Small business cyber security in Ontario: nobody is going to hack you, somebody is going to log in as you
Almost nothing that happens to a 10 to 80 person business is sophisticated. There is no zero day and no hooded figure. Somebody types a working password into a real Microsoft login page, sits in a mailbox for a few weeks reading how you invoice, and then sends one email that changes the bank details.
About this piece
- Article
- Managed IT
- Written by Nicholas Backwell · Founder, Redsilicon
- Updated 2026-08-24
The defences that stop that are boring, cheap and mostly already in the software you pay for.
The short version
- The common entry point is a working password with no second step behind it, not a technical exploit.
- The money leaves through your mailbox, usually as a payment redirection on a real invoice.
- Statistics Canada reported that 16% of Canadian businesses were impacted by cyber security incidents in 2023, and that only 26% had a written cyber security policy.
- Five controls cover most of the realistic risk, and four of them are configuration rather than purchase.
- Cyber insurance and larger customers are both starting to ask for these in writing, so the paperwork has value beyond the protection.
What actually happens, start to finish
The story is almost always the same four steps, and it takes weeks, not minutes.
Step one, somebody gets a password. Not by cracking it. By finding it in a breach dump from an unrelated website where a staff member used the same password, or by sending a link to a login page that looks exactly like Microsoft’s because it is a copy of Microsoft’s.
Step two, they sign in. If there is no second step after the password, that is the whole attack. They are now inside a real mailbox with real permissions and nothing looks unusual to anyone.
Step three, they read. They set up a mail rule that quietly moves messages containing words like “invoice”, “wire” or “bank” into a folder nobody opens, and they watch how your business asks to be paid. They learn your customer names, your payment terms, and how your bookkeeper writes.
Step four, they send one email. It goes to a customer, from your real address, in your real thread, saying the banking has changed. Or it goes to your bookkeeper, apparently from an owner, approving a supplier change.
Nothing gets encrypted. No ransom note appears. Most owners find out when a customer calls to ask why the invoice was paid twice.
What small business cyber security in Ontario actually has to stop
The four realistic entry points, in the order we see them:
- A reused or guessable password on an account with no second step.
- A convincing fake sign-in page delivered by email, often from a real supplier whose own mailbox was taken over first.
- An internet-facing device the vendor no longer patches: an old firewall, a router the ISP left behind, a camera recorder with a port open to the world.
- A payment or banking change that nobody verified by phone.
Notice that only one of the four is about equipment. Three of them are about accounts and habits, which is why buying a better firewall does not fix the problem people think it fixes.
What the numbers say, and what they do not
Statistics Canada published “Impact of cybercrime on Canadian businesses, 2023” in The Daily on 21 October 2024, covering reference year 2023. Two figures from it are worth keeping in your head.
About one in six Canadian businesses, 16%, were impacted by cyber security incidents in 2023. And just over one in four, 26%, had written policies for cyber security in place.
The same release reported that ransomware affected 13% of impacted businesses, and that spending by Canadian businesses to recover from incidents roughly doubled from about $600 million in 2021 to $1.2 billion in 2023.
Read that gap carefully. Ransomware gets the coverage, but it is the smaller share of what happens. The bigger share is the quiet stuff: fraud, redirected payments and stolen credentials. Those rarely make the news because nobody wants to announce them.
The 26% number is the one worth acting on. Three quarters of Canadian businesses had nothing written down. A written policy does not stop an attack by itself, but it is what makes staff behaviour consistent when the owner is on holiday, and it is increasingly what your insurer asks to see.
Source: Statistics Canada, The Daily, 21 October 2024. https://www150.statcan.gc.ca/n1/daily-quotidien/241021/dq241021a-eng.htm
The five controls that stop most of it
1. A second step on every account that touches email
Multi-factor authentication (MFA) is the prompt after the password: a code, or an approval in an app. Turning it on across your Microsoft 365 tenant removes the single most common path in.
Two details matter more than the switch itself. Use an app prompt or a hardware key rather than text messages where you can, because phone numbers can be ported away from you. And turn off the older sign-in methods that bypass the prompt entirely, which is a setting most tenants still have enabled from years ago.
You can turn this on yourself. Budget an afternoon for staff registration and a week of grumbling.
2. Nobody does daily work as an administrator
The account you read mail with should not be the account that can reset everyone’s password. Give administrators a second, separate login used only for admin tasks, with its own second step.
While you are in there, check every mailbox for forwarding rules and for rules that move mail into obscure folders. That is the fingerprint of step three above, and finding one is how you catch an intrusion that is already underway.
3. Back up Microsoft 365 separately
Microsoft keeps your service running. Microsoft does not keep a long term backup of your mailboxes and files for you, and the retention windows in the standard agreement are shorter than most owners assume.
If a mailbox is emptied, or a SharePoint library is wiped by a staff member on their last day, you want a copy that lives outside the tenant. That is a separate product and a separate line on the invoice. It is the cheapest insurance in Microsoft 365 and almost nobody has it until the first incident.
4. Retire anything the vendor no longer patches
The Canadian Centre for Cyber Security publishes guidance on obsolete products (ITSAP.00.095, updated 7 July 2026). Its position is direct: “Continuing to use obsolete products will always carry risk,” and replacement, rather than workarounds, is the preferred response.
The guidance also says to prioritise internet-facing devices, naming firewalls, routers and wireless access points as the highest risk category. That matches what we find on site. The oldest, least loved box in the building is usually the one with a public address on it.
Two practical moves. Keep a list of your equipment with the vendor’s end of support date beside each item. And begin planning the replacement when the vendor announces end of sale, not when support actually ends, because that gives you a budget year instead of an emergency.
Source: Canadian Centre for Cyber Security, ITSAP.00.095, updated 7 July 2026. https://www.cyber.gc.ca/en/guidance/obsolete-products-itsap00095
5. A written rule for money movement
This is the control that costs nothing and stops the specific attack described above.
Write down one rule and put it on the wall by the bookkeeper’s desk: no change to banking details, for any supplier or customer, takes effect until somebody phones the other party on a number we already had on file before the request arrived. Not the number in the email. Not the number in the new invoice.
Add a second rule for internal requests. Any payment instruction that arrives by email from an owner or manager gets verified in person or by phone if it is over an amount you set.
That is your written policy started. It is two paragraphs and it will do more than most of what gets sold as security.
What this means for your building
Take a fifty person distribution business in Ajax with an office at the front of the warehouse. There is a bookkeeper, a general manager, a shared accounts@ mailbox that four people use, and a camera recorder in the electrical room that an installer put in years ago with remote viewing enabled.
The realistic bad day is not somebody breaching the warehouse network. It is the shared accounts@ mailbox, because shared mailboxes with a common password are the accounts nobody registers for a second step. From there, one changed banking detail on a repeat customer invoice, and forty thousand dollars goes somewhere it does not come back from.
The camera recorder is the second problem, quietly. Older recorders with a port open to the internet and firmware the manufacturer stopped updating are a standing invitation, and they sit on the same network as everything else.
Neither of those is a sophisticated attack. Both are fixed in an afternoon by somebody who knows where to look.
What to do about it
- Turn on multi-factor authentication for every user in Microsoft 365, including the shared mailboxes and the owner. Do this before anything else.
- Check every mailbox for forwarding rules and hidden move rules. If you find one you did not create, treat it as a live incident and reset that account’s password immediately.
- Write the payment verification rule, print it, and tell the person who pays invoices that they will never be in trouble for making the phone call.
- Give administrators separate admin accounts and stop using global admin for daily email.
- List every device that touches the internet: firewall, router, access points, camera recorder, anything with remote access. Find the vendor’s support end date for each.
- Add third party backup for Microsoft 365.
Steps one through three are owner and office manager work with no technician required. Steps four through six are where an outside hand helps, especially the device audit, because knowing what is exposed usually means looking at the firewall configuration rather than the box itself. That is normal scope for a cybersecurity review or an ongoing managed IT arrangement.
Want this scoped for your site?
Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.
Before you call
We are too small to be a target. Is that not true?
It is true that nobody is targeting you personally. It is also irrelevant. The attacks that hit small businesses are automated and untargeted: a list of stolen passwords tried against Microsoft logins at scale. Being small does not remove you from the list, it just means nobody chose you.
Do we need a security product, or is this configuration?
Mostly configuration. Of the five controls above, four are settings and habits inside software you already pay for. Only the Microsoft 365 backup is a genuine new purchase for most businesses.
Do we need a written policy if we are ten people?
You need the payment verification rule in writing. A longer policy becomes worth the effort when you start filling in insurance renewals or customer security questionnaires, because both ask what you have documented rather than what you do.
Will multi-factor authentication slow everybody down?
For about a week. After enrolment, most staff see a prompt occasionally rather than daily, because trusted devices stay trusted. The complaints stop faster than you expect.