CybersecurityJune 25, 202611 min

The 10 Costliest Cybersecurity Mistakes Made by Quebec SMBs

Are small businesses really targeted?

Short answer: yes, and they have become the preferred segment. Roughly 60% of cyberattacks target companies with fewer than 100 employees, and the Canadian Centre for Cyber Security reports a sharp rise in incidents disclosed by Quebec SMBs. The average cost of an attack for a small business runs between $120,000 and $450,000 : a figure that directly threatens business continuity.

The belief that a small company is "too small to be interesting" is the number one risk factor. Current campaigns are automated: they sweep IP ranges, test stolen credentials and exploit known vulnerabilities without ever looking at the company name. You are not chosen, you are found.

Here are the ten mistakes we encounter most often in the files we handle, ranked by frequency in forensic engagements.

1. Backups that have never been restored

Almost every SMB backs up. Very few test restoration. On incident day, you discover the backup stopped seven months ago, that it never covered the application server, or that it was encrypted along with everything else because it sat permanently mounted on the network.

The fix: the 3-2-1-1 rule (three copies, two media types, one offsite, one immutable) and a timed restoration exercise every quarter. What you measure is real time to service restoration, not the existence of a backup file.

2. MFA deployed "almost" everywhere

MFA is on for email, but not the VPN. Or not on the legacy administrator account. Or not on the IT provider's access. A single door without a second factor cancels the effort spent on all the others.

The fix: inventory every external entry point, MFA with no exceptions, and a move to phishing-resistant factors for privileged accounts.

3. Administrator accounts used for daily work

The owner, the IT lead and sometimes several employees browse the web and read email with an account holding domain administration rights. One unlucky click hands the attacker the full set of keys.

The fix: separate accounts for administration, just-in-time elevation, and removal of local admin rights on workstations.

4. No inventory of supplier access

The managed service provider, the external accountant, the ERP integrator, the former consultant: each holds permanent access, often shared and rarely revoked. This is the fastest-growing vector in Canada.

The fix: a third-party access register, named accounts, just-in-time access and quarterly review. Require MFA from your suppliers contractually.

5. Patching "when there is time"

Mass-exploited vulnerabilities are weaponized within days of disclosure, on internet-facing equipment: firewalls, VPN gateways, file servers, hypervisors.

The fix: a documented monthly patch window, plus a 72-hour emergency procedure for critical vulnerabilities on internet-exposed assets.

6. Confusing antivirus with detection

Antivirus blocks what it recognizes. It detects neither an attacker using valid credentials nor the misuse of legitimate administration tools.

The fix: endpoint detection and response, centralized logging, and monitoring of unusual sign-in behaviour on identities.

7. No written response plan

On the day it happens, nobody knows who decides to pull the plug, who calls the insurer, or where to find the cloud provider's support number. The first hours are lost to improvisation : and that is exactly where cost explodes.

The fix: a two-page plan is enough to start (roles, call tree, insurer and responder contacts, isolation criteria). Test it once a year in a tabletop exercise.

8. Ignoring Law 25 obligations

Many Quebec SMBs do not know they must keep a confidentiality incident register, notify the Commission d'accès à l'information when there is a risk of serious injury, and designate a privacy officer.

The fix: name the officer, publish the governance policy, open the incident register. It costs little and carries real weight during an audit or a claim.

9. A cyber policy nobody has reread

The policy was signed three years ago and the questionnaire was completed in good faith by someone who has since left. When a claim arises, the gap between declared and actual controls is the leading cause of partial claim denial.

The fix: review the questionnaire annually with whoever runs IT, and document evidence for every declared control.

10. Annual training that changes nothing

A one-hour session per year changes no behaviour, especially against AI-generated emails that are fluent, contextual and error-free.

The fix: monthly phishing simulations, immediate feedback and a blame-free reporting culture. Measure the reporting rate, not just the click rate.

Where to start on a limited budget

1.

Week 1: MFA everywhere, inventory of external access, revoke dormant accounts

2.

Week 2: a real restoration test and an immutable backup copy

3.

Week 3: a two-page response plan and a posted call tree

4.

Week 4: patch internet-facing assets and turn on logging

5.

Month 2: EDR, phishing simulations, baseline Law 25 compliance

Conclusion

None of these ten fixes requires an enterprise budget. They require a decision and an accountable owner. In our files, that is what separates organizations back in business within 48 hours from those that lose three weeks of operations. ITCS Group delivers security posture assessments tailored to Quebec SMBs, with an action plan prioritized by cost-to-impact ratio. Contact us for an initial assessment.

Sources

Canadian Centre for Cyber Security : National Cyber Threat Assessment 2025-2026

Ransomware Threat Overview 2025-2027 : Canadian Centre for Cyber Security

ITCS Group incident response engagements : Quebec SMBs, 2024-2026

Share this articleLinkedInXFacebook