Half Of All Canadian Businesses Hacked

A new survey has terrifying implications for Canadian businesses across the country.

Conducted by marketing research firm Ipsos Canada on behalf of Calgary-based accounting, tax and business consulting firm MNP LLP, the survey found that nearly 60 per cent of Canadian small business owners and C-suite executives either suspect or know for certain they were the victims of an external cyber-attack during the last year, with 50 per cent of C-suite executives indicating that they know for certain that their company experienced a breach.

An additional three in 10 suspected their company was the victim of a breach in the past year, but didn’t know for certain.

And despite the overwhelming evidence indicating otherwise, eight executives in 10 reported being confident in their business’s ability to prevent an external hacking attempt, while 93 per cent of survey respondents indicated confidence in their ability to protect customer data.

In a 7 statement, former Canadion National Police  investigator and current MNP vice president of valuations, forensics, and litigation support Greg Draper called cyberattacks “a reality of doing business,” but added that the survey underlined just how poorly Canadian businesses are equipped to address them.

“There is a significant gap between the perceived preparedness of businesses and the number of data breaches occurring,” Draper said. 

“The number and sophistication of hackers is growing at light speed, but businesses are not evolving their prevention and detection strategies at the same rate. Developing an effective defense against external fraud is an exercise in continuous improvement, not just set-it-and-forget-it. That’s the part that businesses are missing here.”

For example, Draper called it “startling” that only 54 per cent of C-suite executives and small business owners reported using cybersecurity measures such as firewalls.

The findings were especially surprising given that upcoming changes to Canadian privacy laws will require Canadian companies to log and disclose all breaches, Draper noted.

“Along with the costs of a potential business disruption or loss of confidential information, businesses will start to see the breach-related expenses climb sharply when they are forced to publically disclose them,” he said. 

“Loss of customer confidence and potential legal action, fines for non-compliance and the resources to ascertain exactly how hackers got in and then implementing new security measures – the proactive approach to mitigating external fraud risk is far more cost-effective.”

In conducting the online survey, Ipsos polled 1000 owners of small businesses with between five and 99 employees, and 100 C-suite executives at businesses with more than 100 employees, between Jan. 17 and Jan. 26, 2017.

IT World Canada

You Mighy Also Read

Four Steps To Managing Cyber Security Better:

Strategies To Prevent 85% Of Cyber Attacks:

Directors Report January 2017. Cyber Security Checklist For Management (£):

 

 

« Strategies To Prevent 85% Of Cyber Attacks
Insurers Get Much More Cautious About Cyber Risk »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Business Intelligence Associates (BIA)

Business Intelligence Associates (BIA)

BIA's TotalDiscovery is a defensible and cost-effective corporate preservation and legal compliance software solution.

CERT-EU

CERT-EU

CERT-EU is a permanent Computer Emergency Response Team for the EU institutions, agencies and bodies.

a1qa

a1qa

a1qa specializes in the delivery of full-cycle software QA and application testing services.

ThetaRay

ThetaRay

ThetaRay’s solution for Industrial cyber security protects against unknown cyber-attacks that target industry and critical infrastructure.

BTWorks

BTWorks

BTWorks provides identity management and anti-phishing / smishing solutions for web and mobile apps.

ESTsecurity

ESTsecurity

ESTsecurity is a leading company in cyber security providing intelligent security solutions to make world more secure.

SysTools

SysTools

SysTools provides a range of services including data recovery, digital forensics, and cloud backup solutions.

CyberForce Program - US Department of Energy

CyberForce Program - US Department of Energy

The Department of Energy’s (DOE) CyberForce Program is a workforce development program that seeks to inspire and develop the next generation of cyber defenders for the energy sector.

Destel

Destel

Destel is a system integrator and provider of IT services focused on Advanced Network & Security Solutions.

M2SYS

M2SYS

M2SYS is a worldwide leader in identification and authentication solutions.

eResilience

eResilience

eResilience is a division of Referentia Systems, a pioneer in an ultra-secure information safeguarding technique known as “Enclaving”, in which data can be segmented and protected within a network.

IdentityIQ

IdentityIQ

IdentityIQ is a US-based identity theft and credit protection company designed to help users stay on top identity thieves and data breaches.

IP Twins

IP Twins

IP Twins offer a wide range of services related to domain names and online brand protection.

DoControl

DoControl

DoControl gives organizations the automated, self-service tools they need for SaaS applications data access monitoring, orchestration, and remediation.

EasyDMARC

EasyDMARC

EasyDMARC deliver the most comprehensive product for anyone who strives to build the most secure possible defence system for their email ecosystem.

National Cybersecurity Agency (ACN) - Italy

National Cybersecurity Agency (ACN) - Italy

The ACN is the National Authority for Cybersecurity in Italy. the Agency promotes public-private initiatives to strengthen the national cybersecurity and resilience posture.