Canadian Business Website Security Statistics (2026): What the Numbers Mean for Canadian Web Hosting

date icon
date icon

Ask three Canadian sources how many businesses were hit by a cyber attack last year and you will get three different answers. Statistics Canada says 16%. The Canadian Internet Registration Authority (CIRA) says 43% were targeted. An IBM-sponsored study puts the average breach at more than seven million dollars, which would bankrupt most of the businesses in the first survey.

None of these sources is wrong. They measure different things, in different populations, over different periods. That gap matters, because a statistic that is not understood is one that gets misused. Sometimes it is used to frighten a ten-person firm into buying enterprise tooling. Sometimes it convinces a retailer that its risk is too small to take seriously.

This guide collects the most recent Canadian business website security statistics available as of late September 2026. It explains what each one measures and maps each figure to the part of a website’s hosting stack it actually describes. If you run a Canadian business website, it will tell you which numbers apply to you. If you are comparing Canadian web hosting options, it will tell you which questions the data says to ask.

Canadian website security statistics at a glance

Statistic Figure Source and period
Businesses impacted by a cyber incident 16% Statistics Canada, 2023 calendar year
Organizations targeted by an attack (attempted or successful) 43% CIRA survey, 12 months to Aug 2025
Organizations reporting a customer or employee data breach 42% CIRA survey, 12 months to Aug 2025
Average cost of a data breach in Canada CA$7.11 million IBM / Ponemon, Mar 2025 – Feb 2026
Average breach lifecycle (detect and contain) 205 days IBM / Ponemon, Mar 2025 – Feb 2026
Business breach reports to the federal privacy regulator Almost 700 OPC, fiscal 2025-26
Share of PIPEDA breaches involving unauthorized access 81% OPC, fiscal 2024-25
Reported fraud losses in Canada Over CA$704 million Canadian Anti-Fraud Centre, 2025
New WordPress ecosystem vulnerabilities 11,334 Patchstack, 2025 calendar year
Organizations ranking data sovereignty above price 69% CIRA survey, 2025

 

Each of these is explained, with its limitations, below.

Bar chart comparing four Canadian cyber security statistics: 16% impacted, 43% targeted, 42% data breach, 24% ransomware

Why Canadian cyber security statistics seem to contradict each other

The single most useful thing to understand about Canadian security data is what sits under the fraction line. Every percentage has a denominator, and the major Canadian sources use very different ones.

Source Who is counted What counts as an event Sample
Statistics Canada, Canadian Survey of Cyber Security and Cybercrime Enterprises with 10 or more employees, most sectors, excluding public administration Incidents the business judged to have impacted it 12,462 enterprises, 71% response rate
CIRA Cybersecurity Survey Cybersecurity decision-makers in public, private and MUSH-sector organizations Attacks targeted at the organization, attempted or successful 500 online responses
IBM Cost of a Data Breach Organizations worldwide that had already experienced a breach Breaches, costed after the fact 602 organizations globally
Office of the Privacy Commissioner (OPC) Organizations subject to PIPEDA Breaches meeting the “real risk of significant harm” reporting threshold All reports received
Canadian Anti-Fraud Centre (CAFC) Individuals and businesses who chose to report Fraud and attempted fraud Voluntary reports only

Horizontal bar chart showing how CIRA and Statistics Canada figures differ because they count different populations and events

Read that way, the contradictions resolve themselves.

Statistics Canada’s 16% counts only incidents that businesses said affected their operations. It explicitly excludes attacks a business shrugged off, and the agency itself notes that its figures may not capture the total number of attacks. CIRA’s 43% counts attempts. A phishing email that nobody clicked is an attack under one method and a non-event under the other.

The clearest illustration is ransomware. Among businesses that Statistics Canada found were hit by ransomware in 2023, 88% did not pay. In CIRA’s 2025 survey, 74% of ransomware victims did pay, typically $25,000 or more. Both findings are credible. Statistics Canada draws a probability sample covering roughly 205,000 businesses, most of them small. CIRA surveys people whose job is cybersecurity, which skews toward larger organizations with the kind of incident that escalates to a negotiation.

There is also a blind spot worth naming. Statistics Canada’s survey does not cover firms with fewer than 10 employees. A large share of Canadian business websites belong to sole proprietors and micro businesses, and no national survey currently measures their incident rate. If you run a five-person firm, the honest answer is that the data describes businesses bigger than yours.

How to use this: when you quote a statistic in a board report or a client proposal, name the source and state what it counts. “16% of Canadian businesses with 10 or more employees reported an impactful incident in 2023” is defensible. “16% of Canadian businesses were hacked” is not.

How many Canadian businesses are affected, and how that is changing

Statistics Canada’s survey, conducted for Public Safety Canada every two years, is the only nationally representative measure of cyber incidents against Canadian businesses. Its most recent published results cover 2023.

About one in six businesses (16%) were impacted by a cyber security incident in 2023, down from 18% in 2021 and 21% in 2019. The decline held across every size band:

Business size 2019 2021 2023
Small (10–49 employees) 18% 16% 14%
Medium (50–249 employees) 29% 25% 23%
Large (250+ employees) 44% 37% 30%

Fewer businesses reporting impact is good news on its face, but the methods shifted in a worrying direction. Scams and fraud remained the most common method, affecting 50% of impacted businesses, up six points from 2021. Identity theft rose eleven points to 31%. Ransomware rose from 11% to 13% of impacted businesses.

Multiply those rates together and the national picture sharpens. If 13% of the 16% of businesses that were impacted experienced ransomware, roughly two in every hundred businesses in the survey’s scope were hit by ransomware in 2023. This is our calculation from the published rates, not a figure Statistics Canada publishes. It is a useful corrective to headlines that imply ransomware is universal, and a reminder that two in a hundred, across a country, is a great many businesses.

The spending data points the same way. Recovery spending doubled from about $600 million in 2021 to $1.2 billion in 2023. Prevention and detection spending grew far more slowly, from $9.7 billion to $11.0 billion. Fewer businesses are being hit, but each hit costs more.

Readiness has barely moved. Just 26% of businesses had written cyber security policies in 2023, the same as in 2021. Only 22% trained non-IT staff in cyber security skills, and 22% carried cyber risk insurance. Half of businesses (50%) had cyber security employees, down from 61%. The most common reason for having none was that the business relied on outside consultants or contractors instead, cited by 47% of those without staff.

That last figure has a direct bearing on website hosting. For a large share of Canadian businesses, security is something bought rather than staffed, and the hosting company is often the first and closest of those outside providers.

What a data breach costs a Canadian organization in 2026

IBM’s 2026 Cost of a Data Breach Report, released on 29 July 2026, puts the average Canadian breach at a record CA$7.11 million, up from CA$6.98 million in 2025. The average breach exposed 28,500 records and took 205 days to identify and contain, both higher than the previous year.

Three findings from the Canadian results matter most for website owners:

  • Supply-chain compromise was the largest cost amplifier, adding about CA$368,000 to the average breach. A breach that arrives through a supplier, a plugin vendor or a third-party platform costs more than one that starts inside the organization.
  • AI in security operations cut costs sharply. Organizations using it extensively averaged CA$5.5 million per breach, compared with CA$8.91 million for those with none. They also found breaches in 124 days rather than 154.
  • Attackers are using AI too. 28% of Canadian organizations in the study reported an AI-generated attack.

Treat the headline figure with care. The study covers 602 breached organizations worldwide and is built around enterprise-scale incidents. It does not describe a typical small business, and IBM does not publish the size of its Canadian subsample in the release.

For a sense of scale at the small end, divide Statistics Canada’s $1.2 billion in 2023 recovery spending by the approximate number of impacted businesses in the survey’s scope. The result is an average in the tens of thousands of dollars per impacted business, not millions. That is our rough derivation from published totals, and it excludes lost revenue, which Statistics Canada does not cost in the same way. Even so, it is the more realistic planning figure for most Canadian small businesses, and it is still large enough to end one.

What Canada’s privacy regulator sees: PIPEDA breach reports

Since 1 November 2018, organizations subject to PIPEDA, Canada’s federal private-sector privacy law, have had to report breaches of security safeguards to the Office of the Privacy Commissioner when there is a real risk of significant harm. They must also notify the affected individuals, and they must keep a record of every breach for 24 months, whether it was reportable or not. Knowingly failing to meet these obligations is an offence carrying fines of up to $100,000.

The breach report counts have been remarkably stable:

Fiscal year PIPEDA breach reports Accounts or individuals affected
2023-24 693 About 25 million accounts
2024-25 686 About 20 million accounts
2025-26 Almost 700 More than 20 million Canadians

The stability of the count hides a shift in the cause. Unauthorized access, which covers cyber incidents, social engineering and employees misusing their access, accounted for 65% of PIPEDA breach reports in 2021-22. By 2024-25 it accounted for 81%. Accidental disclosure fell from 25% to 13% over the same period. Canadian breaches are increasingly about someone getting in, not something being sent to the wrong address.

Line chart of PIPEDA breach reports by type from 2021-22 to 2024-25, unauthorized access rising from 65% to 81%

The OPC also flagged a growing pattern of supply-chain breaches. In one case, a breach at a single service provider to the pharmaceutical industry affected more than 50 organizations in Canada. A single breach at a shared provider is logged once but felt many times over. It is the same pattern IBM found driving costs.

For a business website, PIPEDA turns security into a record-keeping obligation. Your contact form, your customer accounts, your order database and your server logs all hold personal information. If any of them is breached, the obligation to assess, record and possibly report the breach falls on you, not on your provider. PIPEDA’s accountability principle makes the organization responsible for personal information it transfers to a third party for processing. Your hosting agreement, backups and access logs are part of your compliance evidence.

Fraud and phishing: the email side of website security

Website security does not end at the web server. For most small businesses, the domain name also carries the business email. That makes the domain one of the most exploited assets they own.

The Canadian Anti-Fraud Centre received more than 112,000 fraud reports in 2025, with reported losses of over CA$704 million. Losses reported since 2022 now exceed $2.4 billion. The CAFC estimates that only 5% to 10% of fraud is ever reported, so the true figure is many times higher.

Two lines in the CAFC’s 2025 top-ten table are directly relevant to businesses. Spear phishing, meaning targeted phishing aimed at a specific person or organization, produced CA$67.9 million in reported losses from just 813 reports, the second-highest dollar loss of any category. General phishing drew 2,869 reports. IBM’s 2025 Canadian results identified phishing as the most common initial attack vector, at an average of CA$7.91 million per breach.

The hosting connection is concrete. Whether a fraudster can send convincing email that appears to come from your domain depends largely on three DNS records: SPF, DKIM and DMARC. These records live in your domain’s DNS zone, which your hosting provider or registrar usually manages. A missing or permissive DMARC record is one of the cheapest vulnerabilities to fix and one of the most frequently left open.

Website-layer statistics: CMS and plugin exposure

Most Canadian small business websites run on a content management system, and WordPress is the most common. There is no Canada-specific breakdown of CMS vulnerabilities, so the best available data is global. It comes from Patchstack, a WordPress security vendor whose 2026 report covers 2025. Patchstack sells protection to hosts and site owners, so read its framing with that interest in mind. Its underlying counts are nonetheless the most detailed available.

  • 11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, 42% more than in 2024.
  • 91% were in plugins and 9% in themes. WordPress core had just six, all low priority.
  • 46% had no fix available from the developer by the time the vulnerability was publicly disclosed.
  • Heavily exploited vulnerabilities were attacked fast. Weighted for exploitation intensity, the median time to first mass exploitation was about five hours after disclosure.
  • Old flaws stay dangerous. Only four of the ten most-attacked vulnerabilities in 2025 were published that year.

The implication is uncomfortable but important. When nearly half of disclosed vulnerabilities have no patch at the moment attackers learn about them, “keep your plugins updated” is necessary but not sufficient. In two penetration tests Patchstack ran in 2025, standard network and server-layer filters blocked only 12% of WordPress-specific exploit attempts in the first test and 26% in the broader second test. Generic firewalls struggle with CMS-specific attacks. The attacks often look like normal logged-in traffic.

One seasonal finding is timely as this article goes to publication. Malware data from Monarx, published in the same report, showed malicious file uploads nearly tripling in November and December 2025. The same months bring heavier traffic and lighter IT staffing. For Canadian retailers heading into Black Friday and the holiday season, that is the window when unpatched plugins and untested backups matter most.

Where each statistic lands in your website hosting stack

A statistic is only useful if you can connect it to something you control. The table below maps the numbers above to the layer of a business website they describe, and to the question the data suggests putting to your hosting company.

Stack layer What the data shows Question to ask your hosting company
Application (CMS, plugins, themes) 11,334 WordPress vulnerabilities in 2025; 46% unpatched at disclosure Do you offer virtual patching or application-aware filtering for known CMS vulnerabilities, not just a generic firewall?
Identity and access Unauthorized access behind 81% of PIPEDA breach reports Can every account on my plan use multi-factor authentication, and can I see an access log?
Email and domain CA$67.9M reported spear-phishing losses in 2025 Will you help me set SPF, DKIM and DMARC correctly on my domain?
Backups and recovery Recovery spending doubled to $1.2B How often are backups taken, where are they stored, how long are they kept, and when were restores last tested?
Provider and supply chain Supply-chain compromise adds about CA$368,000 per breach What is your incident notification process, and how quickly would you tell me about a breach affecting my site?
Data location 69% of organizations rank sovereignty above price Where are my site, databases and backups physically stored, and which country’s law governs them?

The table is deliberately built as questions rather than product features. Any hosting provider can list features. The value is in how clearly a provider answers these questions in writing. Well-run web hosting companies answer each of them in plain language in their documentation, service agreement or privacy policy.

Canada web hosting and data sovereignty: what the survey data shows

Sovereignty has moved from a niche compliance concern to a mainstream buying criterion. In CIRA’s 2025 survey, 69% of Canadian organizations named data sovereignty as the most important factor when sourcing a cybersecurity solution, up from 60% in 2024. Only 29% named price. 82% said a provider’s country of origin had become more important, and 56% had reconsidered U.S. vendors because of trade and political uncertainty.

Those figures describe cybersecurity purchasing, not hosting specifically. The underlying concern carries over directly, though: whose law applies to the servers holding customer data. That is the core reason Canadian businesses choose Canada hosting for their websites, and it helps to be precise about what it delivers.

What PIPEDA requires is accountability, not a Canadian address. The federal law does not prohibit storing personal information outside Canada. It holds the organization responsible for protecting that information wherever it goes, including through contracts with processors. Québec’s private-sector law is stricter. Since September 2023, a business must complete a privacy impact assessment before communicating personal information outside the province. For a Québec-facing business, keeping data inside Canada simplifies that obligation considerably.

Keeping a site, its databases and its backups on Canadian hosting infrastructure delivers three practical benefits. It keeps the data under Canadian jurisdiction. It simplifies the privacy disclosures a business must make to its customers. It shortens network paths to Canadian visitors. Data residency is a legal and governance choice. It works alongside the stack-level controls above rather than replacing them.

When comparing Canadian web hosting services, ask where every copy of your data lives, including backups and any content delivery network. A Canadian web hosting company should be able to answer that for each component of your plan. Canadian businesses using providers such as 4GoodHosting, which hosts customer sites on infrastructure in Canada, can add that answer directly to their privacy policy.

A statistics-driven checklist for Canadian web hosting customers

Each item below corresponds to one of the statistics in this guide. Work through it in order. The early items cost little and address the most common causes of breaches.

  1. Turn on multi-factor authentication everywhere. This covers your hosting control panel, CMS administrator accounts, domain registrar and email. Unauthorized access drives four in five PIPEDA breach reports.
  2. Publish a DMARC record. Start in monitoring mode, confirm SPF and DKIM are aligned, then move to enforcement. This directly addresses the spear-phishing losses the CAFC recorded.
  3. Audit your plugins. Remove anything inactive or abandoned, and replace components whose developers have not shipped updates in a year. Plugins account for 91% of new WordPress vulnerabilities.
  4. Add protection that does not depend on a patch existing. Given that 46% of vulnerabilities are unpatched at disclosure, use virtual patching or an application-aware firewall.
  5. Test a restore, not just a backup. Confirm your backups are stored separately from your site, and time how long a full restore takes. Recovery costs doubled between 2021 and 2023.
  6. Write down a one-page incident plan. Only 26% of businesses have written cyber policies. Include who decides whether a breach creates a real risk of significant harm, and where the 24-month breach log is kept.
  7. Document where your data lives. Record your site, databases, backups and email, and match your privacy policy to the answer.
  8. Get your provider’s notification commitment in writing. Supply-chain compromise is Canada’s largest breach cost driver, so know how and when you would be told about an incident on the provider’s side.
  9. Plan for the fourth quarter. Schedule plugin reviews and a restore test before November, when malicious uploads have historically spiked.

What to watch for in the rest of 2026

Several of the figures in this guide are due for replacement soon. Statistics Canada finished collecting data for its 2025 survey on 31 March 2026. The previous edition was published in October 2024, during Cyber Security Awareness Month, so new national business figures may arrive within weeks. CIRA has also published its survey each October. This article will be updated when either source releases new data, and the date at the top of the page will show when that last happened.

Frequently asked questions

What percentage of Canadian businesses experience cyber attacks?

It depends on what is counted. Statistics Canada found that 16% of Canadian businesses with 10 or more employees were impacted by a cyber security incident in 2023, down from 21% in 2019. CIRA’s 2025 survey of cybersecurity decision-makers found that 43% of organizations had been targeted by an attack, attempted or successful, in the previous 12 months. The first counts incidents that affected operations; the second counts attempts.

How much does a data breach cost in Canada?

IBM’s 2026 Cost of a Data Breach Report puts the average Canadian breach at CA$7.11 million, a record, with an average lifecycle of 205 days to identify and contain. That figure reflects enterprise-scale incidents across a global sample of 602 breached organizations. Costs for small businesses are typically far lower but can still be severe relative to their revenue.

How many data breaches are reported to the Privacy Commissioner of Canada?

Businesses filed almost 700 breach reports under PIPEDA in fiscal 2025-26, affecting more than 20 million Canadians, according to the Office of the Privacy Commissioner. The count has held close to 700 for several years: 693 in 2023-24 and 686 in 2024-25. Unauthorized access accounted for 81% of PIPEDA breach reports in 2024-25.

Do Canadian businesses pay ransomware demands?

The two main Canadian sources disagree because they survey different populations. Statistics Canada found that 88% of businesses hit by ransomware in 2023 did not pay. CIRA’s 2025 survey of cybersecurity professionals found that 74% of ransomware victims did pay, typically $25,000 or more. The CIRA sample skews toward larger organizations whose incidents escalated to negotiation.

Does PIPEDA require websites to be hosted in Canada?

No. PIPEDA does not prohibit storing personal information outside Canada, but it makes the organization accountable for protecting that information wherever it is processed, including by third-party providers. Québec’s private-sector privacy law adds a requirement to complete a privacy impact assessment before personal information is communicated outside the province. Many businesses choose Canadian hosting to keep data under Canadian jurisdiction and simplify these obligations.

What is the most common cause of website security breaches in Canada?

Unauthorized access is the leading cause in breaches reported under PIPEDA, rising from 65% of reports in 2021-22 to 81% in 2024-25. It includes cyber attacks, social engineering and misuse of access privileges. Among Canadian businesses surveyed by Statistics Canada, scams and fraud were the most common method, affecting 50% of impacted businesses in 2023.

How quickly are website vulnerabilities exploited?

Very quickly. Patchstack’s 2026 report found that the most heavily exploited WordPress vulnerabilities were typically attacked within about five hours of public disclosure. 46% of vulnerabilities disclosed in 2025 had no developer patch available at the time of disclosure, which is why protection that does not depend on an update is increasingly important.

What should I ask a hosting company about security?

Ask where your site, databases and backups are stored and under which country’s law. Ask how often backups run and when restores were last tested, and whether multi-factor authentication is available on every account. Ask whether the provider offers application-aware protection for your CMS and how quickly it will notify you of an incident on its side. A provider’s written answers to these questions tell you more than a feature list.

Key takeaways

  • Canadian security statistics measure different things. Always check the denominator before quoting a figure.
  • Statistics Canada found that 16% of businesses with 10 or more employees were impacted by a cyber incident in 2023. The rate is falling, but recovery costs doubled to $1.2 billion.
  • No national survey measures incident rates for Canadian businesses with fewer than 10 employees.
  • The average Canadian data breach cost a record CA$7.11 million in IBM’s 2026 study, driven most by supply-chain compromise. Small-business costs are far lower but still serious.
  • Unauthorized access now accounts for 81% of PIPEDA breach reports, up from 65% in 2021-22.
  • Canadians reported over CA$704 million in fraud losses in 2025, and spear phishing was the second-costliest category. Email authentication on your domain is a hosting-layer control.
  • 91% of new WordPress vulnerabilities are in plugins, and 46% have no patch at disclosure.
  • 69% of Canadian organizations rank data sovereignty above price. PIPEDA requires accountability for data, not a Canadian address, while Québec requires an assessment before data leaves the province.

Conclusion

The headline numbers in Canadian cyber security reporting pull in opposite directions because they answer different questions. Fewer mid-sized and larger businesses report being impacted each survey cycle. Yet those that are hit pay more, recover more slowly and increasingly get breached through someone else’s systems. Fraud losses keep setting records, and website software keeps producing vulnerabilities faster than developers patch them.

For a Canadian business website, the practical reading is straightforward. Most of the risk that the data describes sits in a few layers you can inspect: account access, email authentication, plugins, backups and your provider relationships. Canadian web hosting addresses the jurisdiction question in that list. The rest depends on how those layers are configured and maintained. The most useful thing you can do with these statistics is turn each one into a question, then put those questions to yourself and to your provider.

Next step

If you want to check your own site against the stack questions in this guide, the 4GoodHosting team can walk through where your site, databases and backups are stored and what protections are in place on your plan. [Talk to the 4GoodHosting team →]

Related Posts

post
date icon
date icon
Most hosting trend articles are lists of buzzwords: AI, edge, green, serverless. They are hard to act on because they have no dates attached. For a small business owner, the useful question is not “what is fashionable in...
post
date icon
date icon
A VPS is usually sold as a bigger version of shared hosting. That framing undersells it and leads people to buy it for the wrong reason. What you are actually buying is three things that shared hosting cannot...
post
date icon
date icon
Most Vancouver businesses did not choose their WordPress hosting. They inherited it. A web designer built the site, put it on a platform they resell, billed it monthly alongside a maintenance retainer, and set up the account in...
post
date icon
date icon
Vancouver businesses get told constantly that their website needs to be fast. Destination BC tells tourism operators to aim for a two-to-three second load. Every agency page in the city repeats some version of the same warning. Almost...
post
date icon
date icon
Search this question and you get confidently contradictory answers. One guide says move once you pass 2,000 visitors a month. Another says stay on shared hosting until 20,000 or 30,000. That is a fifteen-fold spread between sources selling...
post
date icon
date icon
WordPress runs an enormous share of the business websites in the GTA, and almost none of them are running on infrastructure designed for it. They are running on a general-purpose shared plan that happens to have WordPress installed,...
© 2026 p4e.ca. All rights reserved.