Canadian Small Business Cyber Risk Report 2026: Six Findings by Business Size
We've published the Canadian Small Business Cyber Risk Report 2026, a public data review of cyber risk for Canadian businesses with 10 to 49 employees. The headline: about 1 in 7 Canadian small businesses (14.3%) were impacted by a cyber security incident in 2023, and most had little in writing to manage that risk. Every figure comes from a public source, mainly Statistics Canada's size-by-size tables, with no client or proprietary data.
The report complements our national Cybersecurity Canada Report 2026, which covers fraud losses, breach costs and regulation. This one asks a narrower question: how do the smallest businesses Statistics Canada surveys compare with larger ones?
Small businesses are hit less often, but the gap is closing slowly
In 2023, 14.3% of small businesses were impacted by a cyber security incident, against 29.9% of large businesses, according to Statistics Canada table 22-10-0076-01. The small business rate was 18.8% in 2017. Among small businesses, finance and insurance (21.9%) and professional, scientific and technical services (20.2%) had some of the highest rates.
A lower rate is not the same as a lower stake. Small businesses spent about $300 million recovering from incidents in 2023, according to Statistics Canada. They also spent $2.6 billion on prevention and detection. Spread across the roughly 170,000 small businesses in the survey population, that is about $15,000 per business per year (our calculation, which averages heavy spenders with the many businesses that spent nothing). Nationally, recovery spending doubled between 2021 and 2023 while prevention spending grew about 13% (our calculation).
Most small businesses have nothing in writing
Only 15.4% of small businesses had a written policy to manage internal cyber security risks in 2023, compared with 66.3% of large businesses. Just 10.5% had a written incident reporting policy and 5.7% ran recurring mandatory security training, according to Statistics Canada table 22-10-0130-01. The Cyber Centre makes incident response its first baseline control for a reason: decisions made in advance are the ones that hold up under pressure.
Fewer small businesses have anyone on staff doing security
The share of small businesses with no employees doing cyber security tasks as part of their regular role rose from 34.5% in 2021 to 45.1% in 2023, according to Statistics Canada table 22-10-0129-01. About 37% used a consultant or contractor instead. That can work well, but the Cyber Centre's ITSM.50.030 is clear that the organization "is the data owner and is legally responsible for data security." Our guide to who is responsible for cybersecurity in a small business covers the roles to assign.
Monthly patching fell while attackers shifted to vulnerabilities
Monthly security patching of operating systems dropped from 25.0% to 17.8% of small businesses between 2021 and 2023. Over the same period, attackers moved toward exactly that weakness: Verizon's 2026 Data Breach Investigations Report found vulnerability exploitation is now the most common way into breaches, at 31%, overtaking stolen credentials for the first time in the report's 19 years. For organizations with fewer than 1,000 employees, exploitation of vulnerabilities was also the leading known initial access vector, at 26%, ahead of credential abuse at 13%.
The Cyber Centre's baseline controls recommend that every organization establish a patch management process. For a small business, the practical version is a written patch deadline and a monthly report from whoever does the work.
Ransomware lands mostly on smaller organizations
Of ransomware cases where the victim's size was known, about 96% of victims were small and medium businesses, which Verizon defines as fewer than 1,000 employees, according to the full 2026 DBIR. In Canada, 88% of businesses hit by ransomware in 2023 did not pay.
Few incidents are reported
Only 11.9% of impacted small businesses reported an incident to a police service in 2023, according to Statistics Canada table 22-10-0078-01. The most common reason businesses gave for not reporting was that the incident was resolved internally.
Read the full report
The full report includes a key figures table comparing small, all and large businesses, sections on cost, staffing, patching, ransomware and reporting, a methodology note on definitions and data quality, and a full source list. Statistics Canada collected its next survey cycle, covering 2025, from January to March 2026, and we will update the report when those results are published.
One question to ask your IT lead or provider this week: how many days does it take us to patch a critical vulnerability, and can you show me last month's report? Then see how your business measures up with the free Cybersecurity Canada assessment.
How prepared is your business?
Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.
Check Your ScoreFrequently Asked Questions
What is the Canadian Small Business Cyber Risk Report 2026?
It is a free Cybersecurity Canada report, published October 11, 2026, that compiles public data on cyber risk for Canadian businesses with 10 to 49 employees and compares them with medium and large businesses. Its sources are Statistics Canada, the Canadian Centre for Cyber Security, the Office of the Privacy Commissioner of Canada and Verizon's 2026 Data Breach Investigations Report. It uses no client or proprietary data.
How is the small business report different from the Cybersecurity Canada Report 2026?
The Cybersecurity Canada Report 2026 covers national figures such as fraud losses, breach costs, token theft and regulation. The small business report focuses on how businesses with 10 to 49 employees differ from larger ones on incidents, written policies, staffing, patching, ransomware and reporting, using Statistics Canada's size breakdowns.
What is the biggest gap for Canadian small businesses?
Written policy and routine maintenance. In 2023, 15.4% of Canadian small businesses had a written policy to manage internal cyber security risks and 17.8% patched operating systems monthly or more often, down from 25.0% in 2021, according to Statistics Canada table 22-10-0130-01.
Cite This Page
Suggested citation:
Cybersecurity Canada (2026). Canadian Small Business Cyber Risk Report 2026: Six Findings by Business Size. Retrieved from https://cybersecuritycanada.ca/news/posts/canadian-small-business-cyber-risk-report-2026-key-findings/
Permanent URL: https://cybersecuritycanada.ca/news/posts/canadian-small-business-cyber-risk-report-2026-key-findings/ · Published October 11, 2026
Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.
Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.
How does your organization measure up?
Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.
Take the Free Assessment