Most cyberattacks on small and medium-sized Canadian businesses aren't the work of elite hackers. They're opportunistic — automated scripts probing for the same predictable vulnerabilities, over and over. After conducting security assessments for hundreds of Canadian businesses, we see the same five mistakes nearly every time.
1. No Multi-Factor Authentication
Single-factor authentication (username + password) is the lowest-hanging fruit for attackers. Credential stuffing attacks — where leaked passwords from one breach are tried on other services — succeed because most people reuse passwords.
The fix: Enable MFA on every business-critical account: Microsoft 365, Google Workspace, your banking portal, your cloud infrastructure. Authenticator apps (Microsoft Authenticator, Google Authenticator) are more secure than SMS codes. This single change blocks over 99% of automated credential attacks.
2. Unpatched Software and Operating Systems
Patch Tuesday exists for a reason. When Microsoft or a software vendor releases a security patch, they're also publishing a roadmap for every attacker who reads the security bulletin. Unpatched systems are the most commonly exploited attack surface in SMB breaches.
The fix: Enable automatic updates for operating systems. For third-party software — browsers, office suites, accounting tools — use a patch management solution or set a weekly calendar reminder to check for updates. Managed IT clients at Cleva get automated patching included in their service level.
3. No Endpoint Detection and Response (EDR)
Traditional antivirus compares files against a list of known bad signatures. Modern malware is polymorphic — it changes its signature with every deployment to evade signature-based detection.
The fix: Replace legacy antivirus with an EDR solution like Microsoft Defender for Business, CrowdStrike Falcon Go, or SentinelOne. These tools use behavioral analysis to catch threats that signature-based tools miss. For most Canadian SMBs, Microsoft Defender for Business (included in Microsoft 365 Business Premium) is a cost-effective starting point.
4. No Offsite or Immutable Backups
Ransomware operators know where your backups are. If your backup destination is mounted as a network drive or sits in the same environment as your production data, it will be encrypted along with everything else.
The fix: Implement the 3-2-1 backup rule: 3 copies of data, on 2 different media types, with 1 stored offsite. For Canadian businesses, this typically means local NAS + cloud backup (Azure Backup, Veeam Cloud Connect) with immutability enabled. Test your restores quarterly — a backup you haven't tested is a backup you don't have.
5. Untrained Employees
Phishing remains the #1 initial access vector. No technical control fully substitutes for a workforce that can recognize a suspicious email. The Canadian Anti-Fraud Centre reported $569 million in fraud losses in 2023, with business email compromise accounting for the largest share.
The fix: Run quarterly phishing simulations using a platform like KnowBe4 or Proofpoint Security Awareness Training. Track click rates and tailor training to your highest-risk users. Supplement with a clear policy: if in doubt, call the sender directly — never reply to the email to verify it.
Where to Start
If you're reading this and recognizing your organization in more than two of the above, start here:
- Enable MFA this week — it costs nothing on most platforms
- Schedule an EDR deployment for next month
- Audit your backup destinations and test one restore
If you want a professional assessment, Cleva IT offers a no-obligation Security Gap Analysis for Canadian businesses. We'll map your current posture against the NIST Cybersecurity Framework and give you a prioritized remediation roadmap.