Most breaches at Canadian SMBs are not sophisticated attacks. They are configuration mistakes, unpatched software, and reused passwords. Here is the 10-item checklist we run for every new Sam4Tech engagement.
Baseline hardening
- MFA on every admin account — email, hosting, cloud console, WordPress, GitHub. No exceptions.
- Password manager for the whole company — 1Password Business or Bitwarden Teams. Kills reuse.
- Patch cadence — OS, browsers, WordPress core, plugins, npm packages. Weekly at minimum.
- Automated off-site backups — verified restores quarterly.
- Endpoint protection on every laptop — Microsoft Defender for Business or CrowdStrike Falcon Go.
Web / infrastructure
- HTTPS everywhere with HSTS. Free via Let’s Encrypt or Cloudflare.
- WAF in front of your site — Cloudflare free tier stops most bot traffic.
- Principle of least privilege on cloud IAM. No wildcard permissions.
- Log and alert on failed login spikes, admin actions, and unusual data egress.
People
- Phishing simulation once per quarter. Not to punish — to train.
PIPEDA specific
Under Canada’s Personal Information Protection and Electronic Documents Act, you must have a documented privacy policy, obtain meaningful consent, and report material breaches to the Office of the Privacy Commissioner. If you handle EU data too, GDPR adds bite: 72-hour breach reporting and fines up to 4% of global turnover.
Free 60-minute security review
Sam4Tech offers a no-obligation security review for Canadian businesses under 100 employees. We audit the checklist above and hand you a prioritized fix list. Book yours.