# intrasec > intrasec is a Toronto-based, Canadian-owned IT and cybersecurity advisory and consulting practice for small and growing businesses across Ontario and Canada. We help owners decide what their technology should do, then build it: strategy, projects, and, for existing clients, ongoing managed support. Security is treated as a first principle, not an add-on: every IT decision is a security decision. Last updated: 2026-08-10. Site: https://www.intrasec.ca/ ## About intrasec - Founded: 2020. Based in Toronto's King & Bay district (438 King St W, Toronto, ON M5V 3T9, Canada). - Who we serve: small and growing businesses and founders without a full-time IT department or CIO, in Toronto, across Ontario, and throughout Canada. We qualify by stage, not headcount. - What we do: IT/security advisory and project-based consulting first (decide, then build), with ongoing managed support available as a follow-on for existing clients, delivered by one integrated team rather than separate siloed vendors. - How we work: no fixed contracts, no hidden minimums, no platform lock-in. A named lead on every account, Canadian and in your timezone (Mon to Fri, 8am to 5pm ET). - Contact: [Contact page](https://www.intrasec.ca/contact) (form) or hello@intrasec.ca - LinkedIn: https://www.linkedin.com/company/intrasec-ca - Google Business Profile: https://maps.app.goo.gl/nn9AzyNhvbeNvacq7 - Bing Places: https://www.bing.com/maps?ss=ypid.YN5A4653984959E41A&mkt=en-CA - [About intrasec](https://www.intrasec.ca/about): The company's positioning (built for the stage between break-fix and a big MSP), how it works, the founder-led approach, credentials, and service area. What makes intrasec different: - **Integrated**:IT, cybersecurity, and advisory as one team, so nothing falls between the seams and there is no finger-pointing between vendors. - **Plain-spoken**:technical risk is translated into clear business decisions, with options and a recommendation, no jargon and no fear-selling. - **Local**:Toronto-based and Canadian-owned, with a named lead on every account instead of tiers of anonymous support. - **Security-first**:cybersecurity is baked into every recommendation from the start, not bolted on at the end. ## Services intrasec offers four ways to engage, which can be combined as a business grows: - [Founder Support](https://www.intrasec.ca/founder-support): Practical IT and cybersecurity support built for founders. intrasec handles the technology so founders can stay focused on building the business. - [Advisory Services](https://www.intrasec.ca/advisory-services): Strategic IT and cybersecurity guidance. Covers IT Modernization, Cybersecurity Strategy, Cloud Adoption, and IT Optimization. Delivers a clear, written, prioritized plan you can act on. - [Consulting Services](https://www.intrasec.ca/consulting-services): Project-based technical work for specific challenges. Covers Digital Workplace, Cybersecurity, Infrastructure, and Physical Security. We come in, build what is needed, and leave documentation instead of a dependency. - [Managed Services](https://www.intrasec.ca/managed-services): Offered as a follow-on for clients we have done advisory or project work with: we can also run what we build. Covers Managed Support, Managed Security, Managed Infrastructure, and Backup & Recovery for small businesses in Toronto and across the GTA. Proactive monitoring, fast response, on-site when needed, and a named local team that knows your environment. - [Microsoft 365](https://www.intrasec.ca/microsoft-365): End-to-end Microsoft 365 for small businesses, from licensing and cost optimization, tenant architecture, and migration to identity and access (Entra ID), security (Defender), device management (Intune), compliance and data governance (Purview), email and collaboration, backup, and Copilot readiness. intrasec runs the whole tenant. - [Google Workspace](https://www.intrasec.ca/google-workspace): End-to-end Google Workspace for small businesses, from licensing and cost optimization, domain and tenant architecture, and migration to identity and access (2-Step Verification, SSO), security (Gmail security, Security Center), endpoint and device management, data governance (Google Vault, DLP), email and collaboration (Gmail, Drive, Meet), backup, and Gemini AI readiness. Includes an honest Google Workspace vs Microsoft 365 comparison. - [UniFi (Ubiquiti)](https://www.intrasec.ca/ubiquiti-unifi): Network and physical security for small businesses, designed, built, and managed on Ubiquiti's UniFi platform. Covers network design and segmentation, gateway firewall and IDS, switching and PoE, WiFi 6/7 coverage, UniFi Protect cameras with local recording and AI detection, UniFi Access door control, and centralized management with monitoring and failover. One team for network and physical security. - [Microsoft Azure](https://www.intrasec.ca/microsoft-azure): Microsoft Azure for small businesses, designed, secured, and managed as one governed environment. Covers landing zone and foundation (Cloud Adoption Framework), server and app migration (Azure Migrate, Azure Virtual Desktop), identity and access (Entra ID, MFA, Conditional Access), security and monitoring (Defender for Cloud, Sentinel), backup and disaster recovery (Azure Backup, Site Recovery), and cost management and governance. Certified across Azure plus Microsoft security and identity (AZ and SC certifications). - [Microsoft Intune](https://www.intrasec.ca/microsoft-intune): Microsoft Intune endpoint and device management for small businesses, run across the full device lifecycle: enrollment (Windows Autopilot, Apple and Android, BYOD with MAM), configuration profiles and baselines, compliance policies and Conditional Access, endpoint security (Defender for Endpoint), disk encryption (BitLocker, FileVault), application and update-ring management, and remote actions including selective and full device wipe. Certified MD-102 Endpoint Administrator plus Microsoft 365 and security certifications. - [Cloudflare](https://www.intrasec.ca/cloudflare): Cloudflare edge security and performance for small businesses, set up and managed end to end: authoritative DNS and DNSSEC, SSL/TLS certificates, global CDN and caching, always-on DDoS protection, Web Application Firewall (WAF), bot management and Turnstile, Zero Trust access (Access, Tunnel, WARP) to replace a VPN, and email routing with DMARC. intrasec runs its own site on Cloudflare (Workers, Email Routing, Turnstile, Analytics), so it is a proven in-house stack, not a resold one. ## Hubs The index pages that list everything in each section: - [Blog](https://www.intrasec.ca/blog/): The full index of intrasec's IT and cybersecurity guides and news for Canadian small businesses, filterable by category. - [Free tools](https://www.intrasec.ca/tools/): The hub of intrasec's thirteen free, browser-based IT and security tools for small businesses. - [Readiness quizzes](https://www.intrasec.ca/quiz/): The hub of intrasec's ten free self-assessment quizzes (cybersecurity, SOC 2, PCI DSS, cyber insurance, Canadian privacy, AI governance, incident response, vendor risk, Microsoft 365 security, founder IT). ## Tools Free, no-signup security tools for any domain or website: - [Email Security Checker](https://www.intrasec.ca/tools/email-security-checker): Enter any domain to scan its email security DNS records, SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and DNSSEC, and see what is configured correctly and what leaves it open to spoofing or delivery problems. - [Domain & DNS Checker](https://www.intrasec.ca/tools/domain-dns-checker): Check a domain's registration and expiry, registrar transfer lock, DNS resolution, DNSSEC, and the CAA records that control which certificate authorities can issue TLS certificates for it. - [DNS Propagation Checker](https://www.intrasec.ca/tools/dns-propagation-checker): Look up any DNS record (A, AAAA, CNAME, MX, TXT, NS) across ten major public resolvers worldwide at once and see whether a change has propagated or some resolvers still serve a cached value. - [Subdomain Finder](https://www.intrasec.ca/tools/subdomain-finder): Discover the subdomains of any domain from public Certificate Transparency logs, the forgotten dev, staging and admin hosts that make up its external attack surface. - [Typosquat & Look-alike Domain Finder](https://www.intrasec.ca/tools/typosquat-finder): Generate the common look-alike variants of a domain (misspellings, swapped letters, look-alike characters, other extensions) and see which are registered and resolving, including mail-capable ones set up for email impersonation. - [Website Security Checker](https://www.intrasec.ca/tools/website-security-checker): Scan a website's HTTPS enforcement, HSTS, Content-Security-Policy and other security headers, cookie flags, and software-version disclosure. - [Redirect Checker](https://www.intrasec.ca/tools/redirect-checker): Trace a URL's full redirect chain hop by hop over both http and https, showing every status code, permanent versus temporary redirects, the final destination, loops and broken links. - [AI Visibility Checker](https://www.intrasec.ca/tools/ai-visibility-checker): See whether ChatGPT, Claude, Perplexity and Google's AI can find and cite a website: AI crawler access in robots.txt, llms.txt, sitemap, structured data and how much content is readable without JavaScript. - [Email Header Analyzer](https://www.intrasec.ca/tools/email-header-analyzer): Paste raw email headers to trace the delivery path hop by hop, read the SPF, DKIM and DMARC results, find the originating IP, and spot the mismatches that signal spoofing or phishing. Runs entirely in your browser. - [SPF & DMARC Record Generator](https://www.intrasec.ca/tools/spf-dmarc-generator): Pick the services that send email for a domain and a policy, and get copy-paste SPF, DMARC and MTA-STS DNS records to stop spoofing and fix what the email security checker flags. Runs entirely in your browser. - [Cyber Incident Cost Calculator](https://www.intrasec.ca/tools/incident-cost-calculator): Estimate the likely cost of a data breach or ransomware attack on a Canadian small business, response, downtime and recovery, with a clear breakdown. A rough estimate to frame the risk, runs in your browser. - [Password & Passphrase Generator](https://www.intrasec.ca/tools/password-generator): Generate a strong random password or an easy-to-type passphrase from the EFF wordlist, entirely in the browser with cryptographic randomness. Nothing is sent, stored, or logged. - [Cybersecurity Readiness Quiz](https://www.intrasec.ca/quiz/cybersecurity): A 14-question self-assessment of small-business security fundamentals (MFA, backups, patching, email, training) that returns a maturity score, a breakdown by area, and a prioritised list of what to fix first. - [SOC 2 Readiness Quiz](https://www.intrasec.ca/quiz/soc-2): Twelve high-level questions on access control, monitoring, change and vendor management to gauge how prepared a business is for a SOC 2 audit and where the gaps are. A readiness indicator, not an audit. - [PCI DSS Compliance Quiz](https://www.intrasec.ca/quiz/pci-dss): Twelve plain-language questions, starting with how you accept card payments, to gauge PCI DSS readiness and the controls to close. A readiness check, not the formal SAQ. - [Cyber Insurance Readiness Quiz](https://www.intrasec.ca/quiz/cyber-insurance): Twelve questions mirroring what cyber insurers now require on applications (MFA, EDR, tested backups, email filtering, incident plan) to see whether a business would qualify and where it falls short. - [Canadian Privacy Readiness Quiz](https://www.intrasec.ca/quiz/privacy-law-25): Twelve questions on PIPEDA and Quebec Law 25 readiness, accountability, consent, data inventory, breach response and cross-border transfers. A readiness check, not legal advice. - [AI Governance Readiness Quiz](https://www.intrasec.ca/quiz/ai-governance): Twelve high-level questions on AI policy, data handling, risk, oversight and vendor use to gauge how prepared a business is to adopt AI safely and where the gaps are. A readiness indicator, not an audit or legal advice. - [Incident Response Readiness Quiz](https://www.intrasec.ca/quiz/incident-response): Twelve questions on incident response plan, roles, detection, containment, communications and testing to gauge how ready a business is to handle a cyber incident. A readiness indicator, not an audit. - [Vendor Risk Readiness Quiz](https://www.intrasec.ca/quiz/vendor-risk): Twelve questions on vendor inventory, due diligence, contracts, ongoing monitoring and offboarding to gauge how well a business manages the third-party and supply-chain risk its suppliers bring. A readiness indicator, not an audit. - [Microsoft 365 Security Readiness Quiz](https://www.intrasec.ca/quiz/m365-security): Twelve questions on MFA, conditional access, admin roles, external sharing, threat protection, Secure Score and backup to gauge how well a Microsoft 365 tenant is locked down. A readiness indicator, not an audit. - [Founder IT Readiness Quiz](https://www.intrasec.ca/quiz/founder-it): Twelve questions on identity, devices, backup, email security and basic policies to gauge whether an early-stage business has the IT foundations in place to scale safely. A readiness indicator, not an audit. - [Link Safety Checker](https://www.intrasec.ca/tools/link-safety-checker): Paste a suspicious link to see where it really goes. Expands every redirect to the true destination, then flags URL shorteners, look-alike domains, brand-in-subdomain tricks, newly registered domains, raw IP hosts and risky file types. ## Guides Plain-language, evergreen guides for Canadian small businesses: - [IT documentation every small business needs](https://www.intrasec.ca/blog/it-documentation-for-small-business): The IT documentation every small business needs to avoid being hostage to one person's memory (the bus factor): key accounts and who owns them (never the passwords, which belong in a password manager), important systems and vendors with support contacts, the essentials of the setup (domain, hosting, network, devices), short how-tos for one-person tasks, and recovery basics. Plus how to keep it usable, current, and secure. - [Getting your SaaS sprawl under control](https://www.intrasec.ca/blog/managing-saas-sprawl-for-small-business): How a small business gets SaaS sprawl (the untracked pile-up of app subscriptions) under control: why it costs both money and security, how to inventory what you actually run (bank statements, email receipts, asking the team), how to cut and consolidate duplicates and unused seats, how to close the security gaps (MFA, offboarding access, single sign-on), and how to keep sprawl from creeping back. - [Where AI still needs a human](https://www.intrasec.ca/blog/keeping-a-human-in-the-loop-with-ai): Where a small business should keep a human in the loop when using AI: always for anything published under your name, decisions about people, factual and legal/financial claims, money or irreversible actions, and production code; a lighter touch for low-stakes reversible work. Includes a simple cost-and-reversibility test and the case for writing the line into an AI use policy. - [Consent under Canadian privacy law](https://www.intrasec.ca/blog/consent-under-canadian-privacy-law): How consent works under Canadian privacy law for a small business: the default requirement to have knowledge and consent under PIPEDA and Quebec's Law 25, the difference between implied consent (obvious low-sensitivity uses) and express consent (sensitive data, marketing, sharing), what makes consent valid (informed, specific, freely given, easy to withdraw), and practical steps including the CASL rules for marketing email. - [When someone asks to see (or delete) their data](https://www.intrasec.ca/blog/handling-data-access-and-deletion-requests): How a small business should handle a data access or deletion request under Canadian privacy law: the access, correction, and deletion rights individuals have under PIPEDA and Quebec's Law 25, why a plain-email request is valid, the roughly 30-day response clock, when you can refuse (another person's data, legal retention duties, exemptions), and the simple process (named owner, intake address, data inventory, log) to handle it routinely. - [Who owns what your AI creates?](https://www.intrasec.ca/blog/ai-copyright-and-ownership-for-small-business): Who owns AI-generated work and whether a small business can safely use it: the two separate questions of ownership (copyright generally needs human authorship, so pure AI output is weak) and infringement risk (output can resemble protected work, and you are responsible for its use), what AI vendors' terms and indemnities actually grant, and practical rules plus when to get legal advice. - [Vibe coding: great for launch, hard to scale](https://www.intrasec.ca/blog/vibe-coding-risks-for-small-business): The risks of vibe coding (building apps by prompting AI): great for prototypes, but scaling one into production without deliberate architecture, backend, and security leads to a costly rebuild. Where it helps, where it breaks, and how to use it wisely. - [Do you need a Privacy Officer?](https://www.intrasec.ca/blog/do-you-need-a-privacy-officer): Canadian privacy law already expects a named person accountable for personal information: PIPEDA's accountability principle requires designating one, and under Quebec's Law 25 the CEO or owner is the Privacy Officer by default unless the role is delegated in writing, with the title and contact published. Explains who should hold the role in a small business, what it actually does (contact point, honest privacy policy, access and deletion requests, breach response), and how to make it real in an afternoon with a published address like privacy@yourcompany.ca. - [MFA isn't magic: the sign-in scams that still get past it](https://www.intrasec.ca/blog/mfa-bypass-scams-for-small-business): MFA is the best security move a small business can make and you should keep it on, but "we have MFA" became a false synonym for "we are safe." Attackers rarely BREAK MFA, they trick people into helping. The three real-world bypasses (none crack your second factor): (1) DEVICE-CODE PHISHING, the attacker starts a legitimate sign-in, shows you a short code, gets you to enter it at the real Microsoft/Google page, you approve THEIR session not yours (the trick behind the hotel Wi-Fi / CaptiveCrunch attacks); (2) CONSENT/OAUTH PHISHING, instead of your password you're asked to grant a malicious app permission to your account, click "allow" and it has ongoing access with no password/MFA needed again; (3) ADVERSARY-IN-THE-MIDDLE session theft, a fake login page relays everything including your MFA and copies the finished session token. Common thread: your password and MFA worked, you were tricked into approving/granting/completing something for the attacker. Fixes: move to phishing-resistant MFA (passkeys/hardware keys bound to the real site, they don't work on a fake page or relay, biggest upgrade especially for admins); never approve a code/prompt/consent you didn't personally start (teach the team this reflex); use Conditional Access (restrict device-code flow, require compliant devices, limit risky sign-ins); periodically review and remove unrecognised app (OAuth) permissions. Not a reason to skip MFA, a reason to use the strong kind with guardrails. - [AI meeting assistants for small business: what to know before you turn one on](https://www.intrasec.ca/blog/ai-meeting-assistants-for-small-business): AI meeting assistants (join calls, transcribe, produce a summary with action items) are an easy AI win for a small business, they give attention back and end the "who's taking notes?" scramble. Good at: accurate transcript, concise summary, who-agreed-to-what, automatically; the built-in options (Copilot in Teams, equivalents in Google Meet) are the easiest start because they inherit your existing security and data agreements. The catch: a transcript is a RECORD, sensitive things said now exist in written, searchable, storable form, consider who can access transcripts, how long they're kept (retention applies), and whether you'd want every word of a candid conversation preserved. Consent/courtesy: recording involves other people, tell them ("we use an AI note-taker, let me know if you'd rather we didn't"), it's transparent and where privacy expectations are heading. Choosing one: prefer the built-in option in your existing platform (fewer vendors, inherited security); for a standalone tool apply the same selection questions as any AI tool, does it train on your data, does it sign a DPA, where are recordings stored, can you control retention/access, meeting content is often sensitive so the business tier and clear data promises matter. - [Building a security-aware team without a big budget](https://www.intrasec.ca/blog/security-awareness-culture-small-business): The most cost-effective security upgrade for a small business is a team that pays attention, most incidents start with a person clicking/approving/trusting the wrong thing, so most are preventable by people, no expensive platform needed. Culture beats a once-a-year compliance video: keep it small and continuous (a plain note when a scam is going around, a quick mention of a real phishing email someone caught, a five-minute team-meeting item) to keep people gently alert all the time. Teach the few behaviours that matter: pause on urgency (AI makes fakes convincing); verify money/login requests out of band on a known number; use MFA and a password manager, never reuse passwords; report anything odd fast and know who to tell. Make reporting SAFE and celebrated, early reporting is the most valuable behaviour and only happens if people aren't blamed (blame makes the next person hide it, and hiding turns a small mistake into a big breach), thank people, treat near-misses as wins. Lead from the top, culture follows the owner; it costs consistent attention, not money. - [Data classification: knowing what you actually hold](https://www.intrasec.ca/blog/data-classification-for-small-business): Most small businesses protect all data the same way, which over-protects the trivial and under-protects the sensitive. Data classification is a light habit: sort information by sensitivity so you focus protection where a leak would actually hurt. Why: you can't make sensible protect/share/keep/delete decisions on one undifferentiated pile; classification is the foundation under retention, access control, your privacy policy, and breach planning, and extortion-first attacks make it practical (knowing where crown-jewel data lives tells you what an attacker most wants). Three tiers are enough: Public (would happily post, e.g. marketing/published prices, no special handling); Internal (ordinary business info not for outsiders, reasonable care); Confidential/sensitive (would genuinely hurt if exposed, customer personal info, financial/payment data, contracts, credentials, health data, strongest protection here). Act on it: concentrate tighter access (need-to-know), encryption, careful sharing, backup/monitoring priority, and strictest retention on the confidential tier. Keep it light, name your handful of sensitive data types and where they live, revisit when you add a system; it's a lens, not a filing project. - [Keeping your AI tools and integrations secure](https://www.intrasec.ca/blog/securing-ai-tools-and-integrations-small-business): AI tools are software with real, quiet power, they often read your files, act in your other apps, and hold valuable credentials; adopted in a rush they become an unwatched hole. Keep them safe with ordinary discipline applied to new software: (1) inventory the AI tools you use and what each can reach (email, files, CRM, calendar), including AI features/plug-ins inside tools you already run, an AI assistant with access to your whole mailbox is doing a lot quietly; (2) least privilege, connect each tool only to the data it needs, prefer read-only, read what an integration actually requests (over-permissioned tools turn one compromise into everything); (3) guard the API keys (they let software use paid AI models, a stolen key runs up bills or reaches data), don't hard-code or paste them, rotate if exposed, store properly, treat like a bank password; (4) prefer reputable managed services over unmaintained self-hosted, and patch anything you run (attackers are probing AI infrastructure). Folds into your AI acceptable-use policy and light governance program. - [Questions to ask your IT provider about their own security](https://www.intrasec.ca/blog/questions-to-ask-your-it-provider-security): Your IT provider has the deepest access to your systems (admin credentials, remote-access tools, your passwords and backups) but is rarely audited, and when their tools are attacked (see recent RMM compromises) your business is exposed. You don't need to be technical to check they take their own security seriously. Ask: (1) how they protect their access to you, MFA on every account that can reach your systems, remote-management tools patched promptly and monitored for compromise, how your admin credentials/passwords are stored (vagueness here is the loudest red flag); (2) how they'd handle their own breach, would you be told and how fast, do they have an incident-response plan covering clients, have they had an incident and how did they handle it (you want honesty + a plan, not a spotless record); (3) whether you stay in control, do YOU own your domains/accounts/data (not under their name), could you leave cleanly (a provider holding your domain or M365 tenant has quiet power over you). What good sounds like: they welcome the questions, answer plainly, and can point to real practices; defensiveness is itself the answer. - [AI compliance: which rules actually apply to your small business](https://www.intrasec.ca/blog/ai-compliance-for-small-business): An honest map of AI rules for a Canadian small business (general guidance, not legal advice): (1) EU AI Act, reaches you only if you put AI on the EU market or your AI output reaches people in the EU, for a Canadian firm serving Canadian customers with internal AI use it does not apply; the one piece to check is transparency (public AI chatbot or AI-generated content reaching the EU may owe disclosure). (2) US state AI laws, relevant only if you operate/sell there, aimed mainly at AI in consequential decisions (hiring/credit/housing/insurance). (3) Canada, own AI rules expected to return as standalone legislation (transparency/accountability), not in force yet, but existing privacy law (PIPEDA, Law 25) already applies whenever AI touches personal data. What to do regardless (satisfies all of them): know where you use AI, be transparent when AI meaningfully affects a customer or a decision about a person, keep humans accountable for outcomes, protect the personal data AI touches, i.e. a light AI governance program. Proportionate, not fearful. - [Prompt-writing basics: getting better answers from AI](https://www.intrasec.ca/blog/prompt-writing-for-small-business): Getting good answers from AI is about how you ask, not secret magic words, it is clearly describing what you want, like briefing a capable new assistant. Habits: (1) give context, tell it who you are, who the output is for, and the goal (a one-line prompt gets a generic answer; adding who/for-whom/why gets something you can almost send); (2) say what "good" looks like, specify length, tone, format, ask for a few options, give an example, and iterate by saying what to change rather than starting over (AI is good at iterating); (3) ground it in your real material (paste the notes/draft/data/prior email, it improves your content better than it invents, and stays accurate to your business). Keep two rules: verify anything factual (AI is confidently wrong), and don't paste sensitive/client data into a free consumer tool, use an approved business-tier tool. - [How much should a small business spend on IT and security?](https://www.intrasec.ca/blog/it-security-budget-for-small-business): "How much should we spend on IT/security?" A plain method rather than a magic number: sanity-check against a rough 3-6% of revenue for IT overall (varies widely by industry and tech-dependence, use it to catch spending near-zero or spending-a-fortune-with-no-plan, not as a target); spend in ORDER, basics first (MFA, managed email/devices, patching, tested backups, they prevent the incidents that actually happen), then resilience (backup/recovery, keep working when something breaks), then advanced monitoring/tooling once fundamentals are solid (buying a shiny product while the team has no MFA is back-to-front). Avoid the two expensive mistakes: underspending on the "too small to be targeted" gamble (modern attack economics no longer support it) and overspending on fear-sold overlapping tools. Favour predictable monthly managed cost over surprise emergency-rate capital hits. - [Vendor security: how to vet a supplier before you trust them with your data](https://www.intrasec.ca/blog/vendor-security-assessment-for-small-business): A vendor's security becomes your security: when a supplier is breached, your customers' data can be exposed even though you did nothing wrong, and "our supplier lost it" is not a defence. Right-size the check by how much sensitive data the vendor touches (a payment processor or CRM deserves scrutiny; a font library does not). Questions that matter: recognised certification (SOC 2 / ISO 27001); where data is stored and whether it is encrypted in transit and at rest (relevant to PIPEDA/data residency); will they sign a data processing agreement (DPA); how and how fast they would notify you of a breach; and whether you can export your data and leave cleanly. Red flags: can't answer basic security questions, no security/privacy info on their site, won't sign a DPA, vague on data location, hard to leave. Keep a short record of which vendors hold what data, the backbone of a light privacy management program and the flip side of answering a client security questionnaire. - [How to spot AI-generated scams and deepfakes: a staff guide](https://www.intrasec.ca/blog/spotting-ai-scams-and-deepfakes-small-business): AI has erased the old scam tells (bad spelling, robotic voices), it now writes flawless phishing, clones voices from seconds of audio, and generates deepfake video. A staff guide: (1) stop trusting how a message looks/sounds, polish is no longer proof of authenticity; (2) watch the ASK, not the messenger, almost every scam pushes urgency + secrecy + a money-or-credential request (urgent payment/bank-detail change, gift cards, passwords/codes, re-authentication pages); (3) the one habit that beats every deepfake is verify out of band, confirm on a known number/channel the attacker does not control (call the boss/supplier back on a number you already have); (4) make it culturally safe to pause and verify, never punish the "delay." Same discipline that stops business email compromise. - [Securing Google Workspace: the admin settings that matter](https://www.intrasec.ca/blog/securing-google-workspace-for-small-business): Google Workspace is secure by design but not secure by default for you. The settings a small business should turn on: enforce 2-Step Verification for everyone (prefer authenticator app/passkey over SMS) and block legacy/"less secure app" sign-in that skips it; restrict external Drive sharing and outbound mail auto-forwarding (a quiet mailbox-siphon trick); review and prune connected third-party apps; turn on admin alerts for suspicious logins/sharing/mass-downloads; and protect super-admin accounts with a hardware key, kept few and not used day-to-day. Mostly free on the plan you already pay for. Parallel to the Microsoft 365 sign-in hardening guide for M365 shops. - [Email authentication explained: SPF, DKIM, and DMARC](https://www.intrasec.ca/blog/email-authentication-for-small-business): Three DNS records decide whether a scammer can send email that looks exactly like it came from your business (spoofing your domain to phish customers/staff with your name on it). SPF = a public list of servers allowed to send for your domain (a guest list); DKIM = an invisible tamper-proof signature proving a message genuinely came from you and wasn't altered (a wax seal); DMARC = ties them together, tells receivers what to do on failure (nothing/quarantine/reject), and emails you reports (the policy + security camera). Set them up in ORDER: publish SPF + DKIM for every legitimate sender first, then DMARC in monitor-only mode for a couple of weeks to catch senders you forgot, then tighten to quarantine and finally reject. Jumping straight to reject is the classic mistake that sends your own real email to spam. Check where you stand free with the Email Security Checker. - [Records retention: how long to keep data, and why less is safer](https://www.intrasec.ca/blog/records-retention-for-small-business): Most small businesses keep everything forever by default, but every record you hold is something to protect and something that can be stolen in a breach. Data minimisation (keep only what you need, only as long as you need it) is both safer and a core expectation of PIPEDA and Quebec's Law 25 (don't keep personal info past its purpose). Retention balances two forces: records you're REQUIRED to keep (tax/financial for several years per CRA, employment records) vs data you should DELETE once its purpose is done (unconverted marketing lists, old CVs, answered contact-form messages). Build a one-page schedule: list record types, note why/how long you keep each, set a recurring delete date, and delete securely (live systems + backups + third-party copies). General guidance, not legal/tax advice; confirm exact minimums with a professional. - [AI for customer service, without losing the human touch](https://www.intrasec.ca/blog/ai-for-customer-service-small-business): For a small business whose edge is personal service, use AI behind the scenes (draft-and-review replies, summarise long threads, build an FAQ) rather than burying customers behind a bot. Where it backfires: a customer-facing bot that loops, can't understand real problems, hides the human-escape, or confidently invents a policy/price you never made (you're on the hook). Sensible setup: assist your team don't replace the front desk; if you use a bot make the human escape one obvious tap and reserve it for simple questions; ground it only in your real FAQ/policies; keep customer messages (personal data) out of free consumer tools; and always be honest that it's AI (transparency is where regulation is heading, and customers forgive a labelled bot). - [Cyber insurance: what it actually covers (and what voids a claim)](https://www.intrasec.ca/blog/cyber-insurance-what-it-covers-small-business): What a small business cyber policy really does. First-party cover pays your own costs (investigation, data/system restore, lost income, breach notification, often ransom); third-party cover pays for harm to others (legal costs, settlements, insurable fines); many policies include an incident-response team on call, often worth as much as the money. Gaps that surprise people: it won't pay to upgrade your security afterward, won't cover losses from a known unpatched vulnerability, and invoice/funds-transfer fraud often sits under a much lower sub-limit, read the per-category ceilings. The big trap: the application is a set of promises (you attest to MFA, patching, backups, training), and if a claim shows those weren't true the insurer can reduce or deny it, so answer honestly and fix gaps before you sign. Not insurance advice. - [Writing an AI acceptable-use policy for your team](https://www.intrasec.ca/blog/ai-acceptable-use-policy-for-small-business): Your team is already using AI, so the choice is whether to have a good policy, not whether to have one. Keep it to one page people actually read. The single most important rule: never paste sensitive or confidential information into a public consumer AI tool (those tiers can retain and train on inputs), give the team an approved business-tier tool instead (e.g. Copilot in a paid M365 plan). A good one-pager covers: what AI is for here, which tools are approved (stops "shadow AI"), the data rule, always-verify (AI states falsehoods confidently), be transparent where AI meaningfully affects a customer or a decision about a person, and who to ask. Make the safe path the easy path (provide a good approved tool), walk the team through it once, and revisit when tools change. It's the staff-facing front door to a fuller AI governance program. - [How to choose which AI tools to pay for](https://www.intrasec.ca/blog/choosing-ai-tools-for-small-business): A plain framework for picking AI tools for a small business, so you avoid both FOMO and a pile of unused subscriptions. Start with the recurring JOB you want to speed up, not the tool. The question that matters most: what happens to your data, does it train on your inputs (free/consumer tiers often do; business/enterprise tiers promise not to), is there a data-processing agreement (DPA), and where/how long is data kept (PIPEDA + Law 25). Short rule: for anything touching real business data, pay for the business tier. Prefer AI built into software you already run (Copilot in Microsoft 365, Gemini in Google Workspace) so it inherits your existing security, admin controls, and data agreements. Check the boring-but-decisive things: central admin/access control, a real security posture, clean exit / no lock-in (favour month-to-month), and true total cost (per-seat adds up; cancel the tools it replaces). Buy small, prove it on one or two people for a month against the chosen job, then expand or cancel. - [Cookie consent and website tracking for a small business](https://www.intrasec.ca/blog/cookie-consent-for-small-business): What a Canadian small business actually needs for cookies and website tracking. Cookies split into essential (keep you logged in, cart, make the site work; generally no opt-in needed) and non-essential (analytics, ad/pixel trackers from Google/Meta/LinkedIn; these need meaningful consent). Canada has no single "cookie law," but PIPEDA and Quebec's Law 25 require informed consent to track, and Law 25 expects tracking tech OFF by default until the visitor turns it on. A good banner offers an equally-easy Accept/Reject, actually waits to load non-essential trackers until consent, is brief and honest, and remembers the choice; use a reputable consent-management tool rather than hand-coding. The most underrated move: audit and REMOVE trackers you do not need, less tracking means a simpler banner, shorter privacy policy, and less risk. Pairs with the privacy-policy guide; general guidance, not legal advice. - [Practical AI use cases for a small business (that actually save time)](https://www.intrasec.ca/blog/ai-use-cases-for-small-business): You don't need an AI strategy to get value, just one tedious task and a willingness to edit the output. The reliable wins for a small business: email triage and drafting, meeting notes and summaries (Teams/Google Meet), first drafts of proposals/quotes/policies, spreadsheet and data cleanup, customer replies and FAQs, and marketing copy. The mindset: treat AI as a fast junior assistant, not an oracle, so "generate then verify" (never send output unread; it can state falsehoods confidently). Give it context for better results. The one safety rule: never paste sensitive or confidential data into a free consumer AI tool (those tiers may retain and train on inputs), use the business/enterprise tier (e.g. Copilot in a paid M365 plan) where the provider won't train on your data. Honest limits: not for critical unverifiable accuracy (legal/tax/medical), not a replacement for people you need. Start with one task this week. - [How to write a privacy policy for your small business website](https://www.intrasec.ca/blog/privacy-policy-for-small-business-website): A privacy policy is a public promise about how you handle people's personal information, and for a Canadian small business it is effectively required (PIPEDA + provincial laws like Quebec's Law 25, plus platforms like Google/Meta/payment processors demand a policy URL). What actually goes in it: who you are, what you collect (including IP/analytics data), why, who you share it with, retention and protection, and people's access/correction/deletion choices. The part most policies miss: cookies and third-party tracking (Google Analytics, Meta/LinkedIn pixels, chat widgets) that quietly send visitor data out. Common mistakes: copy-pasting another business's policy (inaccurate the moment you publish), promising "we never share your data" (false the instant you use an email host), and never updating it. Write an honest first version yourself; bring in a lawyer for sensitive data, Law 25, cross-border customers, or real scale. General guidance, not legal advice. - [Locking down Microsoft 365 sign-in security](https://www.intrasec.ca/blog/microsoft-365-sign-in-security-for-small-business): MFA alone is not enough, because it only protects the doors it is applied to. The practical settings that make Microsoft 365 sign-in actually hold: apply MFA to every user (not just admins), every cloud app, and every location, in enforce mode (not report-only); block legacy/basic authentication and password-only paths like ROPC and command-line sign-in that skip the MFA prompt; use Security Defaults for very small tenants with no Conditional Access; give admin accounts phishing-resistant MFA (passkeys/hardware keys) and keep them few and separate; and review or get alerted to unusual sign-ins. Includes a short checklist. Companion to the July 18 M365 password-spraying news. - [Fractional CIO or vCISO: senior IT and security leadership without the full-time hire](https://www.intrasec.ca/blog/fractional-cio-vciso-for-small-business): Explains what a fractional CIO or vCISO does for a 10 to 80 person company: a 12-24 month technology roadmap and budget, vendor decisions, a right-sized security program, questionnaire and compliance ownership, and plain-language reporting. Argues one senior person should cover both roles at small-business scale, lists five signals it is time (two or more is the threshold), and notes a full-time hire is a low-to-mid six-figure salary while fractional buys a few days a month. Ends with five vetting questions, including vendor-commission independence and Canadian context (Law 25, PIPEDA). - [Wi-Fi and network security for a small office](https://www.intrasec.ca/blog/wifi-and-network-security-for-small-business): Your office network is the front door to everything you run. The practical steps for a small business: change default admin/Wi-Fi passwords, run a separate guest network walled off from business systems, use WPA3 (or at least WPA2) with a strong passphrase, keep router/access-point/firewall firmware patched, segment untrusted devices (cameras, IoT, point-of-sale) onto their own VLAN, turn off internet-facing remote administration, and know when to move from a consumer router to business-grade gear as you grow. - [Mobile device and BYOD security for small business](https://www.intrasec.ca/blog/mobile-device-and-byod-security-for-small-business): Phones and tablets hold your business data too. Securing company-owned devices (management enrollment, encryption, screen lock, updates, remote wipe), doing BYOD right with app-level protection that guards company data without touching the personal device, the universal basics (lock, updates, official app stores, MFA/passkeys), a lost-or-stolen and offboarding plan, and a one-page mobile/BYOD policy. - [Defense in depth for small business: why one control is never enough](https://www.intrasec.ca/blog/defense-in-depth-for-small-business): No single security control is enough, because every control fails sometimes. The layered approach for a small business: identity/MFA, least privilege (no standing local admin), endpoint detection, patching, email defenses, tested backups, monitoring/response, and people/training, so that no single failure (including a zero-day) becomes a disaster. The mindset shift: not "what one thing keeps us safe?" but "if this fails, what catches it?" - [Employee monitoring and workplace privacy: a small business guide](https://www.intrasec.ca/blog/employee-monitoring-and-workplace-privacy): What a small business can and should monitor, the Canadian backdrop (PIPEDA and provincial PIPA/Law 25 reasonableness; Ontario's written electronic-monitoring-policy rule for 25+ employees), the four principles (legitimate purpose, proportionality, transparency, boundaries), and what most SMBs actually need (standard security logging + a one-page policy, not surveillance). - [IT infrastructure basics for a growing small business](https://www.intrasec.ca/blog/it-infrastructure-for-small-businesses): Explains the four core pieces of small-business infrastructure: network and Wi-Fi with a separate guest network, central identity with MFA, consistently configured devices, and cloud-hosted servers and storage. Separates the two jobs of building infrastructure and running it, and argues the time to invest is just before the strain: hiring, a second location, or a setup held together by workarounds. The foundations to get right first are central identity, a clean segmented network, consistent devices, and tested backups. - [Backup and recovery: the 3-2-1 rule explained](https://www.intrasec.ca/blog/backup-and-recovery-for-small-businesses): Explains the 3-2-1 backup rule for small businesses: three copies of your data, on two types of storage, with one copy off-site and disconnected. A backup you have never restored from is just a hope, so restore a few files on a schedule, and recovery time matters as much as the backup: being back in hours rather than days depends on design. A clean, disconnected copy lets you refuse a ransomware demand, wipe, and restore, which is why attackers now hunt for backups too. - [Business continuity and disaster recovery: a small business guide](https://www.intrasec.ca/blog/business-continuity-and-disaster-recovery-for-small-business): Why a backup is not a plan. The difference between backup, disaster recovery, and business continuity; how to identify your critical business functions; setting recovery targets (RTO and RPO) in plain language; writing a short continuity plan (roles, out-of-band communication, offline copy, key contacts, workarounds); testing it with a tabletop walk-through and a real restore; and the disruptions to plan for (cyberattack, cloud/SaaS outage, fire/flood, key-person loss, supplier failure). - [Cloud adoption for Canadian small businesses](https://www.intrasec.ca/blog/cloud-adoption-for-canadian-small-businesses): Cloud means renting computing instead of owning it, and this guide gives small businesses a migration order: email and files first (Microsoft 365 or Google Workspace), hosted business apps next, servers last and only when justified. It warns that cloud is rarely cheaper by default, that subscription sprawl is the main cost trap (review spending at least twice a year), and that securing accounts and data stays your job. Also covers choosing a Canadian data region when privacy obligations or client contracts require it. - [Do you need to back up Microsoft 365? The shared-responsibility gap](https://www.intrasec.ca/blog/do-you-need-to-back-up-microsoft-365): Why "it's in Microsoft 365" is not the same as "it's backed up." The shared-responsibility model (Microsoft keeps the service running; protecting your data inside the tenant is on you), what M365 does and does not protect, the real gaps (deletion past the recycle bin, malicious/compromised-account deletion, ransomware syncing to the cloud, misconfigured retention, offboarding), native tools vs a true third-party backup, and when a paid backup is worth it. - [Secure remote and hybrid work: a small business guide](https://www.intrasec.ca/blog/secure-remote-work-for-small-business): How to let a team work from anywhere without opening the business up: the perimeter shift from network to user and device, securing devices (managed enrollment, encryption, app protection for BYOD), securing access (MFA everywhere, zero trust vs the old VPN, never expose RDP), protecting data (keep it in the sanctioned cloud, conditional access), the human layer, and a one-page remote-work policy. - [Securing employee onboarding and offboarding: a small business guide](https://www.intrasec.ca/blog/employee-onboarding-and-offboarding-security): The identity lifecycle (joiner-mover-leaver) for small businesses: least-privilege onboarding, adding and removing access on role changes, a same-day offboarding checklist (disable the identity account, kill sessions and MFA, rotate shared secrets, wipe the device, preserve data, catch the non-SSO apps, revoke physical access), and quarterly access reviews. - [Passwords and passkeys: a small business guide to going passwordless](https://www.intrasec.ca/blog/passwords-and-passkeys-for-small-business): Why passwords fail (reuse and phishing), how a team password manager and phishing-resistant MFA fix it, what passkeys are and why they cannot be phished, a realistic rollout order, and why forced periodic password changes are outdated (NIST) advice to drop. - [How to stop business email compromise: a small business playbook](https://www.intrasec.ca/blog/how-to-stop-business-email-compromise): Business email compromise (a hijacked or spoofed email that reroutes a real payment) is the costliest single fraud hitting Canadian small businesses. How the scam works, why small firms are hit hardest, the controls that stop it (verify payment changes out of band, MFA on email, SPF/DKIM/DMARC, dual payment approval, staff training), the warning signs, and what to do in the first hour if you are hit. - [Microsoft Intune licensing explained for small businesses](https://www.intrasec.ca/blog/microsoft-intune-licensing-explained): The Intune SKUs in plain language (Plan 1, Plan 2, the Suite), which Microsoft 365 plans already include Intune (Business Premium, E3, E5 all include Plan 1), per-user vs per-device licensing, how to pick, and the common cost leaks (don't buy Intune you already own, don't double-buy the Suite add-on, use device licenses for shared hardware). - [Data residency for Canadian small businesses: what you actually control](https://www.intrasec.ca/blog/data-residency-for-canadian-small-businesses): Separates data residency (the country where data is stored) from sovereignty (whose laws can compel access), noting the 2018 U.S. CLOUD Act reaches data a U.S. provider stores in Canada. Covers the real levers: Microsoft's Canada Central and Canada East regions plus the Advanced Data Residency add-on, Google Workspace's broad regions that make Canadian residency a harder fit, and Cloudflare's Data Localization Suite. Includes a three-question vendor exercise and when residency genuinely matters: Law 25, health data, and government or enterprise contracts. - [Cybersecurity basics for Canadian small businesses](https://www.intrasec.ca/blog/cybersecurity-basics-for-canadian-small-businesses): Eight plain-language basics that stop most opportunistic attacks on small companies: MFA everywhere (email first), 3-2-1 backups you actually test-restore, automatic updates, a password manager, phishing awareness, limited admin access, device encryption with screen locks, and a one-page incident plan. Notes that PIPEDA expects reasonable safeguards and breach reporting, and that client security questionnaires ask about exactly these controls, so getting them in place can win contracts as well as cut risk. - [Modernizing your small-business IT](https://www.intrasec.ca/blog/modernizing-your-small-business-it): Most small-business IT accumulates rather than gets designed. This guide lists the signs you have outgrown your setup (days-long onboarding, key knowledge in one person's head, software past its security updates), then argues for optimizing before buying: cutting duplicate tools, unused licences, and default settings often beats a new purchase at no extra cost. The sensible order: fix security and supportability first, remove waste, then modernize the rest in stages so the business keeps running. - [Data breach notification: what a Canadian small business must do](https://www.intrasec.ca/blog/data-breach-notification-for-small-business): When you must legally report a data breach in Canada (the "real risk of significant harm" test), who to notify (the OPC, affected individuals, Quebec's CAI under Law 25), what the notice must say, and the breach log you must keep even for non-reportable incidents. - [IT for founders: what to set up first](https://www.intrasec.ca/blog/it-for-founders-what-to-set-up-first): The IT foundations to get right first and in what order, one identity platform, the security basics, consistent devices, real backups, owning your accounts and data, keeping the stack small, and when to bring in help. - [Unified endpoint management for small businesses](https://www.intrasec.ca/blog/unified-endpoint-management-for-small-businesses): Explains unified endpoint management (UEM): one console to enroll, configure, patch, and secure every laptop, desktop, phone, and tablet, with remote lock and wipe for lost devices and same-day offboarding. Readiness signs include passing roughly ten people, remote or hybrid teams, mixed personal and company devices, and client or insurer security questionnaires. Key point: Microsoft 365 plans usually already include Intune, Google Workspace has endpoint management built in, and Apple-heavy shops use Jamf, so this is often about configuring a tool you already pay for. - [How to choose a managed IT provider for your small business](https://www.intrasec.ca/blog/how-to-choose-a-managed-it-provider): A vetting guide for hiring an MSP: define your scope first, then push for guaranteed response times in writing, proof they practise the security they sell, and exactly what the monthly fee excludes. Explains per-user, per-device, flat-rate, and break-fix pricing, and lists the red flags: no written service levels, long lock-in contracts, no references, the provider holding your domain and Microsoft 365 tenant in their name, and a solo operator with no backup. Stresses confirming you own your accounts, data, and documentation, with a clean exit, before signing. - [Physical security basics for small offices](https://www.intrasec.ca/blog/physical-security-for-small-offices): Covers the physical half of protecting a small office: per-person access control (fob, card, or phone) that replaces shared keys and allows instant revocation when someone leaves, a few cameras at entrances with securely stored footage, and a monitored alarm for after-hours break-ins. Also maps where physical meets cyber: an unencrypted stolen laptop is a data breach and a tailgater can plug into your network, so device encryption, screen locks, and a separate guest network cover the overlap. - [Consumer vs business plans: what the business tier really buys you](https://www.intrasec.ca/blog/consumer-vs-business-plans-for-small-business): The price gap between consumer and business software plans mostly buys security, privacy, and control (enforced MFA, a data-processing agreement, central admin, compliance, and company ownership of the account). What you actually get, and when to upgrade. - [Vulnerability management for a small business: a practical guide](https://www.intrasec.ca/blog/vulnerability-management-for-small-business): A five-step vulnerability management loop sized for a business without an IT department: inventory your assets, find weaknesses using vendor advisories and free tools instead of an expensive scanner, prioritize what is internet-facing or actively exploited over raw severity scores, then fix, mitigate, or consciously accept each one, and verify the fix took. Run it as a light monthly or quarterly routine; AI is shrinking the window between a patch appearing and the flaw being exploited. - [How to build a privacy management program for your small business](https://www.intrasec.ca/blog/privacy-management-program-for-small-business): A six-step build of the privacy management program Canadian law now expects: PIPEDA expects it, Quebec's Law 25 requires it, and the proposed federal Bill C-36 would make it the national baseline. The steps: name a privacy officer, map the personal data you hold, set rules for consent, minimal collection, and retention, prepare for access requests and breach reporting (to the regulator and, in Quebec, the Commission d'acces a l'information), put vendor obligations in contracts, then document it and review yearly. - [Microsoft 365 vs Google Workspace for a Canadian small business](https://www.intrasec.ca/blog/microsoft-365-vs-google-workspace-for-small-business): Compares the two platforms for a Canadian small business: Google Workspace wins on simplicity and browser-based collaboration, while Microsoft 365 adds desktop Office plus deeper governance through Entra ID conditional access, Purview data loss prevention, Defender for Office 365, and audit, eDiscovery, and retention tooling. Advises moving to Microsoft 365 when clients or insurers raise the compliance bar, staying on Workspace when it serves you, and treating migration as a planned project covering mail, files, identity with MFA from day one, and training. - [Windows vs Mac for a Canadian small business](https://www.intrasec.ca/blog/windows-vs-mac-for-small-business): Argues both platforms are mature and the costly mistake is running a mixed fleet, which roughly doubles management (Intune vs Jamf), patching pipelines, support skills, and security baselines. Windows suits regulated fields, Windows-only line-of-business software, Microsoft 365 with Entra and Intune, and tight hardware budgets; Mac earns its place for design and development teams, all-Apple shops, and secure-by-default simplicity. The advice: standardize on one platform, with exceptions by role, not personal taste. - [How to roll out Copilot without overwhelming your team](https://www.intrasec.ca/blog/copilot-rollout-for-small-business): The two ways Copilot rollouts go wrong (a support-ticket flood and oversharing that surfaces data people shouldn't see) and how to avoid both: fix access first, roll out in waves, train to deflect tickets, plan the support load, and put licences where the value is. - [Does Quebec's Law 25 apply to your business? A plain-language guide](https://www.intrasec.ca/blog/quebec-law-25-for-small-business): Quebec's Law 25 is Canada's toughest privacy law and can apply even to businesses outside Quebec that handle Quebec residents' data. Who it covers, the core obligations, the penalties (up to $25M or 4% of turnover), and a sensible order to comply. - [Is Cloudflare worth it for a small business? The free stack, honestly](https://www.intrasec.ca/blog/is-cloudflare-worth-it-for-small-business): An honest, balanced look at Cloudflare's free tier for SMBs (DNS, SSL, DDoS protection, CDN, basic firewall, DMARC management), what's genuinely useful, the catches, who it's right for, and how to set it up safely. - [Can customers find you when they ask AI? A small business guide to AI visibility](https://www.intrasec.ca/blog/ai-visibility-for-small-business): As people ask ChatGPT, Perplexity, and Google's AI for recommendations, being findable and citable by AI (GEO) becomes its own discipline. How AI reads your site, the basics and new habits that make you visible, and how to check where you stand. - [How to keep your small business website secure](https://www.intrasec.ca/blog/website-security-for-small-business): Your website is software, and most small business sites get hacked through a neglected plugin or a weak login. A practical checklist: hosting, plugins, logins and MFA, HTTPS, off-site backups, and a plan if it gets hacked. - [Your first hour after a cyberattack: an incident response plan for small business](https://www.intrasec.ca/blog/incident-response-plan-for-small-business): When something goes wrong, the first hour decides how bad it gets. Who runs it, how to contain it, what not to do, the notification obligations under PIPEDA and Law 25, and the one-page plan to write before you need it. - [How to use AI without leaking your client data](https://www.intrasec.ca/blog/ai-data-privacy-for-small-business): Practical rules for using AI without leaking client data. Free consumer AI tools may keep your inputs and train on them; business tiers typically do not, add admin controls, and sign data processing agreements, so check training use, data residency, and retention first. Includes a one-page rule set for staff and a preference for AI inside software you control, like Copilot in your own Microsoft 365 tenant. Under PIPEDA and Quebec's Law 25 (penalties up to $25 million or 4% of worldwide turnover) you stay responsible even when an AI vendor processes the data. - [How to prove Copilot (and any AI tool) is worth the money](https://www.intrasec.ca/blog/measuring-ai-tool-roi-small-business): How to build a fundable business case for Microsoft Copilot or any AI tool, now that Copilot is becoming part of Microsoft 365 pricing. The method: pick a success metric tied to a business objective before the pilot, baseline it, run a six-to-eight-week trial with a defined group, and measure outcomes (proposal turnaround, tickets resolved, cycle time) instead of vanity usage stats. A winning result reads like proposal turnaround dropping from five days to two, worth fourteen more proposals a quarter; often the right call is funding it only for writing-heavy roles. - [Patch management for a small business: stay current without breaking things](https://www.intrasec.ca/blog/patch-management-for-small-business): A patching system for a small business without a security team: inventory every device and app first, then patch internet-facing systems and actively exploited flaws (per CISA's Known Exploited Vulnerabilities list) ahead of high severity scores. Auto-update laptops, phones, and browsers; reserve manual testing for servers and the line-of-business app. Warns that firewalls, VPN appliances, NAS boxes, and printers ship fixes too, and anchors the routine to Patch Tuesday, the second Tuesday of each month, with a named owner and at least a monthly cadence. - [Phishing: how to train a small team to spot it](https://www.intrasec.ca/blog/phishing-training-for-small-teams): A no-budget phishing program for teams of 1 to 50: five tells to teach (urgency, mismatched links, unexpected login or banking requests, look-alike senders, pressure to skip process), then a 30-day rollout: one 20-minute session, a blame-free reporting channel, one safe test using built-in Microsoft 365 or Google Workspace simulators, and a no-names review. Success looks like more reports, falling click rates, and clickers self-reporting fast. Backstops: phishing-resistant MFA, SPF/DKIM/DMARC, quick access revocation. - [Do you need SOC 2? A founder's decision guide](https://www.intrasec.ca/blog/do-you-need-soc-2): A decision guide for founders asked about SOC 2. It is an auditor's report from a licensed CPA firm against the AICPA Trust Services Criteria, not a law or a certificate; Type I covers control design at a point in time, Type II proves controls operated over three to twelve months and is what serious customers want. Pursue it only when a customer or deal requires it: a first Type II commonly runs into tens of thousands of dollars plus months of preparation. Often a completed security questionnaire and solid basics satisfy the asker for far less. - [How to adopt AI in your small business (the practical way)](https://www.intrasec.ca/blog/ai-adoption-for-small-business): A practical adoption path for AI in a small business: start with a real time sink (email drafts, summarizing, customer replies, meeting notes) rather than a tool, prefer the AI already in Microsoft 365 Copilot or Google Workspace over new subscriptions, and pick paid tiers that contractually do not train on your data. Three guardrails: never paste client or confidential data into public AI tools, a human reviews all output before it ships, and staff use only approved tools. Recommends piloting with one team, measuring time saved, then expanding what works. - [How to answer a client security questionnaire](https://www.intrasec.ca/blog/how-to-answer-a-security-questionnaire): What a vendor security questionnaire (SIG, CAIQ, or a client's own 200-question spreadsheet) really tests and how to answer it without losing the deal. Core advice: it is a sales document, not an exam; overstating controls creates contractual liability, while an honest 'planned' answer with a timeframe reassures reviewers. Maps the questions to six themes (access control, data protection, backups, people, incident response, vendors and PIPEDA or SOC 2), and recommends one owner, a reusable answer library, and status labels like implemented or partially implemented. - [How to optimize IT costs without losing capability](https://www.intrasec.ca/blog/it-cost-optimization-for-small-business): How to trim small-business IT spend without cutting muscle: build one list of every tool, license, seat, and renewal date; cancel unused subscriptions, duplicate apps, and zombie cloud resources; right-size license tiers and consolidate onto suites you already pay for, like Microsoft 365. Draws a hard line around security spending (MFA, backups, patching, monitoring), which costs little next to one ransomware incident, and recommends a recurring review once or twice a year with one named owner of the list. - [How to build a cybersecurity strategy for your business](https://www.intrasec.ca/blog/how-to-build-a-cybersecurity-strategy): How to build a cybersecurity strategy for a business of 1 to 50 people, adapted from Info-Tech Research Group's approach. Everything hangs on two pillars: what the organization is trying to achieve, and how much risk it is willing to accept, a leadership call most businesses never make explicitly. From there: define a target state, run a gap analysis across people, process, and technology, and sequence initiatives into a 12 to 24 month roadmap. A credible small-business version fits on a couple of pages and gets revisited yearly. - [How to build an AI governance program for your business](https://www.intrasec.ca/blog/ai-governance-program-for-small-business): How to stand up a right-sized AI governance program: an inventory of every AI tool in use (including shadow AI staff adopted quietly), a one-page acceptable-use policy whose most valuable line lists what never goes into a public chatbot, a two-or-three-person review group instead of a committee, and a risk register leadership reviews regularly. Notes Canada currently has no AI law (the proposed AIDA died with Bill C-27 in early 2025), so the pressure comes from clients, insurers, and PIPEDA; borrows structure from the NIST AI RMF and ISO/IEC 42001. - [PCI compliance for small merchants and service providers](https://www.intrasec.ca/blog/pci-compliance-for-small-merchants): Plain-language PCI DSS guide for small Canadian merchants: PCI is a card-brand contract enforced by your payment processor, not a law, and v4.0.1 is the only active version. Explains the four merchant levels (most small businesses are Level 4 and self-assess), the SAQ types from A to P2PE, and the v4.0.1 changes that became mandatory March 31, 2025: MFA on all access to card data, tracking vendor compliance, and script monitoring on checkout pages. The biggest lever is keeping card data out of your own systems via processors like Stripe, Square, Shopify, or Moneris. - [Web design for small businesses: a practical guide](https://www.intrasec.ca/blog/web-design-for-small-businesses): Why a small business still needs a website it owns (social platforms are rented space), and what to prepare before a build: a clear offer, a basic brand, and the content, which is the slow part. Compares DIY builders (Squarespace, Wix, WordPress: monthly fees, lock-in, more to patch) with custom hand-coded sites, insists you own the domain, hosting, and logins, and covers getting found through SEO plus GEO, being citable by ChatGPT, Perplexity, and AI overviews. Speed and security are design decisions, not extras. - [The top AI risks for a small business, and how to manage them](https://www.intrasec.ca/blog/ai-risks-for-small-businesses): Covers seven AI risks for a small business with a management step for each: hallucinated facts feeding real decisions, biased hiring or credit calls, employees pasting client data into public chatbots, privacy obligations under Canadian law, AI-boosted phishing and voice cloning, unclear ownership of AI output, and over-reliance ("the AI said so" is not a defence). The common thread: a short written policy, human review on anything high-stakes, and sensitive data kept out of public tools. - [What a managed IT provider actually does for you](https://www.intrasec.ca/blog/what-a-managed-it-provider-does): Defines managed IT in plain terms: an outside team handles support, monitoring and maintenance, day-to-day security (MFA, patching, endpoint protection), and tested backups, so fewer things break in the first place. Covers the signs you are ready, like downtime costing real money, client security questionnaires, and technology regularly pulling people off their jobs. Also how to judge providers: a named team over a faceless ticket queue, plain language over fear-selling, no lock-in, and documentation instead of dependency. - [UniFi networking and cameras for a small business](https://www.intrasec.ca/blog/unifi-networking-and-cameras-for-small-business): An honest look at Ubiquiti's UniFi line for small businesses: UniFi Network (gateway, switches, Wi-Fi access points) and UniFi Protect cameras recording to a local NVR, all managed from one console with no per-camera cloud subscription. Covers why it is catching on (VLANs, guest Wi-Fi, and PoE cameras at small-business prices) and the caveats: support is community or IT-provider based, a good result still needs proper design, and cameras are attack surface, so segment them on a VLAN, keep firmware current, and never expose the controller to the internet. - [Regulatory compliance for Canadian small businesses](https://www.intrasec.ca/blog/regulatory-compliance-for-canadian-small-businesses): Maps the compliance a Canadian small business actually faces: PIPEDA (consent, safeguards, breach reporting), Quebec's Law 25 plus BC and Alberta privacy acts, client security questionnaires with SOC 2 or ISO 27001 requests, and industry rules like PCI DSS for card payments and provincial health-privacy laws. The same basics, MFA, tested backups, patching, limited access, and an incident plan, satisfy most of what any framework asks; pursue a formal audit only when a real deal requires it. ## News Dated IT and cybersecurity news, explained in plain language with what it means for a small business: - [AI is driving record Patch Tuesdays](https://www.intrasec.ca/blog/2026-08-11-ai-driving-record-patch-tuesday-small-business): Microsoft's August 2026 Patch Tuesday fixed more than 400 vulnerabilities including an actively exploited WinSock zero-day (CVE-2026-68820) tied to North Korea's Lazarus group. Microsoft credits its own AI-powered vulnerability-discovery system for the record patch volumes, which are becoming the norm. What the trend means for a small business and how to keep patching reliable. - [Fully patched WordPress, still backdoored](https://www.intrasec.ca/blog/2026-08-10-wordpress-bdthemes-supply-chain-small-business): The BdThemes WordPress supply-chain attack (disclosed August 2026): attackers poisoned a remote promotional JSON feed used by seven popular Elementor add-on plugins, injecting code into the admin dashboard to create hidden rogue admins and install a webshell backdoor, all without modifying any plugin file, so patched sites and file-integrity checks missed it. What happened and how a small business should detect and remediate it. - [Hotel Wi-Fi is stealing Microsoft 365 logins: what CaptiveCrunch means for you](https://www.intrasec.ca/blog/2026-08-08-hotel-wifi-m365-captivecrunch-small-business): Microsoft Threat Intelligence detailed CaptiveCrunch, a campaign (attributed to Midnight Blizzard / APT29 / Cozy Bear, Russia-linked, tracked Storm-2945) that turns hotel and conference Wi-Fi into a trap for Microsoft 365 accounts. On compromised networks the attackers control the captive portal and its DNS, redirecting guests to fake "update" pages that push malware and to an M365 login trap. The standout technique is DEVICE-CODE PHISHING: the attacker starts a real Microsoft sign-in, shows the traveler a short code, and asks them to enter it at Microsoft's genuine sign-in page, when they do, they authenticate the ATTACKER's session, not their own, and because they completed normal MFA the stolen session is fully trusted (device-code sign-in is a legitimate feature for devices like smart TVs, abused not broken). Why MFA didn't save them: password and MFA both worked, they just approved the wrong session. Honest framing: Midnight Blizzard mostly targets high-value travelers (diplomats, execs), a typical SMB isn't APT29's target, BUT malicious public Wi-Fi and device-code phishing are spreading to ordinary criminals. What to do: never enter a code or approve a sign-in you didn't personally start (this alone defeats device-code phishing); treat public Wi-Fi as hostile (beware "update required" prompts, use a VPN); move to phishing-resistant sign-in (passkeys/hardware keys) and use Conditional Access to restrict the device-code flow. Sources: The Hacker News + Malwarebytes. - [The AI tool behind the first AI-run ransomware is being exploited again](https://www.intrasec.ca/blog/2026-08-04-langflow-exploited-again-small-business): On Aug 4, 2026 CISA added three more actively-exploited flaws to its KEV catalog, including a code-injection flaw in IBM Langflow, the AI-workflow tool that was the entry point for JADEPUFFER (the first largely-AI-run ransomware), alongside an IT-management tool and a widely-used web server. Langflow builds/hosts AI workflows and agents, so a code-execution flaw is serious because such tools are often connected to your data, other systems, and valuable AI service keys. Second time in weeks Langflow drew attention, fitting a pattern of attackers probing fast-growing, less-hardened AI infrastructure. Why it matters even if you don't run Langflow: the category is the point, every AI tool/plugin/integration you adopt is new software with its own vulnerabilities, data access, and powerful credentials, often set up in a hurry. Don't treat AI tools as exempt from normal security. What to do: inventory your AI tools and what they can reach, keep them patched (prefer managed reputable services over unmaintained self-hosted), and limit their access + guard the API keys. Sources: CISA + The Hacker News. - [Attackers hacked an IT-management tool to reach its customers: the supply-chain risk again](https://www.intrasec.ca/blog/2026-08-03-n-able-n-central-rmm-attack-small-business): On Aug 3, 2026 CISA added an actively-exploited flaw in N-able N-central (CVE-2026-18577, an authentication bypass) to its KEV catalog after attackers used it to gain admin control of N-central servers and reach the businesses those servers manage. N-central is an RMM (remote monitoring and management) platform managed service providers use to administer clients' machines; the flaw followed an earlier incomplete fix, exploitation was seen in the wild from early August, and attackers used the platform's legitimate remote-access ("Take Control") features to reach managed endpoints and establish persistence. Fixed in 2026.3.1 Hotfix 1. Why RMM compromise is serious: these tools have deep trusted access across many businesses at once, so breaking one can reach dozens downstream, same shape of risk as the July SimpleHelp flaw. What a small business should do: ask your IT provider directly whether they use N-central and have patched + checked for compromise, expect transparency (evasion is a red flag), and keep independent tested backups and MFA so a provider-side incident isn't total. Sources: Rapid7 + Help Net Security. - [Owners know the cyber risk but feel unready: the small business preparedness gap](https://www.intrasec.ca/blog/2026-07-27-small-business-cyber-preparedness-gap): A July 2026 survey of 440 small business owners found ~43% name phishing/email scams as their single biggest cyber risk (well ahead of everything else), yet only ~19% feel "very prepared" for an attack. The story is that gap: owners correctly identify the #1 way attackers get in but still feel exposed, usually not from apathy but because cyber feels like an endless, jargon-filled spend with no clear "done." The fix is affordable and finite: MFA on email and important accounts, a little phishing training plus a verify-money-requests-by-phone rule, email authentication (SPF/DKIM/DMARC, checkable free with the Email Security Checker), and tested backups with a one-page incident plan. It's a checklist, not a bottomless project, finishing it turns "we know we're exposed" into "we've handled the obvious ways in." Sources: Small Business Expo survey + StationX. - [Ransomware is now a franchise business: what that means for small firms](https://www.intrasec.ca/blog/2026-07-24-ransomware-as-a-service-market-small-business): A July 2026 trends report counts ~146 active ransomware groups, with ~61 new ones appearing in the past year, driven by the ransomware-as-a-service (RaaS) model: a core group builds the malware and rents it to lower-skill "affiliates" who do the break-ins and split the profit, some running slick web portals to build payloads and manage victims. Why it hits small businesses: when attacking was a craft, criminals chased big targets; RaaS drops the skill/cost barrier, so affiliates go after whoever is easiest, which is smaller firms with lighter defences. Modern ransomware is also extortion-first (steal data, then encrypt), so a backup alone no longer prevents the worst. Defences don't change, they matter more: phishing-resistant MFA on email/VPN/cloud-admin, fast patching of internet-facing systems, tested offline backups, and a written incident-response plan. - [The EU AI Act's August deadline: does a Canadian small business need to care?](https://www.intrasec.ca/blog/2026-07-22-eu-ai-act-deadline-small-business): On August 2, 2026 the bulk of the EU AI Act (the world's first broad AI law) becomes enforceable, including high-risk-system rules and fines for general-purpose-AI providers (up to tens of millions of euros / a share of global revenue). It can reach any organization worldwide that puts an AI system on the EU market or whose AI output is used by people in the EU. Honest scoping for a Canadian small business: for most (no EU customers, AI used internally for drafting/notes/etc.), it does NOT apply, do not start a compliance project you don't need. The one piece that might reach you is the Article 50 transparency obligations (effective Aug 2): if you run a public AI chatbot or publish AI-generated content that reaches EU people, disclose the chatbot and label AI-generated/deepfake content. Even if out of scope, treat it as a preview: Canada's own AI rules (once in the Bill C-27 package) are expected to return as standalone legislation on the same transparency/trust ideas, so being clear about your AI use is a habit worth building now. Proportionate, not fearful. - [wp2shell: a critical WordPress Core flaw, and no plugin needed](https://www.intrasec.ca/blog/2026-07-21-wordpress-core-wp2shell-rce-small-business): On July 17, 2026 WordPress shipped an emergency update for "wp2shell," a pair of WordPress CORE flaws (CVE-2026-63030, a REST API batch-route confusion, chained with CVE-2026-60137, a SQL injection) that let an unauthenticated attacker create an admin account and run code, taking over a default WordPress site with NO vulnerable plugin required. Public exploits appeared within hours; CISA added both to its Known Exploited Vulnerabilities catalog on July 21 (active exploitation). Fixed in WordPress 6.9.5 and 7.0.2. Unlike the usual "plugins are the weak point" story, this hole is in WordPress itself, so keeping plugins tidy does not help, only an up-to-date core does. What to do: update core immediately (6.9.5/7.0.2), confirm auto-updates are on, check for unexpected admin accounts/plugins/changed files, and make sure you have a clean off-site backup from before the patch date. - [JADEPUFFER: the first AI-run ransomware attack, explained for small business](https://www.intrasec.ca/blog/2026-07-20-ai-agent-ransomware-jadepuffer-small-business): In late June 2026, security firm Sysdig documented JADEPUFFER, the first ransomware attack where an AI agent carried out nearly the entire operation: reconnaissance, credential theft, lateral movement, persistence, encryption, destruction, and the ransom note, firing 600+ distinct actions and fixing its own failed step in 31 seconds. It got in via a known flaw (CVE-2025-3248) in an internet-facing Langflow instance. The honest caveat the headlines skip: it was NOT fully autonomous, a human still provisioned the infrastructure, stood up the command-and-control and staging servers, and chose the victim (and supplied prior-compromised root credentials); only the tactical execution was automated. The real lesson for a small business: AI didn't invent a new attack, it made the labour-intensive middle faster and cheaper, so smaller "not worth the effort" targets get hit more often. The defenses are unchanged (they just matter more): patch and shrink your internet-facing surface, enforce least privilege, keep tested offline backups, and monitor for unusual activity. - [Microsoft 365 hit by an 81-million-attempt password-spray](https://www.intrasec.ca/blog/2026-07-18-microsoft-365-password-spraying-small-business): Between June 12-26, 2026, security firm Huntress observed a single campaign throw 81 million+ login attempts at Microsoft 365 accounts, compromising 78 accounts across 64 organizations. It used password-spraying (trying leaked username/password pairs slowly across many accounts) and authenticated via the Azure CLI using ROPC (Resource Owner Password Credentials), which sends the password straight to the token endpoint with no interactive MFA prompt, bypassing MFA in tenants with misconfigured Conditional Access. The lesson for a small business: MFA is only as strong as the policy around it. Common gaps that let it through: MFA scoped to some apps not "all cloud apps," enforced only for admins, required only from unfamiliar locations, or left in report-only mode. It is a fixable configuration problem, not a broken control. See the companion guide on locking down M365 sign-in. - [The AWS outage and your hidden cloud dependencies](https://www.intrasec.ca/blog/2026-07-17-aws-cloudfront-outage-small-business): On July 16 an AWS CloudFront fault (in its newer VPC Origins feature) served errors for ~2.5 hours and took a scattering of unrelated services offline at once (Hugging Face, the UK National Lottery, Fallout 76, with Tailscale and Ubiquiti also reported). Not a cyberattack, a config/capacity problem inside AWS. The real lesson for a small business: your website host, email, booking, payments, and VPN quietly share a handful of underlying clouds you can't name, so one provider's bad morning can knock out several tools at once. Not an argument against the cloud (it's more reliable than a server in your closet, and every provider has bad days). What to do: keep a one-page list of the tools you can't work without, find each one's status page before an outage, keep a low-tech manual fallback for the two or three essentials, and don't tie domain/email/website/DNS to a single account. - [Microsoft wants to keep Canadian data, and AI, in Canada: what's real and what's not](https://www.intrasec.ca/blog/2026-07-16-microsoft-canada-data-sovereignty-copilot): As part of a ~$19B Canadian investment, Microsoft has laid out a five-point "digital sovereignty" plan for Canada, with in-country data processing (including, over time, for Microsoft 365 Copilot AI), confidential computing in Canadian regions, and an open-source Sovereign AI Landing Zone. Honestly framed: it's a real, welcome direction, but Copilot-in-Canada residency is a 2027 roadmap not a switch you can flip today, and residency still isn't sovereignty (Microsoft is a U.S. company subject to the CLOUD Act). For a small business: base decisions on what's in writing for your plan now, and keep asking where your data is actually processed. - [Microsoft is letting you switch off AI in Teams meetings: what it means for your business](https://www.intrasec.ca/blog/2026-07-15-microsoft-teams-ai-toggle-small-business): After user backlash, Microsoft is rolling out an in-meeting toggle (through July 2026) letting a licensed Teams organizer turn Meeting AI (Copilot, Facilitator, Recap) on or off during a live call. The real point for a small business: these features create transcripts/summaries that are business records, so decide your own AI-in-meetings policy (defaults, who can enable, client meetings off, where recaps are stored) rather than letting default-on settings decide for you. - [Windows zero-days keep landing: what a small business does when there's no patch yet](https://www.intrasec.ca/blog/2026-07-14-windows-zero-days-what-small-business-does): A researcher ("Nightmare Eclipse," a former Microsoft employee) has released seven public Windows zero-day PoCs since April 2026 in a feud with Microsoft; some (RoguePlanet/CVE-2026-50656 in Defender, and BlueHammer) worked against fully-patched Windows, and Microsoft has been patching them. Honestly framed (not the speculative "July 14 dump"): a zero-day has no patch during the window it's known, so patching alone is not a strategy; most are privilege-escalation, so the defense is least privilege + EDR + tested backups (defense in depth). - [Windows has a device ID you cannot turn off: what it means, and why a VPN is not anonymity](https://www.intrasec.ca/blog/2026-07-13-windows-global-device-id-privacy-small-business): A newly disclosed persistent Windows device identifier (the GDID), tied to your Microsoft account with no consumer opt-out, surfaced via an FBI filing where it helped de-anonymize a suspect across VPNs. Honestly framed: it is not Microsoft selling your browsing, it is law enforcement using it with legal process; the durable lesson for a business is that a VPN is not anonymity, and privacy is about understanding what your tools collect. - [Ubiquiti just patched 7 critical UniFi flaws: what to do if you run UniFi](https://www.intrasec.ca/blog/2026-07-10-unifi-critical-vulnerabilities-patch-small-business): Ubiquiti patched seven critical UniFi vulnerabilities, led by CVE-2026-50746 (CVSS 10.0, command injection in the UniFi Connect app; fix: update to 3.4.20+); six need no user interaction. Not confirmed exploited yet, but UniFi is a repeat target (CISA flagged actively-exploited UniFi OS flaws a month earlier), so the lesson is patch promptly and have someone own keeping it current. On-brand: intrasec designs and manages UniFi. - [A critical flaw in a remote-support tool, and why your IT provider is part of your attack surface](https://www.intrasec.ca/blog/2026-07-07-simplehelp-rmm-flaw-it-provider-risk): A maximum-severity (CVSS 10.0) authentication-bypass in SimpleHelp RMM (CVE-2026-48558) is being actively exploited to plant credential-stealing malware. Why the remote-support tools your IT provider runs on your systems are part of your attack surface, why outsourcing IT does not outsource the risk, and the questions to ask your provider (do you use SimpleHelp, have you patched, what remote-access tools do you run and how fast do you patch). - [Qilin ransomware is hitting Canadian manufacturers: what small firms should learn](https://www.intrasec.ca/blog/2026-07-06-qilin-ransomware-canadian-manufacturer): The Qilin ransomware group listed a Canadian manufacturer (Chamco) on its dark-web leak site, a claim not independently confirmed by the company. Why small and mid-sized firms are squarely in scope (downtime pressure, ransomware-as-a-service volume, lighter defenses, data-leak extortion), and the controls that actually cut the risk: fast patching, phishing-resistant MFA, and tested immutable backups. - [Microsoft is bundling advanced Intune into Microsoft 365 E3 and E5](https://www.intrasec.ca/blog/2026-07-03-microsoft-intune-licensing-changes-small-business): Alongside the July 1 Microsoft 365 price increase, advanced Intune Suite features (previously a ~$10/user add-on) are being folded into E3 and E5, rolling out to tenants through August 1, 2026. E5 gets the full Intune Suite; E3 and EMS E3 get Intune Plan 2, Remote Help, and Advanced Analytics. What to do: drop any now-redundant Intune Suite add-on and actually turn on what you now own. - [Data sovereignty: why Canadian businesses are rethinking where their data lives](https://www.intrasec.ca/blog/2026-07-02-data-sovereignty-canadian-small-business): CIRA's 2025 survey shows 69% of Canadian organizations now rank data sovereignty as their top factor when choosing security tools. What the trend means for a small business, why the US CLOUD Act makes "where" really a "who" question, and why it is worth understanding but not a substitute for the basics. - [Ransomware now steals your data first: why backups are no longer enough](https://www.intrasec.ca/blog/2026-06-30-ransomware-data-theft-canadian-small-business): The 2026 numbers (Fortinet: ransomware victims up 389%; IBM: the average Canadian breach near $7M) show ransomware shifting to data theft and double extortion, so backups alone no longer cover the risk. A small business now has to make data hard to steal AND be ready for the leak (incident response + breach notification). - [A fake AI workspace scam is tricking employees into leaking data](https://www.intrasec.ca/blog/2026-06-29-openai-poisoned-tenant-scam-small-business): A new "poisoned tenant" attack (found by Push Security): attackers create a fake company ChatGPT workspace and send a genuine OpenAI invite that passes every check, so staff who join feed their prompts (code, client data, strategy) to the attacker. The fix is AI governance, one sanctioned workspace, verify invites, never paste sensitive data into an account you didn't set up. - [If you run UniFi gear, patch it now: CISA flags active attacks](https://www.intrasec.ca/blog/2026-06-26-ubiquiti-unifi-vulnerability-small-business): CISA added three actively-exploited, max-severity Ubiquiti UniFi OS flaws (CVE-2026-34908/34909/34910) to its KEV catalog; chained, they give an unauthenticated attacker full control of the UniFi console that runs a small office's network and cameras. Update to UniFi OS Server 5.0.8+, get the admin interface off the internet, and check for unknown admin accounts. - [Your Microsoft 365 bill goes up July 1: what small businesses should do](https://www.intrasec.ca/blog/2026-06-25-microsoft-365-price-increase-small-business): Microsoft 365 commercial prices rise July 1, 2026 (Business Basic $6→$7, Standard $12.50→$14; Business Premium unchanged), with added security features bundled in. What's changing, what you get, and how renewing before July 1 can lock current rates. - [AI tools are starting to ask for your ID: what it means for your business](https://www.intrasec.ca/blog/2026-06-24-ai-id-verification-small-business): From July 8, 2026, Claude can ask some consumer-plan users (Free, Pro, Max) for a government ID, selfie, and face scan via the third party Persona; business tiers are exempt. The privacy concerns, the consumer-tier scope, and what founders should do. - [AI is now finding and fixing software flaws: what it means for small business](https://www.intrasec.ca/blog/2026-06-23-ai-finds-fixes-vulnerabilities-small-business): OpenAI's GPT-5.5-Cyber and the AI-found Squidbleed bug show AI now finds and patches software flaws at machine scale. The software you rely on gets safer, but the window to patch shrinks, so a vulnerability management habit matters more than ever. - [Canada's Bill C-36 privacy overhaul: what it means for small business](https://www.intrasec.ca/blog/2026-06-22-bill-c-36-privacy-reform-small-business): Canada's third attempt to rewrite private-sector privacy law (the PPCDA, replacing PIPEDA): a new regulator, fines up to $25M or 5% of revenue, and a required privacy program. Still only a bill, but the direction is clear. - [The push to AI agents is real: what it means for a small business](https://www.intrasec.ca/blog/2026-06-19-ai-agents-arriving-small-business): Microsoft and the industry are racing to AI "agents" that act, not just answer. What agentic AI realistically means for a small business, what's hype, and why identity and access governance has to come first. - [Canada's Bill C-8 is now law: what it means for your small business](https://www.intrasec.ca/blog/2026-06-18-bill-c-8-critical-cyber-systems-small-business): Bill C-8, the Critical Cyber Systems Protection Act, received Royal Assent on June 16. Most small businesses aren't directly regulated, but its cybersecurity requirements will reach them through customer contracts, insurers, and supply-chain expectations. - [Cloudflare just made DMARC management free: easier protection from email spoofing](https://www.intrasec.ca/blog/2026-06-17-cloudflare-dmarc-management-free-small-business): Cloudflare made its DMARC Management tool generally available and free for any domain on its DNS. Why DMARC matters for a small business, how the free tool removes the painful reporting step, and how to get to an enforced policy. - [A Check Point VPN flaw is being used by ransomware gangs: patch now](https://www.intrasec.ca/blog/2026-06-16-check-point-vpn-zero-day-small-business): A critical Check Point VPN and firewall flaw (CVE-2026-50751) lets attackers bypass the login, and a ransomware crew is already using it. Why it matters to a small business (Spark is their SMB firewall), and what to do. - [If your business runs on WordPress, your plugins are the weak point](https://www.intrasec.ca/blog/2026-06-15-wordpress-plugin-security-small-business): A supply-chain attack backdoored 30+ WordPress plugins and a critical flaw left an estimated 150,000 sites exposed. Why plugins are the biggest risk to a small business website, and what to do this week. - [Canada's national AI strategy wants your small business using AI](https://www.intrasec.ca/blog/2026-06-14-canada-ai-strategy-small-business): Ottawa's "AI for All" strategy aims to push business AI adoption from about 12% to 60% and create 250,000 jobs by 2031, with SME support and a new procurement program. What a national AI push actually means for a small business. - [Canada's privacy watchdog just made AI a top priority: what it means for you](https://www.intrasec.ca/blog/2026-06-13-privacy-commissioner-ai-report-small-business): Canada's Privacy Commissioner tabled a report making AI governance a top enforcement priority, alongside nearly 700 business breach reports affecting 20 million Canadians. What it means for a small business. - [Copilot is becoming part of your Microsoft 365 bill on July 1](https://www.intrasec.ca/blog/2026-06-12-microsoft-365-copilot-pricing-small-business): On July 1 Microsoft folds Copilot into its Business Basic, Standard, and Premium plans as "with Copilot" versions, replacing the roughly $30 per-user add-on, with introductory pricing through September 30, 2026 and an annual commitment. Base plans rise the same day (Business Standard goes from - [Copilot is becoming part of your Microsoft 365 bill on July 1](https://www.intrasec.ca/blog/2026-06-12-microsoft-365-copilot-pricing-small-business)2.50 to - [Copilot is becoming part of your Microsoft 365 bill on July 1](https://www.intrasec.ca/blog/2026-06-12-microsoft-365-copilot-pricing-small-business)4 per user); with Copilot, Standard lands in the low $20s and Premium around $32. Decide deliberately which seats need Copilot, budget for the increase either way, and put AI guardrails in place before switching everyone on. - [Microsoft just shipped its biggest-ever Patch Tuesday: how to triage 200 fixes](https://www.intrasec.ca/blog/2026-06-11-record-patch-tuesday-small-business): Microsoft's June 10, 2026 Patch Tuesday fixed more than 200 vulnerabilities, its largest ever, with dozens rated critical, at least one already exploited, and wormable Windows networking flaws needing no user action; Veeam, Fortinet, Ivanti, and SAP shipped urgent fixes the same week. For a small business the post gives a triage order: patch internet-facing systems first, let actively exploited flaws jump the queue, automate routine updates, test only what could break, and do not skip the appliances and machines nobody logs into. - [Windows 10's safety net runs out this October: what to do now](https://www.intrasec.ca/blog/2026-06-10-windows-10-end-of-support-deadline-small-business): Windows 10 support ended October 14, 2025, and the consumer Extended Security Updates bridge ends October 13, 2026; businesses can buy ESU through October 2028 at prices that climb each year. Office apps stay patched until October 10, 2028, which lulls owners into thinking they are covered while the OS underneath is not. The move for a small business: inventory every PC in the next 30 days, upgrade eligible machines to Windows 11 free (roughly 8th-gen Intel or Ryzen 2000 with TPM 2.0), replace the rest, and use ESU only as a short bridge before this October. - [When QuickBooks went dark: the SaaS outage lesson for small business](https://www.intrasec.ca/blog/2026-06-10-quickbooks-outage-saas-resilience-small-business): QuickBooks went down for hundreds of North American users on June 8, 2026, blocking invoicing, payroll, and tax filing mid-pay-run; some payroll submissions returned an IDS Server error and both Online and desktop versions were hit. The takeaway for any cloud-dependent business: bookmark each vendor's status page, keep exportable backups of invoices and payroll records, have a manual bank fallback for payday, and map the three or four SaaS apps whose outage would stop your business for a day. - [Payroll pirate attacks are hijacking Canadian paycheques](https://www.intrasec.ca/blog/2026-06-09-payroll-pirate-attacks-canadian-employees): Microsoft is tracking Storm-2755, a "payroll pirate" campaign that deliberately targets Canadian employees. Attackers use SEO poisoning and paid ads to rank fake Office 365 login pages, relay the sign-in in real time to steal session tokens (bypassing ordinary MFA), then email HR to change direct-deposit details or edit them in platforms like Workday, hiding replies with inbox rules until payday. Defences: phishing-resistant MFA such as passkeys or FIDO2 keys, out-of-band verification of every banking change, and reaching Microsoft 365 by bookmark, never by search. - [Your biggest cyber risk is a vendor you already trust](https://www.intrasec.ca/blog/2026-06-08-supply-chain-vendor-risk-small-business): The 2026 Verizon Data Breach Investigations Report found third-party involvement in breaches jumped 60% in a year to 48% of all breaches, and unpatched-vulnerability exploitation (31%) overtook stolen credentials as the top entry point for the first time in 19 years; ransomware appeared in 48% of breaches, though 69% of victims refused to pay. For a small business the fix is practical: list every vendor holding your data, vet new ones for MFA, encryption, and SOC 2 or ISO 27001, grant the least access that works, patch fast, and keep a vendor-breach plan ready. - [AI-powered fraud is hitting Canadian small businesses](https://www.intrasec.ca/blog/2026-06-07-ai-fraud-deepfakes-canadian-small-business): A KPMG Canada survey of 251 business leaders found that among companies hit by fraud, 81% said it was AI-enabled: AI-generated phishing (60%), deepfake documents (39%), and voice-clone impersonation of executives (24%), yet only 26% have a tested response plan. The Canadian Anti-Fraud Centre logged a record $704 million in reported fraud losses in 2025. For a small business the defence is process, not product: confirm every payment or banking change by callback on a known number, require two approvals on transfers, and treat urgency plus secrecy as the red flag. - [Palo Alto and SonicWall VPNs are under active attack](https://www.intrasec.ca/blog/2026-06-06-palo-alto-sonicwall-vpn-attacks-small-business): Palo Alto's GlobalProtect authentication bypass CVE-2026-0257 is under active exploitation (CISA set a June 1, 2026 federal patch deadline), while the Akira ransomware crew breaches SonicWall SSL VPNs via year-old CVE-2024-40766 and harvested credentials, encrypting files in under four hours, sometimes 55 minutes. One group probed Palo Alto portals with over 7,000 IPs in a day, then turned on SonicWall. Small businesses should patch both now, re-verify MFA, reset credentials, restrict portal access, and keep offline backups. - [What Canada's ChatGPT privacy ruling means for small business](https://www.intrasec.ca/blog/2026-06-05-chatgpt-privacy-ruling-canada-small-business): On May 6, 2026 Canada's federal Privacy Commissioner and the Quebec, BC, and Alberta regulators ruled that OpenAI trained ChatGPT on Canadians' personal information, including health and children's data, without valid consent. The core principle: publicly accessible online does not mean free to collect. For a small business, pasting customer or employee data into a chatbot is a PIPEDA disclosure you are accountable for, and BC, Alberta, and Quebec's Law 25 set a stricter bar than the federal floor. Regulators expect documented AI and data policies before a complaint, not after. - [Canada joins Anthropic's Mythos AI: what it means for small business](https://www.intrasec.ca/blog/2026-06-04-anthropic-mythos-ai-canada-small-business): Anthropic's Mythos model finds and exploits software vulnerabilities better than nearly any human expert, uncovering thousands of flaws including a 27-year-old OpenBSD bug; access is limited to vetted Project Glasswing partners with up to - [Canada joins Anthropic's Mythos AI: what it means for small business](https://www.intrasec.ca/blog/2026-06-04-anthropic-mythos-ai-canada-small-business)00 million US in usage credits. On June 2, 2026 the Canadian Centre for Cyber Security joined as the program expanded to roughly 200 organizations in over 15 countries. The lesson for small businesses: the gap between disclosure and exploitation has collapsed from months to minutes, so patching is urgent and too-small-to-target thinking is dead. - [What 50,000 IT support tickets reveal for small business](https://www.intrasec.ca/blog/2026-06-04-it-support-benchmark-small-business): A 2026 benchmark of 50,000+ IT support tickets across 30+ organizations: software issues drive 38% of tickets, 22% stop someone from working, onboarding a new hire takes a median of roughly 76 elapsed hours, and automation cuts median resolution from about 71 hours to 4.4. Staffing ran a median of 1.6 IT people per 100 employees, which for a 1-50 person business is well under one full-time hire. The takeaway: small-business IT load is routine and predictable, downtime is the real cost, and managed support with automation beats an informal part-time arrangement. - [AI-ready devices: what RTX Spark means for small business](https://www.intrasec.ca/blog/2026-06-04-ai-ready-devices-rtx-spark-small-business): Breaks down Computex 2026's AI hardware news: NVIDIA's RTX Spark platform (Arm CPU, Blackwell graphics, 128GB shared memory, around one petaflop) ships fall 2026 from Dell, HP, Lenovo, ASUS, MSI, and Microsoft, whose Surface Laptop Ultra is the flagship; the 3,999 USD DGX Spark desktop runs models up to 200 billion parameters locally. For most small teams a standard 45-TOPS Copilot+ PC is enough; Spark-class machines pay off only for keeping client data fully in-house, AI development, or heavy creative work. - [Shadow AI: your team is probably leaking data into chatbots](https://www.intrasec.ca/blog/2026-06-03-shadow-ai-data-leakage-small-business): New 2026 reports quantify shadow AI: 77% of employees have pasted company information into AI tools and 82% of them used personal accounts (LayerX), about 40% of AI interactions expose sensitive data (Cyberhaven), and Verizon's breach report now ranks shadow AI a top insider risk. Pastes into a browser tab slip past DLP and firewalls entirely, as Samsung's leaked source code showed. The fix is not a ban, which just drives use onto personal phones: provide an approved business-tier tool and a one-page rule on what never goes into a chatbot. - [AI-powered cyberattacks by the numbers](https://www.intrasec.ca/blog/2026-06-03-ai-powered-cyberattacks-small-business): 2026 figures on AI-driven attacks: 87% of organizations faced an AI-powered attack in the past year, 82.6% of phishing emails show signs of AI generation and get clicked more than four times as often, IBM found 1 in 6 breaches involve attacker AI, FBI-reported phishing losses tripled from about $70 million in 2024 to roughly $216 million in 2025, and deepfake fraud is up over 2,000% since 2022. The defense list is unchanged but now non-negotiable: phishing-resistant MFA, second-channel verification of money and password requests, endpoint protection, and tested backups. - [Cyber insurance in 2026: what Canadian small businesses need to qualify](https://www.intrasec.ca/blog/2026-06-03-cyber-insurance-canada-small-business): Canadian cyber insurers in 2026 underwrite your actual controls: MFA on everything including VPNs and admin accounts, EDR on every device, tested offline or immutable backups, and critical patches applied within roughly 14 to 30 days. Applications now run 8 to 25 pages and take two to four weeks. The trap is denied claims: the application is a legal attestation, and a post-breach investigation that finds one admin account without MFA can void or reduce the payout. Premiums now follow security posture, so closing the gaps before you apply usually pays for itself. - [What Canada's tightening privacy rules mean for your small business](https://www.intrasec.ca/blog/2026-06-03-canada-privacy-law-changes-small-business): Canada's federal privacy overhaul is expected in 2026: a PIPEDA replacement with a penalty tribunal and fines up to the greater of C$25 million or 5 percent of global revenue, with children's privacy and AI deepfakes named priorities. Quebec's Law 25 is already fully in force with penalties of $25 million or 4 percent of turnover, and mandatory breach reporting applies to businesses of every size today. Do now: name a privacy owner, keep vendor due-diligence records, write a short breach plan, update the privacy policy. - [A new phishing kit is bypassing Microsoft 365 MFA](https://www.intrasec.ca/blog/2026-06-02-phishing-kit-bypasses-microsoft-365-mfa): An FBI advisory from May 21, 2026 warns about Kali365, a phishing-as-a-service kit that hijacks Microsoft 365 accounts without stealing passwords. Victims enter a short device code on a genuine Microsoft sign-in page, and that approval hands attackers the access tokens that skip MFA entirely, so "check the URL" advice fails. The defence: never enter a login or device code unless you started the sign-in yourself, move toward passkeys, and turn on conditional access so tokens from unexpected devices or locations are challenged. - [What Canada's cyber threat assessment means for your small business](https://www.intrasec.ca/blog/2026-06-02-canada-cyber-threat-assessment-small-business): The Canadian Centre for Cyber Security's National Cyber Threat Assessment names ransomware the top cybercrime threat to Canadian organizations: incidents grew roughly 26% a year from 2021 to 2024, the average ransom paid hit about - [What Canada's cyber threat assessment means for your small business](https://www.intrasec.ca/blog/2026-06-02-canada-cyber-threat-assessment-small-business).13 million in 2023, and fraud losses rose from $383 million in 2021 to $567 million in 2023. Cybercrime-as-a-service kits put small businesses in the automated target pool, as incidents at Petro-Canada, London Drugs, and Ontario hospitals show. The two defenses to start with: MFA everywhere and tested backups kept separate from your network. - [Ransomware is now targeting small businesses](https://www.intrasec.ca/blog/2026-06-01-ransomware-now-targeting-small-businesses): Late-May reporting shows ransomware groups deliberately shifting to small local businesses, construction companies, accounting firms, car dealerships, and dental and physiotherapy clinics, because they are easier to breach and quicker to pay; analysts project damages could top $275 billion a year by 2031. The entry points are ordinary: reused passwords, phishing, software past its update life, and remote-access sprawl. The control that decides the outcome is tested backups kept separate from the main network, paired with MFA, neither of which needs an enterprise budget. ## Optional - [Terms of Use](https://www.intrasec.ca/terms-of-use) - [Privacy Policy](https://www.intrasec.ca/privacy-policy) - [Cookie Policy](https://www.intrasec.ca/cookie-policy)