Ask three Canadian sources how many businesses were hit by a cyber attack last year and you will get three different answers. Statistics Canada says 16%. The Canadian Internet Registration Authority (CIRA) says 43% were targeted. An IBM-sponsored study puts the average breach at more than seven million dollars, which would bankrupt most of the businesses in the first survey.
None of these sources is wrong. They measure different things, in different populations, over different periods. That gap matters, because a statistic that is not understood is one that gets misused. Sometimes it is used to frighten a ten-person firm into buying enterprise tooling. Sometimes it convinces a retailer that its risk is too small to take seriously.
This guide collects the most recent Canadian business website security statistics available as of late September 2026. It explains what each one measures and maps each figure to the part of a website’s hosting stack it actually describes. If you run a Canadian business website, it will tell you which numbers apply to you. If you are comparing Canadian web hosting options, it will tell you which questions the data says to ask.
| Statistic | Figure | Source and period |
| Businesses impacted by a cyber incident | 16% | Statistics Canada, 2023 calendar year |
| Organizations targeted by an attack (attempted or successful) | 43% | CIRA survey, 12 months to Aug 2025 |
| Organizations reporting a customer or employee data breach | 42% | CIRA survey, 12 months to Aug 2025 |
| Average cost of a data breach in Canada | CA$7.11 million | IBM / Ponemon, Mar 2025 – Feb 2026 |
| Average breach lifecycle (detect and contain) | 205 days | IBM / Ponemon, Mar 2025 – Feb 2026 |
| Business breach reports to the federal privacy regulator | Almost 700 | OPC, fiscal 2025-26 |
| Share of PIPEDA breaches involving unauthorized access | 81% | OPC, fiscal 2024-25 |
| Reported fraud losses in Canada | Over CA$704 million | Canadian Anti-Fraud Centre, 2025 |
| New WordPress ecosystem vulnerabilities | 11,334 | Patchstack, 2025 calendar year |
| Organizations ranking data sovereignty above price | 69% | CIRA survey, 2025 |
Each of these is explained, with its limitations, below.
Bar chart comparing four Canadian cyber security statistics: 16% impacted, 43% targeted, 42% data breach, 24% ransomware
The single most useful thing to understand about Canadian security data is what sits under the fraction line. Every percentage has a denominator, and the major Canadian sources use very different ones.
| Source | Who is counted | What counts as an event | Sample |
| Statistics Canada, Canadian Survey of Cyber Security and Cybercrime | Enterprises with 10 or more employees, most sectors, excluding public administration | Incidents the business judged to have impacted it | 12,462 enterprises, 71% response rate |
| CIRA Cybersecurity Survey | Cybersecurity decision-makers in public, private and MUSH-sector organizations | Attacks targeted at the organization, attempted or successful | 500 online responses |
| IBM Cost of a Data Breach | Organizations worldwide that had already experienced a breach | Breaches, costed after the fact | 602 organizations globally |
| Office of the Privacy Commissioner (OPC) | Organizations subject to PIPEDA | Breaches meeting the “real risk of significant harm” reporting threshold | All reports received |
| Canadian Anti-Fraud Centre (CAFC) | Individuals and businesses who chose to report | Fraud and attempted fraud | Voluntary reports only |
Horizontal bar chart showing how CIRA and Statistics Canada figures differ because they count different populations and events
Read that way, the contradictions resolve themselves.
Statistics Canada’s 16% counts only incidents that businesses said affected their operations. It explicitly excludes attacks a business shrugged off, and the agency itself notes that its figures may not capture the total number of attacks. CIRA’s 43% counts attempts. A phishing email that nobody clicked is an attack under one method and a non-event under the other.
The clearest illustration is ransomware. Among businesses that Statistics Canada found were hit by ransomware in 2023, 88% did not pay. In CIRA’s 2025 survey, 74% of ransomware victims did pay, typically $25,000 or more. Both findings are credible. Statistics Canada draws a probability sample covering roughly 205,000 businesses, most of them small. CIRA surveys people whose job is cybersecurity, which skews toward larger organizations with the kind of incident that escalates to a negotiation.
There is also a blind spot worth naming. Statistics Canada’s survey does not cover firms with fewer than 10 employees. A large share of Canadian business websites belong to sole proprietors and micro businesses, and no national survey currently measures their incident rate. If you run a five-person firm, the honest answer is that the data describes businesses bigger than yours.
How to use this: when you quote a statistic in a board report or a client proposal, name the source and state what it counts. “16% of Canadian businesses with 10 or more employees reported an impactful incident in 2023” is defensible. “16% of Canadian businesses were hacked” is not.
Statistics Canada’s survey, conducted for Public Safety Canada every two years, is the only nationally representative measure of cyber incidents against Canadian businesses. Its most recent published results cover 2023.
About one in six businesses (16%) were impacted by a cyber security incident in 2023, down from 18% in 2021 and 21% in 2019. The decline held across every size band:
| Business size | 2019 | 2021 | 2023 |
| Small (10–49 employees) | 18% | 16% | 14% |
| Medium (50–249 employees) | 29% | 25% | 23% |
| Large (250+ employees) | 44% | 37% | 30% |
Fewer businesses reporting impact is good news on its face, but the methods shifted in a worrying direction. Scams and fraud remained the most common method, affecting 50% of impacted businesses, up six points from 2021. Identity theft rose eleven points to 31%. Ransomware rose from 11% to 13% of impacted businesses.
Multiply those rates together and the national picture sharpens. If 13% of the 16% of businesses that were impacted experienced ransomware, roughly two in every hundred businesses in the survey’s scope were hit by ransomware in 2023. This is our calculation from the published rates, not a figure Statistics Canada publishes. It is a useful corrective to headlines that imply ransomware is universal, and a reminder that two in a hundred, across a country, is a great many businesses.
The spending data points the same way. Recovery spending doubled from about $600 million in 2021 to $1.2 billion in 2023. Prevention and detection spending grew far more slowly, from $9.7 billion to $11.0 billion. Fewer businesses are being hit, but each hit costs more.
Readiness has barely moved. Just 26% of businesses had written cyber security policies in 2023, the same as in 2021. Only 22% trained non-IT staff in cyber security skills, and 22% carried cyber risk insurance. Half of businesses (50%) had cyber security employees, down from 61%. The most common reason for having none was that the business relied on outside consultants or contractors instead, cited by 47% of those without staff.
That last figure has a direct bearing on website hosting. For a large share of Canadian businesses, security is something bought rather than staffed, and the hosting company is often the first and closest of those outside providers.
IBM’s 2026 Cost of a Data Breach Report, released on 29 July 2026, puts the average Canadian breach at a record CA$7.11 million, up from CA$6.98 million in 2025. The average breach exposed 28,500 records and took 205 days to identify and contain, both higher than the previous year.
Three findings from the Canadian results matter most for website owners:
Treat the headline figure with care. The study covers 602 breached organizations worldwide and is built around enterprise-scale incidents. It does not describe a typical small business, and IBM does not publish the size of its Canadian subsample in the release.
For a sense of scale at the small end, divide Statistics Canada’s $1.2 billion in 2023 recovery spending by the approximate number of impacted businesses in the survey’s scope. The result is an average in the tens of thousands of dollars per impacted business, not millions. That is our rough derivation from published totals, and it excludes lost revenue, which Statistics Canada does not cost in the same way. Even so, it is the more realistic planning figure for most Canadian small businesses, and it is still large enough to end one.
Since 1 November 2018, organizations subject to PIPEDA, Canada’s federal private-sector privacy law, have had to report breaches of security safeguards to the Office of the Privacy Commissioner when there is a real risk of significant harm. They must also notify the affected individuals, and they must keep a record of every breach for 24 months, whether it was reportable or not. Knowingly failing to meet these obligations is an offence carrying fines of up to $100,000.
The breach report counts have been remarkably stable:
| Fiscal year | PIPEDA breach reports | Accounts or individuals affected |
| 2023-24 | 693 | About 25 million accounts |
| 2024-25 | 686 | About 20 million accounts |
| 2025-26 | Almost 700 | More than 20 million Canadians |
The stability of the count hides a shift in the cause. Unauthorized access, which covers cyber incidents, social engineering and employees misusing their access, accounted for 65% of PIPEDA breach reports in 2021-22. By 2024-25 it accounted for 81%. Accidental disclosure fell from 25% to 13% over the same period. Canadian breaches are increasingly about someone getting in, not something being sent to the wrong address.
Line chart of PIPEDA breach reports by type from 2021-22 to 2024-25, unauthorized access rising from 65% to 81%
The OPC also flagged a growing pattern of supply-chain breaches. In one case, a breach at a single service provider to the pharmaceutical industry affected more than 50 organizations in Canada. A single breach at a shared provider is logged once but felt many times over. It is the same pattern IBM found driving costs.
For a business website, PIPEDA turns security into a record-keeping obligation. Your contact form, your customer accounts, your order database and your server logs all hold personal information. If any of them is breached, the obligation to assess, record and possibly report the breach falls on you, not on your provider. PIPEDA’s accountability principle makes the organization responsible for personal information it transfers to a third party for processing. Your hosting agreement, backups and access logs are part of your compliance evidence.
Website security does not end at the web server. For most small businesses, the domain name also carries the business email. That makes the domain one of the most exploited assets they own.
The Canadian Anti-Fraud Centre received more than 112,000 fraud reports in 2025, with reported losses of over CA$704 million. Losses reported since 2022 now exceed $2.4 billion. The CAFC estimates that only 5% to 10% of fraud is ever reported, so the true figure is many times higher.
Two lines in the CAFC’s 2025 top-ten table are directly relevant to businesses. Spear phishing, meaning targeted phishing aimed at a specific person or organization, produced CA$67.9 million in reported losses from just 813 reports, the second-highest dollar loss of any category. General phishing drew 2,869 reports. IBM’s 2025 Canadian results identified phishing as the most common initial attack vector, at an average of CA$7.91 million per breach.
The hosting connection is concrete. Whether a fraudster can send convincing email that appears to come from your domain depends largely on three DNS records: SPF, DKIM and DMARC. These records live in your domain’s DNS zone, which your hosting provider or registrar usually manages. A missing or permissive DMARC record is one of the cheapest vulnerabilities to fix and one of the most frequently left open.
Most Canadian small business websites run on a content management system, and WordPress is the most common. There is no Canada-specific breakdown of CMS vulnerabilities, so the best available data is global. It comes from Patchstack, a WordPress security vendor whose 2026 report covers 2025. Patchstack sells protection to hosts and site owners, so read its framing with that interest in mind. Its underlying counts are nonetheless the most detailed available.
The implication is uncomfortable but important. When nearly half of disclosed vulnerabilities have no patch at the moment attackers learn about them, “keep your plugins updated” is necessary but not sufficient. In two penetration tests Patchstack ran in 2025, standard network and server-layer filters blocked only 12% of WordPress-specific exploit attempts in the first test and 26% in the broader second test. Generic firewalls struggle with CMS-specific attacks. The attacks often look like normal logged-in traffic.
One seasonal finding is timely as this article goes to publication. Malware data from Monarx, published in the same report, showed malicious file uploads nearly tripling in November and December 2025. The same months bring heavier traffic and lighter IT staffing. For Canadian retailers heading into Black Friday and the holiday season, that is the window when unpatched plugins and untested backups matter most.
A statistic is only useful if you can connect it to something you control. The table below maps the numbers above to the layer of a business website they describe, and to the question the data suggests putting to your hosting company.
| Stack layer | What the data shows | Question to ask your hosting company |
| Application (CMS, plugins, themes) | 11,334 WordPress vulnerabilities in 2025; 46% unpatched at disclosure | Do you offer virtual patching or application-aware filtering for known CMS vulnerabilities, not just a generic firewall? |
| Identity and access | Unauthorized access behind 81% of PIPEDA breach reports | Can every account on my plan use multi-factor authentication, and can I see an access log? |
| Email and domain | CA$67.9M reported spear-phishing losses in 2025 | Will you help me set SPF, DKIM and DMARC correctly on my domain? |
| Backups and recovery | Recovery spending doubled to $1.2B | How often are backups taken, where are they stored, how long are they kept, and when were restores last tested? |
| Provider and supply chain | Supply-chain compromise adds about CA$368,000 per breach | What is your incident notification process, and how quickly would you tell me about a breach affecting my site? |
| Data location | 69% of organizations rank sovereignty above price | Where are my site, databases and backups physically stored, and which country’s law governs them? |
The table is deliberately built as questions rather than product features. Any hosting provider can list features. The value is in how clearly a provider answers these questions in writing. Well-run web hosting companies answer each of them in plain language in their documentation, service agreement or privacy policy.
Sovereignty has moved from a niche compliance concern to a mainstream buying criterion. In CIRA’s 2025 survey, 69% of Canadian organizations named data sovereignty as the most important factor when sourcing a cybersecurity solution, up from 60% in 2024. Only 29% named price. 82% said a provider’s country of origin had become more important, and 56% had reconsidered U.S. vendors because of trade and political uncertainty.
Those figures describe cybersecurity purchasing, not hosting specifically. The underlying concern carries over directly, though: whose law applies to the servers holding customer data. That is the core reason Canadian businesses choose Canada hosting for their websites, and it helps to be precise about what it delivers.
What PIPEDA requires is accountability, not a Canadian address. The federal law does not prohibit storing personal information outside Canada. It holds the organization responsible for protecting that information wherever it goes, including through contracts with processors. Québec’s private-sector law is stricter. Since September 2023, a business must complete a privacy impact assessment before communicating personal information outside the province. For a Québec-facing business, keeping data inside Canada simplifies that obligation considerably.
Keeping a site, its databases and its backups on Canadian hosting infrastructure delivers three practical benefits. It keeps the data under Canadian jurisdiction. It simplifies the privacy disclosures a business must make to its customers. It shortens network paths to Canadian visitors. Data residency is a legal and governance choice. It works alongside the stack-level controls above rather than replacing them.
When comparing Canadian web hosting services, ask where every copy of your data lives, including backups and any content delivery network. A Canadian web hosting company should be able to answer that for each component of your plan. Canadian businesses using providers such as 4GoodHosting, which hosts customer sites on infrastructure in Canada, can add that answer directly to their privacy policy.
Each item below corresponds to one of the statistics in this guide. Work through it in order. The early items cost little and address the most common causes of breaches.
Several of the figures in this guide are due for replacement soon. Statistics Canada finished collecting data for its 2025 survey on 31 March 2026. The previous edition was published in October 2024, during Cyber Security Awareness Month, so new national business figures may arrive within weeks. CIRA has also published its survey each October. This article will be updated when either source releases new data, and the date at the top of the page will show when that last happened.
What percentage of Canadian businesses experience cyber attacks?
It depends on what is counted. Statistics Canada found that 16% of Canadian businesses with 10 or more employees were impacted by a cyber security incident in 2023, down from 21% in 2019. CIRA’s 2025 survey of cybersecurity decision-makers found that 43% of organizations had been targeted by an attack, attempted or successful, in the previous 12 months. The first counts incidents that affected operations; the second counts attempts.
How much does a data breach cost in Canada?
IBM’s 2026 Cost of a Data Breach Report puts the average Canadian breach at CA$7.11 million, a record, with an average lifecycle of 205 days to identify and contain. That figure reflects enterprise-scale incidents across a global sample of 602 breached organizations. Costs for small businesses are typically far lower but can still be severe relative to their revenue.
How many data breaches are reported to the Privacy Commissioner of Canada?
Businesses filed almost 700 breach reports under PIPEDA in fiscal 2025-26, affecting more than 20 million Canadians, according to the Office of the Privacy Commissioner. The count has held close to 700 for several years: 693 in 2023-24 and 686 in 2024-25. Unauthorized access accounted for 81% of PIPEDA breach reports in 2024-25.
Do Canadian businesses pay ransomware demands?
The two main Canadian sources disagree because they survey different populations. Statistics Canada found that 88% of businesses hit by ransomware in 2023 did not pay. CIRA’s 2025 survey of cybersecurity professionals found that 74% of ransomware victims did pay, typically $25,000 or more. The CIRA sample skews toward larger organizations whose incidents escalated to negotiation.
Does PIPEDA require websites to be hosted in Canada?
No. PIPEDA does not prohibit storing personal information outside Canada, but it makes the organization accountable for protecting that information wherever it is processed, including by third-party providers. Québec’s private-sector privacy law adds a requirement to complete a privacy impact assessment before personal information is communicated outside the province. Many businesses choose Canadian hosting to keep data under Canadian jurisdiction and simplify these obligations.
What is the most common cause of website security breaches in Canada?
Unauthorized access is the leading cause in breaches reported under PIPEDA, rising from 65% of reports in 2021-22 to 81% in 2024-25. It includes cyber attacks, social engineering and misuse of access privileges. Among Canadian businesses surveyed by Statistics Canada, scams and fraud were the most common method, affecting 50% of impacted businesses in 2023.
How quickly are website vulnerabilities exploited?
Very quickly. Patchstack’s 2026 report found that the most heavily exploited WordPress vulnerabilities were typically attacked within about five hours of public disclosure. 46% of vulnerabilities disclosed in 2025 had no developer patch available at the time of disclosure, which is why protection that does not depend on an update is increasingly important.
What should I ask a hosting company about security?
Ask where your site, databases and backups are stored and under which country’s law. Ask how often backups run and when restores were last tested, and whether multi-factor authentication is available on every account. Ask whether the provider offers application-aware protection for your CMS and how quickly it will notify you of an incident on its side. A provider’s written answers to these questions tell you more than a feature list.
The headline numbers in Canadian cyber security reporting pull in opposite directions because they answer different questions. Fewer mid-sized and larger businesses report being impacted each survey cycle. Yet those that are hit pay more, recover more slowly and increasingly get breached through someone else’s systems. Fraud losses keep setting records, and website software keeps producing vulnerabilities faster than developers patch them.
For a Canadian business website, the practical reading is straightforward. Most of the risk that the data describes sits in a few layers you can inspect: account access, email authentication, plugins, backups and your provider relationships. Canadian web hosting addresses the jurisdiction question in that list. The rest depends on how those layers are configured and maintained. The most useful thing you can do with these statistics is turn each one into a question, then put those questions to yourself and to your provider.
If you want to check your own site against the stack questions in this guide, the 4GoodHosting team can walk through where your site, databases and backups are stored and what protections are in place on your plan. [Talk to the 4GoodHosting team →]





