Skip to main content

Security

Cybersecurity Checklist for Small Businesses in BC

A cybersecurity checklist for BC small businesses built on the Canadian Centre for Cyber Security’s baseline controls, plus what PIPA and PIPEDA require after a breach.

Updated By YVR Technology

A cybersecurity checklist for a small business in BC can follow the Canadian Centre for Cyber Security’s Baseline cyber security controls for small and medium organizations. It sets out 13 controls, from an incident response plan to multifactor authentication (MFA), backups and access control, for organizations with fewer than 500 employees, and aims to deliver 80% of the benefit for 20% of the effort.

This checklist follows those controls in order, adds the Cyber Centre’s newer advice on MFA, Wi-Fi and backups, and covers BC privacy law. BC’s Personal Information Protection Act (PIPA) requires reasonable security but, as of September 2026, doesn’t require breach notification; federal PIPEDA does require reporting breaches that create a real risk of significant harm.

Start with the Cyber Centre’s baseline controls

The Cyber Centre built the baseline controls around cybercrime, which it judged the threat most likely to affect small and medium organizations. The current version, V1.2, was last updated in 2020, and the Cyber Centre says its information remains valid. Before the controls themselves, it asks you to:

  • decide which systems are in scope, including cloud and contracted services;
  • assess the harm if your information were disclosed, altered or unavailable;
  • identify your main cyber threat;
  • name someone in a leadership role who is responsible for IT security; and
  • commit to improving step by step.

They’re designed for medium or lower potential harm; organizations facing more serious harm or advanced threats need more comprehensive measures.

Controls 1–4: response plan, patching, security software and configuration

1. Develop an incident response plan

Write down who handles an incident and how to reach outside help, stakeholders and regulators, and keep an up-to-date printed copy for when systems are down. The Cyber Centre’s incident response guidance adds a backup contact for each team member and says to test and revise the plan every year.

2. Automatically patch operating systems and applications

Turn on automatic updates for all software and hardware, including routers and other network devices, and replace products that no longer receive updates. Windows 10 and Office 2016 and 2019, for example, reached end of support on October 14, 2025.

3. Enable security software

Run anti-malware that updates and scans automatically on every connected device, and turn on the software firewalls built into those devices.

4. Securely configure devices

Change every default administrator password, turn off features you don’t use and turn on the security features you need.

Controls 5–7: authentication, training and backups

5. Use strong user authentication

Use MFA wherever possible, and require it for financial accounts, system and cloud administrators, other privileged users and senior executives. Force password changes only when there’s a sign of compromise, and set clear rules on password length, reuse and password managers. The Cyber Centre’s 2024 MFA guidance strongly recommends phishing-resistant methods, such as FIDO-based ones, along with number matching and limits on repeated sign-in prompts. If you use Microsoft 365, security defaults turn on MFA at no extra cost; our Microsoft 365 migration checklist covers the options.

6. Provide employee awareness training

Train staff on passwords, spotting malicious emails and links, approved software, and safe use of the internet and social media. The Cyber Centre’s phishing guidance adds phishing simulations and a clear internal process for verifying and reporting suspicious messages. Teach people to confirm unusual requests, such as new banking details, through a separate channel.

7. Back up and encrypt data

Back up essential business information, keep backups encrypted with access limited to the people who restore them, and check that restores work. The baseline says long-term backups, such as weekly ones, must be stored offline, while frequent ones, such as daily backups, may stay online. The Cyber Centre’s ransomware playbook goes further: keep two or more backups offline, test them on a regular schedule such as monthly, and scan a backup for malware before restoring from it. Some cloud backup services offer immutable storage, which Microsoft defines as storage that can’t be altered, deleted or overwritten for a specified period.

Controls 8–10: mobile devices, network and email, cloud services

8. Secure mobility

Decide whether staff use company-owned or personal phones, keep work and personal data separate, allow apps only from trusted sources and require encryption. Consider an enterprise mobility management tool, and tell staff to avoid unknown and open Wi-Fi networks.

9. Establish basic perimeter defences

Put a firewall between your network and the internet, use a DNS firewall to block known malicious domains, and require a VPN with MFA for remote access. For Wi-Fi, the baseline asks for WPA2 or better, preferably WPA2-Enterprise; the Cyber Centre’s 2024 Wi-Fi guidance calls WPA3 the strongest encryption currently available. Change default router passwords, never connect guest Wi-Fi to your internal network, and isolate point-of-sale systems behind a firewall.

This control also covers email: filter incoming and outgoing mail and implement DMARC. The Cyber Centre’s email domain protection guidance explains the three records:

  • SPF lists the IP addresses allowed to send email on your domain’s behalf.
  • DKIM signs outgoing messages with a cryptographic signature that receivers check against a public key published in your DNS.
  • DMARC requires SPF or DKIM to pass for the domain in the visible From address, tells receivers what to do with messages that fail, and lets receivers send you reports.

The Cyber Centre says complete protection needs all three, configured to tell recipients to reject inauthentic messages, and that domains you don’t use for email should be protected too.

10. Secure cloud and outsourced IT services

Understand how each provider handles, accesses and stores your sensitive information, and protect cloud admin accounts with MFA, separate from your internal admin accounts. The baseline also says to require a SOC 3 report from cloud providers. For vendors with access to your systems, the Cyber Centre’s 2025 supply chain guidance suggests asking what ongoing connections they keep and how quickly they’ll tell you about a cyber event, writing notification deadlines into contracts and re-evaluating suppliers regularly.

Controls 11–13: websites, access control and portable media

11. Secure websites

Make sure your website addresses the OWASP Top 10 vulnerabilities and that you know which level of the OWASP Application Security Verification Standard it needs to meet. If someone else builds or runs your site, make that a contract requirement.

12. Implement access control and authorization

Give each person their own account with only the access their job needs, use admin accounts for admin work only, not email or web browsing, and remove accounts that are no longer needed. The Cyber Centre’s guidance on administrative privileges adds MFA for every admin account and removing special privileges once they’re not needed.

Make offboarding a routine. The Cyber Centre’s security control catalogue lists disabling access, revoking credentials, collecting tokens, keys and ID cards, and keeping access to the information the person managed. In some terminations, it says to consider disabling accounts before the person is told. Change shared passwords they knew, too.

13. Secure portable media

Allow only encrypted USB drives and other portable media that the business owns and tracks, and wipe or destroy them before disposal.

The printable cybersecurity checklist

Small business cybersecurity checklist

  • Name the person responsible for IT security and list every system in scope, including cloud services.
  • 1. Write an incident response plan, keep a printed copy and test it every year.
  • 2. Turn on automatic updates and replace unsupported software and hardware.
  • 3. Run self-updating anti-malware and built-in firewalls on every device.
  • 4. Change default passwords and turn off unused features.
  • 5. Require MFA wherever possible, starting with admin, cloud and financial accounts.
  • 6. Train staff on phishing and give them a simple way to report it.
  • 7. Keep encrypted backups, including offline copies, and test restores regularly.
  • 8. Choose a phone ownership model, separate work data and require encryption.
  • 9. Use a firewall, secure Wi-Fi, a separate guest network, and SPF, DKIM and DMARC set to reject.
  • 10. Check how cloud providers and vendors access your data, and protect cloud admin accounts with MFA.
  • 11. Check your website against the OWASP Top 10.
  • 12. Apply least privilege, keep admin accounts for admin work and offboard people promptly.
  • 13. Allow only company-owned, encrypted portable media, and wipe it before disposal.
  • Keep records of MFA enrolment, backup tests and training.

Cyber insurance questionnaires

The baseline suggests considering a cyber insurance policy that covers incident response and recovery, not just liability. The Insurance Bureau of Canada says most cyber insurers look at security protocols and best practices when assessing risk. Its 2023 self-assessment for small businesses used questions similar to those on an application: whether you collect and store customers’ personal information, what security procedures you have and how often employees get cyber safety training.

Answer every question accurately, and keep records such as MFA enrolment reports, backup test results and training dates to support your answers.

BC privacy law and what to do after a breach

Which law applies

BC’s PIPA applies to private-sector organizations in the province, and section 34 requires “reasonable security arrangements” to protect personal information. PIPA doesn’t apply where the federal Personal Information Protection and Electronic Documents Act (PIPEDA) does. The federal privacy commissioner says PIPEDA always applies to federally regulated organizations, such as banks, airlines and telecommunications companies, and to businesses handling personal information that crosses provincial or national borders in the course of commercial activity.

After a breach under PIPA

PIPA has no mandatory breach notification (we checked the law as current to September 15, 2026), but BC’s Information and Privacy Commissioner is calling for it and strongly recommends reporting breaches as a best practice. Its guidance for private organizations sets out four steps:

  1. Contain the breach: stop the unauthorized access, recover records, change access codes and call police if theft or another crime is involved, without destroying evidence.
  2. Evaluate the risks: what information was involved, how sensitive it is, how many people are affected and what harm could follow.
  3. Notify: tell affected individuals as soon as possible when that can help them avoid or reduce harm, directly where you can, and consider whether insurers, regulators or the commissioner should also know.
  4. Prevent: investigate the cause, fix it, update policies and train staff.

If PIPEDA applies

You must report to the federal commissioner any breach of security safeguards that creates a real risk of significant harm, notify affected individuals as soon as feasible, notify organizations that could reduce the harm, such as police or your payment processor, and keep a record of every breach for two years, whether or not it was reportable. Knowingly breaking these rules can lead to fines.

Report the cyber incident

Separately, report a cyber incident to the Cyber Centre if you need help recovering. That doesn’t start a criminal investigation, so contact local police if you need one. To report fraud or try to recover money, the Cyber Centre points businesses to the RCMP’s National Cybercrime and Fraud Reporting System.

Choosing a provider and what drives cost

Questions to ask

The Cyber Centre’s guidance for buyers of managed services suggests questions like these:

  • How do your staff access our systems? Do they use MFA and separate admin accounts, and are their actions logged individually?
  • How, and how quickly, will you tell us about a security incident?
  • Where are our data, backups and logs stored?
  • Can you show third-party evidence of your security, such as an ISO 27001 certificate or a SOC report?
  • How do you vet your own suppliers, and how do we move our data if we leave?

You can also ask about CyberSecure Canada certification, which is based on the national standard CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations. The Standards Council of Canada accredits the certification bodies.

What drives cost

There’s no standard price; quotes are built from your environment and the scope you choose. The main drivers:

  • Size: the number of users, devices, locations and cloud services to protect.
  • Scope: a one-time assessment and fixes, or ongoing management and monitoring, and which hours are covered.
  • Tools and licences: for example, Microsoft’s Canadian site lists Microsoft 365 Business Premium, which includes Defender for Business, at CAD $29.80 per user per month paid yearly, against $19.00 for Business Standard (versions with Teams, September 2026).
  • Starting point: how much needs fixing first, such as unsupported computers or missing backups.
  • Requirements: insurer questionnaires, client contracts or a certification audit.

Ask for quotes that list what’s included, the hours covered and what happens during an incident. Our cybersecurity service explains how YVR Technology helps businesses across Greater Vancouver and the Fraser Valley, and our managed IT services cost guide covers ongoing support pricing. Or get in touch.

FAQ

Frequently asked questions

How much do cybersecurity services typically cost?

There's no standard price. Quotes depend on how many users, devices and locations you have, whether you want a one-time assessment or ongoing management and monitoring, which hours are covered, the security tools and licences involved, and how much needs fixing first. Ask each provider to list what's included and what happens during an incident. See our cybersecurity service.

How do you choose a reputable cybersecurity provider?

The Canadian Centre for Cyber Security suggests asking how the provider's staff access your systems, including MFA, separate admin accounts and logging, how quickly they'll tell you about an incident, where your data and backups are stored, and how you get your data back if you leave. Ask for third-party evidence such as an ISO 27001 certificate or SOC report, and whether they hold CyberSecure Canada certification.

What should a small business do after a data breach in BC?

Follow the BC privacy commissioner's four steps: contain the breach, evaluate the risks, notify affected people when that can help them avoid or reduce harm, and fix the cause. Contact police if a crime is involved. PIPA doesn't require breach reporting as of September 2026, but the commissioner strongly recommends it. If PIPEDA applies, reporting breaches that create a real risk of significant harm is mandatory.

Is privacy breach notification mandatory in BC?

Not under BC's Personal Information Protection Act as of September 2026. The BC commissioner continues to call for mandatory reporting and strongly recommends reporting breaches as a best practice. Organizations covered by federal PIPEDA, including federally regulated businesses and those handling personal information across provincial or national borders, must report breaches that create a real risk of significant harm. BC public bodies have separate mandatory rules.

What is CyberSecure Canada certification?

It's a certification for small and medium organizations based on the national standard CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations. Innovation, Science and Economic Development Canada stopped being the program authority on March 31, 2023, and now directs businesses to the Standards Council of Canada, which accredits the certification bodies. Certified organizations can display the CyberSecure Canada mark.

Where do you report a cyber attack in Canada?

The Canadian Centre for Cyber Security directs organizations that need help recovering from an incident, such as ransomware, to report it to the Cyber Centre. That doesn't start a criminal investigation, so contact local police if you need one. To report fraud or try to recover lost money, it points businesses to the RCMP's National Cybercrime and Fraud Reporting System. A privacy breach may also need reporting to a privacy commissioner.

Get in touch

Book a free consultation

Tell us about your business and what you need from technology. We reply within one business day.

  1. 01

    Tell us what's going on

    Send the form or call. A rough idea of your team size and current setup helps us come prepared.

  2. 02

    A 30-minute conversation

    We ask about your people, systems and goals, and flag anything urgent we notice along the way.

  3. 03

    A written proposal

    Clear scope, a plain-English plan and pricing laid out line by line. Nothing starts until you approve it.

Prefer to talk it through?

(778) 819-0730

Monday – Friday, 8:00 am – 5:00 pm

No obligation. We reply within one business day.

Call nowBook a consult