Cybersecurity Canada, the public research initiative Cyber Unit operates, has published the Canadian Small Business Cyber Risk Report 2026, a free review of public data on businesses with 10 to 49 employees. One finding stands out for any business that outsources IT: in 2023, 45.1% of Canadian small businesses had no employees doing cyber security tasks as part of their regular role, up from 34.5% in 2021, according to Statistics Canada.
When nobody inside the business owns security, the IT provider effectively does, whether or not the contract says so. This article pulls out the report's findings that matter most in that relationship and turns them into five questions to ask. The full report, with every source, lives on cybersecuritycanada.ca.
What the Canadian small business cyber risk report found
The report uses Statistics Canada's 2023 size breakdowns, the latest published, plus Verizon's 2026 Data Breach Investigations Report and Canadian government sources. It uses public data only. The figures most relevant to outsourced IT:
- 14.3% of Canadian small businesses were impacted by a cyber security incident in 2023 (Statistics Canada table 22-10-0076-01).
- 37.1% used a consultant or contractor to manage cyber security risks, and 17.8% patched operating systems for security monthly or more often, down from 25.0% in 2021 (table 22-10-0130-01).
- 15.4% had a written policy to manage internal cyber security risks and 10.5% had a written incident reporting policy (same table).
- About 96% of ransomware victims with a known size were organizations with fewer than 1,000 employees, according to Verizon's 2026 DBIR.
For national figures on fraud losses and breach costs, see our summary of the Cybersecurity Canada Report 2026.
Why outsourcing does not move the accountability
Hiring a provider moves the work, not the responsibility. The Canadian Centre for Cyber Security's guidance for consumers of managed services (ITSM.50.030) says the organization and the provider both have roles, but "your organization is the data owner and is legally responsible for data security." The same principle applies to US businesses working with a managed service provider: the contract defines the provider's tasks, and the business keeps the risk.
That is why the low written-policy numbers matter. A provider can only meet expectations that someone has written down. If 85% of small businesses have no written internal security policy, most providers are working from assumptions.
Five questions to ask your IT provider
Each question maps to a gap in the report. Ask for answers in writing.
- "How many days does it take you to install a critical security patch, and can I see last month's report?" Verizon's 2026 report found exploitation of vulnerabilities is now the leading known way into breaches at organizations with fewer than 1,000 employees, at 26%. A patch SLA puts the deadline and the proof in the contract.
- "Which of our internet-facing devices, such as firewalls and VPNs, are you responsible for updating?" Verizon found ransomware victims were typically chosen because they had compromised credentials (38%) or unpatched vulnerabilities in edge devices (29%). Devices nobody owns are the ones that go unpatched.
- "Who leads if we have an incident tonight, and where is that written down?" Only 10.5% of Canadian small businesses had a written incident reporting policy in 2023. Our article on incident response planning covers the decisions worth making in advance.
- "When did you last restore our data from backup as a test, and how long did it take?" In Canada, 88% of businesses hit by ransomware in 2023 did not pay, according to Statistics Canada. A tested restore is what makes that choice possible. See backup and recovery assumptions that often fail.
- "Which accounts still sign in without phishing-resistant MFA?" Only 45.4% of Canadian small businesses reported identity and access management measures in 2023. Our piece on phishing-resistant authentication explains why hardware keys and passkeys are replacing SMS codes for admin and finance accounts.
If a provider struggles with these, our guide to evaluating a managed IT or cybersecurity provider lists the criteria and red flags to check before renewing.
What the data does not show
The report is careful about its limits, and readers should be too. Statistics Canada covers businesses with 10 or more employees, so the smallest firms are not in the data. Its latest published cycle covers 2023; the next cycle, covering 2025, was collected from January to March 2026 and Cybersecurity Canada plans to update the report when it is released. Verizon's dataset is global and defines small and medium businesses as fewer than 1,000 employees, so its figures are not combined with the Canadian ones.
The durable lesson
Small businesses are not hit as often as large ones, but they are far less likely to have the basics in writing, and the share with anyone on staff watching security is shrinking. If an outside provider is filling that gap, the most useful thing an owner can do is make the expectations explicit: patch deadlines, incident roles, restore tests and MFA coverage. To see where your own gaps are, take our free quick security assessment: 22 questions, under five minutes.
This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Figures are drawn from public sources, including Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime and Verizon's 2026 Data Breach Investigations Report, as summarized in the Canadian Small Business Cyber Risk Report 2026, and may change as new data is published. Organizations should consult qualified cybersecurity professionals before making operational changes based on this article.