A cybersecurity checklist for a small business in BC can follow the Canadian Centre for Cyber Security’s Baseline cyber security controls for small and medium organizations. It sets out 13 controls, from an incident response plan to multifactor authentication (MFA), backups and access control, for organizations with fewer than 500 employees, and aims to deliver 80% of the benefit for 20% of the effort.
This checklist follows those controls in order, adds the Cyber Centre’s newer advice on MFA, Wi-Fi and backups, and covers BC privacy law. BC’s Personal Information Protection Act (PIPA) requires reasonable security but, as of September 2026, doesn’t require breach notification; federal PIPEDA does require reporting breaches that create a real risk of significant harm.
Start with the Cyber Centre’s baseline controls
The Cyber Centre built the baseline controls around cybercrime, which it judged the threat most likely to affect small and medium organizations. The current version, V1.2, was last updated in 2020, and the Cyber Centre says its information remains valid. Before the controls themselves, it asks you to:
- decide which systems are in scope, including cloud and contracted services;
- assess the harm if your information were disclosed, altered or unavailable;
- identify your main cyber threat;
- name someone in a leadership role who is responsible for IT security; and
- commit to improving step by step.
They’re designed for medium or lower potential harm; organizations facing more serious harm or advanced threats need more comprehensive measures.
Controls 1–4: response plan, patching, security software and configuration
1. Develop an incident response plan
Write down who handles an incident and how to reach outside help, stakeholders and regulators, and keep an up-to-date printed copy for when systems are down. The Cyber Centre’s incident response guidance adds a backup contact for each team member and says to test and revise the plan every year.
2. Automatically patch operating systems and applications
Turn on automatic updates for all software and hardware, including routers and other network devices, and replace products that no longer receive updates. Windows 10 and Office 2016 and 2019, for example, reached end of support on October 14, 2025.
3. Enable security software
Run anti-malware that updates and scans automatically on every connected device, and turn on the software firewalls built into those devices.
4. Securely configure devices
Change every default administrator password, turn off features you don’t use and turn on the security features you need.
Controls 5–7: authentication, training and backups
5. Use strong user authentication
Use MFA wherever possible, and require it for financial accounts, system and cloud administrators, other privileged users and senior executives. Force password changes only when there’s a sign of compromise, and set clear rules on password length, reuse and password managers. The Cyber Centre’s 2024 MFA guidance strongly recommends phishing-resistant methods, such as FIDO-based ones, along with number matching and limits on repeated sign-in prompts. If you use Microsoft 365, security defaults turn on MFA at no extra cost; our Microsoft 365 migration checklist covers the options.
6. Provide employee awareness training
Train staff on passwords, spotting malicious emails and links, approved software, and safe use of the internet and social media. The Cyber Centre’s phishing guidance adds phishing simulations and a clear internal process for verifying and reporting suspicious messages. Teach people to confirm unusual requests, such as new banking details, through a separate channel.
7. Back up and encrypt data
Back up essential business information, keep backups encrypted with access limited to the people who restore them, and check that restores work. The baseline says long-term backups, such as weekly ones, must be stored offline, while frequent ones, such as daily backups, may stay online. The Cyber Centre’s ransomware playbook goes further: keep two or more backups offline, test them on a regular schedule such as monthly, and scan a backup for malware before restoring from it. Some cloud backup services offer immutable storage, which Microsoft defines as storage that can’t be altered, deleted or overwritten for a specified period.
Controls 8–10: mobile devices, network and email, cloud services
8. Secure mobility
Decide whether staff use company-owned or personal phones, keep work and personal data separate, allow apps only from trusted sources and require encryption. Consider an enterprise mobility management tool, and tell staff to avoid unknown and open Wi-Fi networks.
9. Establish basic perimeter defences
Put a firewall between your network and the internet, use a DNS firewall to block known malicious domains, and require a VPN with MFA for remote access. For Wi-Fi, the baseline asks for WPA2 or better, preferably WPA2-Enterprise; the Cyber Centre’s 2024 Wi-Fi guidance calls WPA3 the strongest encryption currently available. Change default router passwords, never connect guest Wi-Fi to your internal network, and isolate point-of-sale systems behind a firewall.
This control also covers email: filter incoming and outgoing mail and implement DMARC. The Cyber Centre’s email domain protection guidance explains the three records:
- SPF lists the IP addresses allowed to send email on your domain’s behalf.
- DKIM signs outgoing messages with a cryptographic signature that receivers check against a public key published in your DNS.
- DMARC requires SPF or DKIM to pass for the domain in the visible From address, tells receivers what to do with messages that fail, and lets receivers send you reports.
The Cyber Centre says complete protection needs all three, configured to tell recipients to reject inauthentic messages, and that domains you don’t use for email should be protected too.
10. Secure cloud and outsourced IT services
Understand how each provider handles, accesses and stores your sensitive information, and protect cloud admin accounts with MFA, separate from your internal admin accounts. The baseline also says to require a SOC 3 report from cloud providers. For vendors with access to your systems, the Cyber Centre’s 2025 supply chain guidance suggests asking what ongoing connections they keep and how quickly they’ll tell you about a cyber event, writing notification deadlines into contracts and re-evaluating suppliers regularly.
Controls 11–13: websites, access control and portable media
11. Secure websites
Make sure your website addresses the OWASP Top 10 vulnerabilities and that you know which level of the OWASP Application Security Verification Standard it needs to meet. If someone else builds or runs your site, make that a contract requirement.
12. Implement access control and authorization
Give each person their own account with only the access their job needs, use admin accounts for admin work only, not email or web browsing, and remove accounts that are no longer needed. The Cyber Centre’s guidance on administrative privileges adds MFA for every admin account and removing special privileges once they’re not needed.
Make offboarding a routine. The Cyber Centre’s security control catalogue lists disabling access, revoking credentials, collecting tokens, keys and ID cards, and keeping access to the information the person managed. In some terminations, it says to consider disabling accounts before the person is told. Change shared passwords they knew, too.
13. Secure portable media
Allow only encrypted USB drives and other portable media that the business owns and tracks, and wipe or destroy them before disposal.
The printable cybersecurity checklist
Small business cybersecurity checklist
- Name the person responsible for IT security and list every system in scope, including cloud services.
- 1. Write an incident response plan, keep a printed copy and test it every year.
- 2. Turn on automatic updates and replace unsupported software and hardware.
- 3. Run self-updating anti-malware and built-in firewalls on every device.
- 4. Change default passwords and turn off unused features.
- 5. Require MFA wherever possible, starting with admin, cloud and financial accounts.
- 6. Train staff on phishing and give them a simple way to report it.
- 7. Keep encrypted backups, including offline copies, and test restores regularly.
- 8. Choose a phone ownership model, separate work data and require encryption.
- 9. Use a firewall, secure Wi-Fi, a separate guest network, and SPF, DKIM and DMARC set to reject.
- 10. Check how cloud providers and vendors access your data, and protect cloud admin accounts with MFA.
- 11. Check your website against the OWASP Top 10.
- 12. Apply least privilege, keep admin accounts for admin work and offboard people promptly.
- 13. Allow only company-owned, encrypted portable media, and wipe it before disposal.
- Keep records of MFA enrolment, backup tests and training.
Cyber insurance questionnaires
The baseline suggests considering a cyber insurance policy that covers incident response and recovery, not just liability. The Insurance Bureau of Canada says most cyber insurers look at security protocols and best practices when assessing risk. Its 2023 self-assessment for small businesses used questions similar to those on an application: whether you collect and store customers’ personal information, what security procedures you have and how often employees get cyber safety training.
Answer every question accurately, and keep records such as MFA enrolment reports, backup test results and training dates to support your answers.
BC privacy law and what to do after a breach
Which law applies
BC’s PIPA applies to private-sector organizations in the province, and section 34 requires “reasonable security arrangements” to protect personal information. PIPA doesn’t apply where the federal Personal Information Protection and Electronic Documents Act (PIPEDA) does. The federal privacy commissioner says PIPEDA always applies to federally regulated organizations, such as banks, airlines and telecommunications companies, and to businesses handling personal information that crosses provincial or national borders in the course of commercial activity.
After a breach under PIPA
PIPA has no mandatory breach notification (we checked the law as current to September 15, 2026), but BC’s Information and Privacy Commissioner is calling for it and strongly recommends reporting breaches as a best practice. Its guidance for private organizations sets out four steps:
- Contain the breach: stop the unauthorized access, recover records, change access codes and call police if theft or another crime is involved, without destroying evidence.
- Evaluate the risks: what information was involved, how sensitive it is, how many people are affected and what harm could follow.
- Notify: tell affected individuals as soon as possible when that can help them avoid or reduce harm, directly where you can, and consider whether insurers, regulators or the commissioner should also know.
- Prevent: investigate the cause, fix it, update policies and train staff.
If PIPEDA applies
You must report to the federal commissioner any breach of security safeguards that creates a real risk of significant harm, notify affected individuals as soon as feasible, notify organizations that could reduce the harm, such as police or your payment processor, and keep a record of every breach for two years, whether or not it was reportable. Knowingly breaking these rules can lead to fines.
Report the cyber incident
Separately, report a cyber incident to the Cyber Centre if you need help recovering. That doesn’t start a criminal investigation, so contact local police if you need one. To report fraud or try to recover money, the Cyber Centre points businesses to the RCMP’s National Cybercrime and Fraud Reporting System.
Choosing a provider and what drives cost
Questions to ask
The Cyber Centre’s guidance for buyers of managed services suggests questions like these:
- How do your staff access our systems? Do they use MFA and separate admin accounts, and are their actions logged individually?
- How, and how quickly, will you tell us about a security incident?
- Where are our data, backups and logs stored?
- Can you show third-party evidence of your security, such as an ISO 27001 certificate or a SOC report?
- How do you vet your own suppliers, and how do we move our data if we leave?
You can also ask about CyberSecure Canada certification, which is based on the national standard CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations. The Standards Council of Canada accredits the certification bodies.
What drives cost
There’s no standard price; quotes are built from your environment and the scope you choose. The main drivers:
- Size: the number of users, devices, locations and cloud services to protect.
- Scope: a one-time assessment and fixes, or ongoing management and monitoring, and which hours are covered.
- Tools and licences: for example, Microsoft’s Canadian site lists Microsoft 365 Business Premium, which includes Defender for Business, at CAD $29.80 per user per month paid yearly, against $19.00 for Business Standard (versions with Teams, September 2026).
- Starting point: how much needs fixing first, such as unsupported computers or missing backups.
- Requirements: insurer questionnaires, client contracts or a certification audit.
Ask for quotes that list what’s included, the hours covered and what happens during an incident. Our cybersecurity service explains how YVR Technology helps businesses across Greater Vancouver and the Fraser Valley, and our managed IT services cost guide covers ongoing support pricing. Or get in touch.