Home › Cyber security
Cyber security
Small businesses picture hackers breaking through something. What actually takes the money is a plausible message asking for a payment to go to a different account, arriving at a moment when it seems reasonable. The defences that work against it are cheap, procedural, and mostly not technical at all.
Why this is on an accountant's website. Because the target is usually the money and the records, both of which are mine to worry about, and because a loss of records is a tax compliance problem as well as an operational one.
None of this makes me an IT professional. Where the budget allows one, get one. What follows is the part that overlaps with how money moves through a business.
The terminology is less useful than the situations, so here are both.
| Phishing | A mass email pretending to be a bank, the CRA or a supplier, hoping someone enters a password |
|---|---|
| Spear phishing | The same thing aimed at one person, using real details about your business. Far more convincing, and increasingly easy to produce |
| Spoofing | Making a message appear to come from an address or domain it did not. The sender name looks right; the actual address does not |
| Business email compromise | Someone is genuinely inside a mailbox, reading real conversations, and joins one at the right moment |
| Man in the middle | Communications intercepted and altered in transit, so both parties believe they are speaking to each other |
| Ransomware | Files encrypted and a payment demanded. For a small business the damage is usually the downtime and the lost records rather than the ransom |
Payment redirection is the fraud that actually empties small business bank accounts, and it does not require anything sophisticated.
An invoice arrives from a supplier you use, referring to work that genuinely happened, in a thread that may be real. It notes that banking details have changed. Somebody in accounts payable updates the record and pays. The money is gone within hours and is rarely recoverable, because you authorized the transfer.
The variation aimed at owner-managed businesses is a message that appears to be from the owner, to whoever handles payments, asking for an urgent transfer while the owner is travelling or in meetings. Urgency and authority are the entire technique.
Ranked by what they prevent against what they cost, which is not how these lists are usually ordered.
One rule, and it defeats the most expensive attack. Any change to payment details gets confirmed by telephone, using a number from your own records, never a number in the message requesting the change.
Write it down as a policy, tell whoever pays the bills that they will never be criticized for making that call, and mean it. Most of these frauds succeed because somebody suspected and did not want to seem difficult.
If you do one technical thing, do this, and do email before banking. Email is the master key: it resets every other password you own, and it holds the conversations an attacker needs to be convincing.
Authenticator apps are meaningfully stronger than codes by text message. Both are enormously better than nothing.
Segregation of duties in its cheapest form: the person who sets up a payment is not the person who releases it. Most business banking supports it, few small businesses turn it on, and it converts a single mistake into something requiring two.
Training once, at onboarding, decays. Frequency matters more than duration: a few minutes regularly beats an annual session nobody remembers by March, and the content has to keep moving because the attacks do. Messages that were once recognizable by their poor grammar are now written well, at scale, and tailored using details taken from your website and your staff's public profiles.
What works in practice:
That last point does more than the rest combined. A culture where people quietly delete their mistakes is the one that gets hurt, because the hours after a click are when the damage can still be limited.
The phrase is repeated so often it has stopped being examined, and it is only half true.
Where the technical controls are good, a person clicking something bad is contained. The stolen password fails at two-factor authentication. Access to one mailbox does not reach the accounting system. Encrypted files are restored from a backup the attacker could not touch. The click still happened; the consequence did not.
Where those controls are absent, one click is the entire event. So "people are the weakest link" is frequently a description of missing technical controls rather than of the people.
The practical distinction is this: training reduces how often something gets through, and controls reduce what happens when it does. You want both, and holding staff responsible for a failure that had no containment behind it teaches the wrong lesson to everyone watching.
Many businesses still force a password change every 90 days because it feels like diligence. Current security guidance has moved away from that, and it is worth knowing why before renewing the policy.
Forced rotation produces predictable passwords. People append a number, increment it, and write the result somewhere. The password gets weaker each cycle while the policy reports compliance. Guidance now favours changing passwords when there is reason to, meaning evidence or suspicion of compromise, rather than on a calendar.
What replaces it:
If you are going to keep a rotation policy, keep it for shared or administrative accounts where the risk of an old credential lingering is real. Applying it to everyone tends to buy compliance rather than security.
An untested backup is a hope. Restore something from it, deliberately, and find out how long it takes and whether the files are usable. Keep a copy that is not connected to the network, since ransomware encrypts what it can reach.
The records obligation does not care that you were attacked. A business must keep its books and records and produce them on request. Losing them to ransomware is not an answer, and reconstructing years of records under time pressure is expensive in a way that dwarfs what prevention would have cost.
This is the point where cyber security stops being an IT topic and becomes a compliance one.
Most of your data now sits with someone else: the payroll bureau, the cloud accounting platform, the portal your documents move through. You have outsourced the processing. You have not outsourced the responsibility.
A service organization control report is an independent auditor's report on the controls a provider operates. Asking for one is normal, and providers of any size expect the question.
| SOC 1 | Controls relevant to financial reporting. The one that matters if a provider processes transactions that end up in your statements, such as payroll |
|---|---|
| SOC 2 | Controls around security, availability, confidentiality and privacy. The one relevant to data protection |
| Type I | The controls were suitably designed at a point in time. Weaker |
| Type II | The controls also operated effectively over a period, usually six to twelve months. This is the one worth having |
Two things people miss when handed one. Read the exceptions, since the value is in what the auditor found rather than in the report existing. And read the complementary user entity controls, a section listing what the report assumes you are doing. Providers rely on those assumptions, and if you are not doing them, the assurance does not reach as far as you think.
Trust, but verify. A provider unwilling to discuss any of this is telling you something.
Worth it as soon as the budget allows, and worth approaching the way you would any other adviser. Ask what they are certified in, ask who else they support, and ask what happens at two in the morning when something breaks.
The same verification applies here as anywhere. Someone with administrative access to everything you own should be someone whose credentials you have checked, whose work someone else could pick up, and whose access you can revoke without asking them to do it.
Cyber coverage is now widely available and reasonably priced at small business scale. It typically responds to incident response costs, business interruption, data restoration, liability, and sometimes funds transfer fraud, though that last one is often limited and is worth checking specifically given it is the likeliest loss.
The overlooked part is what comes with the policy rather than after a claim. Insurers have a direct interest in you not claiming, so they routinely provide staff training modules, phishing simulations, policy templates, risk assessments and access to a breach response team on a hotline.
Much of that is material a business would otherwise pay for separately, and a great deal of it goes unused because nobody realizes it is included. If you already hold a policy, the practical step is to ask your broker what resources come with it before buying training elsewhere.
Two cautions. Applications ask specific questions about your controls, and answering optimistically about something like two-factor authentication can affect a claim. And most policies carry conditions you have to actually meet, which is a reason to read them rather than file them.
Worth a note since it is the part I am actually responsible for. Businesses now spend substantially on cloud subscriptions and implementation projects, and there is an accounting question about whether that spending is an asset or an expense.
Canadian standards address customers' accounting for cloud computing arrangements, distinguishing an arrangement that gives you a software intangible from one that is simply a service you consume, and dealing with implementation and configuration costs. There is also a simplification available that allows the expenditures to be expensed as incurred.
For most owner-managed businesses this is a policy choice to make deliberately rather than a difficult judgment, and it belongs alongside the other choices covered under accounting policy. It matters most where an implementation is large enough that capitalizing or expensing it visibly changes the year.
Adopt a rule that any change to a supplier's or employee's banking details is verified by telephone, using a number from your own records rather than one supplied in the message requesting the change. Payment redirection is the fraud that most often takes money from small businesses, and this defeats it. Two-factor authentication on email is the best technical step alongside it.
Contact your bank immediately, since recovery depends almost entirely on speed and becomes unlikely once funds have moved on. Report it to police and to your insurer if you hold cyber coverage. Then assume your email may be compromised: change passwords, enable two-factor authentication, and check for forwarding rules an intruder may have set up to monitor replies.
Current guidance has moved away from it. Forced rotation tends to produce predictable passwords that get weaker each cycle, since people append and increment a number and often write the result down. The preferred approach is changing on evidence or suspicion of compromise rather than on a schedule, combined with long passphrases, a unique password for every service, and a password manager to make that practical. Rotation still has a place for shared and administrative accounts.
Yes, and it is a normal request. Look for a SOC 1 Type II if they process transactions that flow into your financial statements, since Type II covers whether controls operated over a period rather than merely being designed. Read the exceptions the auditor noted, and read the section on complementary user entity controls, which sets out what the report assumes you are doing at your end.
Usually, and often for reasons beyond the claim. Policies at this scale are reasonably priced and commonly include staff training, phishing simulations, policy templates and access to a breach response team, much of which would otherwise be bought separately and much of which goes unused because nobody asks. Check specifically whether funds transfer fraud is covered and to what limit, since that is the likeliest loss.
The obligation to keep books and records and produce them on request does not disappear because of an attack. Reconstructing records after the fact is expensive and slow, which is why tested backups, including one kept disconnected from the network, are worth more than they appear on a list of IT costs.
This page covers general practices as at August 2026 and is not IT security advice or an assessment of your circumstances. I am a CPA rather than a security professional, and anything beyond the procedural measures above is properly a question for someone qualified in the field.
If nobody can answer that immediately, it is worth twenty minutes. No charge.
Call (905) 207-9639