Most breaches at Canadian SMBs are not sophisticated attacks. They are configuration mistakes, unpatched software, and reused passwords. Here is the 10-item checklist we run for every new Sam4Tech engagement.

Baseline hardening

  1. MFA on every admin account — email, hosting, cloud console, WordPress, GitHub. No exceptions.
  2. Password manager for the whole company — 1Password Business or Bitwarden Teams. Kills reuse.
  3. Patch cadence — OS, browsers, WordPress core, plugins, npm packages. Weekly at minimum.
  4. Automated off-site backups — verified restores quarterly.
  5. Endpoint protection on every laptop — Microsoft Defender for Business or CrowdStrike Falcon Go.

Web / infrastructure

  1. HTTPS everywhere with HSTS. Free via Let’s Encrypt or Cloudflare.
  2. WAF in front of your site — Cloudflare free tier stops most bot traffic.
  3. Principle of least privilege on cloud IAM. No wildcard permissions.
  4. Log and alert on failed login spikes, admin actions, and unusual data egress.

People

  1. Phishing simulation once per quarter. Not to punish — to train.

PIPEDA specific

Under Canada’s Personal Information Protection and Electronic Documents Act, you must have a documented privacy policy, obtain meaningful consent, and report material breaches to the Office of the Privacy Commissioner. If you handle EU data too, GDPR adds bite: 72-hour breach reporting and fines up to 4% of global turnover.

Free 60-minute security review

Sam4Tech offers a no-obligation security review for Canadian businesses under 100 employees. We audit the checklist above and hand you a prioritized fix list. Book yours.