Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
KEY TAKEAWAYS
- Statistics Canada recorded 16 percent of Canadian businesses impacted by a cyber security incident in 2023, with large firms hit hardest at 30 percent.
- Canadian recovery spending doubled from roughly CA$600 million in 2021 to CA$1.2 billion in 2023.
- Cyber insurance underwriters now deny or reduce claims when MFA, EDR, or tested backups are missing at the time of loss.
- PIPEDA has no 72-hour breach clock. The duty is to report as soon as feasible and to keep breach records for 2 years.
- Six baseline controls close most of the gap, and managed security for a Canadian SMB runs CA$180 to CA$250+ per user per month.
Why does cybersecurity matter for a Canadian SMB in 2026?
According to Statistics Canada (2024), 16 percent of Canadian businesses were impacted by a cyber security incident in 2023. Large businesses took the highest rate at 30 percent, not the smallest ones. Total recovery spending doubled over two years, from roughly CA$600 million in 2021 to CA$1.2 billion in 2023.
A single incident can erase a year of profit and trigger a reporting obligation to the Privacy Commissioner in the same week. That is why I treat the question as a cash-flow question rather than an IT question when a Toronto or Hamilton owner asks me to justify the spend.
Across our 41 Canadian SMB client fleets, Fusion Computing runs managed detection and response around the clock from Toronto, Hamilton, and Vancouver. In our experience the businesses that get hurt worst are not the ones with the weakest tools. They are the ones with no one accountable for whether the tools still work.
Talk to a CISSP-led Canadian security team
The 5 most-expensive consequences of weak cybersecurity: a cost comparison.
According to the Canadian Centre for Cyber Security (2020), its Baseline Cyber Security Controls set out 13 controls for small and medium organizations. The first is a written incident response plan, and the third is to consider buying a cyber insurance policy. Both exist because the recovery bill is the expensive part.
The ransom figure is rarely the largest line on the post-incident invoice. Five categories compound during and after the event, and four of them keep running for 18 to 36 months. The ranges below are what our engineers found across Canadian SMB incident work.
| Consequence. | Typical Canadian SMB cost. | Likelihood after a serious incident. |
|---|---|---|
| Incident response and forensics. | CA$50k to CA$150k. | Near certain. |
| Business interruption, 14 to 21 days. | CA$80k to CA$400k. | High for ransomware. |
| Regulatory and legal exposure. | CA$25k to CA$200k. | High when personal data is involved. |
| Ransom or extortion, if paid. | CA$200k or more. | Variable. Payment does not guarantee recovery. |
| Reputation and customer churn. | 5 to 15 percent revenue impact in year one. | Persistent for 18 to 36 months. |
For Ontario professional services firms, reputation is often the largest line. A breach becomes the first result when a prospect searches the company name, and 1 incident can end client relationships that took a decade to build.
The threat landscape facing Canadian businesses: an overview.
According to the Canadian Centre for Cyber Security (2024), ransomware is the top cybercrime threat facing Canada’s critical infrastructure. That judgement is scoped to critical infrastructure, not to Canadian organizations generally. The same assessment calls fraud and scams the most common form of cybercrime affecting Canadians.
Three forces are reshaping what a Canadian SMB actually faces. Identity attacks scaled by generative AI. Ransomware sold as a turnkey franchise. Supply chain compromises that reach hundreds of victims through 1 vendor.
| Threat. | 2021 baseline. | What we see in 2026. |
|---|---|---|
| Ransomware. | Targeted, mostly enterprise. | Sold as a service. Double extortion is the default. |
| Phishing. | Human-crafted, often clumsy. | Model-generated, fluent in both official languages. |
| Deepfakes. | Lab demonstrations. | Voice and video used in CFO and wire-transfer fraud. |
| Business email compromise. | Direct executive impersonation. | Vendor-thread hijack and accounts-payable fraud rings. |
The Canadian Anti-Fraud Centre catalogues spear phishing across both email and the phone channel, with a supplier and contractor variant aimed squarely at businesses. The pattern I see on live incidents is consistent. Attackers take credentials, sit quietly inside a mailbox for weeks, then redirect a real invoice. Ask us to check your mailbox rules for that footprint.
Why every Canadian SMB is now a target.
According to Microsoft Research (2023), multi-factor authentication reduced compromise risk by 99.22 percent across all studied accounts. For accounts whose credentials had already leaked, the reduction measured 98.56 percent. Those two figures are the closest thing the industry has to a controlled measurement of MFA.
The idea that a small business is too small to attack ended when ransomware became a franchise. Affiliates buy access to proven kits, scan for exposed Remote Desktop Protocol, unpatched VPN appliances, or Microsoft 365 tenants without conditional access, then run one playbook against anything that answers.
What makes a Canadian SMB attractive is data density per dollar of defence. A 30-person dental practice holds health records under PHIPA. A 60-person logistics firm holds customer payment data and Canada Revenue Agency filings. The data is valuable, the budgets are smaller, and the person running IT usually wears three other hats.
Cyber insurance: how it changed in 2024-2026, and what underwriters now require.
Canadian cyber insurance stopped being a backstop for missing controls. Underwriters now want evidence of MFA on all admin and remote access, behaviour-based endpoint detection on every device, immutable and tested backups, a documented incident response plan, and patch cycles that close severe vulnerabilities inside the stated window, which is typically 14 or 30 days. Where those proofs are missing at the time of loss, claims get reduced or denied.
Premiums for businesses with weak postures rose sharply over the past three years, and some high-risk sectors are being declined outright. A scoped cybersecurity assessment mapped to a recognized framework is now a renewal prerequisite for most carriers writing Canadian SMB risk. Carriers at the CA$5 million revenue tier increasingly expect annual network penetration testing alongside it. Ask us to run the underwriter questionnaire against your environment before you renew.
PIPEDA, PHIPA, Bill C-8: regulatory pressure and the reporting requirements.
According to the Privacy Commissioner of Canada (2018), a breach posing a real risk of significant harm must be reported as soon as feasible. Records of every breach must be kept for two years, whether or not the harm threshold is met. There is no 72-hour clock in PIPEDA.
Federally, PIPEDA requires reasonable safeguards over personal information, mandatory notification to the Commissioner and to affected individuals, and that recordkeeping duty. Knowingly violating the breach provisions is an offence carrying a fine of up to CA$100,000 per violation.
The same attackers reach your staff through personal accounts. For the individual version of these safeguards, see our cybersecurity help for individuals guide.
Quebec’s Law 25 layers further obligations on any business with customers in the province, and its breach standard is “promptly” rather than a fixed hour count. Bill C-8 received royal assent on June 15, 2026 as S.C. 2026, c. 9, and it builds a critical cyber systems framework for federally regulated telecommunications, finance, energy, and transportation.
Most Canadian SMBs sit outside the C-8 perimeter and inside its supply chain, which is where the pressure actually lands. I have already seen the questionnaire arrive from a regulated customer rather than from a regulator.
“Every serious Canadian incident I have worked in 14 years came down to the same 3 gaps. An account without real MFA. A backup nobody had restored from. No written plan for the first 4 hours. Fix those and the worst day of the year becomes a bad afternoon.”
Mike Pearlstein, CISSP, CEO of Fusion Computing Limited, on Canadian SMB incident work through 2025 and 2026.
The 6 controls every Canadian SMB should have, explained.
According to PIPEDA Schedule 1 (2026), Principle 4.1.3 keeps an organization responsible for personal information it hands to a third party for processing. Contractual or other means must provide a comparable level of protection. That is why we treat every control below as evidence you can produce, not a box you can tick.
Security does not require a six-figure budget. It requires the right controls in the right order. The baseline below maps to CIS Controls v8.1 and to the questions on current Canadian cyber insurance applications.
| Control. | What good looks like. | What we deploy. |
|---|---|---|
| 1. Identity and MFA. | Phishing-resistant MFA on every account, conditional access on admin and remote. | Microsoft Entra ID plus a managed password vault. |
| 2. Endpoint detection and response. | Behaviour-based detection with managed response on every laptop, server, and virtual machine. | Microsoft Defender for Endpoint plus a managed detection service. |
| 3. Email security. | DMARC at p=reject, attachment sandboxing, brand impersonation defence. | Microsoft Defender for Office 365. |
| 4. Network and edge. | Next-generation firewall with inspection, segmented guest and device networks, monitored around the clock. | A managed next-generation firewall platform. |
| 5. Backup and recovery. | 3-2-1-1-0 backup, immutable copy off-network, quarterly restore test. | An immutable backup platform with tested restores. |
| 6. People and process. | Awareness training, quarterly phishing simulation, annual incident response tabletop. | Managed by Fusion Computing. |
Most businesses Fusion Computing assesses are missing three or more of these. The gap is rarely willingness to invest. It is that IT has been managed reactively, with nobody owning the question of whether the stack would survive a real incident. Have us score your six controls and you will know inside a week.
Get your 90-day cybersecurity roadmap
What does basic cybersecurity actually cost?
Fusion Computing prices managed cybersecurity for a Canadian SMB at CA$180 to CA$250+ per user per month, under CISSP-led oversight. That covers licences, monitoring around the clock, patching, awareness training, and the people who respond when an alert fires at 2 a.m. For a 50-person business the programme lands between CA$6,500 and CA$9,000 per month.
Set that against a single incident response engagement starting at CA$50,000, a 14-day ransomware outage, or a denied insurance claim. In my experience owners only run that comparison once. Of our clients who have been through one, none has argued the arithmetic afterwards. The cost of the programme is a fraction of the first serious incident it prevents.
The number I care about more is time. Fusion Computing measured restore performance across client environments last quarter, and the accounts running quarterly restore tests came back inside hours. We measured the untested ones too. The accounts that had never tested a restore took days, and two of them discovered their oldest good copy was already encrypted.
Frequently asked questions.
These are the eight things Canadian owners and operations leads raise with us on a first call. Every answer reflects Canadian regulator guidance checked on August 5, 2026, plus what Fusion Computing observes on live client environments.
Why is cybersecurity important for small business?
Small businesses hold valuable client and health data while running thinner control stacks than enterprises. Statistics Canada put 16 percent of Canadian businesses in the impacted column for 2023, and recovery spending nationally reached CA$1.2 billion that year.
How much should a small business spend on cybersecurity?
Managed cybersecurity runs CA$180 to CA$250+ per user per month in our Canadian book of business. For a 50-person company that is CA$6,500 to CA$9,000 monthly, covering MFA, endpoint detection, email security, backup, and awareness training.
What are the biggest cyber threats to Canadian businesses in 2026?
Ransomware, model-generated phishing, business email compromise, and supply chain compromise. The Canadian Centre for Cyber Security names ransomware the top cybercrime threat to Canada’s critical infrastructure in its 2025-2026 National Cyber Threat Assessment.
Does PIPEDA require us to report a breach within 72 hours?
No. PIPEDA requires a report to the Privacy Commissioner as soon as feasible once a breach is found to pose a real risk of significant harm, plus records of every breach kept for 2 years. The 72-hour deadline belongs to the GDPR.
Will cyber insurance still pay if we get hit?
Only if the controls named in your application were in place at the time of loss. Carriers writing Canadian SMB risk now verify MFA, endpoint detection, backups, and incident response plans during claims. Missing controls reduce or void the payout.
What is the difference between antivirus and EDR?
Antivirus matches signatures of known malware. Endpoint detection and response, such as Microsoft Defender for Endpoint, watches behaviour, isolates a compromised device, and gives responders the telemetry to investigate. Insurers now treat the second as the baseline.
How long does a cyberattack take to recover from?
For a Canadian SMB hit by ransomware without tested backups, expect 14 to 21 days of degraded operations, plus 3 to 6 months of legal and reputational follow-on work. Tested restores compress the first number to hours.
Where do I start if we have nothing in place?
Start with a scoped assessment mapped against CIS Controls v8.1 and current cyber insurance underwriting questions. The output is a prioritized 90-day plan with the highest-risk gaps closed first, and it usually costs less than one day of downtime.
Once the case for spending is made, the next artefact is a scored register. Our guide to how to conduct a cybersecurity risk assessment walks the seven steps end to end.
Related resources.
Continue on the FC security stack: cybersecurity services, the case for multi-factor authentication, the cyber insurance coverage checklist, PIPEDA compliance for small business, and awareness training for small business.

