026 Insights

Understanding CVSS Scores: What the Numbers Behind Software Vulnerabilities Actually Mean

When a vulnerability is rated 8.8 or 10.0, what does that actually mean for your business? Here's a plain-language guide to CVSS scores and why they m...

Read more
How to Choose a Cybersecurity Provider for Your Canadian Small Business
March 24, 2026 Guide

How to Choose a Cybersecurity Provider for Your Canadian Small Business

Managed service providers, MSSPs, consultants, and vCISOs — the options for outsourced cybersecurity are growing. Here's how Canadian small businesses...

Read more
Why Our Free Cybersecurity Assessment Doesn't Collect Your Data
March 22, 2026 Insights

Why Our Free Cybersecurity Assessment Doesn't Collect Your Data

Most online assessment tools require your email before showing results. Ours doesn't collect anything — not your name, not your email, not your answer...

Read more
What Canadian Businesses Need to Know About Bill C-26
March 20, 2026 Compliance

What Canadian Businesses Need to Know About Bill C-26

Bill C-26's cybersecurity provisions — now reintroduced as Bill C-8 — would impose mandatory obligations on critical infrastructure operators in Canad...

Read more
New PIPEDA Enforcement Actions: What Changed and What Canadian SMBs Must Do Now
March 14, 2026 Compliance

New PIPEDA Enforcement Actions: What Changed and What Canadian SMBs Must Do Now

The Office of the Privacy Commissioner of Canada is enforcing PIPEDA more aggressively than ever. Here's what recent enforcement actions mean for smal...

Read more
AI-Powered Phishing: What's Changed for Canadian Businesses in 2026
March 8, 2026 Threats

AI-Powered Phishing: What's Changed for Canadian Businesses in 2026

AI tools have made phishing emails faster to create, harder to detect, and more convincing than ever. Here's what Canadian small businesses need to kn...

Read more
Building an Incident Response Plan for Your Canadian Business
March 7, 2026 Best Practices

Building an Incident Response Plan for Your Canadian Business

The Canadian Centre for Cyber Security designates incident response planning as the first of its 13 Baseline Controls. Here is what the guidance says,...

Read more
What to Do in the First 24 Hours After a Cyber Attack
February 28, 2026 Guide

What to Do in the First 24 Hours After a Cyber Attack

When a cyber attack hits, the decisions you make in the first hours determine how much damage your business sustains. This step-by-step guide walks Ca...

Read more
Cyber Insurance: What Canadian SMBs Need to Understand
February 22, 2026 Insights

Cyber Insurance: What Canadian SMBs Need to Understand

Cyber insurance adoption among Canadian businesses remains low, and denied claims are making headlines. Here is what the market looks like, what insur...

Read more
Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack
February 21, 2026 Threats

Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack

Ransomware remains the top cybercrime threat facing Canadian organizations. Here is what Canadian SMBs should do before an attack happens, what to do...

Read more
USB Drives and Portable Media: The Security Risk Sitting in Your Desk Drawer
February 20, 2026 Best Practices

USB Drives and Portable Media: The Security Risk Sitting in Your Desk Drawer

USB drives remain one of the easiest ways for data to leave your business and one of the quietest ways for threats to get in. Here's what Canadian SMB...

Read more
Vendor and Third-Party Risk: How Your Suppliers Can Become Your Weakest Link
February 14, 2026 Best Practices

Vendor and Third-Party Risk: How Your Suppliers Can Become Your Weakest Link

Your cybersecurity is only as strong as the least secure vendor with access to your systems or data. Here's how Canadian small businesses can assess a...

Read more
Windows Notepad Vulnerability: What Canadian Businesses Should Know
February 11, 2026 Threats

Windows Notepad Vulnerability: What Canadian Businesses Should Know

A critical flaw in Windows Notepad could let attackers take control of your PC through a simple file. Here's what Canadian business owners need to kno...

Read more
Notepad++ Supply Chain Attack: What Canadian Businesses Should Know
February 10, 2026 Threats

Notepad++ Supply Chain Attack: What Canadian Businesses Should Know

A Chinese state-sponsored group hijacked Notepad++ updates for months, delivering targeted malware through a trusted update channel. Here's what happe...

Read more
The Hidden Cost of Assuming Your Business Is Too Small to Attack
February 10, 2026 Insights

The Hidden Cost of Assuming Your Business Is Too Small to Attack

The belief that your business is too small to be targeted isn't just wrong — it's the most expensive cybersecurity assumption a Canadian SMB can make....

Read more
How to Use Your Cybersecurity Assessment Results
February 7, 2026 Guide

How to Use Your Cybersecurity Assessment Results

Completed the assessment? Here's how to interpret your score, prioritize improvements, and build a practical security roadmap for your organization.

Read more
Why Canadian SMBs Can No Longer Ignore Cybersecurity
February 1, 2026 Insights

Why Canadian SMBs Can No Longer Ignore Cybersecurity

Canadian small businesses face growing cyber threats. Learn why cybersecurity has become a business necessity, not just an IT concern.

Read more
When Cyber Attacks Become Physical Threats
January 28, 2026 Threats

When Cyber Attacks Become Physical Threats

Cyber attacks don't always stay digital. Criminals are using email compromises, system hacks, and signal jamming as stepping stones to physical crimes...

Read more
Backup and Recovery: 5 Assumptions That Fail When It Matters
January 25, 2026 Best Practices

Backup and Recovery: 5 Assumptions That Fail When It Matters

Most businesses think their backups are fine — until they try to restore from them. Here are five common backup assumptions that fail during a real in...

Read more
Why Your Canadian Business Needs an AI Usage Policy
January 20, 2026 Best Practices

Why Your Canadian Business Needs an AI Usage Policy

Your employees are already using AI tools — with or without your knowledge. Here's why a clear AI usage policy protects your business and what it shou...

Read more
Understanding Canada's Baseline Cyber Security Controls for SMBs
January 15, 2026 Standards

Understanding Canada's Baseline Cyber Security Controls for SMBs

The Canadian Centre for Cyber Security has published baseline controls specifically designed for small and medium organizations. Here's what you need...

Read more
The Real Cost of Cyber Downtime for Canadian SMBs
January 5, 2026 Insights

The Real Cost of Cyber Downtime for Canadian SMBs

When systems go offline due to a cyber incident, the costs go far beyond the ransom demand. Here's what Canadian small businesses actually face.

Read more
Business Email Compromise (BEC): Canada's Most Costly Cyber Threat
December 30, 2025 Threats

Business Email Compromise (BEC): Canada's Most Costly Cyber Threat

Business email compromise doesn't use malware or exploit software vulnerabilities. It exploits trust — and it's responsible for more financial losses...

Read more
Remote Work Security for Canadian Businesses
December 18, 2025 Best Practices

Remote Work Security for Canadian Businesses

Remote and hybrid work is here to stay. Here's how Canadian SMBs can keep their data secure when employees work outside the office.

Read more
Cloud Security Basics for Canadian Small Businesses
December 12, 2025 Best Practices

Cloud Security Basics for Canadian Small Businesses

Moving to the cloud doesn't mean your data is automatically secure. Microsoft 365, Google Workspace, and other cloud platforms require configuration —...

Read more
How to Recognize Phishing Emails: A Guide for Canadian Businesses
December 5, 2025 Threats

How to Recognize Phishing Emails: A Guide for Canadian Businesses

Phishing is the number one cyber threat to Canadian businesses. Learn the warning signs and how to protect your organization.

Read more
Employee Security Awareness Training: What Actually Works
November 28, 2025 Best Practices

Employee Security Awareness Training: What Actually Works

Annual compliance videos don't change behaviour. Here's what the research says about effective security awareness training for Canadian small business...

Read more
Password Security: What Canadian Businesses Get Wrong
November 20, 2025 Best Practices

Password Security: What Canadian Businesses Get Wrong

Forced password rotation, short minimums, and no password manager — here are the most common password mistakes Canadian SMBs make and how to fix them.

Read more
Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs
November 10, 2025 Best Practices

Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs

MFA blocks over 99% of automated account attacks. It's free to enable on most business platforms, takes minutes to set up, and is increasingly require...

Read more
Why Cybercriminals Target Small Businesses
November 1, 2025 Threats

Why Cybercriminals Target Small Businesses

Small businesses are not too small to be targeted. Here's why cybercriminals see Canadian SMBs as attractive targets and what you can do about it.

Read more
5 Easy Cybersecurity Wins for Canadian Small Businesses
October 28, 2025 Guide

5 Easy Cybersecurity Wins for Canadian Small Businesses

You don't need a massive budget or a dedicated IT team to meaningfully improve your cybersecurity. These five actions can be implemented quickly and a...

Read more
Canada's Privacy Landscape: What Small Businesses Need to Know
October 15, 2025 Compliance

Canada's Privacy Landscape: What Small Businesses Need to Know

PIPEDA, provincial laws, and breach reporting — a plain-language overview of the privacy obligations that apply to Canadian small businesses.

Read more