Key Figures at a Glance
The short answer: about 1 in 7 Canadian small businesses (14.3%) were impacted by a cyber security incident in 2023, and most had little in writing to manage the risk. Only 15.4% had a written internal cyber security policy and 17.8% patched operating systems monthly, according to Statistics Canada. In this report, a small business has 10 to 49 employees, the definition Statistics Canada uses. Each figure is for 2023, the latest year published.
| Figure (2023) | Small (10 to 49) | All businesses | Large (250+) | Source |
|---|---|---|---|---|
| Impacted by a cyber security incident | 14.3% | 16.1% | 29.9% | Statistics Canada, Table 22-10-0076-01 |
| Written policy to manage internal cyber security risks | 15.4% | 20.3% | 66.3% | Statistics Canada, Table 22-10-0130-01 |
| Written policy to report cyber security incidents | 10.5% | 14.4% | 57.7% | Statistics Canada, Table 22-10-0130-01 |
| Recurring mandatory cyber security training for employees | 5.7% | 9.5% | 52.3% | Statistics Canada, Table 22-10-0130-01 |
| Monthly or more frequent security patching of operating systems | 17.8% (25.0% in 2021) | 22.6% | 72.4% | Statistics Canada, Table 22-10-0130-01 |
| No employees who do cyber security tasks as part of their regular role | 45.1% (34.5% in 2021) | 41.9% | 10.3% | Statistics Canada, Table 22-10-0129-01 |
| Use a consultant or contractor to manage cyber security risks | 37.1% | 38.6% | 48.3% | Statistics Canada, Table 22-10-0130-01 |
| Identity and access management in place | 45.4% | 50.7% | 88.8% | Statistics Canada, Table 22-10-0001-01 |
| Cyber risk insurance | 19.1% (13.7% in 2021) | 22.3% | 58.0% | Statistics Canada, Table 22-10-0130-01 |
| No cyber security risk management arrangements at all | 22.3% | 19.9% | 3.1% | Statistics Canada, Table 22-10-0130-01 |
| Impacted businesses that reported an incident to police | 11.9% | 12.7% | 15.5% | Statistics Canada, Table 22-10-0078-01 |
Executive Summary
This report compiles public data on the cyber risk facing Canadian small businesses, broken out by business size wherever the source allows. It draws on Statistics Canada's Canadian Survey of Cyber Security and Cybercrime (2023 reference year, released October 21, 2024), the Canadian Centre for Cyber Security, the Office of the Privacy Commissioner of Canada and Verizon's 2026 Data Breach Investigations Report. For national figures on fraud losses, breach costs and regulation, see the Cybersecurity Canada Report 2026.
Six findings for Canadian small business owners:
- About 1 in 7 small businesses were hit in 2023, and recovery is getting more expensive. 14.3% of small businesses were impacted by a cyber security incident, down from 18.8% in 2017. Nationally, spending to recover from incidents doubled from about $600 million in 2021 to $1.2 billion in 2023, and small businesses accounted for about $300 million of it.
- Very few small businesses have security in writing. 15.4% had a written policy to manage internal cyber security risks, 10.5% had a written incident reporting policy, 6.3% had a business continuity plan that covers cyber threats and 3.6% had a written policy for supply chain partners.
- The people gap is widening. 45.1% of small businesses had no employees who do cyber security tasks as part of their regular role, up from 34.5% in 2021. 37.1% relied on a consultant or contractor to manage cyber security risks.
- Patching went backwards while attackers moved to vulnerabilities. Monthly security patching of operating systems fell from 25.0% to 17.8% of small businesses between 2021 and 2023. Verizon's 2026 report found exploiting vulnerabilities is now the top way into breaches overall (31%) and at organizations with fewer than 1,000 employees (26%).
- Ransomware is a small business problem. About 96% of ransomware victims with a known size in Verizon's 2026 dataset were small and medium businesses. In Canada, 88% of businesses hit by ransomware in 2023 did not pay.
- Most incidents never reach police. Only 11.9% of impacted small businesses reported an incident to a police service. Separately, the federal privacy commissioner received 696 breach reports from businesses in 2025 to 2026, affecting 20,328,495 Canadian accounts.
How Often Are Canadian Small Businesses Hit by Cyber Attacks?
About 1 in 7. In 2023, 14.3% of Canadian small businesses (10 to 49 employees) were impacted by a cyber security incident, compared with 23.1% of medium businesses and 29.9% of large businesses, according to Statistics Canada table 22-10-0076-01. The small business rate has drifted down from 18.8% in 2017, 18.4% in 2019 and 16.2% in 2021.
Industry matters. Among small businesses, the highest 2023 rates were in finance and insurance (21.9%), information and cultural industries (21.6%) and professional, scientific and technical services (20.2%), the category that includes law, accounting, engineering and consulting firms. The lowest were in arts, entertainment and recreation (8.3%) and construction (9.5%). These rates come from the same Statistics Canada table.
What hit them? Across all impacted businesses, scams and fraud were the most common method (50%), followed by identity theft (31%, up 11 percentage points from 2021) and ransomware (13%), according to The Daily, October 21, 2024. The survey measures incidents that impacted a business, not attempted attacks, so these figures describe incidents with real consequences.
What Do Cyber Incidents Cost Canadian Small Businesses?
Small businesses spent about $300 million recovering from cyber security incidents in 2023 and $2.6 billion preventing and detecting them, according to Statistics Canada. National recovery spending doubled from about $600 million in 2021 to $1.2 billion in 2023, while prevention and detection spending rose from $9.7 billion to $11.0 billion, about 13% (our calculation).
Spread across the roughly 170,000 small businesses in the survey population, $2.6 billion works out to about $15,000 per small business per year (our calculation; it averages businesses that spent heavily with the many that spent nothing). Statistics Canada also reports that the share of all businesses spending anything on prevention or detection fell from 61% in 2021 to 56% in 2023.
The operational impact is broader than the bill. Among impacted small businesses in 2023, 15.1% reported additional repair or recovery costs, 13.5% lost revenue, 13.3% said employees were prevented from doing their day-to-day work and 7.2% were required to notify external parties of a breach, according to Statistics Canada table 22-10-0133-01.
How Many Canadian Small Businesses Have a Written Cybersecurity Policy?
Very few. In 2023, only 15.4% of Canadian small businesses had a written policy to manage internal cyber security risks, compared with 66.3% of large businesses, according to Statistics Canada table 22-10-0130-01. Written incident reporting policies were rarer (10.5%), and only 3.6% had a written policy covering cyber risk from supply chain partners.
The planning and training numbers are similar. 6.3% of small businesses had a business continuity plan with processes to manage cyber security threats, 12.9% had a procedure for notifying employees of incidents or threats, and 5.7% ran recurring mandatory cyber security training. 22.3% had no cyber security risk management arrangements of any kind. Cyber risk insurance is the one area moving up quickly, from 13.7% of small businesses in 2021 to 19.1% in 2023.
The Cyber Centre treats a written plan as foundational: incident response is Baseline Control BC.1, the first of its 13 controls, and its baseline controls recommend security awareness training on a regular, ongoing basis rather than as a one-time event.
Who Handles Cybersecurity in a Canadian Small Business?
Increasingly, no one on staff. In 2023, 45.1% of Canadian small businesses had no employees who complete cyber security tasks as part of their regular responsibilities, up from 34.5% in 2021, according to Statistics Canada table 22-10-0129-01. The share with employees responsible for overseeing cyber security risks fell from 58.7% to 47.6%.
Outside help fills part of the gap. 37.1% of small businesses used a consultant or contractor to manage cyber security risks in 2023, and 21.0% had a member of senior management responsible for cyber security decisions. Across all business sizes, the most common reason for having no cyber security employees was using consultants or contractors instead (47%), according to Statistics Canada.
Outsourcing moves the work, not the accountability. The Cyber Centre's guidance for consumers of managed services (ITSM.50.030) says the organization and its provider both have roles, but "your organization is the data owner and is legally responsible for data security." Our guide on who is responsible for cybersecurity in a small business covers the roles to assign.
Are Canadian Small Businesses Keeping Up With Patches?
No, and the trend is going the wrong way. Only 17.8% of Canadian small businesses patched or updated operating systems for security reasons monthly or more often in 2023, down from 25.0% in 2021, according to Statistics Canada table 22-10-0130-01. Monthly software patching fell from 23.9% to 18.2%. Among large businesses, 72.4% patched operating systems monthly.
That gap matters more now. Verizon's 2026 Data Breach Investigations Report, published May 19, 2026, found that exploitation of vulnerabilities has overtaken stolen credentials as the most common initial access vector for breaches, at 31%, the first time in the report's 19 years (Verizon news release). For organizations with fewer than 1,000 employees, exploitation of vulnerabilities led known initial access vectors at 26%, ahead of credential abuse (13%) and phishing (9%) (2026 DBIR, small and medium-sized businesses section).
Verizon also found that only 26% of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog were fully remediated by organizations in 2025, down from 38%, and the median time to full resolution rose to 43 days (2026 DBIR executive summary). The Cyber Centre's baseline controls recommend that organizations establish a patch management process.
How Big Is the Ransomware Risk for Small Businesses?
Large. Of the ransomware cases where Verizon knew the victim's size, about 96% of victims were small and medium businesses, which Verizon defines as fewer than 1,000 employees (2026 DBIR). Verizon describes these attackers as opportunistic: victims were typically chosen because they had compromised credentials (38%) or unpatched vulnerabilities in edge devices (29%), not because of their industry or revenue.
Canadian data points the same way. Ransomware hit 13% of impacted Canadian businesses in 2023, up from 11% in 2021. 88% of ransomware victims did not pay; of those that did, 84% paid less than $10,000 and 4% paid more than $500,000 (Statistics Canada). Globally, Verizon found ransomware in 48% of all breaches, and 69% of ransomware victims did not pay (2026 DBIR executive summary). These are different populations, so the payment rates should not be compared directly.
The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 says ransomware is the top cybercrime threat facing Canada's critical infrastructure, and judges that ransomware will almost certainly continue to be the most impactful cyber threat facing Canadian organizations over the next two years (NCTA 2025-2026, pages 6 and 22). It also assesses that ransomware actors are almost certainly opportunistic and do not target specific industries (page 25), and CSE's release announcing the assessment also names ransomware as the top cybercrime threat facing Canada's critical infrastructure.
Do Canadian Small Businesses Report Cyber Incidents?
Rarely. Only 11.9% of Canadian small businesses impacted by a cyber security incident in 2023 reported it to a police service, compared with 15.5% of large businesses, according to Statistics Canada table 22-10-0078-01. Among businesses of all sizes that did not report every incident, 55% said it was resolved internally, 35% said it was too minor and 31% said IT consultants or contractors resolved it (The Daily).
Privacy breaches are a separate reporting duty. The Office of the Privacy Commissioner of Canada received 696 breach reports from businesses under PIPEDA in 2025 to 2026, affecting 20,328,495 Canadian accounts. Unauthorized access accounted for 78% of those business breach reports, and more than two-thirds of those (68%) were the result of a cybersecurity incident (OPC Annual Report 2025-2026; OPC news release, June 2026). Our guide on how to report a cyber attack in Canada explains where a business should report first.
What Should a 10 to 50 Person Business Do First?
Close the gaps the data shows are widest, in this order. Each item maps to the Cyber Centre's 13 Baseline Controls, which ITSM.10.089 sets out for organizations with fewer than 500 employees.
- Name an owner. Decide who in leadership is accountable for cyber security, even if a provider does the technical work.
- Write two short documents. A one-page internal security policy and a one-page incident response plan with phone numbers. Only 15.4% and 10.5% of small businesses had these in writing.
- Set a patch deadline. Agree in writing how quickly operating systems, software and internet-facing devices such as firewalls and VPNs get patched, and ask for a monthly report.
- Lock down accounts. Turn on multi-factor authentication for email, remote access and admin accounts. 45.4% of small businesses reported identity and access management measures in 2023.
- Train on a schedule. Short, recurring training beats a one-time session. Only 5.7% of small businesses made it mandatory and recurring.
- Test the backups. A restore you have actually tested is what makes not paying a ransom a real option.
One question to ask your IT lead or provider this week: "How many days does it take us to patch a critical vulnerability, and can you show me last month's report?" Then take the free Cybersecurity Canada assessment to see how your business compares across all 13 Baseline Controls.