Canada: Cybersecurity Guidance For Small And Medium Organizations

Last Updated: July 17 2019
Article by Bradley J. Freedman

Small and medium organizations are increasingly being targeted by cyber criminals, but often have limited financial and human resources available to implement comprehensive cybersecurity measures. In March 2019, the Canadian Centre for Cyber Security issued Baseline Cyber Security Controls for Small and Medium Organizations to help Canadian small and medium organizations get the most out of their cybersecurity investments.

Cybersecurity for Small and Medium Organizations

Cybersecurity is important for organizations of all kinds and sizes. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2018 warns that "cybercrime is the cyber threat most likely to affect Canadians and Canadian businesses in 2019", and "sophisticated cyber threat actors will likely continue to exploit the trusted relationships between businesses and their suppliers and service providers for espionage and cybercrime purposes".

Cyber criminals are increasingly targeting small and medium organizations, including to obtain data about their customers and business partners and as a means of accessing the information technology systems and data of their business partners. Cyberattacks can cause small and medium organizations to suffer potentially devastating financial losses and liabilities. However, comprehensive cyber risk management programs, such as the NIST Cybersecurity Framework and ISO/IEC 27001:2013, can be expensive and time consuming to implement and beyond the financial and human resources means of most small and medium organizations.

Government agencies and other organizations have issued basic cybersecurity guidance for small and medium organizations with limited resources. For example, see: Small Business Information Security: The Fundamentals (NIST); Small Biz Cyber Planner 2.0, Cyber Security Planning Guide and Cybersecurity for Small Business (FCC); Cyber Security Small Business Guide (NCSC); the Essential Eight (ACSC); and Get Cyber Safe Guide for Small and Medium Businesses (Government of Canada). For more information see BLG bulletin Cybersecurity Guidance for Small and Medium Size Enterprises.

The Baseline Cyber Security Controls Guide

The Canadian Centre for Cyber Security was established in October 2018 to be the Canadian government's unified source of expert advice, guidance, services and support on cybersecurity for government, critical infrastructure owners and operators, the private sector and the Canadian public. The Centre has recently published helpful cybersecurity guidance for small and medium organizations, including Protecting High-Value Information: Tips for Small and Medium Organizations and Supply chain security for small and medium-sized organizations.

In March 2019, the Centre issued Baseline Cyber Security Controls for Small and Medium Organizations (the "Guide") to provide a condensed set of advice and guidance, including thirteen baseline cybersecurity controls, to help Canadian small and medium organizations (i.e. less than 499 employees) maximize the effectiveness of their cybersecurity investments. The Guide reflects the view that organizations can mitigate most cyber threats through awareness and best practices, and can successfully apply the 80/20 rule – achieve 80% of the benefit from 20% of the effort – in the cybersecurity domain.

The Guide explains that each organization must consider its particular circumstances to determine whether the recommended baseline cybersecurity controls are sufficient and appropriate. The relevant circumstances include: (1) the size of the organization; (2) the information systems and data that are in scope for the implementation of the controls; (3) the value of the organization's information systems and data, and the risk of injury to the confidentiality, integrity and availability of the information systems or data; and (4) the cybersecurity threat level faced by the organization.

The Guide recommends that organizations assign responsibility for cybersecurity to an individual in a leadership role (e.g. a chief information security officer), and assess the adequacy of their financial spending and internal staffing for information technology and cybersecurity. The Guide also recommends that organizations "adopt the thinking that they will suffer a data breach at some point and thus be in a position to detect, respond, and recover".

Following is a summary of the baseline cybersecurity controls recommended by the Guide:

  1. Develop an Incident Response Plan: Have a basic written incident response plan (in both hard and soft copies) for how to respond to cybersecurity incidents of varying severity, including a plan for engaging external assistance. The plan should identify the individuals is responsible for handling incidents, including communicating with external parties, stakeholders and regulators and complying with breach reporting obligations. Consider purchasing cybersecurity insurance that includes coverage for incident response and recovery activities. Consider implementing a security event monitoring system for detecting, monitoring, and responding to cybersecurity incidents.
  2. Automatically Patch Operating Systems and Applications: Enable automatic patching for all software and hardware, or establish full vulnerability and patch management solutions. Replace software and hardware that are not capable of automatic updates, or have a business process to ensure regular manual updates.
  3. Enable Security Software: Enable anti-virus and anti-malware solutions, which update and scan automatically, on all connected devices.
  4. Securely Configure Devices: Implement secure configurations for all devices, change all default passwords on all devices, turn off unnecessary device features/functionalities, and enable all relevant security features on all devices.
  5. Use Strong User Authentication: Require two-factor authentication for important accounts (e.g. financial accounts, system administrators, cloud administration, privileged users and senior executives), and implement two-factor authentication for other accounts wherever possible. Require password changes only on suspicion or evidence of password compromise. Have clear policies on password length and reuse, the use of password managers and how passwords should be securely stored.
  6. Employee Awareness Training: Provide cybersecurity awareness and training for all employees, focusing on practical and easily implementable measures such as: (a) use of passwords; (b) identification of malicious emails and links; (c) use of approved software; (d) appropriate Internet use; and (e) use of social media.
  7. Backup and Encrypt Data: Backup systems that contain essential business information, using an appropriate backup frequency, and ensure that recovery mechanisms can effectively and efficiently restore those systems. Securely store backups in an encrypted state and subject to restricted access. Consider storing backups offsite to provide diversity in the event of a disaster.
  8. Secure Mobility: Determine an ownership model for mobile devices, and document the rationale and associated risks. Enforce separation between work and personal data on mobile devices with access to corporate IT resources. Ensure that employees only download mobile device apps from trusted sources. Require that all mobile devices store sensitive information in a secure, encrypted state. Implement an appropriate enterprise mobility management solution for all mobile devices, or document the risks assumed by not implementing such a solution. Enforce or educate users to: (a) disable automatic connections to open networks; (b) avoid connecting to unknown Wi-Fi networks; (c) limit the use of Bluetooth and NFC for the exchange of sensitive information; and (d) use corporate Wi-Fi or cellular data network connectivity rather than public Wi-Fi.
  9. Establish Basic Perimeter Defences: Implement a dedicated firewall at boundaries between corporate networks and the Internet. Implement a DNS firewall for outbound DNS requests to the Internet. Activate software firewalls on devices within networks, or document the alternative measures in place. Require secure connectivity to all corporate IT resources, and require VPN connectivity with two-factor authentication for all remote access to corporate networks. Secure internal Wi-Fi, preferably with WPA2-Enterprise. Never connect public Wi-Fi networks to corporate networks. Follow the Payment Card Industry Data Security Standard (PCI DSS) for all point-of-sale terminals and financial systems, segment those systems from other parts of the corporate network, and isolate those systems from the Internet. Implement domain-based message authentication, reporting and conformance (DMARC) on all email services.
  10. Secure Cloud and Outsourced IT Services: Require all cloud service providers to share an SSAE 16 SOC 3 report that confirms they achieved Trust Service Principles compliance. Evaluate comfort with how outsourced IT providers handle and access sensitive information (e.g. their privacy policies, data security incident notification processes, data deletion processes, physical location and security of data centres, and physical location of personnel), and with the laws in the jurisdictions where outsourced IT providers store or use sensitive information. Encrypt sensitive information stored outside local IT systems, and ensure secure access to data stored in the cloud. Ensure that IT infrastructure and users communicate securely with all cloud services and applications. Ensure that administrative accounts for cloud services use two-factor authentication and differ from internal administrator accounts.
  11. Secure Websites: Ensure that corporate websites meet the Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS) guidelines.
  12. Implement Access Control and Authorization: Follow the principle of least privilege – provision accounts with the minimum functionality and data access necessary for assigned tasks, restrict administrator privileges to an as-required basis, and remove accounts and functionalities when no longer required for assigned tasks. Permit administrator accounts to perform only administrative activities, and not user-level activities. Ensure all users have unique individual accounts, and minimize or eliminate the use of shared or shared-use accounts. Have a process to revoke accounts when they are no longer required (e.g. when employees leave). Consider implementing a centralized authorization control system.
  13. Secure Portable Media/Storage Devices: Ensure the exclusive use of organization-owned secure portable media (e.g. USB drives) and storage devices that have strong asset controls and use encryption. Have processes for the sanitization or destruction of portable media and storage devices before disposal.


The baseline controls recommended by the Guide are important, but might not be sufficient to comply with applicable laws or industry-specific requirements. For example:

Many of the baseline controls recommended by the Guide have legal implications, including compliance with privacy/personal information protection, labour/employment and human rights laws. Timely legal advice can assist organizations to implement the baseline controls in a manner that complies with applicable laws.

In addition, the involvement of lawyers in cybersecurity activities (e.g. assessing an organization's cybersecurity maturity, conducting testing/training activities and responding to cybersecurity incidents and data breaches) is necessary to establish legal privilege over communications and reports relating to those activities. Organizations should consider implementing a legal privilege strategy to help avoid inadvertent and unnecessary disclosures of privileged legal advice given during cybersecurity activities. For more information, see BLG bulletins Cyber Risk Management – Legal Privilege Strategy (Part 1); Cyber Risk Management – Legal Privilege Strategy (Part 2); Legal Privilege for Data Security Incident Investigation Reports; and Loss of Legal Privilege over Cyberattack Investigation Report.

About BLG

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on

Click to Login as an existing user or Register so you can print this article.

Similar Articles
Relevancy Powered by MondaqAI
In association with
Related Topics
Similar Articles
Relevancy Powered by MondaqAI
Related Articles
Related Video
Up-coming Events Search
Font Size:
Mondaq on Twitter
Mondaq Free Registration
Gain access to Mondaq global archive of over 375,000 articles covering 200 countries with a personalised News Alert and automatic login on this device.
Mondaq News Alert (some suggested topics and region)
Select Topics
Registration (please scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of

To Use you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.


The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.


Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions