Last updated: August 12, 2026
Cyber Incidents Aren’t Just Headlines: A Practical Cybersecurity Guide for Manitoba Organizations
Most cybersecurity stories happen somewhere else. Hospitals in the States, pipelines, banks with towers downtown. Easy to read, easy to forget. But every so often an incident lands in a community you know, in organizations you recognize, and the question changes. It stops being “how does this happen” and becomes “what would we do?”
That second question is worth sitting with. This guide is built to help you answer it.
The short version:
- Most cyberattacks are automated and untargeted. Size and location alone do not protect Manitoba organizations, or any organization.
- A good incident response comes down to four moves: isolate immediately, notify law enforcement, bring in specialists, communicate honestly.
- Ask four questions this month among your team: who gets the first call, how fast can we isolate a system or machine, what is actually in our backups, and who has authority to shut things down.
- A backup that has never been restore-tested is hope, not a plan.
- Cyber insurance increasingly requires proof of safeguards before paying out. Read the requirements section of your policy.
- Manitoba organizations have breach reporting obligations under PIPEDA, and in some cases PHIA or public-sector privacy legislation
Why do cyberattacks happen to small Manitoba organizations?
Because attackers do not pick targets the way most people assume. The majority of attacks are not aimed at anyone in particular. Automated tools scan the internet around the clock looking for any organization with an unpatched system, a weak password, or an employee who clicks the wrong link. Your size does not protect you. Your location does not protect you. A 40-person organization in southern Manitoba looks identical to a 40-person organization anywhere else when the scan comes through.
Small and mid-sized organizations are often hit harder than large ones for a simple reason: they have fewer layers of defence and less practice responding. The attack is not personal. The damage is.
The numbers back this up. In CIRA’s 2025 Cybersecurity Survey of Canadian organizations across the private, public, and municipal sectors, more than four in ten (43 per cent) reported being targeted by a cyberattack in the past 12 months, and one in four (24 per cent) were hit by ransomware. Statistics Canada’s Canadian Survey of Cyber Security and Cybercrime adds the cost picture: total recovery spending by Canadian businesses doubled in just two years to roughly $1.2 billion in 2023, even as the share of businesses impacted declined from 21 per cent in 2019 to 16 per cent in 2023. Getting hit is becoming less common and more expensive at the same time. And looking ahead, the Canadian Centre for Cyber Security’s National Cyber Threat Assessment 2025-2026 names ransomware the top cybercrime threat facing Canada’s critical infrastructure and expects extortion tactics to escalate.
What should you do if your organization is hit by a cyberattack?
Isolate affected systems immediately, notify law enforcement, bring in incident response specialists, and communicate honestly. Speed and decisiveness in the first hours matter more than anything else. In practice:
- Isolate affected systems immediately. Disconnecting compromised systems from the network stops an incident from spreading. Sometimes that means voluntarily taking core systems offline while you sort out what is affected. That feels drastic. It is the right call.
- Notify law enforcement. In Canada, that means local police and reporting through the Canadian Centre for Cyber Security.
- Bring in specialists. Incident response is its own discipline. Even organizations with capable IT teams benefit from outside experts who handle breaches every week.
- Communicate honestly. Telling staff, customers, and the public what you know, what you do not know yet, and what you are doing about it builds trust rather than eroding it.
If you ever see a local organization do these four things, that is not a sign of weakness. That is what competence under pressure looks like.
What is the difference between proactive and reactive cybersecurity?
Proactive cybersecurity reduces the odds that anything goes wrong and shrinks the damage when it does. Reactive cybersecurity responds after something has already gone wrong. The difference shows up in cost, downtime, and stress.
|
Reactive organization |
Proactive organization |
|
|
Backup gaps |
Discovered during a crisis |
Found in a scheduled test and fixed quietly |
|
Who is in charge |
Figured out during the incident |
Written down before it mattered |
|
Security tools |
Installed and assumed to work |
Verified and tested on a schedule |
|
Cost of an incident |
Days of downtime, recovery fees, lost trust |
Hours of contained disruption, if anything |
|
Insurance claim |
At risk if safeguards were not in place |
Documented and defensible |
Most organizations believe they are more proactive than they are. The honest test is not whether you have security tools. It is whether anyone is verifying they work.
What questions should I ask about my organization’s security this month?
If recent events have you wondering where your organization stands, start with these four questions. Ask them of whoever handles your technology, whether that is a person on staff or a company you pay.
- If something looked wrong at 7 a.m. tomorrow, who gets the first call? Not “IT.” A name and a number that everyone on your team knows.
- How fast could we cut one infected computer off from everything else? The answer should be minutes, and someone should be able to explain exactly how.
- If our systems were locked right now, what is actually in our backups? And when was a restore last tested, not just confirmed that the backup job ran? A backup that has never been restore-tested is hope, not a plan.
- Who has the authority to shut things down without calling a meeting first? Small incidents become large ones while people wait for permission.
If the answers come easily, good. If they do not, you have found your starting point, and you found it on a calm day instead of a bad one.
How do I know if my backups would actually save my business?
Test a restore. That is the whole answer. Pick a real file, a real server, or a real system, and have your IT provider recover it while you watch. Time it. Then ask two follow-up questions: how far back do our backups go, and are any copies stored somewhere that an attacker inside our network could not reach?
Modern ransomware specifically hunts for backups before it locks anything, because attackers know backups are what let you refuse to pay. If your backups live on the same network as everything else, with the same passwords, they are part of the problem, not the solution.
Does cyber insurance cover incidents like this?
Sometimes, and less often than people assume. Cyber insurance policies in Canada increasingly require proof of specific safeguards before they pay out: multi-factor authentication, tested backups, endpoint protection, staff training. Organizations have had claims denied because the security posture described on the application did not match reality.
Two practical steps: read your policy’s requirements section this month and confirm with whoever manages your technology that each requirement is actually in place and documented. If you do not carry cyber insurance, the requirements list from any Canadian insurer is still a useful free checklist of what the industry considers the baseline.
What are a Manitoba organization’s legal obligations after a breach?
Private-sector organizations in Manitoba fall under PIPEDA, Canada’s federal privacy law. If a breach creates a real risk of significant harm to individuals, you are required to report it to the Office of the Privacy Commissioner of Canada, notify the affected individuals, and keep records of the breach. Municipalities and public bodies have separate obligations under Manitoba’s Freedom of Information and Protection of Privacy Act (FIPPA). Organizations handling health information have obligations under Manitoba’s PHIA.
The common thread: “we did not know we had to report it” is not a defence. Knowing your obligations before an incident is part of being prepared.
Where should an organization start if all of this feels overwhelming?
Start with the four questions above. They cost nothing and take one meeting. From there, an honest gap assessment against a recognized baseline tells you where you actually stand, and a prioritized plan turns the anxiety into a to-do list.
The organizations that handle incidents well are not the ones that never worried. They are the ones that turned their worry into preparation while things were quiet.
At SolutionsIT, we have been helping Manitoba organizations do exactly that since 1987, first as two independent IT companies and today as one team, from our offices in Winkler, Portage la Prairie, and Winnipeg. If you want a second set of eyes on your current setup, we are easy to find.
Frequently asked questions
How common are cyberattacks on small businesses in Canada? Very. Canadian small and mid-sized businesses are targeted constantly because automated attacks do not discriminate by size, and smaller organizations typically have fewer defences. Most incidents never make the news.
Should we pay a ransom if we get hit? Law enforcement and the Canadian Centre for Cyber Security advise against paying. Payment funds future attacks, offers no guarantee of recovery, and may create legal exposure depending on who receives the money. Tested backups are what make refusing possible.
How much should a small Manitoba business spend on cybersecurity? There is no universal number, but the right frame is risk, not budget. One day of full downtime, priced in lost revenue and recovery costs, is usually the most honest benchmark for what prevention is worth.
Who do you report a cyber incident to in Canada? Three places, depending on the situation: your local police service, the Canadian Centre for Cyber Security (which accepts incident reports online at cyber.gc.ca), and the Canadian Anti-Fraud Centre if money or fraud is involved. If personal information was compromised and there’s a real risk of significant harm, PIPEDA also requires reporting to the Office of the Privacy Commissioner of Canada. Reporting isn’t just an obligation; it can bring help.
What do the early signs of a ransomware attack look like? Files that won’t open or have strange new extensions, ransom notes appearing on screens, security tools that have been mysteriously disabled, accounts locked out, or systems suddenly running slow. If anyone in your organization sees these, the correct response is to disconnect the affected machine and make the first call immediately, not to investigate on their own.
Can our current IT provider handle a serious incident? Ask them the four questions in this guide. A capable provider will have crisp answers and welcome the conversation. Vague answers are themselves an answer.
Pocket Line: Attackers don’t pick targets; software does. The organizations that come through an incident well are the ones that decided who does what, and tested their backups, on a calm day.