How exposed is the average Canadian small business to cyber crime? The honest answer is: far more exposed than most owners believe, and the gap between the threat and the preparation is where the real damage happens. Here is what the most recent Canadian data actually shows.
Nearly half were attacked in a single year

When the Canadian Federation of Independent Business surveyed 4,639 of its members, 45% of small businesses reported experiencing a random cyber attack within the past year, and 27% had been deliberately targeted. A further 11% had faced a whaling attempt — an email impersonating the owner or a senior leader to trick staff into transferring money or data. In some sectors it was worse still: 58% of wholesale businesses and 57% of professional-services firms reported random attacks.
The national picture: fewer incidents, twice the cost
Statistics Canada's most recent cybercrime survey found that about 1 in 6 Canadian businesses (16%) were impacted by a cyber security incident in 2023. The rate has drifted down since 2019 — but the cost has gone sharply the other way. Total spending on recovery doubled from roughly $600 million in 2021 to $1.2 billion in 2023, and small and medium businesses accounted for about half of it: roughly $300 million each in recovery costs. Fewer businesses are being hit, but each hit hurts twice as much.
Ransomware: small ransoms, big disruption
Among impacted businesses, 13% reported a ransomware attack in 2023, up from 11% in 2021. Most victims (88%) refused to pay, and of those that did pay, 84% paid under $10,000. The ransom itself is rarely the real cost — the downtime, the recovery work, the notification obligations and the lost customer confidence are. Nationally, reported fraud losses reached a record $704 million in 2025, and because only an estimated 5–10% of victims report, the true figure is likely measured in billions.
The preparation gap
Set the threat numbers beside the readiness numbers and the problem is obvious. Only around a quarter of Canadian businesses have a written cyber security policy. In the CFIB survey, just 11% of small businesses provided mandatory cyber security training to employees, and 8% offered it as an option. Nearly half of small firms are being probed by attackers every year, while nine in ten have no trained staff and no documented policy to fall back on.
What a small business should take from this
Attackers do not skip small businesses — they automate against them. The defence is not a bigger IT budget; it is a baseline: documented policies, staff who can recognise a phishing or impersonation attempt, controlled access to data, and a tested plan for the day something gets through. That baseline is exactly what the Canada Cyber-Safe accreditation is designed to put in place, with fees starting at $1,200 CAD for individuals and $1,500 CAD for businesses of up to 50 staff.
Sources
Statistics Canada — Impact of cybercrime on Canadian businesses, 2023
CFIB — Nearly half of small businesses have experienced random cyberattacks in the past year
Cybersecurity Canada Report 2026 — State of Canadian SMB Cybersecurity
