The Real Cost of a Cyberattack for a Canadian SMB

Reviewed by IT Cares certified technicians · Updated July 2026

Canadian small business owner reviewing security audit documents and financial statements after a cyberattack, showing the real cost breakdown
The invoice for a cyberattack rarely stops at the ransom or the forensics bill — the largest costs often show up months later, in lost customers and higher premiums.

When a Canadian small or mid-sized business gets hit by ransomware or a data breach, the sticker-shock number people quote — the ransom demand, or the forensics invoice — is almost never the real total. The true cost of a cyberattack is made up of two very different kinds of expense: direct costs that show up as actual invoices in the weeks after an incident, and indirect costs that bleed out over the following 12 to 24 months in the form of customers who quietly stop calling, insurance renewal quotes that jump, and RFPs your business no longer gets shortlisted for. Most owners plan for the first category and are blindsided by the second, which is usually larger.

This guide breaks down both halves of that bill in Canadian-dollar terms, using patterns IT Cares has observed across SMB clients, published incident-cost research, and the regulatory obligations that apply specifically in Canada under PIPEDA and Quebec's Law 25. It's written for the owner of a 10-, 40-, or 100-person business who wants an honest number to plan around — not an enterprise CISO with a seven-figure security budget.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians. We work with Canadian SMBs before, during, and after security incidents — deploying protection, and also cleaning up after the fact when a client calls us mid-attack. The dollar ranges here reflect real patterns we've seen, not vendor marketing numbers designed to sell you a bigger security budget than you need.

What "Cost of a Cyberattack" Actually Includes

Ask a small business owner what a cyberattack costs and most will say "the ransom" or "fixing the computers." That's understandable — those are the costs you see first, the ones with an actual invoice attached. But for an SMB, the ransom or the IT remediation bill is frequently the smallest piece of the total cost, not the largest.

A more complete way to think about it is as two separate budgets you're forced to spend, on two different timelines:

For an SMB specifically, the balance between these two categories tends to skew harder toward indirect costs than most owners expect, precisely because small businesses depend disproportionately on relationships, referrals, and repeat business — the exact things a publicized breach damages most.

Why the True Cost Catches Most Owners Off Guard

There's a specific reason SMB owners consistently underestimate what an incident will cost, and it isn't naivety — it's a planning bias built into how invoices arrive. Direct costs land as concrete numbers with due dates: a forensics firm sends a bill, a law firm sends a bill, an insurer confirms a deductible. Those numbers are easy to plan around because they behave like every other business expense you've ever budgeted for. Indirect costs don't work that way. No one sends an invoice labelled "lost customer, month four" or "declined RFP, month nine." Those losses show up buried inside ordinary-looking revenue reports, months after the incident itself has been resolved and largely forgotten internally — which makes it genuinely difficult to connect cause and effect, even for an owner looking directly at the numbers.

This delay matters because it changes decision-making in the moment. A business owner staring at a $45,000 ransom demand is weighing that number against the cost of downtime this week — not against a customer relationship that quietly erodes over the following year. Every dollar figure in this guide is presented specifically to correct for that bias: not to replace the urgency of the direct costs, but to make sure the slower-moving, larger costs get weighed in the same decision.

Not sure where your business actually stands?

A security audit identifies the gaps that turn a phishing email into a six-figure incident — before it happens, not after.

Direct Costs: The Invoices That Arrive First

Ransom and extortion payments

For businesses hit by ransomware, the ransom demand is usually the first number anyone hears — and it's rarely the number actually paid. Attackers frequently set an initial demand knowing negotiation is expected, and Canadian SMBs that do end up paying commonly settle somewhere between $10,000 and $150,000 CAD, though demands against larger operations can run into the millions. Critically, paying the ransom does not guarantee recovery. A meaningful share of businesses that pay still don't receive a working decryption key, receive one that only partially works, or discover the attacker kept a copy of the stolen data regardless and demands a second payment not to leak it — a pattern known as double extortion that has become close to the industry norm rather than the exception. The Canadian Centre for Cyber Security explicitly advises against paying for exactly these reasons, alongside the fact that payment funds further criminal activity.

There's also a slower cost tied to the payment decision itself that's easy to miss: cryptocurrency has to be acquired, which for a business with no prior exposure to digital currency exchanges can take days and typically requires setting up new accounts under time pressure — days during which the business remains down and the daily downtime cost keeps accruing regardless of how quickly the ransom itself gets sourced.

Incident response and digital forensics fees

Before you can safely restore anything, someone needs to determine how the attacker got in, what they accessed, whether they're still inside your network, and what needs to be rebuilt versus simply cleaned. Professional incident response and forensics engagements for an SMB-scale breach typically run from $8,000 to $60,000 CAD, depending on how many systems are involved and whether the investigation needs to produce a formal report for insurers, regulators, or legal counsel. This is frequently a mandatory step for cyber insurance claims, not an optional add-on — most policies require a panel-approved forensics firm before they'll pay out.

The scope of a forensics engagement also tends to expand once investigators start looking, not shrink. A business that expects a quick confirmation of "yes, ransomware, here's the entry point" often ends up paying for a fuller investigation once the forensics team finds evidence the attacker had access for weeks before deploying the ransomware payload — which changes both the legal notification analysis and the total hours billed.

IT remediation and hardware replacement

Beyond forensics, someone has to actually rebuild: reimaging infected machines, restoring from backup, patching the vulnerability that let the attacker in, replacing hardware that's been compromised at a firmware level, and rebuilding servers from scratch in worse cases. For a small business this commonly runs $5,000 to $40,000 CAD; for a mid-sized business with more servers, more endpoints, and more complex infrastructure, $25,000 to $100,000+ CAD is realistic.

A detail that surprises many owners: remediation frequently costs more than simply restoring a working system, because "working again" and "actually secure" are different bars to clear. Rebuilding correctly means closing the vulnerability that let the attacker in in the first place — patching software, resetting every credential the attacker may have touched, and often replacing rather than simply reformatting hardware that could still contain a persistence mechanism. Skipping that step to save money is exactly how businesses end up hit a second time within the same year.

Legal fees

Legal counsel gets involved early in almost every serious incident — to advise on notification obligations, to review and negotiate with the insurer, to handle any ransom negotiation communications, and increasingly to manage exposure if a lawsuit from an affected customer or business partner follows. Legal fees for an SMB incident typically range from $5,000 for a straightforward, contained matter to $75,000+ CAD if litigation or a regulatory investigation follows.

Counsel experienced in breach response also plays a quieter but valuable role: managing communications so that internal incident notes and preliminary findings are covered appropriately, since poorly worded internal emails written in the panic of the first 48 hours have a way of resurfacing during a later regulatory review or lawsuit.

Regulatory notification costs

If personal information is involved, Canadian businesses have real legal obligations. Under PIPEDA (the federal law), any breach of security safeguards that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and to affected individuals. In Quebec, Law 25 imposes similar but distinct obligations, including notification to the Commission d'accès à l'information (CAI) and a public incident register businesses must maintain. The practical costs — legal review of what happened, drafting notices, mailing or emailing affected individuals, setting up a dedicated phone line or web page for questions, and in more serious cases offering credit monitoring — commonly run from $3,000 for a small, contained incident to $50,000+ CAD for a breach affecting thousands of records.

Businesses operating in more than one province need to account for the fact that these obligations don't perfectly overlap — a Quebec business with customers in Ontario may need to satisfy both PIPEDA and Law 25 requirements simultaneously, on different timelines, with different regulators, which is exactly the kind of complexity that drives up legal review time.

Extortion negotiation and crisis communications

Many businesses that engage with an attacker do so through a specialized ransomware negotiation firm rather than directly, both to protect the business from negotiation mistakes and because insurers frequently require it. These services typically add $5,000 to $25,000 CAD on top of whatever ransom is ultimately paid. Separately, a crisis communications consultant to help manage customer, staff, and sometimes media messaging can add another $3,000 to $15,000 CAD, particularly for a business with any public profile.

Temporary staff and contractor costs

While systems are down, someone still has to answer phones, process orders manually, and keep the business functioning. Businesses frequently bring in temporary staff or pay existing staff overtime to manage manual workarounds during an outage, and separately need contract IT staff or a managed services provider to support the rebuild if internal IT capacity isn't sufficient — together commonly adding $2,000 to $20,000 CAD depending on downtime length.

Owners of businesses without an in-house IT department often underestimate this line item most of all, because it's easy to assume "our regular computer guy will just fix it" without accounting for the fact that incident response is a specialized skill set most general IT support providers don't practice regularly — meaning the rebuild may require a second, more specialized vendor on top of whoever normally handles day-to-day support.

Indirect Costs: The Bill That Arrives Later — and Is Usually Bigger

Customer churn and lost repeat business

This is frequently the single largest cost of a cyberattack for an SMB, and it's the one owners most consistently underestimate because it never arrives as a single invoice — it shows up as a slow decline in repeat orders and renewals over the following year. Based on published breach research and patterns IT Cares has observed across clients, a business that experiences a publicized breach or a lengthy, visible outage typically sees 10% to 40% customer churn within twelve months, with the exact figure depending heavily on how sensitive the exposed data was, how the business communicated during the incident, and how easily customers can switch to a competitor. A consumer-facing retailer with easy alternatives sits at the higher end of that range; a B2B service provider with contracts and switching costs sits at the lower end — but rarely at zero.

How a business communicates during the incident meaningfully changes where it lands in that range. Customers who are notified promptly, given specific and honest information, and offered a clear remediation step (a password reset, credit monitoring, a direct contact for questions) churn noticeably less than customers who find out about a breach from a news report or a competitor before hearing anything from the business itself. Silence, or a notification that reads as vague and legally hedged rather than genuinely informative, tends to push churn toward the higher end of the range.

Reputational damage and lost future contracts

Beyond existing customers leaving, a known breach affects your ability to win new business. Increasingly, mid-size and enterprise clients — and virtually all government contracts — include a vendor security questionnaire or require cyber insurance and specific controls as a condition of doing business. A recent, known incident can disqualify a bidder outright during procurement, or trigger enough additional scrutiny that a smaller competitor without that history wins instead. This effect is genuinely difficult to put a precise number on, but for B2B service providers, contractors, and professional firms, it's frequently the largest single indirect cost over a multi-year horizon.

This cost also compounds in a way direct costs don't: a lost contract this year is also lost referral business and lost renewal revenue in every subsequent year that client relationship would have continued, which is why the multi-year total for a professional services firm can end up dwarfing everything else on this list even though no single year's loss looks dramatic in isolation.

Employee time, morale, and turnover

Incidents consume enormous amounts of staff time — not just IT staff during the technical response, but leadership managing communications, customer service handling angry calls, and finance managing the cash flow disruption. Beyond the direct time cost, the stress of a major incident measurably affects morale, and it's common for businesses to see elevated turnover in the six to twelve months following a serious breach, particularly among staff who felt directly implicated (an employee who clicked a phishing link, for instance) or who bore the brunt of the crisis response. Replacing and retraining even one or two mid-level employees commonly costs $15,000 to $40,000 CAD each when you account for recruiting, onboarding, and lost productivity during the transition.

How leadership handles the employee who "caused" the incident matters more than owners often expect for staff morale broadly. A public blame culture in the aftermath of a phishing-triggered breach tends to make the rest of the team quieter about reporting suspicious emails going forward — the opposite of what a business actually needs after an incident — while a response focused on process rather than individual fault tends to preserve the reporting culture that catches the next attempt earlier.

Higher cyber insurance premiums — or losing insurability

Cyber insurance renewal after a claim rarely comes back at the same price. It's common for premiums to increase 25% to 100%+ at the next renewal following a paid claim, and insurers frequently impose new conditions — mandatory MFA, endpoint detection and response, specific backup requirements — as a condition of continued coverage. In more severe cases, particularly for a business in a higher-risk industry or one with a second incident, insurers decline to renew coverage at all, which itself becomes a business cost: many client contracts and lending agreements now require proof of active cyber insurance.

Insurers underwrite renewal pricing largely off the same signal a forensics report already generated: what specifically failed, and whether the business fixed it. A renewal application that can point to concrete remediation — MFA now enforced everywhere, a new backup architecture, a completed security audit — genuinely does soften the premium increase compared to a business that simply asks to renew "as before" without demonstrating anything changed.

Lost productivity during downtime

Separate from the temporary staffing costs above, there's a pure lost-output cost to downtime itself — revenue that simply doesn't happen while systems are down, projects that slip, and billable work that can't be delivered. For a services business billing by the hour or the project, a week of significant disruption can represent a direct hit to revenue on top of every other cost on this list, distinct from what it costs to fix the underlying problem.

Cost of rebuilding trust and marketing recovery

After the technical rebuild is done, many businesses spend meaningfully on rebuilding market confidence — updated security messaging on their website, a renewed push on customer testimonials and case studies, sometimes a formal PR effort to control the narrative, and in some cases discounted pricing or added service guarantees offered specifically to retain nervous customers. This is real spend that doesn't show up in any incident-response budget line but is a direct consequence of the breach.

For businesses that rely heavily on word of mouth and local reputation — professional services, healthcare-adjacent practices, and retail chief among them — this category can stretch on longer than any other cost on this list, simply because trust rebuilds on a slower timeline than a server does.

Direct vs. Indirect Costs at a Glance

Cost TypeExamplesTypical Range (CAD)When It Hits
Ransom / extortion Ransom payment, negotiation fees, second-extortion demands $10,000 – $150,000+ Days 1–14
Forensics / incident response Root-cause investigation, insurer-mandated forensics report $8,000 – $60,000 Days 1–30
IT remediation & hardware Reimaging, rebuilding servers, replacing compromised hardware $5,000 – $100,000+ Weeks 1–6
Legal fees Notification advice, insurer negotiation, litigation defence $5,000 – $75,000+ Weeks 1–52
Regulatory notification PIPEDA/Law 25 notices, OPC/CAI reporting, credit monitoring $3,000 – $50,000+ Weeks 2–8
Temporary staff / contractors Overtime, manual workarounds, contract IT support $2,000 – $20,000 Weeks 1–4
Customer churn Lost repeat business, cancelled contracts, non-renewals 10%–40% of affected revenue Months 1–12
Lost future contracts Failed vendor security questionnaires, lost RFPs Highly variable — often largest long-term cost Months 3–36
Higher insurance premiums Renewal increase, new mandatory controls, non-renewal +25%–100%+ at renewal Months 6–18
Staff turnover Recruiting, onboarding, lost productivity replacing staff $15,000 – $40,000 per employee Months 3–18

Three Illustrative Canadian Scenarios

The following are composite scenarios built from patterns IT Cares has observed across SMB engagements — not real, individually identifiable clients — but the numbers and sequence of events reflect realistic outcomes for businesses of these sizes and industries.

Scenario 1: A 25-person Ontario manufacturing firm hit by ransomware

A mid-sized parts manufacturer near Kitchener had an employee open an infected attachment on a Friday afternoon. By Monday, production scheduling software, accounting, and file servers were all encrypted. The attacker demanded $80,000 USD in cryptocurrency. With no tested offline backup for the scheduling system, the company was down for 11 days — losing an estimated $6,000/day in production delays alone. After negotiation, they paid $45,000 CAD for a decryption key that worked on roughly 80% of encrypted files; the remainder had to be rebuilt manually from paper records and supplier re-sends. Total direct cost including forensics, remediation, and the ransom: roughly $140,000 CAD. Two long-standing customers, citing "supply reliability concerns," moved a portion of their orders to a competitor over the following six months — an estimated 15% revenue impact from that account relationship going forward.

Scenario 2: A 12-person Quebec accounting firm hit by business email compromise

An accounting firm in the Montreal area had a partner's email account compromised through a convincing phishing page. The attacker monitored the inbox for three weeks, then intercepted a legitimate client wire transfer instruction and redirected $95,000 CAD to a fraudulent account during a real estate closing. The firm's cyber insurance covered the majority of the loss after a deductible and a lengthy claims investigation, but the policy explicitly excluded coverage for the client's separate financial loss, leading to a difficult conversation and an eventual negotiated partial reimbursement to preserve the relationship. The firm also had to notify affected clients under Law 25 given the email exposure, adding roughly $8,000 CAD in legal and notification costs. The reputational cost proved harder to absorb than the financial one: in a business built entirely on trust with sensitive financial information, the firm lost two clients outright and spent the better part of a year rebuilding confidence with the rest.

Scenario 3: A 40-person BC retailer hit by a customer data breach

A multi-location retailer in the Lower Mainland discovered an unpatched e-commerce plugin had allowed attackers to access a database containing roughly 14,000 customer records, including names, addresses, and partial payment information. Forensics confirmed the exposure met the "real risk of significant harm" threshold under PIPEDA, triggering mandatory notification to the Office of the Privacy Commissioner and to all affected customers. Notification costs (legal review, mailing, a dedicated support line, and one year of credit monitoring offered to affected customers) totalled approximately $62,000 CAD. Roughly 22% of affected customers didn't make another purchase in the following year, a meaningfully larger effect on repeat business than the direct notification cost. At renewal, the retailer's cyber insurance premium increased by 60%, and the insurer required mandatory MFA and a web application firewall as a condition of continued coverage.

The pattern across all three scenarios

In every case, the direct, invoiced costs were significant — but the indirect costs (lost customers, a damaged relationship, a much higher insurance premium) ended up being comparable to or larger than the direct bill within twelve months. Budgeting only for "what the ransom might cost" consistently understates the real exposure.

What these three scenarios also share is a preventable root cause: an unpatched plugin, a phishing page convincing enough to fool an experienced professional, and a missing offline backup. None of these businesses were reckless or unusually careless by industry standards — they looked, on paper, like a typical Canadian SMB with a reasonably competent general IT setup. That's precisely the point: baseline security hygiene that would have cost a few thousand dollars a year would have either prevented the incident outright or dramatically shortened the recovery and reduced the indirect fallout in every one of these cases.

Is Your SMB Financially Exposed? Quick Self-Check

Work through this list honestly. Each unchecked box represents a real gap between what an incident would cost you and what you're currently prepared to absorb.

If you checked fewer than seven of these, your business is likely more financially exposed to a cyberattack than your current planning accounts for — worth a closer look before an incident forces the conversation.

What Should a Canadian SMB Budget for Cyber Resilience?

These are planning ranges, not quotes — actual cost depends on industry, data sensitivity, and existing infrastructure — but they're a reasonable starting point for budgeting conversations.

Business SizePrevention (per employee/year)Cyber Insurance (annual)Incident Response Retainer
Under 10 employees $150 – $400 $800 – $2,500 $0 – $2,000 (often skipped at this size)
10–50 employees $250 – $600 $2,000 – $8,000 $2,000 – $6,000/year
50–100 employees $400 – $900 $6,000 – $20,000+ $5,000 – $15,000/year

The math here is straightforward once you've seen the cost ranges above: spending even $500 per employee per year on prevention is dramatically cheaper than a single incident that costs $30,000 to $250,000 CAD once direct and indirect costs are combined. An incident response retainer in particular — a pre-negotiated agreement with a security firm to respond immediately rather than scrambling to find one during a live attack — is one of the highest-leverage line items on this list, since response speed correlates directly with downtime length, which correlates directly with cost.

It's worth being honest about how these budgets should shift over time rather than staying static. A business in its first year of taking security seriously should expect to spend closer to the top of these ranges, since it's typically starting from a gap-filled baseline — no MFA, no tested backup, no written incident response plan. Once those foundational gaps are closed, ongoing spend can often trend toward the middle or lower end of the range, since maintaining good posture costs less than building it from nothing. The mistake to avoid is treating any single year's spend as a one-time project rather than an ongoing line item, since new employees, new software, and new attacker techniques all continuously reopen gaps that were closed the year before.

Canadian Government Resources for SMB Cyber Resilience

Several Canadian government bodies offer free or subsidized support specifically aimed at small business, and they're underused relative to how genuinely useful they are.

If your business operates in Quebec, Law 25 imposes additional, distinct obligations beyond PIPEDA — our guide on Law 25 vs. PIPEDA for multi-province businesses breaks down exactly where the two frameworks differ and what that means for notification timelines and your incident register.

Want a straight answer on where you actually stand?

IT Cares' managed IT and cybersecurity plans are built specifically for Canadian SMBs — no enterprise-scale pricing, no jargon.

Frequently Asked Questions

How much does a cyberattack really cost a small business in Canada?
For a small Canadian business (under 50 employees), a serious incident — a ransomware attack or a data breach involving customer information — typically lands somewhere between $30,000 and $250,000 CAD once you add direct costs (forensics, remediation, legal, notification) and indirect costs (downtime, lost customers, higher insurance premiums) together. Larger incidents involving regulatory investigation, lawsuits, or a multi-week shutdown can run well past that. The direct, visible costs are usually only 40-60% of the true total.
Does cyber insurance cover ransomware payments in Canada?
Most Canadian cyber insurance policies do cover ransomware, but coverage isn't automatic or unconditional. Insurers typically require you to have had baseline controls in place (MFA, endpoint protection, patched systems, backups) at the time of the attack, and a growing number of policies now exclude or cap extortion payments, or require insurer approval before you pay. Some policies also carve out coverage if the ransomware is later attributed to a nation-state actor, under war exclusion clauses. Read your policy's specific ransomware and extortion clauses before you assume you're covered for the full amount.
Is a small business actually a realistic target for cyberattacks?
Yes, and in some ways small businesses are a more attractive target than large enterprises, not less. Most ransomware and phishing campaigns today are automated and opportunistic — they scan for any exposed, unpatched, or weakly protected system, not specifically Fortune 500 companies. Small businesses often have weaker defenses, no dedicated IT security staff, and are more likely to pay a smaller ransom quickly to get back online, which makes them statistically efficient targets even though the payout per victim is lower than for large enterprises.
What's the average downtime after a ransomware attack?
Industry data consistently puts average ransomware downtime somewhere between one and three weeks, though the range is wide. A well-prepared SMB with tested offline backups and an incident response plan can sometimes restore core operations within a few days. A business with no tested backup, no incident response plan, and systems that need to be rebuilt from scratch can be down for a month or longer, particularly if forensic investigators need to preserve systems as evidence before remediation can begin.
Should a small business ever pay a ransomware ransom?
Law enforcement agencies, including the Canadian Centre for Cyber Security, generally advise against paying, because payment doesn't guarantee you'll get a working decryption key, doesn't guarantee the attacker hasn't kept a copy of your data anyway, and directly funds further criminal activity. That said, a business without functioning backups facing total data loss sometimes concludes paying is the only path to survival, which is precisely why prevention and tested backups matter more than any decision made in the moment of a live attack.
How much does a data breach notification cost in Canada under PIPEDA or Law 25?
The notification process itself — legal review, drafting notices, mailing or emailing affected individuals, setting up a call centre or web page for questions, and reporting to the Office of the Privacy Commissioner of Canada or Quebec's CAI under Law 25 — commonly runs from a few thousand dollars for a small, contained breach to well over $50,000 CAD for a breach affecting thousands of records that requires credit monitoring or a dedicated response line. Fines for non-compliance with notification obligations are a separate and additional cost.
How much do customers actually churn after a company is breached?
Published research and IT Cares' own observations across SMB clients put typical customer churn after a publicized breach or major outage somewhere between 10% and 40% of the affected customer base within the following year, depending heavily on how the business communicates during the incident, how sensitive the exposed data was, and how competitive the customer's alternatives are. B2B clients with contracts and switching costs tend to churn less than consumer-facing businesses with easy alternatives.
Does a cyberattack affect a small business's ability to win future contracts?
Increasingly, yes. Many larger clients and government contracts now include vendor security questionnaires or require cyber insurance and specific controls as a condition of doing business, and a known recent breach can disqualify a bidder outright or trigger much closer scrutiny during procurement. This effect is harder to quantify than a ransom payment, but for B2B service providers it can be one of the largest indirect costs of an incident.
What should a small business budget per year for cyber resilience?
As a rough planning range, businesses under 10 employees typically spend $150 to $400 CAD per employee per year on baseline prevention (endpoint protection, backup, MFA, basic monitoring), businesses of 10-50 employees often land between $250 and $600 per employee once managed detection and an incident response retainer are added, and businesses of 50-100 employees frequently invest $400 to $900 per employee as compliance and cyber insurance requirements grow more demanding. These are planning ranges, not quotes — actual cost depends heavily on industry, data sensitivity, and existing infrastructure.

The Cheapest Time to Deal With This Is Before It Happens

A security audit costs a fraction of even the smallest incident on this page. Let IT Cares show you exactly where your gaps are — no jargon, no enterprise pricing.

Comments (3)

DR
Daniel R., Mississauga
July 23, 2026

The customer churn number is what got me. We budgeted for a ransom scenario but never thought about what happens to the client list afterward. Forwarding this to my partners.

MC
Mireille C., Laval
July 22, 2026

The accounting firm scenario hit close to home — we had a near miss with a wire transfer last year. Getting MFA fully enforced across the office next month, no more exceptions for "just this one client system."

KT
Kevin T., Surrey
July 21, 2026

Didn't realize insurance premiums jump that much after a claim. Worth reading the actual ransomware clause in our policy instead of just assuming we're covered.

Leave a Comment

Get Protected