Home › Cyber security

Cyber security

The attack is usually an email about banking details.

Small businesses picture hackers breaking through something. What actually takes the money is a plausible message asking for a payment to go to a different account, arriving at a moment when it seems reasonable. The defences that work against it are cheap, procedural, and mostly not technical at all.

Call (905) 207-9639 What actually helps

Why this is on an accountant's website. Because the target is usually the money and the records, both of which are mine to worry about, and because a loss of records is a tax compliance problem as well as an operational one.

None of this makes me an IT professional. Where the budget allows one, get one. What follows is the part that overlaps with how money moves through a business.

What actually happens

The terminology is less useful than the situations, so here are both.

PhishingA mass email pretending to be a bank, the CRA or a supplier, hoping someone enters a password
Spear phishingThe same thing aimed at one person, using real details about your business. Far more convincing, and increasingly easy to produce
SpoofingMaking a message appear to come from an address or domain it did not. The sender name looks right; the actual address does not
Business email compromiseSomeone is genuinely inside a mailbox, reading real conversations, and joins one at the right moment
Man in the middleCommunications intercepted and altered in transit, so both parties believe they are speaking to each other
RansomwareFiles encrypted and a payment demanded. For a small business the damage is usually the downtime and the lost records rather than the ransom

The one that takes the money

Payment redirection is the fraud that actually empties small business bank accounts, and it does not require anything sophisticated.

An invoice arrives from a supplier you use, referring to work that genuinely happened, in a thread that may be real. It notes that banking details have changed. Somebody in accounts payable updates the record and pays. The money is gone within hours and is rarely recoverable, because you authorized the transfer.

The variation aimed at owner-managed businesses is a message that appears to be from the owner, to whoever handles payments, asking for an urgent transfer while the owner is travelling or in meetings. Urgency and authority are the entire technique.

The controls that are worth it

Ranked by what they prevent against what they cost, which is not how these lists are usually ordered.

Verify banking changes by voice, on a number you already had

One rule, and it defeats the most expensive attack. Any change to payment details gets confirmed by telephone, using a number from your own records, never a number in the message requesting the change.

Write it down as a policy, tell whoever pays the bills that they will never be criticized for making that call, and mean it. Most of these frauds succeed because somebody suspected and did not want to seem difficult.

Two-factor authentication, starting with email

If you do one technical thing, do this, and do email before banking. Email is the master key: it resets every other password you own, and it holds the conversations an attacker needs to be convincing.

Authenticator apps are meaningfully stronger than codes by text message. Both are enormously better than nothing.

Two people on significant payments

Segregation of duties in its cheapest form: the person who sets up a payment is not the person who releases it. Most business banking supports it, few small businesses turn it on, and it converts a single mistake into something requiring two.

Training, and why it has to keep happening

Training once, at onboarding, decays. Frequency matters more than duration: a few minutes regularly beats an annual session nobody remembers by March, and the content has to keep moving because the attacks do. Messages that were once recognizable by their poor grammar are now written well, at scale, and tailored using details taken from your website and your staff's public profiles.

What works in practice:

That last point does more than the rest combined. A culture where people quietly delete their mistakes is the one that gets hurt, because the hours after a click are when the damage can still be limited.

On people being the weakest link

The phrase is repeated so often it has stopped being examined, and it is only half true.

Where the technical controls are good, a person clicking something bad is contained. The stolen password fails at two-factor authentication. Access to one mailbox does not reach the accounting system. Encrypted files are restored from a backup the attacker could not touch. The click still happened; the consequence did not.

Where those controls are absent, one click is the entire event. So "people are the weakest link" is frequently a description of missing technical controls rather than of the people.

The practical distinction is this: training reduces how often something gets through, and controls reduce what happens when it does. You want both, and holding staff responsible for a failure that had no containment behind it teaches the wrong lesson to everyone watching.

Passwords, where the advice has changed

Many businesses still force a password change every 90 days because it feels like diligence. Current security guidance has moved away from that, and it is worth knowing why before renewing the policy.

Forced rotation produces predictable passwords. People append a number, increment it, and write the result somewhere. The password gets weaker each cycle while the policy reports compliance. Guidance now favours changing passwords when there is reason to, meaning evidence or suspicion of compromise, rather than on a calendar.

What replaces it:

If you are going to keep a rotation policy, keep it for shared or administrative accounts where the risk of an old credential lingering is real. Applying it to everyone tends to buy compliance rather than security.

Backups you have actually restored

An untested backup is a hope. Restore something from it, deliberately, and find out how long it takes and whether the files are usable. Keep a copy that is not connected to the network, since ransomware encrypts what it can reach.

The records obligation does not care that you were attacked. A business must keep its books and records and produce them on request. Losing them to ransomware is not an answer, and reconstructing years of records under time pressure is expensive in a way that dwarfs what prevention would have cost.

This is the point where cyber security stops being an IT topic and becomes a compliance one.

The systems you do not run yourself

Most of your data now sits with someone else: the payroll bureau, the cloud accounting platform, the portal your documents move through. You have outsourced the processing. You have not outsourced the responsibility.

SOC reports, and what to ask for

A service organization control report is an independent auditor's report on the controls a provider operates. Asking for one is normal, and providers of any size expect the question.

SOC 1Controls relevant to financial reporting. The one that matters if a provider processes transactions that end up in your statements, such as payroll
SOC 2Controls around security, availability, confidentiality and privacy. The one relevant to data protection
Type IThe controls were suitably designed at a point in time. Weaker
Type IIThe controls also operated effectively over a period, usually six to twelve months. This is the one worth having

Two things people miss when handed one. Read the exceptions, since the value is in what the auditor found rather than in the report existing. And read the complementary user entity controls, a section listing what the report assumes you are doing. Providers rely on those assumptions, and if you are not doing them, the assurance does not reach as far as you think.

Trust, but verify. A provider unwilling to discuss any of this is telling you something.

Working with an IT professional

Worth it as soon as the budget allows, and worth approaching the way you would any other adviser. Ask what they are certified in, ask who else they support, and ask what happens at two in the morning when something breaks.

The same verification applies here as anywhere. Someone with administrative access to everything you own should be someone whose credentials you have checked, whose work someone else could pick up, and whose access you can revoke without asking them to do it.

Cyber insurance, and the part people overlook

Cyber coverage is now widely available and reasonably priced at small business scale. It typically responds to incident response costs, business interruption, data restoration, liability, and sometimes funds transfer fraud, though that last one is often limited and is worth checking specifically given it is the likeliest loss.

The overlooked part is what comes with the policy rather than after a claim. Insurers have a direct interest in you not claiming, so they routinely provide staff training modules, phishing simulations, policy templates, risk assessments and access to a breach response team on a hotline.

Much of that is material a business would otherwise pay for separately, and a great deal of it goes unused because nobody realizes it is included. If you already hold a policy, the practical step is to ask your broker what resources come with it before buying training elsewhere.

Two cautions. Applications ask specific questions about your controls, and answering optimistically about something like two-factor authentication can affect a claim. And most policies carry conditions you have to actually meet, which is a reason to read them rather than file them.

The accounting side of all this software

Worth a note since it is the part I am actually responsible for. Businesses now spend substantially on cloud subscriptions and implementation projects, and there is an accounting question about whether that spending is an asset or an expense.

Canadian standards address customers' accounting for cloud computing arrangements, distinguishing an arrangement that gives you a software intangible from one that is simply a service you consume, and dealing with implementation and configuration costs. There is also a simplification available that allows the expenditures to be expensed as incurred.

For most owner-managed businesses this is a policy choice to make deliberately rather than a difficult judgment, and it belongs alongside the other choices covered under accounting policy. It matters most where an implementation is large enough that capitalizing or expensing it visibly changes the year.

Questions

What is the single most useful thing to do?

Adopt a rule that any change to a supplier's or employee's banking details is verified by telephone, using a number from your own records rather than one supplied in the message requesting the change. Payment redirection is the fraud that most often takes money from small businesses, and this defeats it. Two-factor authentication on email is the best technical step alongside it.

Someone changed our supplier's bank details and we paid. What now?

Contact your bank immediately, since recovery depends almost entirely on speed and becomes unlikely once funds have moved on. Report it to police and to your insurer if you hold cyber coverage. Then assume your email may be compromised: change passwords, enable two-factor authentication, and check for forwarding rules an intruder may have set up to monitor replies.

Should we force staff to change passwords every 90 days?

Current guidance has moved away from it. Forced rotation tends to produce predictable passwords that get weaker each cycle, since people append and increment a number and often write the result down. The preferred approach is changing on evidence or suspicion of compromise rather than on a schedule, combined with long passphrases, a unique password for every service, and a password manager to make that practical. Rotation still has a place for shared and administrative accounts.

Should I ask my payroll provider for a SOC report?

Yes, and it is a normal request. Look for a SOC 1 Type II if they process transactions that flow into your financial statements, since Type II covers whether controls operated over a period rather than merely being designed. Read the exceptions the auditor noted, and read the section on complementary user entity controls, which sets out what the report assumes you are doing at your end.

Is cyber insurance worth it for a small business?

Usually, and often for reasons beyond the claim. Policies at this scale are reasonably priced and commonly include staff training, phishing simulations, policy templates and access to a breach response team, much of which would otherwise be bought separately and much of which goes unused because nobody asks. Check specifically whether funds transfer fraud is covered and to what limit, since that is the likeliest loss.

Ransomware destroyed our records. Does the CRA make allowances?

The obligation to keep books and records and produce them on request does not disappear because of an attack. Reconstructing records after the fact is expensive and slow, which is why tested backups, including one kept disconnected from the network, are worth more than they appear on a list of IT costs.

This page covers general practices as at August 2026 and is not IT security advice or an assessment of your circumstances. I am a CPA rather than a security professional, and anything beyond the procedural measures above is properly a question for someone qualified in the field.

Not sure who verifies a banking change?

If nobody can answer that immediately, it is worth twenty minutes. No charge.

Call (905) 207-9639