Baseline Controls News Resources Glossary About
Public Data Report · 2026 Edition

The State of Cyber Risk for Canadian Small Businesses, 2026

Cyber incident rates, written policies, staffing, patching, ransomware and reporting for Canadian businesses with 10 to 49 employees, compared with medium and large businesses. Public data from Statistics Canada, the Canadian Centre for Cyber Security, the Office of the Privacy Commissioner of Canada and Verizon.

Published by Cybersecurity Canada · A Cyber Unit initiative · Published: October 11, 2026
14.3%
of Canadian small businesses (10 to 49 employees) were impacted by a cyber security incident in 2023
Statistics Canada, Table 22-10-0076-01
17.8%
of small businesses patched operating systems monthly or more often in 2023, down from 25.0% in 2021
Statistics Canada, Table 22-10-0130-01
5.7%
of small businesses ran recurring mandatory cyber security training for employees
Statistics Canada, Table 22-10-0130-01
~96%
of ransomware victims with a known size were SMBs (fewer than 1,000 employees)
Verizon 2026 DBIR

Key Figures at a Glance

The short answer: about 1 in 7 Canadian small businesses (14.3%) were impacted by a cyber security incident in 2023, and most had little in writing to manage the risk. Only 15.4% had a written internal cyber security policy and 17.8% patched operating systems monthly, according to Statistics Canada. In this report, a small business has 10 to 49 employees, the definition Statistics Canada uses. Each figure is for 2023, the latest year published.

Figure (2023)Small (10 to 49)All businessesLarge (250+)Source
Impacted by a cyber security incident14.3%16.1%29.9%Statistics Canada, Table 22-10-0076-01
Written policy to manage internal cyber security risks15.4%20.3%66.3%Statistics Canada, Table 22-10-0130-01
Written policy to report cyber security incidents10.5%14.4%57.7%Statistics Canada, Table 22-10-0130-01
Recurring mandatory cyber security training for employees5.7%9.5%52.3%Statistics Canada, Table 22-10-0130-01
Monthly or more frequent security patching of operating systems17.8% (25.0% in 2021)22.6%72.4%Statistics Canada, Table 22-10-0130-01
No employees who do cyber security tasks as part of their regular role45.1% (34.5% in 2021)41.9%10.3%Statistics Canada, Table 22-10-0129-01
Use a consultant or contractor to manage cyber security risks37.1%38.6%48.3%Statistics Canada, Table 22-10-0130-01
Identity and access management in place45.4%50.7%88.8%Statistics Canada, Table 22-10-0001-01
Cyber risk insurance19.1% (13.7% in 2021)22.3%58.0%Statistics Canada, Table 22-10-0130-01
No cyber security risk management arrangements at all22.3%19.9%3.1%Statistics Canada, Table 22-10-0130-01
Impacted businesses that reported an incident to police11.9%12.7%15.5%Statistics Canada, Table 22-10-0078-01

Executive Summary

This report compiles public data on the cyber risk facing Canadian small businesses, broken out by business size wherever the source allows. It draws on Statistics Canada's Canadian Survey of Cyber Security and Cybercrime (2023 reference year, released October 21, 2024), the Canadian Centre for Cyber Security, the Office of the Privacy Commissioner of Canada and Verizon's 2026 Data Breach Investigations Report. For national figures on fraud losses, breach costs and regulation, see the Cybersecurity Canada Report 2026.

Six findings for Canadian small business owners:

  1. About 1 in 7 small businesses were hit in 2023, and recovery is getting more expensive. 14.3% of small businesses were impacted by a cyber security incident, down from 18.8% in 2017. Nationally, spending to recover from incidents doubled from about $600 million in 2021 to $1.2 billion in 2023, and small businesses accounted for about $300 million of it.
  2. Very few small businesses have security in writing. 15.4% had a written policy to manage internal cyber security risks, 10.5% had a written incident reporting policy, 6.3% had a business continuity plan that covers cyber threats and 3.6% had a written policy for supply chain partners.
  3. The people gap is widening. 45.1% of small businesses had no employees who do cyber security tasks as part of their regular role, up from 34.5% in 2021. 37.1% relied on a consultant or contractor to manage cyber security risks.
  4. Patching went backwards while attackers moved to vulnerabilities. Monthly security patching of operating systems fell from 25.0% to 17.8% of small businesses between 2021 and 2023. Verizon's 2026 report found exploiting vulnerabilities is now the top way into breaches overall (31%) and at organizations with fewer than 1,000 employees (26%).
  5. Ransomware is a small business problem. About 96% of ransomware victims with a known size in Verizon's 2026 dataset were small and medium businesses. In Canada, 88% of businesses hit by ransomware in 2023 did not pay.
  6. Most incidents never reach police. Only 11.9% of impacted small businesses reported an incident to a police service. Separately, the federal privacy commissioner received 696 breach reports from businesses in 2025 to 2026, affecting 20,328,495 Canadian accounts.

How Often Are Canadian Small Businesses Hit by Cyber Attacks?

About 1 in 7. In 2023, 14.3% of Canadian small businesses (10 to 49 employees) were impacted by a cyber security incident, compared with 23.1% of medium businesses and 29.9% of large businesses, according to Statistics Canada table 22-10-0076-01. The small business rate has drifted down from 18.8% in 2017, 18.4% in 2019 and 16.2% in 2021.

Industry matters. Among small businesses, the highest 2023 rates were in finance and insurance (21.9%), information and cultural industries (21.6%) and professional, scientific and technical services (20.2%), the category that includes law, accounting, engineering and consulting firms. The lowest were in arts, entertainment and recreation (8.3%) and construction (9.5%). These rates come from the same Statistics Canada table.

What hit them? Across all impacted businesses, scams and fraud were the most common method (50%), followed by identity theft (31%, up 11 percentage points from 2021) and ransomware (13%), according to The Daily, October 21, 2024. The survey measures incidents that impacted a business, not attempted attacks, so these figures describe incidents with real consequences.

What Do Cyber Incidents Cost Canadian Small Businesses?

Small businesses spent about $300 million recovering from cyber security incidents in 2023 and $2.6 billion preventing and detecting them, according to Statistics Canada. National recovery spending doubled from about $600 million in 2021 to $1.2 billion in 2023, while prevention and detection spending rose from $9.7 billion to $11.0 billion, about 13% (our calculation).

Spread across the roughly 170,000 small businesses in the survey population, $2.6 billion works out to about $15,000 per small business per year (our calculation; it averages businesses that spent heavily with the many that spent nothing). Statistics Canada also reports that the share of all businesses spending anything on prevention or detection fell from 61% in 2021 to 56% in 2023.

The operational impact is broader than the bill. Among impacted small businesses in 2023, 15.1% reported additional repair or recovery costs, 13.5% lost revenue, 13.3% said employees were prevented from doing their day-to-day work and 7.2% were required to notify external parties of a breach, according to Statistics Canada table 22-10-0133-01.

How Many Canadian Small Businesses Have a Written Cybersecurity Policy?

Very few. In 2023, only 15.4% of Canadian small businesses had a written policy to manage internal cyber security risks, compared with 66.3% of large businesses, according to Statistics Canada table 22-10-0130-01. Written incident reporting policies were rarer (10.5%), and only 3.6% had a written policy covering cyber risk from supply chain partners.

The planning and training numbers are similar. 6.3% of small businesses had a business continuity plan with processes to manage cyber security threats, 12.9% had a procedure for notifying employees of incidents or threats, and 5.7% ran recurring mandatory cyber security training. 22.3% had no cyber security risk management arrangements of any kind. Cyber risk insurance is the one area moving up quickly, from 13.7% of small businesses in 2021 to 19.1% in 2023.

The Cyber Centre treats a written plan as foundational: incident response is Baseline Control BC.1, the first of its 13 controls, and its baseline controls recommend security awareness training on a regular, ongoing basis rather than as a one-time event.

Who Handles Cybersecurity in a Canadian Small Business?

Increasingly, no one on staff. In 2023, 45.1% of Canadian small businesses had no employees who complete cyber security tasks as part of their regular responsibilities, up from 34.5% in 2021, according to Statistics Canada table 22-10-0129-01. The share with employees responsible for overseeing cyber security risks fell from 58.7% to 47.6%.

Outside help fills part of the gap. 37.1% of small businesses used a consultant or contractor to manage cyber security risks in 2023, and 21.0% had a member of senior management responsible for cyber security decisions. Across all business sizes, the most common reason for having no cyber security employees was using consultants or contractors instead (47%), according to Statistics Canada.

Outsourcing moves the work, not the accountability. The Cyber Centre's guidance for consumers of managed services (ITSM.50.030) says the organization and its provider both have roles, but "your organization is the data owner and is legally responsible for data security." Our guide on who is responsible for cybersecurity in a small business covers the roles to assign.

Are Canadian Small Businesses Keeping Up With Patches?

No, and the trend is going the wrong way. Only 17.8% of Canadian small businesses patched or updated operating systems for security reasons monthly or more often in 2023, down from 25.0% in 2021, according to Statistics Canada table 22-10-0130-01. Monthly software patching fell from 23.9% to 18.2%. Among large businesses, 72.4% patched operating systems monthly.

That gap matters more now. Verizon's 2026 Data Breach Investigations Report, published May 19, 2026, found that exploitation of vulnerabilities has overtaken stolen credentials as the most common initial access vector for breaches, at 31%, the first time in the report's 19 years (Verizon news release). For organizations with fewer than 1,000 employees, exploitation of vulnerabilities led known initial access vectors at 26%, ahead of credential abuse (13%) and phishing (9%) (2026 DBIR, small and medium-sized businesses section).

Verizon also found that only 26% of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog were fully remediated by organizations in 2025, down from 38%, and the median time to full resolution rose to 43 days (2026 DBIR executive summary). The Cyber Centre's baseline controls recommend that organizations establish a patch management process.

How Big Is the Ransomware Risk for Small Businesses?

Large. Of the ransomware cases where Verizon knew the victim's size, about 96% of victims were small and medium businesses, which Verizon defines as fewer than 1,000 employees (2026 DBIR). Verizon describes these attackers as opportunistic: victims were typically chosen because they had compromised credentials (38%) or unpatched vulnerabilities in edge devices (29%), not because of their industry or revenue.

Canadian data points the same way. Ransomware hit 13% of impacted Canadian businesses in 2023, up from 11% in 2021. 88% of ransomware victims did not pay; of those that did, 84% paid less than $10,000 and 4% paid more than $500,000 (Statistics Canada). Globally, Verizon found ransomware in 48% of all breaches, and 69% of ransomware victims did not pay (2026 DBIR executive summary). These are different populations, so the payment rates should not be compared directly.

The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 says ransomware is the top cybercrime threat facing Canada's critical infrastructure, and judges that ransomware will almost certainly continue to be the most impactful cyber threat facing Canadian organizations over the next two years (NCTA 2025-2026, pages 6 and 22). It also assesses that ransomware actors are almost certainly opportunistic and do not target specific industries (page 25), and CSE's release announcing the assessment also names ransomware as the top cybercrime threat facing Canada's critical infrastructure.

Do Canadian Small Businesses Report Cyber Incidents?

Rarely. Only 11.9% of Canadian small businesses impacted by a cyber security incident in 2023 reported it to a police service, compared with 15.5% of large businesses, according to Statistics Canada table 22-10-0078-01. Among businesses of all sizes that did not report every incident, 55% said it was resolved internally, 35% said it was too minor and 31% said IT consultants or contractors resolved it (The Daily).

Privacy breaches are a separate reporting duty. The Office of the Privacy Commissioner of Canada received 696 breach reports from businesses under PIPEDA in 2025 to 2026, affecting 20,328,495 Canadian accounts. Unauthorized access accounted for 78% of those business breach reports, and more than two-thirds of those (68%) were the result of a cybersecurity incident (OPC Annual Report 2025-2026; OPC news release, June 2026). Our guide on how to report a cyber attack in Canada explains where a business should report first.

What Should a 10 to 50 Person Business Do First?

Close the gaps the data shows are widest, in this order. Each item maps to the Cyber Centre's 13 Baseline Controls, which ITSM.10.089 sets out for organizations with fewer than 500 employees.

  1. Name an owner. Decide who in leadership is accountable for cyber security, even if a provider does the technical work.
  2. Write two short documents. A one-page internal security policy and a one-page incident response plan with phone numbers. Only 15.4% and 10.5% of small businesses had these in writing.
  3. Set a patch deadline. Agree in writing how quickly operating systems, software and internet-facing devices such as firewalls and VPNs get patched, and ask for a monthly report.
  4. Lock down accounts. Turn on multi-factor authentication for email, remote access and admin accounts. 45.4% of small businesses reported identity and access management measures in 2023.
  5. Train on a schedule. Short, recurring training beats a one-time session. Only 5.7% of small businesses made it mandatory and recurring.
  6. Test the backups. A restore you have actually tested is what makes not paying a ransom a real option.

One question to ask your IT lead or provider this week: "How many days does it take us to patch a critical vulnerability, and can you show me last month's report?" Then take the free Cybersecurity Canada assessment to see how your business compares across all 13 Baseline Controls.

Check Your Readiness

How does your business compare with these numbers?

The assessment maps directly to the CCCS Baseline Controls and gives you a clear, prioritized view of where to focus first. 50 questions, under 30 minutes, 100% confidential: your answers never leave your browser.

Frequently Asked Questions

What percentage of Canadian small businesses are hit by cyber attacks?

In 2023, 14.3% of Canadian small businesses (10 to 49 employees) were impacted by a cyber security incident, about 1 in 7, according to Statistics Canada table 22-10-0076-01. That compares with 23.1% of medium businesses and 29.9% of large businesses. The small business rate has eased from 18.8% in 2017, but national spending to recover from incidents doubled to about $1.2 billion between 2021 and 2023.

How many Canadian small businesses have a written cybersecurity policy?

Few. In 2023, 15.4% of Canadian small businesses had a written policy to manage internal cyber security risks, 10.5% had a written policy for reporting incidents and 3.6% had one covering supply chain partners, according to Statistics Canada table 22-10-0130-01. Among large businesses, 66.3% had an internal risk policy.

How often do Canadian small businesses patch their systems?

Only 17.8% of Canadian small businesses patched or updated operating systems for security reasons monthly or more often in 2023, down from 25.0% in 2021, according to Statistics Canada. For software the figure was 18.2%. Verizon's 2026 Data Breach Investigations Report found exploitation of vulnerabilities was the most common known initial access vector in breaches at organizations with fewer than 1,000 employees, at 26%.

Do Canadian small businesses have cybersecurity staff?

Fewer than before. In 2023, 45.1% of Canadian small businesses had no employees who complete cyber security tasks as part of their regular responsibilities, up from 34.5% in 2021, and 37.1% used a consultant or contractor to manage cyber security risks, according to Statistics Canada tables 22-10-0129-01 and 22-10-0130-01.

Are small businesses targeted by ransomware?

Yes. Verizon's 2026 Data Breach Investigations Report found that about 96% of ransomware victims with a known organization size were small and medium businesses, which Verizon defines as fewer than 1,000 employees. In Canada, Statistics Canada found 88% of businesses hit by ransomware in 2023 did not pay. The Canadian Centre for Cyber Security calls ransomware the top cybercrime threat facing Canada's critical infrastructure.

Do Canadian small businesses report cyber incidents to police?

Rarely. Only 11.9% of Canadian small businesses impacted by a cyber security incident in 2023 reported it to a police service, according to Statistics Canada table 22-10-0078-01. Across all sizes, the main reasons for not reporting were that the incident was resolved internally (55%), was too minor (35%) or was resolved through IT consultants or contractors (31%).

If a small business outsources its IT, who is responsible for cybersecurity?

The business. The Canadian Centre for Cyber Security's guidance for consumers of managed services (ITSM.50.030) says the organization and the managed service provider both have roles, but "your organization is the data owner and is legally responsible for data security." This is general information, not legal advice.

When will newer Statistics Canada data on business cyber security be available?

Statistics Canada collected the next cycle of the Canadian Survey of Cyber Security and Cybercrime from January 14 to March 31, 2026, covering the 2025 calendar year. This report uses the 2023 cycle, released October 21, 2024, which is the latest published. Cybersecurity Canada will update this report when the 2025 results are published.

Methodology, Data Vintage, and Limitations

This report is a secondary analysis of published public data only. No proprietary, client or customer data of any kind is used, and nothing in it comes from Cybersecurity Canada or Cyber Unit records. Every figure is attributed to a named public source with a link.

Definitions and data vintage

  • Business size. Statistics Canada's survey covers enterprises with 10 or more employees, excluding public administration. Small means 10 to 49 employees, medium 50 to 249 and large 250 or more. The 2023 cycle surveyed 12,462 enterprises with a 71% response rate, and its target population included about 170,000 small businesses. Businesses with fewer than 10 employees are not covered.
  • Verizon's definition is different. The 2026 DBIR treats organizations with fewer than 1,000 employees as small and medium businesses, and its dataset is global. Verizon figures are never combined with Statistics Canada figures in this report.
  • Data year. Statistics Canada figures describe calendar 2023, published October 21, 2024, the most recent cycle released as of October 11, 2026. The 2025 cycle was collected from January 14 to March 31, 2026, and this report will be updated when those results are published. OPC figures cover the April 2025 to March 2026 fiscal year. Verizon says its 2026 DBIR is based on 2025 data.
  • Data quality. Statistics Canada grades each estimate from A (excellent) to F (too unreliable to publish). This report uses only estimates graded A or B.
  • Our calculations. Figures marked "our calculation" (the roughly 13% rise in prevention spending and the roughly $15,000 average per small business) are derived from Statistics Canada totals and are not official statistics.

Other limitations

  • Impacts, not attempts. Statistics Canada measures incidents that impacted a business, so the incident rates understate the number of attempted attacks.
  • Self-reported. The survey relies on what businesses know and report. In 2023, 7.5% of small businesses did not know which cyber security measures they had in place.
  • Different populations. Ransom payment rates from Statistics Canada (Canadian businesses) and Verizon (global breach dataset) measure different groups and should not be compared directly.

Sources

Every figure in this report comes from the following public sources. Links were opened and checked on October 11, 2026.

Statistics Canada

Canadian Centre for Cyber Security / Communications Security Establishment

Office of the Privacy Commissioner of Canada

Verizon

Cite This Report

Suggested citation:

Cybersecurity Canada (2026). The State of Cyber Risk for Canadian Small Businesses, 2026. Retrieved from https://cybersecuritycanada.ca/small-business-cyber-risk-report-2026/

For media inquiries or to request the underlying source list as a structured document, contact info@cybersecuritycanada.ca.

Free Assessment

How does your organization compare?

Take the free Cybersecurity Canada assessment to measure your organization against the Canadian Centre for Cyber Security's 13 Baseline Controls. 50 questions, under 30 minutes, 100% confidential: your answers never leave your browser.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.