Baseline Controls News Resources Glossary About

CIRA 2026 Survey: Canadian Cybersecurity Budgets Up, Confidence Down

CIRA 2026 Survey: Canadian Cybersecurity Budgets Up, Confidence Down

Canadian organizations are spending more on cybersecurity than ever, but their confidence in those investments is falling. That is the core finding of the 2026 CIRA Cybersecurity Survey, published October 6, 2026, by the Canadian Internet Registration Authority (CIRA). The survey of more than 500 cybersecurity decision-makers across private sector, public sector, and MUSH organizations (municipalities, universities, schools, and hospitals) reveals a widening gap between investment and perceived readiness.

For Canadian small businesses, the survey highlights three priorities that should shape decisions: building in-house capabilities, rethinking vendor selection, and preparing for AI-powered threats.

Why Are Canadian Organizations Losing Confidence in Their Cybersecurity Budgets?

76% of surveyed organizations increased their cybersecurity budgets over the past year, according to the CIRA survey. Yet only 67% of decision-makers believe that spending is sufficient to keep pace with threats. That confidence level is down from 74% in 2025.

Several factors explain the shift. The share of organizations with total IT budgets below $50,000 more than doubled, rising from 11% to 23% year over year. At the same time, the threat landscape grew more complex: AI-enabled attacks, ransomware, and supply chain incidents all increased pressure on security teams.

The CIRA survey notes that organizations "appear to want more control, but control comes with responsibility. Internal teams still need enough funding, skilled people and specialized support to keep up with evolving cyber threats." For small businesses especially, this means that simply increasing a budget line is not enough. The budget must translate into controls that actually reduce risk.

How Many Canadian Organizations Are Managing Cybersecurity In-House?

67% of surveyed organizations now manage cybersecurity internally or on-site, up from 61% in 2025, according to CIRA. Among organizations using SIEM, XDR, or SOAR solutions, 63% built those capabilities in-house, compared with 40% the previous year.

This shift toward internal ownership aligns with broader sovereignty concerns (discussed below), but it also carries risk. In-house teams need adequate staffing, training, and tooling to keep pace. The CIRA survey found that 98% of organizations provide cybersecurity awareness training, which is encouraging. However, training alone does not substitute for technical controls like multi-factor authentication or tested backup and recovery procedures.

One question for your IT lead: "If we manage security in-house, do we have a documented incident response plan, and when did we last test it?" The CIRA survey found 87% of organizations have an incident response plan, but six in 10 of those with a plan used it during the past year.

Why Does Canadian Data Residency Matter More Now?

91% of respondents told CIRA it is important that their cybersecurity records are stored and processed in Canada. 89% said it matters that a cybersecurity vendor is Canadian-owned, headquartered in Canada, or primarily operating here. Nearly seven in 10 organizations prioritize data sovereignty over price when selecting a cybersecurity vendor.

These preferences are now affecting procurement decisions. According to the survey, four in 10 organizations have reviewed, reduced, or replaced a cybersecurity vendor based in the U.S. or another foreign country because of trade, political, or sovereignty concerns. Canadian Underwriter reported that "Canadian ownership and data residency have shifted from a preference to a requirement for many respondents."

For Canadian SMBs, this trend creates both opportunity and obligation. If your vendors store threat intelligence, logs, or incident response records in the United States, your customers and partners may start asking questions. Conversely, demonstrating Canadian data residency can become a competitive advantage.

How Concerned Are Canadian Organizations About AI-Enabled Cyber Threats?

More than eight in 10 cybersecurity decision-makers are concerned about threats from AI tools or AI-enabled attacks, according to CIRA. The share ranking AI-enabled attacks among the threats with the greatest potential impact rose from 21% in 2023 to 37% in 2026. Concerns center on data gathered by AI tools, AI-generated phishing, and deepfake content.

At the same time, AI adoption within organizations continues to grow. Two-thirds of Canadian organizations have integrated AI tools into their workflows, unchanged from 2025 but up from 44% in 2023. Half of organizations now have an AI policy, and another 36% are developing one.

The practical implication: organizations are adopting AI while simultaneously worrying about how attackers use the same technology. Our AI usage policy guide explains what Canadian businesses should include in their policies. Attackers are already using AI to craft more convincing phishing emails, so training programs need to address these newer tactics.

What Does the Survey Show About Ransomware in Canada?

39% of organizations experienced an attempted or successful cyberattack in the past 12 months, down from 43% in 2025. About two in 10 respondents said their organization was a victim of a successful ransomware attack, down from 24% the previous year. The share reporting a customer or employee data breach fell from 43% to 28%.

However, the consequences for victims remain severe. Among organizations that experienced a successful ransomware attack, 76% reported data was taken from their network or cloud service, and 75% paid the ransom. Separately, 74% of all respondents support legislation prohibiting Canadian organizations from making ransom payments.

Recovery times are improving. Half of affected organizations restored their IT systems in less than a week, up from 42% in 2025. But recovery is rarely a solo effort: 62% of organizations sought outside help, and 92% said a checklist for choosing a qualified incident response provider would be valuable. Our incident response pillar page covers what the CCCS recommends, and our guide on what to do in the first 24 hours after an attack provides a practical starting point.

How Does the CIRA Survey Compare to Other Canadian Cybersecurity Data?

The CIRA 2026 findings align with other recent Canadian reports. The Cybersecurity Canada Report 2026, published earlier this year, documented CA$704 million in reported fraud losses to the Canadian Anti-Fraud Centre in 2025 and noted that 67% of investigated incidents in Sophos research stemmed from identity attacks.

What the CIRA survey uniquely captures is the Canadian buyer sentiment shift: 91% now say Canadian data residency matters, and four in 10 organizations have already reviewed, reduced, or replaced a foreign cybersecurity vendor.

What Should Canadian Businesses Do With This Data?

The CIRA survey suggests three immediate actions for Canadian SMBs:

  1. Audit your budget-to-control translation. Spending more does not automatically mean being more secure. Map your cybersecurity spending to the 13 Baseline Cyber Security Controls and identify which controls are underfunded or untested.

  2. Verify where your data lives. If you use a managed security provider, ask where your threat intelligence, logs, and incident records are stored. If the answer is outside Canada, decide whether that aligns with your customer expectations and your own risk tolerance.

  3. Update your incident response plan for AI-era threats. If your last plan revision predates 2024, it likely does not address AI-generated phishing, deepfakes, or the speed of modern attacks. The CIRA survey found six in 10 organizations with a plan used it in the past year; if yours has not been exercised, schedule a tabletop exercise.

One question to ask your IT provider this month: "Based on the CIRA survey findings, which of the 13 Baseline Controls would you say we are weakest on, and what would it cost to close that gap?"

If you do not have a clear answer, start with our free cybersecurity assessment. It evaluates your organization against all 13 CCCS controls, runs entirely in your browser with no data collection, and produces a prioritized action list. Understanding your current state is the first step toward closing the gap between spending and actual security.

Free Assessment

How prepared is your business?

Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.

Check Your Score

Frequently Asked Questions

What did the CIRA 2026 Cybersecurity Survey find about Canadian organizations?

The survey of more than 500 Canadian cybersecurity decision-makers found that 76% increased their budgets over the past year, but only 67% believe their investment is sufficient to keep pace with threats. That confidence figure is down from 74% in 2025. Meanwhile, 91% say it matters that their cybersecurity data is stored and processed in Canada.

How many Canadian organizations experienced a cyberattack in 2026?

According to the CIRA 2026 survey, 39% of organizations experienced an attempted or successful cyberattack or incident in the past 12 months. That figure is down from 43% in 2025. Among ransomware victims, 75% paid the ransom and 76% reported data was taken from their network or cloud service.

Are Canadian organizations concerned about AI-enabled cyber threats?

Yes. The CIRA 2026 survey found more than eight in 10 cybersecurity decision-makers are concerned about threats from AI tools or AI-enabled attacks. The share ranking AI-enabled attacks among the threats with the greatest potential impact rose from 21% in 2023 to 37% in 2026.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). CIRA 2026 Survey: Canadian Cybersecurity Budgets Up, Confidence Down. Retrieved from https://cybersecuritycanada.ca/news/posts/cira-2026-survey-canadian-cybersecurity-budgets-confidence/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.

Take the Free Assessment