KEY TAKEAWAYS
- Canada’s federal cyber authority names the same three starting controls in its published baseline for small organizations: strong user authentication, employee awareness training, and automatic patching.
- Microsoft researchers measured multi-factor authentication cutting account-compromise risk by 99.22 percent across a full population, and by 98.56 percent where the password had already leaked.
- Verizon’s 2026 breach report puts software vulnerabilities at 31 percent of breaches, ahead of stolen passwords, so patching has moved up the queue for 2026.
- Statistics Canada counted 16 percent of Canadian businesses impacted by a cyber incident in 2023, and only 22 percent running a formal training programme.
Mike Pearlstein is CEO of Fusion Computing and holds the CISSP. He has led Fusion’s managed IT and cybersecurity practice since 2012, serving Canadian businesses across Toronto, Hamilton, and Metro Vancouver.
The three most effective cybersecurity measures for a Canadian SMB are multi-factor authentication on every account, continuous security awareness training for every employee, and disciplined vulnerability and patch management on every device. Those are not our three favourites. They are three of the baseline controls the Canadian Centre for Cyber Security (2026) publishes for organizations under 500 employees.
| Measure. | Baseline control. | Published evidence. | Typical rollout. |
|---|---|---|---|
| Multi-factor authentication. | BC.5.1 Use Strong User Authentication. | 99.22% lower compromise risk (Microsoft Research, 2023). | 2 to 4 weeks. |
| Security awareness training. | BC.6.1 Provide Employee Awareness Training. | Only 22% of Canadian businesses ran formal training (Statistics Canada, 2024). | Continuous, monthly cadence. |
| Vulnerability and patch management. | BC.2.1 Automatically Patch Operating Systems and Applications. | 31% of breaches now start at a software vulnerability (Verizon, 2026). | 6 to 10 weeks to full coverage. |
Fusion Computing is a CISSP-led managed security services provider serving Canadian businesses since 2012. All security operations align to CIS Controls v8.1, with 24/7 managed detection and response, endpoint protection, and incident response. Delivered from Canadian offices with all data stored in Canada.
1. Strong Authentication Practices
According to Meyer et al. at Microsoft (2023), multi-factor authentication reduced the risk of account compromise by 99.22 percent across the study population, and by 98.56 percent in the subset where credentials had already leaked. The study covered Azure Active Directory accounts. It remains the largest published measurement of what MFA actually stops.

The strong-authentication control reads: organizations should implement two-factor authentication wherever possible, and document every instance where they decide not to. That second half is the part Canadian SMBs skip. Fusion Computing treats the exception log as the deliverable, because an unlogged exception is where the intruder lands. Ask us to review your exception list before you call the rollout finished.
MFA asks a user to prove identity in more than one way:
- Something known, such as a password or a PIN.
- Something held, such as a hardware token or an authenticator prompt on a phone.
- Something inherent, such as a fingerprint or facial recognition.
Not every second factor is equal. SMS codes fall to SIM-swap and prompt-fatigue attacks. In Microsoft 365 tenants we deploy number matching, then Conditional Access in Entra ID that blocks sign-ins by device posture and impossible-travel signal. Legacy authentication protocols get switched off in the same change window, because they bypass the policy entirely.
“We (MD Charlton) chose Fusion after evaluating several MSPs, and we’ve been extremely pleased with their performance. Their transparency and responsiveness, both from the service desk and in guiding us through smart, understandable technology decisions, have been top notch. They’ve been a key partner in helping us strengthen our cybersecurity while keeping our business running smoothly.”
2. Security Awareness Training
According to Statistics Canada (2024), 16 percent of Canadian businesses were impacted by a cyber security incident in 2023. Only 22 percent provided formal training to staff. Just 26 percent held a written security policy. Canadian businesses spent over CA$300 million on training that year.

The awareness-training control asks organizations to invest in training for every employee, and names the topics: password practice, identification of malicious email and links, approved software, appropriate internet use, and safe social media. That list is 6 years old and still matches what lands in a Canadian inbox this quarter.
Training that works looks different from training that gets bought:
- Short monthly modules, not a 90-minute annual session everyone clicks through.
- Simulated phishing using current Canadian pretexts, including CRA refund lures and payroll-change requests.
- Reporting that tracks click rate and report rate per team, so finance and reception get different follow-up.
[ORIGINAL DATA] Across our 41 Canadian SMB client fleets we measured report rate, rather than click rate, as the number that predicts a contained incident. That reading is anonymized client data and an FC internal benchmark from Q2 2026. In our practice, a team that reports a live phish inside 15 minutes gives the response desk a usable head start.
The wider case for the spend, including breach costs, insurance conditions, and PIPEDA duties, is set out in our guide to why cybersecurity is important for Canadian businesses.
3. Vulnerability and Patch Management
According to the Verizon Data Breach Investigations Report (2026), 31 percent of breaches now start with a software vulnerability. That puts unpatched code ahead of stolen passwords as the leading way in. The ordering is new, because the 2025 edition had credentials in front.

[CONTRARIAN THESIS] This measure is numbered third and should probably be numbered first in 2026. Most SMB security advice still opens with identity because identity was the top vector for a decade. The 2026 data moved. A Canadian firm with excellent MFA and a 2019 firewall appliance still has an open front door.
Machine-learning detection changes what an unpatched appliance looks like on the wire, which is the argument our guide to AI in cybersecurity for Canadian SMEs works through in detail.
The Cyber Centre patching control asks Canadian organizations to enable automatic updates across every application and device, or to run a full vulnerability and patch management programme. The second option exists because automatic patching cannot reach everything in a 40-person office:
- Network appliances, VPN concentrators, and NAS units that update only by hand.
- Line-of-business applications where a vendor certifies a specific version.
- Devices past end of support, which the baseline says to replace rather than patch.
Fusion Computing prioritises the queue against the CISA Known Exploited Vulnerabilities catalog (2026) rather than raw CVSS score. A medium-severity flaw with confirmed exploitation outranks a critical-severity flaw nobody has weaponised. That single reordering is what makes a 6 to 10 week programme finishable for a 40-person business.
How Much These Three Measures Cost a Canadian SMB
According to Statistics Canada (2024), Canadian businesses spent CA$11.0 billion preventing and detecting cyber incidents in 2023 and a further CA$1.2 billion recovering from them. Recovery spending doubled from roughly CA$600 million in 2021. Prevention grew 13 percent over the same two years.
Priced separately, the three measures are cheap. MFA is included in most Microsoft 365 business licences. Awareness platforms sit in the low single digits per user per month. Patch automation rides on whatever monitoring tool already runs on the endpoint. The cost is the labour to keep all three honest week after week.
Fusion Computing prices managed cybersecurity at CA$130 to CA$180 per user per month depending on regulatory exposure, and full managed IT with cybersecurity included from CA$180 per user per month. Engagements run on a term agreement rather than a rolling arrangement, because a security programme measured in weeks produces nothing. Ask us to scope your three-control gap before you budget a number.
A 90-Day Checklist for Sequencing the Three Measures
According to the Canadian Centre for Cyber Security (2026), the baseline is deliberately partial. Organizations should implement as many of the 13 control areas as possible, accepting that not every business can implement every one. Fusion Computing reads that as permission to sequence rather than an excuse to stall.
[NOVEL FRAMEWORK] The order below is the one that survives contact with a 40-person Canadian business that has no internal IT lead:
- Days 1 to 14. Inventory identities. Find every shared mailbox, service account, and admin login. This is the step that decides whether the rest lands.
- Days 15 to 30. Enforce MFA on email, remote access, and any finance system, with number matching on and legacy protocols off.
- Days 31 to 60. Start monthly training and the first simulated phish. Publish report rate by team, never click rate by person.
- Days 61 to 90. Turn on automatic patching everywhere it reaches, then hand-schedule the appliances it does not, ranked against the CISA exploited-vulnerability catalog.
Two things break this schedule in a Canadian SMB. One is an unowned line-of-business application that fails the moment its service account gets a second factor. The other is a Windows 10 device past end of support that cannot take the patch at all. Both surface inside the first 14 days when the identity inventory is done properly.
What Canadian Privacy Law Requires When a Control Fails
According to the Office of the Privacy Commissioner of Canada (2018), a business must report a breach where there is a real risk of significant harm. It must also keep a record of every breach of safeguards for 2 years, reportable or not.
[REGULATOR QUOTE] PIPEDA section 10.1 (2026) requires the report to be made “as soon as feasible after the organization determines that the breach has occurred”. There is no 72-hour clock in Canadian federal privacy law. That number belongs to the European GDPR and gets copied into Canadian vendor marketing constantly.
The obligation that catches Canadian SMBs is the record, not the report. Every breach of safeguards goes in the log for 2 years whether or not it met the harm threshold, and the Commissioner can ask for it. In our practice the log is also the fastest way to show a cyber insurer that the three controls above were running before the claim.
Cyber Centre Baseline vs CIS Controls v8.1: Which Guide to Follow
According to the Center for Internet Security (2026), the 18 CIS Controls carry 153 safeguards across 3 implementation groups. Implementation Group 1 is the tier it calls essential cyber hygiene, and it covers the same ground as the Cyber Centre baseline.
Canadian buyers ask which of the two to follow. Fusion Computing recommends the Cyber Centre baseline for the board conversation, because it is Canadian, free, and written in plain language. We recommend CIS Implementation Group 1 for the engineering work, because each safeguard is testable and maps cleanly to audit evidence.
Conclusion
According to the Canadian Centre for Cyber Security (2026), ransomware will almost certainly remain the most impactful cyber threat facing Canadians. Authentication, awareness, and patching are the 3 controls that shorten that story. Pick the first one, finish it, then talk to our team about the next.
Frequently Asked Questions
What are the three most effective cybersecurity measures for Canadian SMBs?
Multi-factor authentication on every account, continuous security awareness training, and disciplined vulnerability and patch management. The Canadian Centre for Cyber Security publishes all 3 in its baseline controls for small and medium organizations. Together they address credential theft, human error, and software exploitation, which are the dominant routes into a Canadian small business.
How much does multi-factor authentication actually reduce risk?
Microsoft researchers published a 2023 study of Azure Active Directory accounts measuring a 99.22 percent reduction in compromise risk across the population, and 98.56 percent for accounts whose credentials had already leaked. Beware the widely repeated 99.9 percent figure, which has no published study behind it. The measured numbers are strong enough without rounding them up.
Does PIPEDA give Canadian businesses 72 hours to report a breach?
No. PIPEDA section 10.1 requires a report “as soon as feasible after the organization determines that the breach has occurred”, with no fixed deadline in hours or days. The 72-hour clock belongs to the European GDPR. Canadian businesses must also keep a record of every breach of security safeguards for 2 years, whether or not it was reportable.
How much does a cybersecurity programme covering these three measures cost?
Fusion Computing prices managed cybersecurity at CA$130 to CA$180 per user per month depending on regulatory exposure, and full managed IT with cybersecurity included from CA$180 per user per month. A 40-user Ontario business therefore lands between roughly CA$5,200 and CA$7,200 a month for the security programme. Engagements run on a term agreement.
How long does it take to get all three measures running?
Plan on 90 days for a business under 60 seats with no internal IT lead. Identity inventory takes the first 2 weeks, MFA enforcement lands by day 30, training and the first simulated phish start around day 45, and full patch coverage closes out by day 90. The identity inventory is the step that decides whether the other two arrive on schedule.
Which second factor should a Canadian small business use?
Prefer an authenticator app with number matching, or a hardware security key for finance and administrator accounts. SMS codes are better than nothing and worse than everything else, because SIM-swap and prompt-fatigue attacks defeat them. In Microsoft 365 tenants, switch off legacy authentication protocols in the same change window, because they bypass the policy entirely.
How often should security awareness training run?
Monthly, in short modules, with a simulated phishing exercise every 4 to 6 weeks. An annual 90-minute session satisfies an insurer checkbox and changes very little behaviour. Track report rate by team rather than click rate by person: a team that flags a live phish inside 15 minutes gives your response desk a usable head start.
Is patching really more important than passwords in 2026?
The 2026 Verizon Data Breach Investigations Report puts software vulnerabilities at 31 percent of breaches, ahead of stolen passwords for the first time. That does not demote authentication, which still blocks the largest volume of automated attacks. It means a business with excellent MFA and an unpatched perimeter appliance has not finished the job.
What do these three measures cover that antivirus alone does not?
Signature-based antivirus matches files against a list of known bad software, so it misses fileless techniques and freshly compiled malware. Authentication stops the intruder from logging in as staff. Training stops the click that starts the chain. Patching removes the flaw that lets code run in the first place. Behavioural endpoint detection then covers what still slips through.
Do Canadian cyber insurers ask about these controls?
Yes. MFA coverage, staff training cadence, and patch currency appear on most Canadian underwriting questionnaires, and evidence is requested at renewal rather than taken on trust. Console screenshots showing agent coverage, a dated training report, and a patch compliance summary are the three artifacts that move a renewal along fastest.
How do Canadian SMBs differ from enterprises here?
The controls are identical; the staffing is not. A 500-person firm assigns an analyst to read the endpoint console. Of our clients under 60 seats, none has anyone free to do that after 6 PM. That gap, rather than any difference in threat, is why managed detection and response is normally the right shape for a Canadian small business.
What should a Canadian SMB do first after a suspected incident?
Isolate the affected devices, preserve logs before anything is rebuilt, and start the breach record the same day. Assess whether the incident creates a real risk of significant harm, which is the PIPEDA reporting trigger. Then bring in forensics to establish scope and root cause, and close the control that failed before restoring normal operations.
Related Resources
Why this matters for Canadian SMBs: The Cyber Centre ransomware playbook (2026) recommends the same three controls as the first line of prevention. CIS Controls v8.1 (2026) place all 3 inside Implementation Group 1, the tier it calls essential cyber hygiene.
The Canadian Anti-Fraud Centre (2024) publishes annual statistics on reported fraud against Canadian businesses, and states that most fraud is never reported at all. Read its figures as a floor.
Fusion Computing serves Canadian businesses across:
Cybersecurity Services. Toronto · Cybersecurity Services. Hamilton · Cybersecurity Services. Vancouver
Last reviewed: August 2026. Fusion Computing

