Cybersecurity

Your small business is in the crosshairs. Are you truly protected?

Your small business is in the crosshairs. Are you truly protected?

72% of Canadian small and medium-sized businesses (SMEs) experienced a cyberattack in 2024, a 9-percentage-point increase from the previous year. And most of them thought they were adequately protected. Here’s the reality on the ground, backed by the numbers.

72 %
Canadian small and medium-sized businesses were hit by a cyberattack in 2024
63 %
Quebec SMEs targeted over the past year
60 k$
Average ransom paid in Canada — and only 60% of the data recovered

The Situation in Quebec

Cybercriminals don't distinguish between large companies and small and medium-sized businesses

If you think cyberattacks only target large corporations, the numbers prove you wrong. According to the 2023 KPMG survey, 63% of Quebec SMEs were attacked in the past year. And the situation is getting worse: in 2024, that figure reached 72% across Canada.

The problem isn’t that SMEs are careless. It’s that they’re less equipped to defend themselves; 65% say they lack the qualified staff to manage cybersecurity, and 70% don’t have the financial resources to invest in appropriate solutions.

As a result, they become prime targets. They’re easier to attack and less likely to fight back.

🇨🇦 STATISTICS CANADA — 2023 SURVEY

In 2023, total cyber incident recovery costs in Canada doubled compared to 2021. Canadian businesses are paying increasingly higher costs to recover from attacks that could have been prevented.

Threats in numbers

The 4 Threats That Are Crippling Quebec's Small and Medium-Sized Businesses

These attacks don't exploit highly complex flaws. They capitalize on everyday vulnerabilities—an email that wasn't properly verified, a reused password, an outdated system.

Ransomware

59 %

Canadian companies that have fallen victim to a ransomware attack. Your data is encrypted, your operations are paralyzed.

Phishing

95%

Cybersecurity incidents often start with a phishing email. It’s the most common—and most effective—point of entry.

Weak Passwords

74%

Many Quebec SMEs have aging systems or infrastructure that make them vulnerable to credential stuffing attacks.

Unsecured devices

70%

Many Canadian small and medium-sized businesses lack the staff to monitor their systems. Remote work, personal devices, and public Wi-Fi: all of these are open doors to security breaches.

Understanding to Protect Yourself

How Ransomware Works and Why $160,000 Isn't Enough

Ransomware doesn't strike as it does in the movies. It sneaks in, spreads silently, and strikes when you're most vulnerable.

Anatomy of a Ransomware Attack
1

Infiltration — Day 1

An employee clicks on a link in an email that appears to be from your supplier, Revenu Québec, or even your bank. The software installs itself in the background.

2

Silent Spread — Days 2–14

The software maps your network, identifies your backups and your most sensitive data, and spreads without triggering any alarms.

3

Activation — D-Day

All your data is encrypted simultaneously. A message appears: Pay in cryptocurrency within 48 hours or lose everything. Your operations come to a complete halt.

4

The True Cost — Coming Weeks

Even when you pay for it, on average only 60% of the data is recovered. Add to that weeks of downtime, recovery costs, reputational damage, and legal obligations (Bill 25).

⚠️ What No One Tells You

66% of Canadian small and medium-sized businesses have no plan in place in the event of a ransomware attack—according to the 2024 KPMG survey. It’s not a lack of willingness. It’s a lack of time, resources, and often information about available solutions.

Legal Obligation

Act 25: A Requirement, Not an Option

Since September 2023, Act 25 has been fully in effect in Quebec. It applies to all businesses that collect personal data, regardless of their size. Whether it’s a customer contact list, an email list, or employee files—this applies to you.

Designated Manager

You must appoint a privacy officer and publish their contact information.

Incident Log

Any privacy incident must be recorded in a log and assessed according to specific criteria.

Mandatory Notification

In the event of a breach that poses a serious risk, you must notify the CAI and the affected individuals.

Heavy fines

Violations may result in fines of up to $25 million or 4% of global revenue.

Compliance with Act 25 is not just a legal obligation; it also demonstrates your commitment to your clients and partners. Eosium helps you assess your compliance and implement the necessary measures.

Your next step won't cost you a thing.

A free 30-minute consultation to understand your current situation, identify your top vulnerabilities, and determine what to prioritize. Let's talk about it!   Book a call →