5 signs your SMB is an easy target for cyberattacks
“We’re too small for hackers to care about.” It’s something we hear all the time from small business owners, and it’s exactly why so many businesses end up vulnerable. Cybercriminals don’t always pick victims by size. They look for open doors. A poorly protected mailbox, an unpatched computer or a busy employee who pays a fake invoice is often all it takes.
In Quebec and across Canada, phishing, email fraud and ransomware hit the neighbourhood accounting firm just as much as the manufacturer on the South Shore. The Canadian Anti-Fraud Centre even has a dedicated page on frauds targeting businesses.
Here are five warning signs that should set off alarm bells, and what you can do about each one.
1. Your accounts are protected by a password and nothing else
If access to your email, Microsoft 365, accounting software or online banking relies only on a password, you’re exposed. Passwords get stolen through phishing, guessed, or sold after a data breach on some other website. And when the same password is used in several places, one stolen password unlocks everything.
What to do: turn on multi-factor authentication (MFA) everywhere you can, starting with email and admin accounts. Use a business password manager to get rid of reused passwords and the ones stuck on a sticky note.
2. Your team has never been trained to spot phishing
Most attacks start with a message: a fake Canada Post email, a text claiming to be from the Canada Revenue Agency, a link to a bogus shared document. Spear phishing is even sneakier. A fraudster studies your business, spoofs or hacks a supplier’s email account, and sends an invoice with “updated banking details.” Get Cyber Safe, together with the Canadian Anti-Fraud Centre, describes this exact scenario in its post on spear phishing.
If nobody on your team knows the warning signs, and a single email is enough to change someone’s direct deposit or approve a wire transfer, you’re an ideal target.
What to do: give your staff short, regular awareness training, and set one simple rule: any change to banking details or any urgent payment request must be confirmed by phone, using a number you already know (not the one in the email).
3. Updates happen “when we have time”
A computer that has been showing “Restart to install updates” for three weeks, a firewall that hasn’t been updated since the day it was installed, an old PC still running Windows 10 even though Microsoft ended support in October 2025: these are known, documented weaknesses, and attackers exploit them automatically.
What to do: automate updates for Windows, macOS, browsers and common software. Take inventory of your devices and plan to replace the ones that are no longer supported. Don’t forget routers, printers and network-connected cameras.
4. You have backups… but you’ve never tested them
Ransomware encrypts your files and demands payment to unlock them. Your best defence is a reliable backup. The problem is that many SMBs discover on the day of the attack that their backup was incomplete, stopped running months ago, or was permanently connected to the same network and got encrypted too.
Also keep in mind that having your files in the cloud (OneDrive, SharePoint, Google Drive) doesn’t mean they’re backed up. Sync also copies deletions and encrypted files.
What to do: follow the 3-2-1 rule (three copies, on two different types of storage, with one offsite or isolated), and run a real restore test a few times a year. A backup you’ve never restored is a hope, not a plan.
5. Nobody is in charge of security, or of personal information
In many SMBs, IT security belongs to “everyone,” which means it belongs to no one. There’s no list of who has access to what, no incident plan, and no one really knows what personal information the business holds about its customers and employees.
In Quebec, that also has legal consequences. Under Law 25 (Loi 25), which modernized the province’s private-sector privacy law, every business must, among other things:
- have a person in charge of the protection of personal information (by default, the person with the highest authority in the business, who can delegate this role in writing), and publish that person’s title and contact information on the company website;
- keep a register of all confidentiality incidents, including those that don’t present a serious risk;
- promptly notify the Commission d’accès à l’information (CAI) and the affected individuals when an incident presents a risk of serious injury.
The CAI explains these obligations on its page about confidentiality incidents (in French).
What to do: clearly assign who is responsible for security and personal information, write a one-page incident response plan (who to call, what to disconnect, how to document), and take inventory of the sensitive data you keep.
Did any of these signs sound familiar?
Don’t worry: you’re not alone, and most of these gaps can be fixed without a huge budget. The key is knowing where to start. And if you’re ever targeted by or fall victim to fraud, report it to your local police and to the Canadian Anti-Fraud Centre.
At NeoTech Cloud Solutions, we help Greater Montreal SMBs with cybersecurity and managed IT, fully remotely, in English and French. Learn more about our cybersecurity services.
Book your free cyber check
In one short meeting, we’ll review your accounts, backups, updates and day-to-day practices, and you’ll walk away with a clear list of priorities. No jargon, no commitment.
Prefer to talk to us directly? Call 438-476-2322 or email info@neotechcloudsolutions.com.