Cyber Security for Small and Medium Enterprises (SMEs)

Written by Thao Nguyen, JD Candidate 2026

Early investment into building a strong cybersecurity framework will be beneficial for SMEs in the long run. In Canada, small and medium organizations (SMEs) have been found to be the likeliest target of cyber threat activity in the form of cybercrime for data theft and ransom. [1]

Canadian privacy laws require private businesses, including SMEs, to install proper cyber security safeguards to protect the personal data that they collect from their users under the regulatory privacy frameworks imposed by the provincial and federal governments. [2] Most prominently, the Canadian Personal Information and Protection of Electronic Documents Act ("PIPEDA") requires businesses to safeguard collected personal data to protect against loss, theft, unauthorized access, copying, use or modification (Principle 4.7). [3]

PIPEDA gives the Privacy Commissioner the power to investigate any complaints against a business and issue reports which a complaint could use to apply to a Canadian court for a hearing. [4] The court may issue orders to the SME to correct its practices, publish notice about the correction, and pay damages to the complainant. [5] Therefore, data breaches can incur enormous financial costs for SMEs including ransom payment or court-awarded damages paid to victims.

To help support SMEs with improving their cybersecurity capability, the Government of Canada provides SMEs with resources for education and training, certifications, grants and tax incentives.

Education and Training

One of those agencies is the Canadian Centre for Cyber Security (the "Cyber Centre"), an entity under the Communications Security Establishment Canada, which provides expert advice, guidance, services and support on cyber security for Canadians and acts as a hub for voluntary reporting of cyber incidents. [6]

The Cyber Centre publishes the Baseline Cyber Security Controls for Small and Medium Organizations (the "Guide") that lays out the recommended baseline controls with the goal to help SMEs achieve 80% of benefit from 20% effort or get the most out of their cyber security investments.

The baseline controls are composed of 13 different recommendations for cyber security investments: 1. Develop an Incident Response Plan; 2. Automatically patch operating systems and applications; 3. Enable security software; 4. Securely configure devices; 5. Use strong user authentication; 6. Provide employee awareness training; 7. Backup and encrypt data; 8. Secure mobility; 9. Establish basic perimeter defences; 10. Secure cloud and outsourced IT services; 11. Secure websites; 12. Implement access control and authorization; 13. Secure portable media.

Additionally, the Cyber Centre's Learning Hub offers courses to elevate Canadian residents and SMEs to learn about cyber security. The Cyber Security for small and medium organizations course covers explanations and examples of the 13 aforementioned baseline controls plus leadership accountability cyber security risk assessment and computer security log management for SMEs. [7]

Certifications

Beside the resources offered by the Cyber Centre, the Government of Canada issues a Cyber Security Assessment and Certification for Small and Medium-Sized Enterprises for those that implement the baseline controls. [8] Certified organizations will receive the permission to display the CyberSecure Certification Mark on their websites or at their physical locations to demonstrate the achievement of meeting the baseline controls. [9] The designation is valid for two years after it is awarded. [10]

SMEs can also obtain other certification including the Digital Governance Council's CyberReady Validation Program. The Digital Governance Council is a not-for-profit organization that plays a critical role in setting Canadian standards through its Digital Governance Standards Institute. Its new CyberReady Validation Program launched in February 2025 allows an organization to validate or verify the organization's cybersecurity plans and practices with an independent review or audit. This program aims at strengthening stakeholder and public trust and confidence in an organization's digital practices. The program costs $250 to $750 depending on the requested service. [11]

Grants and Tax Incentives

The Accelerated Investment Incentive provides SMEs with tax incentives for capital investments including investments into cyber technologies. [12] The Accelerated Investment Incentive, in a nutshell, provides an enhanced first-year allowance for eligible property subject to the capital cost allowance rules which gives the tax payers up to three times the normal first-year deduction. [13] Cyber eligible property may include cyber equipment and assets such as computers, software, and infrastructures.

Research and experimental projects for cyber initiatives receive grants and tax incentives. First, the Cyber Security Innovation Network funds high-impact cyber technology projects encompassing research, development, product and service commercialization, and talent development. Second, the Scientific Research and Experimental Development (SR&ED) tax incentive program allows a business to claim a deduction against income or provides an investment tax incentive for eligible expenses for basic, applied research, experimental development, or support work. [14]

SMEs can take advantage of these programs and resources from the Government of Canada and other non-profit organizations to bolster their cybersecurity capability. This can save SMEs money in their initial cyber investment and set up a strong foundation for their cyber systems which will establish trust with the SMEs' customers and partners and reduce risks of future cyber incidents.

Note: The above information does not constitute legal advice. No guarantees are made as to accuracy, completeness, or applicability to individual situations.

Endnotes

1. Government of Canada, Baseline Cyber Security Controls Small and Medium Organizations, online: https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations.

2. PIPEDA, SC 2000, c5; PIPA.

3. PIPEDA, Principle 4.7.

4. PIPEDA, s. 14(1).

5. PIPEDA, s. 16.

6. Government of Canada, Canadian Centre for Cyber Security, online: https://www.cyber.gc.ca/en; Government of Canada, Report a cyber incident, online: https://www.cyber.gc.ca/en/incident-management.

7. Cyber Canada, Learning Hub's Cyber Security Small Medium Organizations, online: https://www.cyber.gc.ca/en/education-community/learning-hub/courses/cyber-security-small-medium-organizations.

8. Government of Canada, CyberSecure, online: https://ised-isde.canada.ca/site/cybersecure-canada/en.

9. Government of Canada, CyberSecure Canada's Display Requirements, online: https://ised-isde.canada.ca/site/cybersecure-canada/en/display-requirements.

10. Ibid.

11. Osler, https://www.osler.com/en/insights/updates/practical-approach-cybersecurity-trust-standards-validation-programs/; Digital Governance Council, online: https://dgc-cgn.org/.

12. Government of Canada, Accelerated investment incentive, online: https://www.canada.ca/en/revenue-agency/services/tax/businesses/topics/sole-proprietorships-partnerships/report-business-income-expenses/claiming-capital-cost-allowance/accelerated-investment-incentive.html.

13. Ibid.

14. Government of Canada, Scientific Research and Experimental Development Tax Incentive Program, online: https://www.canada.ca/en/revenue-agency/services/scientific-research-experimental-development-tax-incentive-program.html.

Previous
Previous

Disclosure Considerations for Inventors

Next
Next

From Founder to Director: Understanding Basic Duties Under ABCA