Cybersecurity, in plain English

What actually goes wrong at businesses with five to thirty people, why it happens, and what is worth doing about it. No jargon, and no attempt to frighten you.

The honest starting point

Most small businesses are not targeted. Nobody chooses them. What happens instead is that automated tools sweep the whole internet looking for anything unlocked, and a business gets caught because something was left open — not because anyone singled it out.

That is genuinely reassuring and genuinely worrying at the same time. It means you are unlikely to face a determined attacker. It also means the basics matter far more than anything sophisticated, because the basics are exactly what the automated sweep is looking for.

Our own website absorbs roughly 900 automated probes a day — hunting for WordPress installs, exposed configuration files, and cloud credentials left in the open. That is background noise for any domain on the internet, yours included.

The four things that actually cause losses

Not the exotic ones. These four account for most of what we see and most of what small businesses actually lose money to.

1. Someone changes a bank account

An email arrives from a supplier — or from you — asking to update payment details. It looks right because it is written to look right. The money goes to the wrong account and does not come back.

The fix is a rule, not a product: any change to payment details gets confirmed by phone, on a number you already had. Never a number from the email.

2. Email sent in your name

If your domain does not publish a DMARC record, anyone can send email that appears to come from it. Your customers have no way to tell.

We measured this locally: of 197 Alberta business domains, 44.7% publish nothing at all. It is usually a DNS change rather than a project — see the study or check your own domain.

3. A backup that was never tested

Backups fail quietly. Jobs stop, disks fill, and the software carries on reporting success. Nobody finds out until the day it matters.

The fix costs an hour: restore one real file and time it. That number is your actual recovery time. Everything else is an assumption.

4. Accounts nobody closed

People leave and their accounts stay open — email, the accounting system, the remote access tool nobody remembers buying. Those accounts get no password changes and nobody notices them being used.

The fix is a list: write down every system a person has access to, and close them the day they leave.

What is worth money, and what is not

Plenty of security spending at this size buys very little. A rough order of what actually reduces risk per dollar:

Notice how much of that costs nothing. Security at this size is mostly decisions, not purchases — which is also why it gets postponed, because there is no invoice forcing the issue.

What about compliance?

If you handle personal information about customers or staff, Canadian privacy law applies to you — PIPEDA federally and Alberta's PIPA provincially — regardless of how small you are. Neither requires a security department. Both expect you to know what personal information you hold, to protect it sensibly, and to be able to say what happened if it goes wrong.

If you take card payments, your provider will ask about PCI DSS. For most small businesses that is a self-assessment questionnaire rather than an audit, and the answers depend mostly on how the payment terminal connects to your network.

Where to start

Ten questions about what your business actually does — not what you know. Two minutes, no signup, and you get a prioritised list rather than a score.