Cyberwall Blog · September 24, 2026

Your Best Defence Is You. But Who Is "YOU"?

One client was back to full functionality within 48 hours of a serious cyber incident. Another lost three weeks of business data. The difference wasn't luck, and it wasn't the training their staff took in October. It came down to four controls that need a decision from leadership, not the front desk.

By Alex Plotkin, CEO

One of our clients was back to full functionality within 48 hours of a serious cyber incident. In another, some systems could only be restored from a backup about a month old. Three weeks of business data was gone. Work out what three weeks of lost invoices, orders and payroll records would cost you to rebuild. The difference was not luck, and it was not the training their staff took in October.

Every October, something predictable happens in small and mid-sized companies across Canada. A poster goes up in the kitchen. A training module gets assigned. Someone runs a phishing simulation. Then it is November.

None of that is wasted effort. Cyber Security Awareness Month is a worthwhile campaign, and this year’s Government Cyber Safe theme, “Your best defence is You,” is a good one. The question is who the “you” refers to in your business.

Verizon’s 2026 Data Breach Report found that exploiting unpatched software is now the most common route: 31% of breaches, up from 20% the year before. Stolen credentials appear somewhere in 39%. Neither is something an employee can catch. A missed patch never appears in anyone’s inbox, and neither does a stolen password on a legitimate login page.

The phishing that still lands no longer looks the way people were trained to expect. For years the advice was to watch for typos and awkward grammar. But AI has removed those signals. Worse, staff now believe a well-written, correctly branded email is the safe one.

Statistics Canada reports that recovery costs for Canadian businesses hit by cyber incidents have doubled to $1.2 billion, while spending on prevention has risen only modestly.

Which brings the question back to “YOU.” The controls that matter most cannot be handled at the front desk. They require a decision from someone with authority.

Patching. It needs an owner and a date. “IT takes care of it” is not good enough. Name the person, set the window, and decide who signs off on the remediation report.

Multi-factor authentication. It has to cover anything, especially that touches money. Most organisations have it on email. Fewer have it on the accounting platform, payroll, banking portal and remote access, where the funds move.

Supplier banking changes. Any change to a supplier’s banking details should trigger a phone call to the number already on file, not the one in the email. Canadians reported a record $704 million in fraud losses last year, and the Competition Bureau estimates that fewer than 1 in 10 frauds are reported at all.

Backups. They need to be restored and validated at least once every few months. Until a restore has been proven, what you have is a backup record, not a recovery plan. When did someone last watch a restore of your main file server, start to finish?

There is a regulatory dimension too. If a breach included personal or financial information, PIPEDA requires notification to the Privacy Commissioner and to the individuals affected. That obligation sits with the business, not the IT department.

A better use of October than a poster: book an hour with whoever runs your IT and work through the four items above. The Canadian Centre for Cyber Security publishes “Baseline Cyber Security Controls for SMB”, a thirteen item guide. Employee awareness training is one of the thirteen.

Reading the list is the straightforward part. The harder question is whether the controls you believe are in place are actually configured, current and working. A checklist cannot answer that.

At Cyberwall, we help organisations assess cybersecurity risks and implement the right security controls. If you would like to understand where your organization stands, we are here to help.

Not ready to wait on a blog post?

Book a call and get a straight answer for your specific situation, no searching required.