72% of Canadian small and medium-sized businesses (SMEs) experienced a cyberattack in 2024, a 9-percentage-point increase from the previous year. And most of them thought they were adequately protected. Here’s the reality on the ground, backed by the numbers.
The Situation in Quebec
Cybercriminals don't distinguish between large companies and small and medium-sized businesses
If you think cyberattacks only target large corporations, the numbers prove you wrong. According to the 2023 KPMG survey, 63% of Quebec SMEs were attacked in the past year. And the situation is getting worse: in 2024, that figure reached 72% across Canada.
The problem isn’t that SMEs are careless. It’s that they’re less equipped to defend themselves; 65% say they lack the qualified staff to manage cybersecurity, and 70% don’t have the financial resources to invest in appropriate solutions.
As a result, they become prime targets. They’re easier to attack and less likely to fight back.
In 2023, total cyber incident recovery costs in Canada doubled compared to 2021. Canadian businesses are paying increasingly higher costs to recover from attacks that could have been prevented.
Threats in numbers
The 4 Threats That Are Crippling Quebec's Small and Medium-Sized Businesses
These attacks don't exploit highly complex flaws. They capitalize on everyday vulnerabilities—an email that wasn't properly verified, a reused password, an outdated system.
59 %
Canadian companies that have fallen victim to a ransomware attack. Your data is encrypted, your operations are paralyzed.
95%
Cybersecurity incidents often start with a phishing email. It’s the most common—and most effective—point of entry.
74%
Many Quebec SMEs have aging systems or infrastructure that make them vulnerable to credential stuffing attacks.
70%
Many Canadian small and medium-sized businesses lack the staff to monitor their systems. Remote work, personal devices, and public Wi-Fi: all of these are open doors to security breaches.
Understanding to Protect Yourself
How Ransomware Works and Why $160,000 Isn't Enough
Ransomware doesn't strike as it does in the movies. It sneaks in, spreads silently, and strikes when you're most vulnerable.
Infiltration — Day 1
An employee clicks on a link in an email that appears to be from your supplier, Revenu Québec, or even your bank. The software installs itself in the background.
Silent Spread — Days 2–14
The software maps your network, identifies your backups and your most sensitive data, and spreads without triggering any alarms.
Activation — D-Day
All your data is encrypted simultaneously. A message appears: Pay in cryptocurrency within 48 hours or lose everything. Your operations come to a complete halt.
The True Cost — Coming Weeks
Even when you pay for it, on average only 60% of the data is recovered. Add to that weeks of downtime, recovery costs, reputational damage, and legal obligations (Bill 25).
66% of Canadian small and medium-sized businesses have no plan in place in the event of a ransomware attack—according to the 2024 KPMG survey. It’s not a lack of willingness. It’s a lack of time, resources, and often information about available solutions.
Legal Obligation
Act 25: A Requirement, Not an Option
Since September 2023, Act 25 has been fully in effect in Quebec. It applies to all businesses that collect personal data, regardless of their size. Whether it’s a customer contact list, an email list, or employee files—this applies to you.
Designated Manager
You must appoint a privacy officer and publish their contact information.
Incident Log
Any privacy incident must be recorded in a log and assessed according to specific criteria.
Mandatory Notification
In the event of a breach that poses a serious risk, you must notify the CAI and the affected individuals.
Heavy fines
Violations may result in fines of up to $25 million or 4% of global revenue.
Compliance with Act 25 is not just a legal obligation; it also demonstrates your commitment to your clients and partners. Eosium helps you assess your compliance and implement the necessary measures.