On February 25, 2024, ransomware knocked out roughly 80% of the City of Hamilton’s computer network. Phone lines, transit apps, property tax and permit systems went dark. The attackers wanted $18.5 million. The city refused to pay, which was the right call. Then came the second blow: its insurer denied the claim, because multi-factor authentication hadn’t been fully rolled out when the attackers got in. By the summer of 2025, Hamilton’s recovery bill had reached $18.3 million, and taxpayers were on the hook for all of it, according to Global News. It’s a costly case study in why every organization needs a ransomware defence plan.
Hamilton is a city of more than half a million people with an IT department. Now picture the same attack on a 25-person accounting firm, a dental clinic or a regional distributor. There’s no ransomware response team on staff and no capital budget to absorb an eight-figure hit. For many small businesses, a bad ransomware incident is the kind of event they don’t come back from.
The good news is that most ransomware gets in through a handful of well-known doors, and the fixes are neither exotic nor especially expensive. This is a practical ransomware defence plan for small businesses, built mostly on free guidance from the Canadian Centre for Cyber Security.
How big is the ransomware problem in Canada?
The Canadian Centre for Cyber Security, part of the Communications Security Establishment, calls ransomware the top cybercrime threat to Canada’s critical infrastructure. Its National Cyber Threat Assessment 2025-2026 notes that Canadian ransomware incidents grew about 26% a year from 2021, and that the average ransom paid by Canadian victims reached roughly $1.13 million in 2023. It also judges that ransomware gangs are “almost certainly opportunistic,” hitting whoever is easy rather than picking particular industries. Small doesn’t mean safe. It often means easy.
Statistics Canada’s Canadian Survey of Cyber Security and Cybercrime fills in the business picture. About one in six Canadian businesses (16%) were hit by a cyber security incident in 2023. Among those affected, 13% faced ransomware, up from earlier surveys. The cost of recovering from incidents doubled in two years, to about $1.2 billion in 2023. And only 26% of businesses had a written cyber security policy.
Two more numbers from that survey are revealing. Of the businesses that reported paying a ransom, 84% paid less than $10,000. And most firms that didn’t report incidents to police said they handled it internally or through an IT contractor. That fits what security people see: a long tail of smaller, quieter attacks on small companies that never make the news.
Canadian cases worth learning from
- London Drugs (2024): The B.C.-based retailer closed all 79 of its Western Canadian stores for more than a week after an attack in late April. The LockBit gang later demanded $25 million. The company said it was “unwilling and unable” to pay, and the gang leaked corporate files.
- Nova Scotia Power (2025): Attackers got into the utility’s servers around March 19, 2025, but it wasn’t discovered until late April. Data on about 280,000 customers, including social insurance and bank account numbers, was stolen. The utility refused to pay. Billing was disrupted for roughly eight months, and the share of customers behind on payments doubled.
- City of Hamilton (2024): As above, a $18.3-million lesson in what happens when a basic control isn’t in place, and when the insurance policy says so in writing.
How ransomware actually gets in
Ransomware isn’t usually a brilliant hack. It’s a business process. Criminal groups buy or rent ransomware kits (the Cyber Centre describes this “ransomware-as-a-service” model in detail), buy stolen passwords from other criminals, and work through lists of exposed targets.
The incident response firm Coveware, which handles ransomware negotiations, tracks how attackers get in. Across its 2025 and 2026 reports, the same routes keep coming up:
- Compromised remote access, such as VPNs and remote desktop accessed with stolen or guessed passwords and no second factor.
- Phishing and social engineering, including increasingly sophisticated calls to help desks to reset passwords or MFA.
- Unpatched software, especially internet-facing firewalls, VPN appliances and file-transfer tools.
Modern gangs also steal data before encrypting it, so they can threaten to publish it even if you restore from backup. That’s what happened at London Drugs and Nova Scotia Power. Backups protect your operations. They don’t protect your secrets.

The ransomware defence plan: five controls that matter most
The Cyber Centre publishes a set of baseline cyber security controls for organizations with fewer than 500 employees. It’s 13 categories built on an 80/20 idea: a modest set of controls that blocks most of what small businesses face. If you do nothing else, do these five.
1. Backups you can actually restore (the 3-2-1 rule)
The classic rule is 3-2-1: keep three copies of important data, on two different types of storage, with one copy off-site. For ransomware, add a crucial twist: at least one copy must be offline or immutable, meaning it can’t be changed or deleted from your normal network. Attackers routinely hunt for backups and destroy them first.
The Cyber Centre’s updated ransomware playbook, re-released in January 2026, recommends two or more backups stored offline, plus ideally a cloud copy, and suggests testing restores on a schedule, such as monthly. That last part is where most small businesses fail. A backup you’ve never restored is a hope, not a plan. Time how long a full restore takes, too. If it’s three days, your business is down for three days.
2. Multi-factor authentication everywhere that matters
Turn on MFA for email, remote access, cloud admin consoles, accounting systems and your backup system itself. Hamilton shows that this isn’t just a security question; insurers increasingly treat missing MFA as grounds to deny a claim. Where you can, use phishing-resistant methods such as passkeys or hardware security keys for administrators, and enable number matching on app-based prompts so staff can’t approve a login just by tapping “yes.”
3. Patch fast, especially at the edge
Turn on automatic updates for operating systems, browsers and office software. Then make a short list of everything that faces the internet (firewall, VPN, remote access tools, website, file-sharing apps) and check for updates to those weekly. Edge devices are a favourite entry point, and attackers often move within days of a fix being published. If a device is too old to get updates, replace it.
4. Least privilege and separation
Staff shouldn’t use admin accounts for daily work. Give admin rights only to the people who need them, through separate accounts. Keep backups on systems that use different credentials from the main network. If you can, split the network so a compromised front-desk PC can’t reach the file server directly.
5. Train people on the attacks that actually happen
Generic phishing training has limited value. Focus on specifics: how to spot a fake invoice or payment-change request, why no one should approve an MFA prompt they didn’t start, and how your help desk or IT provider verifies identity before resetting a password. Coveware’s 2026 reporting singles out help-desk manipulation as a growing route in.

Write your incident response plan before you need it
When ransomware hits, the first hours are chaotic. Screens show ransom notes. Staff are calling. Nobody knows who’s in charge. A two-page plan, written now, makes a big difference.
The Cyber Centre’s playbook organizes response into four phases (Prepare, Observe, Resolve and Understand). For a small business, that boils down to a short checklist:
- Who decides. Name an incident lead and a backup, with personal phone numbers, because email may be down.
- Who you call. Your IT provider, your cyber insurer’s breach hotline (many require you to call them first and use their approved responders), a lawyer, and your bank.
- How to contain. Disconnect affected machines from the network, but don’t wipe or power them off before evidence is preserved.
- Who you must tell. Report to local police, the Canadian Anti-Fraud Centre and the Cyber Centre. If personal information was likely exposed and creates a “real risk of significant harm,” federal privacy law requires notifying the Privacy Commissioner and affected individuals.
- How you’ll keep operating. Paper forms, a list of critical phone numbers, and a way to pay staff for a week without your systems.
On the ransom itself, the Cyber Centre’s guidance is blunt: paying doesn’t guarantee you’ll get your data back. Coveware’s July 2026 report adds that even when victims pay for data to be deleted, criminals have kept copies; law enforcement found LockBit had retained stolen data from victims who paid. Paying may also carry legal risk if the group is under sanctions. This is a decision for your lawyer and insurer, not a panicked owner at 2 a.m. (And this article isn’t legal advice.)
Cyber insurance: useful, but read the fine print
Statistics Canada found 22% of businesses had cyber insurance in 2023, up from 16% two years earlier. A good policy can cover forensic investigators, legal advice, breach notification, business interruption and, in some cases, extortion payments.
But insurers have tightened up. Expect an application questionnaire that asks whether you use MFA, how you back up, whether you have endpoint detection software and how often you patch. Treat those answers as promises. If you say you have MFA and an investigation shows the attacker came in through an account without it, you may end up in Hamilton’s position. A few practical tips:
- Ask your broker what’s excluded and what security controls are conditions of coverage.
- Check whether the policy includes access to a breach response team and how quickly they engage.
- Confirm limits for business interruption, which for a small firm is often the largest real cost.
- Keep evidence that your controls are in place (MFA reports, backup logs), so you can prove it later.
Your 30-day ransomware checklist
If this all feels like a lot, here’s a realistic sequence for a small business with an outside IT provider:
- Week 1: Turn on MFA for email, remote access and every admin account. Confirm your backups exist and that one copy is offline or immutable.
- Week 2: Do a test restore of something important, like your accounting data. Time it. List every internet-facing device and confirm it’s patched.
- Week 3: Remove admin rights from daily-use accounts. Write the two-page incident plan and print it.
- Week 4: Run a 20-minute session with staff on fake invoices, MFA fatigue and reporting suspicious messages. Review your cyber insurance against the controls you now have.
For a structured follow-up, the Cyber Centre’s baseline controls document is free and written for organizations your size, and the federal CyberSecure Canada certification program, now administered by the Standards Council of Canada, gives small and medium-sized businesses a way to show customers they meet that baseline.
None of this makes you immune. Hamilton, London Drugs and Nova Scotia Power all had more resources than most small firms. But attackers are opportunistic. When you close the easy doors, most of them move on to someone who hasn’t.
Sources and further reading
- Canadian Centre for Cyber Security: Ransomware playbook (ITSM.00.099)
- Canadian Centre for Cyber Security: Baseline cyber security controls for small and medium organizations
- Canadian Centre for Cyber Security: National Cyber Threat Assessment 2025-2026
- Statistics Canada: Impact of cybercrime on Canadian businesses, 2023
- Global News: Hamilton facing full $18.3M cyberattack bill after insurer denies claim
- Global News: London Drugs hackers seek millions in ransom
- Global News: NS Power says billing back to normal after cyberattack
- Coveware: Q2 2026 ransomware report
- CISA: #StopRansomware guide
- Innovation, Science and Economic Development Canada: CyberSecure Canada


