Already dealing with a fraud incident? Get help now →

Resources

Short, practical guides, Canadian privacy-law obligations, and official sources for Canadian businesses. We publish slowly and only when a guide is genuinely useful — this page is a working reference, not a news feed.

Free tool

Payment Verification Policy Generator

Answer six quick questions and get a free, one-page Payment Verification Policy sized to how your business actually works — instantly, no signup required. Print it, download it, or have it emailed to you.

Generate my policy →
Practical guides

Start with these two.

How to verify a payment-change request

A convincing email asking to update banking details is one of the most common ways small businesses lose money. The fix is a process, not software:

  1. Pause. Treat every request to change payment details as unverified until proven otherwise — even if it follows a real conversation.
  2. Find the contact yourself. Use a phone number from your own records, a signed contract, or a previous verified invoice. Never use the contact details in the request itself.
  3. Confirm verbally. Speak to a person you know, or who can prove who they are, before any money moves.
  4. Write it down. Record who confirmed the change, how, and when. Make this a step someone owns — not a favour someone does.

Build a one-page first-response contact list

When email, files, booking, or payment systems stop working, the first hour goes better if nobody has to guess. One page, printed and shared:

  • Decision-maker — who has authority to act and approve spending in an incident.
  • IT provider contact — the person or company who can actually touch the systems.
  • Insurer and bank — policy number and fraud-line phone numbers.
  • Key systems list — email, files, accounting, booking/POS, and who administers each.
  • Communication owner — who tells staff, customers, or clients, and through what channel.

Construction

Draw requests and supplier banking changes: a verification checklist

Construction payments are high-value, frequent, and often time-pressured — which is exactly why verification has to be a written habit, not a judgment call:

  1. Treat every change as unverified. Any new banking detail, draw request, or "updated invoice" is unconfirmed until proven otherwise — even mid-project, even from a contact you know.
  2. Confirm by phone, using your own records. Call the number in your master agreement or last verified invoice. Never use the contact details in the request itself.
  3. Set a two-person rule. Choose a dollar threshold above which a second person must sign off before money moves.
  4. Record the confirmation. One line in the project file: who confirmed, how, and when.
  5. Capture details once, properly. When a new subcontractor or supplier starts, collect banking details through a verified channel and store them where the person paying can actually find them.

Health & Wellness

Before your practice adopts a new app or AI tool: six questions

Booking platforms, clinical systems, and AI features can all be helpful — but your practice stays responsible for the patient information it hands over. Ask these before anything new goes live:

  1. What patient or client information would this tool receive?
  2. Where is that information stored, and does it leave Canada?
  3. Who in the practice owns the account and the data in it?
  4. Can we export or delete our information if we stop using it?
  5. How would the provider tell us if they had a security incident?
  6. Who is our named privacy contact for questions about this tool?

This is practical operational guidance, not legal advice — where professional rules apply, confirm with your college or association.

Practical business risks

Where problems usually start — in ordinary business processes

Most incidents we see do not begin with sophisticated attacks. They begin with everyday moments: an invoice, a password, a forgotten update, a handy new tool. These four scenarios are educational starting points, drawn from Canadian government guidance and published incident research.

reported fraud losses in Canada have more than quadrupled in five years — from about $165M in 2020 to a record $704M+ in 2025
Canadian Anti-Fraud Centre ↗
73%
of Canadian small businesses reported experiencing a cybersecurity incident — from phishing to denial-of-service attacks
BDC Small Business Cybersecurity Survey, February 2025 ↗
$704M+
in fraud losses reported to the Canadian Anti-Fraud Centre in 2025 — the highest year on record
Canadian Anti-Fraud Centre ↗
26%
only 26% of Canadian businesses have a written cybersecurity policy — unchanged since 2021
Statistics Canada CSCSC, 2023 (latest released) ↗
$1.2B
spent by Canadian businesses recovering from cyber incidents in 2023 — double the 2021 figure
Statistics Canada CSCSC, 2023 (latest released) ↗
Scenario — payment requests
Unexpected invoices and urgent emails

A message that looks like a supplier, a manager, or a client asks for a payment, a bank-account change, or a quick favour. It can follow a real conversation and arrive at a busy moment. The request itself is the attack.

The weakness is usually not a careless employee; it is a process that lets one person approve an unusual request without verification.

Verify unusual payment changes using a known contact — a phone number you already have on file, never the contact details supplied in the request itself.
Scenario — account access
Stolen or reused passwords

A password reused across services, or exposed in an unrelated breach, can open business email, cloud storage, accounting tools, or banking. From inside an email account, an attacker can reset other passwords and make fraudulent requests look genuine.

Credential abuse remains a leading route into business systems — Verizon DBIR 2025
Turn on a second sign-in step (multi-factor authentication) for business email, banking, and administrator accounts first — it makes a stolen password far less useful.
Scenario — maintenance
Software nobody owns

Security updates repair known weaknesses in computers, phones, routers, browsers, and key business software. Once a weakness is public, attackers can scan broadly for organizations that have not applied the fix.

This is usually an operational problem, not a technical one: nobody owns the update routine, an old device is forgotten, or specialized software is excluded from automatic updates.

Assign one person or provider responsibility for updates — including the router, phones, browsers, and any software that falls outside automatic updates.
Scenario — outside tools
Outside tools holding client information

Booking, accounting, payroll, client-management, and IT-support providers may hold your client information or have privileged access to your systems. A failure at one provider can affect many of its customers at once.

Your business remains responsible for understanding where client information goes and what safeguards your providers use.

Keep a simple list: each provider, the information they hold, who has access, a contact for problems, and how offboarding works when the relationship ends.
Canadian privacy context

Privacy responsibilities: a practical starting point

Privacy responsibilities depend on what your business does, where it operates, what personal information it handles, and where that information travels. This overview is practical information, not legal advice.

PIPEDA — Federal Privacy Law
Commercial activities
PIPEDA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activities. It also applies to personal information that crosses provincial or national borders during commercial activities, including in provinces with substantially similar private-sector laws. Core duties include accountability, meaningful consent, limiting collection and retention, appropriate safeguards, openness, and individual access.
Certain knowing breach-reporting and record-keeping offences can carry fines up to $100,000
Quebec Law 25 (Bill 64)
Enterprises subject to Quebec law
Quebec's private-sector privacy law, modernized by Law 25, requires accountable privacy governance, clear public privacy information, safeguards, incident assessment and reporting where serious injury risk exists, and privacy impact assessments in specified circumstances. Applicability outside Quebec is fact-specific and should not be assumed solely because one Quebec resident visits a website.
The statute provides for administrative penalties up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4%
BC PIPA & Alberta PIPA
BC and Alberta businesses
British Columbia and Alberta have substantially similar private-sector privacy laws that generally govern intra-provincial handling of personal information. Both address consent, accountability, safeguards, and access, but their incident-reporting requirements are not identical. PIPEDA can still apply when personal information crosses provincial or national borders in commercial activities.
Coverage and enforcement differ by statute — determine which law applies before relying on a single checklist
Federal Privacy Reform
Monitor — not yet law
Bill C-27 proposed replacing parts of PIPEDA with the Consumer Privacy Protection Act, but it belonged to the previous Parliament and did not become law. PIPEDA remains the current federal private-sector privacy law. Businesses should maintain sound privacy practices and monitor any future replacement legislation rather than describing the former bill as imminent.
Current priority: comply with the laws in force and track future federal reform
PIPEDA timing: "as soon as feasible" — not a fixed 72 hours
When a breach of security safeguards creates a real risk of significant harm, an organization subject to PIPEDA must report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible after making that determination. It must also keep records of every breach, including those that do not meet the reporting threshold. A documented response process helps the organization assess, contain, record, and escalate incidents without losing critical time.
Core PIPEDA practices for organizations within its scope — in plain language
  • A privacy policy that clearly tells clients what you collect, why you collect it, and how you protect it
  • Meaningful consent before collecting personal information from clients or website visitors
  • A named person responsible for privacy compliance in your organization
  • Reasonable security safeguards appropriate to the sensitivity of the information you hold
  • A process for individuals to request access to their information and seek corrections
  • Retention and secure-disposal practices tied to identified business purposes
  • A documented breach response process — including assessment, records, escalation, reporting, and notification
  • Records of any breaches, even those you determine don't require reporting