A 12-person accounting firm in Edmonton starts Monday with a routine deadline. Instead, staff find the shared drive encrypted, a ransom note on every workstation, and a client engagement letter that must be signed that morning. The firewall is still powered on, the Wi-Fi password was changed recently, and the backup system reports that it completed its overnight job. None of that tells the owner whether the business can recover.
That scenario is uncomfortable because it reflects how small-business network security works now. The priority isn't only choosing stronger Wi-Fi encryption or installing antivirus once. It's controlling identities, remote access, edge devices, cloud accounts, permissions, backups, and the ongoing changes that create new gaps.
Canadian businesses still face material exposure. Statistics Canada's most recent national cyber survey found that 16% of businesses were impacted by cyber security incidents in 2023, compared with 21% in 2019 and 18% in 2021. Only 26% had written cybersecurity policies in 2023, while Canadian businesses spent $1.2 billion recovering from cybersecurity incidents, compared with $600 million in 2021. These figures are reported in Statistics Canada's Canadian cybersecurity reporting.
The practical answer is a prioritized, ongoing plan. You're not trying to build perfect security. You're trying to make it difficult to get in, limit how far an intruder can move, detect suspicious activity early, and restore the work that keeps your business operating.
Table of Contents
- Why Small Business Network Security Matters Right Now
- Harden the Perimeter and Wi-Fi the Right Way
- Patch Devices and Lock Down Endpoints
- Build Backups and Recovery You Can Trust
- Set Up Monitoring and Logging Without a SOC
- Plan Your Incident Response Before You Need It
- When Ongoing Local Support Makes Sense
Why Small Business Network Security Matters Right Now
The threats reaching small offices in 2026 aren't just the spray-and-pray viruses many owners remember from a decade ago. Attackers increasingly look for stolen credentials, exposed VPNs and firewalls, poorly protected cloud administration accounts, and remote-access tools that nobody reviews after installation. A forgotten camera, printer, or smart appliance can then provide another path into a flat office network.
CIRA's 2025 survey found that 24% of Canadian organizations suffered ransomware in the prior 12 months, and 74% of victims paid, typically $25,000 or more, according to Kapa Cyber's Canadian SMB cybersecurity statistics. The same Canadian coverage notes that attacks on small organizations rose from 259 in 2024 to 276 in 2025. Those numbers don't mean every Edmonton business faces the same risk, but they do show why “we're too small” isn't a security strategy.
A one-time firewall setup can't keep pace with staff turnover, firmware releases, new cloud applications, home devices, and changing remote-access requirements. A rule that was sensible when it was created can become an unnecessary opening later. An account that belonged to a contractor can remain active long after the project ends.
Technician's rule: You can't protect a network you haven't mapped, and you can't monitor a network that nobody owns.
Start with an honest first-day walkthrough
Treat the first visit as a technician's checklist, not a formal audit. Document the environment before changing it:
- Internet connections: Record every fibre, cable, cellular, or backup connection and identify which equipment handles failover.
- Edge equipment: Note the router and firewall manufacturer, model, firmware version, support status, and approximate firmware age.
- Wireless coverage: List every access point, SSID, staff network, guest network, and wireless bridge.
- Cloud services: Record Microsoft 365, Google Workspace, accounting platforms, file-sharing tools, point-of-sale systems, and other services that hold business data.
- Remote access: Identify VPNs, remote desktop tools, vendor portals, support agents, and who can connect from outside the office.
- Unmanaged devices: Ask about personal laptops, home computers, phones, tablets, cameras, smart TVs, printers, and other equipment connected to the business network.
- Backups: Locate the actual backup copies. Confirm whether they're connected, immutable, offline, encrypted, and restorable.
Inventory accounts as carefully as hardware. List global administrators, firewall administrators, cloud owners, shared logins, service accounts, vendor accounts, and former employee accounts. A network diagram that shows switches but omits who can change the firewall is incomplete.
Map how information moves
Follow a client file from arrival to storage, editing, sharing, backup, and deletion. Ask which users can reach it, which systems synchronize it, and whether a supplier or contractor can access it remotely. Data flow matters more than checking boxes because it shows where a compromised identity could move next.
Take photographs of the rack and equipment labels. Screenshot firewall rules before changing them. Write down which vendor logs in remotely, what they use, and who approved that access. Preserve the evidence in a dated assessment document, including unknowns and assumptions.
If you want a focused starting point, use Nerds 2 You's threat assessment service to document the current environment and prioritise practical fixes. The written assessment becomes the baseline for every later improvement. Honest notes now are cheaper than discovering during an outage that nobody knows where the backups, admin accounts, or remote-access controls are.

Harden the Perimeter and Wi-Fi the Right Way
Start at the internet edge. Replace default router and firewall administrator credentials, disable management from the public internet, turn off UPnP, and place a proper firewall in front of the internal network if the current router can't provide meaningful controls. Canadian government guidance recommends a firewall that monitors traffic and filters malicious sources, along with antivirus protection that detects known malware and suspicious behaviour. See the Canadian government's small-business cybersecurity guide for the baseline.
Wireless configuration should follow the same discipline:
- Use strong encryption: Choose WPA3 where the equipment supports it, or WPA2-Enterprise where identity-based access is practical.
- Separate staff and guests: Put employees on a staff SSID or VLAN, and place visitors on a guest network with no route to internal systems.
- Disable WPS: Convenience features can weaken control over who joins the network.
- Retire old settings: Remove default SSIDs, stale access points, and passwords reused across offices, homes, and vendors.
- Limit signal spill: Adjust transmit power so the network doesn't reach farther than the business needs.
DNS filtering adds a low-effort layer by blocking known malicious destinations before a user reaches them. It won't stop a compromised account or a brand-new threat, but it can prevent routine contact with dangerous domains. If a firewall rule needs to deny a known hostile address, this guide on how to block an IP address provides useful general context.
For Edmonton offices using centrally managed wireless equipment, Ubiquiti UniFi network support can help organise access points, SSIDs, VLANs, and monitoring in one environment. Verify the result by joining the guest network, confirming it receives internet access, and testing that it cannot reach printers, file servers, cameras, or administrative interfaces.
Patch Devices and Lock Down Endpoints
Patching is unglamorous, which is why it gets neglected. Enable automatic updates on Windows, macOS, mobile devices, browsers, productivity applications, and security tools, then verify monthly that updates have applied. A device that reports “automatic updates enabled” but has failed updates is still exposed.
Replace equipment that can no longer receive security updates. The practical mid-2026 deadline in this playbook is to replace devices still running Windows 7, Windows 8, or macOS 11, because those platforms no longer provide the security-patch foundation a business should depend on. For routers, switches, and firewalls, log in quarterly, review vendor advisories, and apply supported firmware. Put the current firmware version and date on a label attached to the device so the next technician can see its maintenance history immediately.

Make lost hardware and stolen credentials less useful
Standardise on one or two laptop brands where possible. Consistent hardware simplifies imaging, driver management, replacement, and troubleshooting. Enforce full-disk encryption, such as BitLocker or FileVault, and store the managed recovery key with the person responsible for IT, never on the laptop itself.
Require a password manager and MFA on every business account. Start with email, Microsoft 365, Google Workspace, VPNs, accounting platforms, and administrator accounts. Use phishing-resistant MFA for high-value access where the platform supports security keys or passkeys. A stolen password should not be enough to open the company's email or remote-access gateway.
Segmentation limits the damage when a contractor opens a malicious attachment or an employee enters credentials into a fake sign-in page. Put point-of-sale terminals, cameras, printers, voice systems, and guest Wi-Fi on separate VLANs. A compromised camera shouldn't be able to connect to accounting systems, and a visitor's phone shouldn't be able to browse internal shares.
Control permissions as tightly as devices
Every employee should use a unique account with MFA. Shared logins destroy accountability and make investigations harder because nobody can reliably connect an action to a person. Give users the minimum access needed for their role. A marketing assistant doesn't need payroll access, and an occasional administrator shouldn't receive global administrator rights in Microsoft 365 or Google Workspace.
Use role groups rather than handing out permanent elevated access. Disable accounts on the day an employee leaves, revoke sessions and VPN access, recover company equipment, and rotate shared secrets they knew. The purpose isn't to create a fortress that blocks work. It's to ensure that one bad decision stays confined to one device or account instead of becoming a company-wide crisis.
Build Backups and Recovery You Can Trust
Backups aren't measured by storage volume. They're measured by whether the business can resume work after ransomware, hardware failure, or accidental deletion. Use the 3-2-1 rule, three copies, two different media types, and one copy offline or immutable.
A practical small-office design combines a cloud backup service with versioning and a retention lock that ordinary users can't delete, plus an encrypted external SSD rotated to a safe location. Keep the encryption key separately. Ransomware can reach connected backup drives and synchronised cloud folders, so the isolated copy is the part that protects recovery.
Use Nerds 2 You's data backup solutions as a starting point when you need help selecting or organising a recovery approach.
Backup strategy comparison for small offices
| Approach | Ransomware Resilience | Recovery Speed | Cost |
|---|---|---|---|
| Connected external drive only | Low, because malware may reach it | Potentially quick if untouched | Lower |
| Cloud sync without protected versions | Low, because deletions can synchronise | Quick for ordinary file recovery | Ongoing |
| Versioned cloud backup | Stronger, if retention controls prevent deletion | Practical for files and supported systems | Ongoing |
| Offline or immutable copy combined with cloud backup | Strongest of these options | Depends on restore process and bandwidth | Higher |
| Manual copies with no restore testing | Unknown | Unknown | Variable |
Test a full restore every quarter. Document which server boots first, which credentials decrypt each copy, who contacts the provider, and what the business can operate without. Time the recovery and record the result. A backup you've never restored from is hope, not a recovery plan.
Set Up Monitoring and Logging Without a SOC
A five-to-fifty-person office doesn't need a security operations centre to gain useful visibility. It does need logging turned on, centralised, reviewed, and tied to a person who knows what action to take.
Enable logs on the firewall, router, DNS service, cloud identity platform, and important servers. Send those feeds to a hosted SIEM or an MSP-grade collector rather than leaving every record trapped on the device that generated it. Tools such as Wazuh can support collection and analysis, but the right choice depends on who will maintain the system and respond to alerts.
Watch for events that deserve attention
Don't alert on everything. Excessive noise trains people to ignore the dashboard. Start with events that indicate account takeover, privilege abuse, or data movement:
- Repeated authentication failures: Alert when failed logins exceed your agreed threshold over a short period, especially from an unfamiliar address or location.
- New administrative access: Alert when an administrator creates an account, receives increased permissions, or changes a privileged group.
- Unexpected geography: Flag outbound traffic, VPN access, or cloud sign-ins involving countries where your staff and suppliers don't operate.
- Unusual file-server transfers: Investigate a large or unusual transfer, especially outside normal working patterns or involving a user who doesn't normally handle that data.
- Security-control changes: Alert when someone disables endpoint protection, modifies firewall rules, or turns off logging.
Each alert needs a named owner and a written response. “Investigate” isn't a response. Specify who checks the account, who isolates the device, who contacts management, and what evidence must be preserved.
Useful monitoring is boring until it matters. A short list of actionable alerts beats a colourful dashboard nobody opens.
Review the system and make the policy visible
Review important logs weekly. Check quarterly that the firewall, router, DNS service, cloud platforms, and servers are still writing logs and that the collector is receiving them. Keep at least 30 days of hot logs and 12 months of cold logs when your systems and budget can support that retention model. These are operational targets, not guarantees that every incident can be reconstructed.
Policies should be short enough for employees to use. Write a one-page acceptable-use policy, password and MFA rules, a bring-your-own-device statement, and a remote-work checklist for laptops used at home or in cafés. Store them where employees work, not only in an HR folder.
Require signed annual acknowledgements, post reminders in kitchens and meeting rooms, and reserve a five-minute monthly slot for one topic, such as suspicious invoices or fake support calls. Run a phishing simulation at roughly one test per employee per month, using coaching rather than humiliation for anyone who clicks. Include MFA enrolment and the reporting process in day-one onboarding.
Name one human owner for each policy. Committees rarely update documents when a vendor changes a login process or an employee starts working remotely.

Plan Your Incident Response Before You Need It
The first hour should not depend on memory. Post a printed runbook beside the network equipment and keep an offline copy with emergency contacts.
- Isolate the device: Disconnect the affected computer from wired and wireless networks, but don't power it off if you can avoid it.
- Preserve evidence: Photograph the screen, note the time, leave open sessions intact, and don't log in, reboot, or start deleting files.
- Call the technical contact: Contact your pre-vetted IT provider, incident responder, or internal technical lead.
- Protect accounts: Change credentials for accounts touched by the incident, following technical advice so you don't destroy useful evidence.
- Control communication: The incident lead decides what staff, clients, insurers, banks, and vendors need to know.
Assign an incident lead, communications lead, legal contact, and notetaker. The notetaker records times, decisions, screenshots, phone calls, and actions. Keep the insurer's breach hotline, cyber-fraud contact, legal adviser, IT contact, and Canadian Anti-Fraud Centre details on the same card.
For a breach involving personal information, CFIB explains that a Canadian business facing a data breach caused by cybercrime that could cause significant harm must report it to the Office of the Privacy Commissioner, notify affected individuals, and keep a record of the breach. Review CFIB's guidance on protecting a small business from cybercrime and obtain legal advice for obligations under PIPEDA and any sector-specific Alberta requirements, including rules affecting health or education data.
After containment, hold a blameless review. Record what happened, which control failed, what evidence was available, what delayed the response, and who owns each correction. Recheck those actions over the following 60 days, including access rights, edge-device patches, restore testing, MFA coverage, and policy updates.

When Ongoing Local Support Makes Sense
A one-time setup is useful, but it decays. Staff leave, vendors add remote tools, firmware ages, cloud permissions expand, and backups fail. Ongoing support and network monitoring keep the baseline alive instead of leaving the owner to discover a problem during a Monday outage.
For a small business, ongoing help makes particular sense when you have roughly 10 or more endpoints, regulatory or sensitive data, remote staff who need reliable access, or no internal person who can respond when a firewall alert appears. The decision isn't about buying the largest service package. It's about comparing the cost of one day offline with the recurring cost of keeping controls maintained.
Look for a partner that can provide:
- Documented reviews: Quarterly reviews should cover devices, firmware, admin accounts, remote access, backups, and unresolved risks.
- Patch confirmation: You should receive evidence that updates applied, not a general statement that patching is included.
- Response targets: The agreement should define who responds, during which hours, and what qualifies as an emergency.
- Visible records: You should be able to see relevant logs, asset lists, firewall changes, and incident notes.
- Clear scope: Break-fix repairs and the security baseline should be listed separately, so you know what ongoing support covers.
A vague monthly invoice, proprietary tools you can't inspect, or reluctance to share logs are warning signs. Full MSP services may suit a business that wants to outsource most IT decisions. Co-managed support may fit an owner with an internal administrator who needs specialised network monitoring and escalation. Match the arrangement to your risk tolerance and in-house capability.
When assessing a technical partner, a case study for IT security hiring can help illustrate the difference between a defined security role and a collection of loosely assigned tasks. Ask direct questions about documentation, ownership, access to records, and what happens after the initial configuration.
Nerds 2 You doesn't provide remote services or full MSP services, but it does provide ongoing support and network monitoring for small and medium businesses. Nerds 2 You handles most major hardware repairs on site, but it doesn't provide board-level repairs, so confirm that the support scope matches your equipment and operational needs.
Nerds 2 You Edmonton provides on-site network setup, wired and wireless configuration, guest Wi-Fi, hardware troubleshooting, backup guidance, and ongoing support for Edmonton homes and businesses. To turn this playbook into a documented plan, visit Nerds 2 You Edmonton, arrange an on-site review, and ask for clear priorities for identity, edge devices, segmentation, monitoring, and recovery testing.
Contact Nerds 2 You for quality professional service
Experience the difference with our dedicated team of experts ready to assist you. Whether you need immediate support or have questions about our services, we are here to help. Reach out today and let us provide you with the reliable service you deserve. Your satisfaction is our priority and we guarantee a prompt response to all inquiries.
