No jargon, no fear-mongering — just specific, actionable guidance grounded in how this industry actually operates.
Two years ago, multi-factor authentication (MFA) was a "nice to have" line on a cyber insurance questionnaire. Today, it's often the single control that determines whether an insurer will cover you at all — and at what price.
Insurers have paid out enough business email compromise claims to know exactly which control would have stopped most of them: MFA on the accounts fraudsters actually target — email, banking portals, and accounting software. As a result, many insurers now treat missing MFA not as a minor gap, but as grounds to decline coverage entirely, regardless of how strong the rest of your security posture looks.
Most firms have MFA on their main email login by now. Where the gap actually shows up is everywhere else: the accounting software used to process draws, the bank's own web portal, and any project management tool where change orders and payment approvals happen. Insurers increasingly ask about all of these specifically, not just email.
Turn on MFA everywhere a payment or banking decision can be made — not just where it's most convenient to set up. If you're not sure which of your systems support it, that's a reasonable place to start a conversation with whoever manages your IT, or with a vCISO who can do that inventory for you.
Download This Article (PDF)As a general contractor, you vet subcontractors constantly — insurance, WSIB, safety records. One question almost never makes the list, and it's becoming one of the most consequential: how good is their cybersecurity?
A typical Canadian project connects 15 to 40 subcontractors. It doesn't matter how strong your own security is if a subcontractor's compromised mailbox is how fraud enters your project — your project's security is only as strong as the least-protected subcontractor on it.
"Do you use multi-factor authentication on your email?" The single highest-value question on the list.
"How do you verify changes to banking or payment details?" You want to hear they call to confirm, using a number they already have.
"Who do we contact if we suspect a fraudulent email claiming to be from your company?" Get a real name and number before there's a problem.
"Has your team had any security awareness training?" A team that can't recognize phishing is easier to compromise.
Any change to a subcontractor's banking details, from anyone, gets verified by phone before a payment goes out — regardless of how legitimate the email looks.
Download This Article (PDF)Not every progress-draw scam comes from a hacked account. Many come from a domain that just looks real — one swapped letter, one added hyphen, one different extension — sent at exactly the moment a real payment is expected.
Train your team to check the sender's full domain, not just the display name your inbox shows by default. A message that appears to come from "Accounts Payable" can hide almost any domain behind it — the display name means nothing on its own.
Watch for domains that substitute a letter (rn for m), add an extra word or hyphen, or use a different top-level extension (.co instead of .ca) than the real company uses.
The same rule that stops most progress-draw fraud stops this too: verify any change to payment details by phone, using a number you already have on file — never one provided in the suspicious email itself. You don't need to catch every fake domain by eye. You just need one consistent habit that makes the fake domain irrelevant.
Download This Article (PDF)Canadian SMEs typically face breach costs between $100,000 and $500,000 — a range that can be an existential threat to a firm your size, not just an unpleasant line item.
It's rarely just the stolen funds. The real total usually includes the direct loss itself, weeks of lost productivity while systems are rebuilt, the cost of specialists brought in to investigate and remediate, higher insurance premiums at your next renewal, and in some cases, the client relationships that don't survive the disruption.
A 500-person enterprise can absorb a six-figure incident as a bad quarter. A 50-person contractor often can't — the same incident can consume a year's margin, or more.
Measured against that range, a properly run MDR and vCISO program isn't a cost center — it's closer to insurance you're already paying for indirectly, just without the coverage. The math tends to favour prevention once the real range is on the table.
Download This Article (PDF)If you run an HVAC, mechanical, or building controls business, you've probably never thought of yourself as working with "operational technology." But the building management systems and HVAC controllers you install every day are OT — and increasingly one of the most exploited entry points into a business's core network.
CISA attributed 23% of 2024 critical infrastructure incidents to building automation and control system vulnerabilities. The most common reason: default passwords that are never changed after install.
Your own business: if your firm manages building systems remotely for clients, that connection is a two-way door.
Your clients' exposure: every building management system you install is a live system running years after your crew leaves.
Most firms your size don't need a full-time security executive. But there's a point where "no dedicated security function" stops being fine — here's how to tell if you've reached it.
1. You're being asked security questions in RFPs that nobody on your team feels confident answering.
2. Your cyber insurance renewal got noticeably harder, or the premium jumped without a clear explanation.
3. You've had at least one "close call" — a suspicious email, a nearly-processed fraudulent invoice — even if nothing was actually lost.
4. You're growing past the size where informal IT habits still work, typically somewhere past 20-30 employees.
5. No one could tell you, today, what your actual incident response plan is if something went wrong tomorrow.
A virtual CISO gives you the strategic security leadership those situations call for — risk assessments, a practical roadmap, and ongoing advisory — without the cost of a full-time executive hire.
Download This Article (PDF)If you've renewed a cyber insurance policy recently, you may have noticed the questionnaire got a lot longer and a lot more specific.
MFA on every account, especially email and financial systems.
Endpoint detection and response (EDR) — basic antivirus is generally no longer sufficient.
Tested, offline or immutable backups — with evidence of a recent restore test.
A written incident response plan — who gets called first, who has authority.
Written payment-verification procedures — given how often claims trace back to payment fraud.
Employee security awareness training — ideally with some form of testing.
If you run a construction or engineering firm in Canada, there's a good chance you've never heard the term "progress-draw fraud" — but you've almost certainly heard the story.
A typical Canadian project connects 15 to 40 subcontractors, each submitting invoices and draw requests through email — the least secure, least monitored channel in most small firms' operations. Canadian contractor Bird Construction was hit with a $9 million CAD ransomware demand in 2019.
1. Compromised subcontractor mailbox. A fraudster sends "updated" banking details from inside a genuinely real conversation.
2. Look-alike domain impersonation. A domain one character off from the real one, timed to a real payment.
1. A written payment-verification procedure — verify by phone, using a number already on file.
2. MFA on every account in the payment chain.
3. A second sign-off on any payment above a set threshold.
Download This Article (PDF)Book a free 30-minute risk assessment. No obligation, no jargon — just a clear picture of your exposure.