“We’re too small to interest hackers.” That’s the sentence cybersecurity professionals hear most often from Quebec SMEs, and it’s the one that costs the most.
Key points
- Targeting is automated: it doesn’t check your headcount or your industry.
- The attacker’s economics favour the least protected organizations.
- Six controls, realistic on an SME budget, intercept most scenarios.
- A backup that has never been restored is an assumption, not a control.
Does the risk depend on your size?
No. In its 2025-2027 Ransomware Threat Overview, the Canadian Centre for Cyber Security confirms that ransomware attacks continue to rise in Canada and that all Canadian organizations are at risk, regardless of size.
The same organization notes that phishing and stolen credentials remain the two dominant initial access vectors: the two most mundane entry points there are. Understanding why SMEs have become a preferred target isn’t an academic exercise; it’s the prerequisite for investing in the right place, on an SME budget.
Why you, specifically?
Because ransomware has become an organized franchise industry. Groups develop the tools and extortion infrastructure, then lease them to affiliates for a percentage of the ransoms. This industrialization has three direct consequences for the least protected organizations.
1. Targeting is largely automated. Scans that look for unpatched remote access, an exposed remote desktop, or a vulnerable website make no distinction between a ten-employee company and a multinational. They exploit the flaw wherever it sits.
2. The economics favour SMEs. A large enterprise has detection teams, proven backups, and negotiators. An SME is statistically less protected, more dependent on its systems to operate, and therefore more likely to pay quickly. Several modest ransoms take less effort than one large ransom contested for weeks.
3. You’re also a path to something bigger. An SME that supplies a major client is a doorway into that client, and this quickly turns into a contractual requirement from your customers.
The Canadian Centre for Cyber Security also expects ransomware operators to intensify their extortion tactics over the coming years, refining the pressure applied to victims.
What does an attack look like, from a leadership perspective?
In five stages, each offering a point of interception. Initial access, installation and privilege escalation, data exfiltration, encryption, then pressure. The longest phase is invisible: the attacker often stays in the network for days or weeks before encrypting anything.
- Initial access. A credible phishing email (a fake invoice, a rigged e-signature link), stolen credentials reused without multi-factor authentication, or exposed unpatched equipment, remote access and firewalls chief among them.
- Installation and escalation. The attacker consolidates access, obtains administrative privileges, and moves quietly. This phase can last weeks, silently.
- Exfiltration. Before encrypting anything, modern groups copy your data: customer files, financial information, employee data. This is the lever behind double extortion: pay to decrypt, and pay to avoid publication.
- Encryption. File servers, business applications, and, systematically, any backups reachable from the network. Operations stop.
- Pressure. A countdown, threats of publication, direct contact with your customers or partners. The goal: get you to pay fast, under stress.
This is exactly what a proportionate defence should be built around: not preventing step 1 at all costs, but making sure no step goes unseen.
Is the real cost limited to the ransom?
No, and the ransom is often just the visible part. Nationally, recovery costs reported by Canadian businesses doubled between 2021 and 2023, from $600 million to $1.2 billion according to Statistics Canada. The breakdown clarifies where the priorities lie.
- Operational disruption: days, sometimes weeks, without billing, production, or access to customer files.
- Technical recovery: rebuilding systems, emergency external expertise billed at incident rates.
- Legal obligations: if personal information was exfiltrated, and this is the dominant scenario, you’re facing a confidentiality incident under Law 25. A register, an assessment of the risk of serious harm, notification to the Commission d’accès à l’information (Quebec’s access-to-information oversight body) and to the affected individuals. Add legal fees and exposure to private lawsuits.
- Reputation and business relationships: customers to reassure, clients reassessing your reliability, insurance premiums rising even when coverage isn’t outright denied.
On the inevitable question of paying, the position of Canadian authorities is consistent: it is not recommended. It guarantees neither data recovery nor non-publication, it funds the criminal ecosystem, and it marks you as a payer for future attacks. The real response is built before the incident.
Which controls actually change the equation?
Six, realistic on an SME budget, because most successful attacks exploit basic weaknesses. Multi-factor authentication, tested backups, rapid patching of what’s exposed, monitored detection, segmentation, and human preparedness with a written plan.
- Multi-factor authentication everywhere possible: email, remote access, administrative tools. This is the control with the best cost-to-impact ratio, and it neutralizes credential theft, involved in a large share of compromises.
- Backups following the 3-2-1 rule, with an offline or immutable copy, and regular restoration tests. A backup that has never been tested is an assumption, not a control.
- Rapid patching of exposed systems, prioritizing actively exploited vulnerabilities (CISA’s Known Exploited Vulnerabilities catalog). Ransomware groups have heavily exploited unpatched perimeter equipment.
- Detection on endpoints and servers, with real monitoring. The attacker spends days in the network before encrypting: that’s a detection window, provided someone is watching.
- Segmentation and least privilege. Limiting what a compromised device can reach, particularly isolating backups and critical systems, turns a potential disaster into a contained incident.
- Human and organizational preparedness: phishing awareness, and above all a written, tested response plan with contacts ready. In the first hours, improvising is very costly.
And if an incident happens anyway: report it to the Canadian Centre for Cyber Security, the Canadian Anti-Fraud Centre, and local authorities, in addition to your Law 25 obligations if personal information is affected.
How does RISS approach this?
With simple logic: measure first, invest next, always validate. The assessment covers the six controls above in your actual environment, validation involves testing that pits your defences against techniques attackers actually use, and incident preparedness is exercised before you need it.
Posture assessment. A structured review: external exposure, multi-factor authentication, backups with an actual restoration test, detection, segmentation. Deliverable: a roadmap prioritized by risk reduction, in executive language.
Offensive validation. Penetration testing and phishing simulation, because the difference between “we have multi-factor authentication” and “our authentication withstands an attack” is measured, not assumed.
Incident preparedness. Development and tabletop exercise of your response plan, aligned with your Law 25 obligations: roles, critical decisions, communication, register, notification.
Integrated compliance. Each control is mapped to Law 25, ISO 27001, and the NIST framework: the same investment serves your security, your responses to insurers, and your customer questionnaires.
FAQ
Doesn’t our cyber insurance already cover us?
It covers part of the cost, not the disruption itself, and its validity depends on the accuracy of your answers on the underwriting questionnaire. Those questionnaires ask specifically about patching timelines, multi-factor authentication, and backups. An inaccurate answer, even in good faith, can jeopardize coverage exactly when you need it. Insurance is a financial risk transfer, not a substitute for controls.
How long does it take to put these six controls in place?
That depends entirely on your current setup, and we don’t give a timeline before assessing it. What we typically see: multi-factor authentication and restoration testing are often completed within days, because the features are already included in your existing licenses. Segmentation and monitored detection take longer, and are best spread across several budget cycles rather than rushed in a single quarter.
Should everything be done at once?
No, and trying is the surest way to finish nothing. The sequence that delivers the most risk reduction for the effort involved is the one above: access first, then backups, then whatever is exposed to the internet. A staged plan that gets followed through beats an ambitious program abandoned after the first quarter.
Sources
- Canadian Centre for Cyber Security: 2025-2027 Ransomware Threat Overview · exposure, access vectors and extortion trends
- Canadian Centre for Cyber Security: Baseline cyber security controls for small and medium organizations · baseline control checklist
- Statistics Canada · recovery costs reported by Canadian businesses, 2021 to 2023
- CISA, Known Exploited Vulnerabilities Catalog · patch prioritization based on confirmed exploitation
- Commission d’accès à l’information du Québec · obligations in the event of a confidentiality incident