By Bronte Bay CPA Professional Corporation · 9 min read
Short answer: A cyberattack on an incorporated Canadian business is not just an IT problem — it is a financial, legal, and CRA problem. Client financial data breached under PIPEDA must be reported to the Privacy Commissioner. A ransomware attack on your Xero file can halt bookkeeping, delay HST filings, and trigger CRA late penalties. A business email compromise attack that redirects a supplier payment is a direct cash loss with no insurance recovery if you did not follow proper controls. This guide covers the Canadian legal framework, 8 specific actions every incorporated business should take, and how to protect your financial data in Xero and Hubdoc.

Canadian incorporated businesses are targeted by cybercriminals for two specific reasons: they hold valuable financial data — client records, banking credentials, CRA account access, payroll information — and they typically have far fewer security resources than the large enterprises that employ dedicated IT security teams. The combination of high-value data and limited protection makes the incorporated professional services firm, the incorporated manufacturer, and the incorporated consultant a more attractive target than most owners realize.
The Canadian Centre for Cyber Security (CCCS) reported a significant increase in ransomware attacks on Canadian businesses in 2025, with professional services firms — accountants, lawyers, consultants, financial advisors — among the most targeted sectors. If your business holds client financial data, employee payroll records, or CRA access credentials, you hold data that has measurable value on the criminal market.
The Canadian Legal Framework — PIPEDA, Bill C-27, and Provincial Privacy Laws

Unlike the US and EU, where cybersecurity regulation varies by sector and geography, Canada has a single federal private-sector privacy law — PIPEDA (Personal Information Protection and Electronic Documents Act) — that applies to most incorporated Canadian businesses in the course of commercial activities.
What PIPEDA Requires of Incorporated Canadian Businesses
- Consent — obtain meaningful consent before collecting, using, or disclosing personal information
- Purpose limitation — use personal information only for the purpose for which it was collected
- Security safeguards — protect personal information with security measures appropriate to the sensitivity of the information
- Mandatory breach reporting — report breaches that create a real risk of significant harm to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible
- Breach record-keeping — maintain records of all breaches for a minimum of 24 months, regardless of whether they were reportable
Bill C-27 — The Coming Changes
Bill C-27, the Digital Charter Implementation Act, proposes to replace PIPEDA with the Consumer Privacy Protection Act (CPPA). If passed, the CPPA would significantly increase penalties for privacy violations — up to 5% of global revenue or $25 million, whichever is greater. The CPPA also introduces stronger consent requirements, a right to disposal of personal information, and new rights for automated decision-making. Incorporated Canadian businesses should monitor Bill C-27’s progress and ensure their privacy policies and security practices are scalable to CPPA requirements.
Provincial Privacy Laws
Three provinces have privacy laws deemed substantially similar to PIPEDA — meaning they apply instead of the federal law within those provinces: Quebec (Law 25 / Act 64), Alberta (PIPA), and British Columbia (PIPA BC). Quebec’s Law 25 is the most demanding — it came into full force in September 2023 and requires a Privacy Impact Assessment for any project involving personal information, mandatory appointment of a privacy officer, and strict breach notification timelines. If your incorporated business operates in Quebec or handles Quebec resident data, Law 25 compliance is not optional.
📋 CPA Note: PIPEDA compliance is not typically a CPA function — it requires a privacy lawyer. However, the financial implications of a breach are a CPA matter: breach response costs, regulatory fines, and reputational damage affecting revenue are all quantifiable. Bronte Bay identifies cybersecurity risk as part of the annual Virtual CFO review and ensures clients have appropriate cyber liability insurance — which requires documented security practices to obtain coverage.
8 Specific Cybersecurity Actions Every Incorporated Canadian Business Must Take

1. Enable Two-Factor Authentication on Every Business Account
Two-factor authentication (2FA) is the single most effective cybersecurity measure available to an incorporated business — and the most underused. Enable it immediately on: Xero, Hubdoc, CRA My Business Account, online banking, email (Microsoft 365 or Google Workspace), and any cloud software used to store client data. The Canadian Centre for Cyber Security estimates that 2FA prevents over 99% of automated credential attacks. Use an authenticator app (Microsoft Authenticator or Google Authenticator) rather than SMS-based 2FA where possible — SMS codes can be intercepted.
2. Use a Password Manager Across the Business
Weak and reused passwords are the most common entry point for corporate account takeovers. A password manager — 1Password, Bitwarden, or Dashlane Business — generates and stores unique, complex passwords for every account. It eliminates the practice of reusing passwords across platforms, which means a breach of one account does not cascade into a breach of all accounts. For an incorporated business with 2–10 employees sharing access to business systems, a business-tier password manager costs approximately $5–$8 per user per month and is a fully deductible corporate expense.
3. Train Every Employee to Recognize Phishing Emails
Phishing — emails designed to appear legitimate that trick recipients into clicking malicious links or providing login credentials — is the entry point for the majority of corporate cyberattacks in Canada. The most dangerous phishing emails in 2026 target: CRA correspondence (fake assessment notices or refund notices), financial institutions (fake banking security alerts), and business email compromise (emails appearing to come from the owner-manager requesting urgent wire transfers or payment detail changes). Train every employee — including the owner — to verify any unusual payment request or login link by calling the sender directly on a known number, never by replying to the email.
4. Implement Role-Based Access in Xero
Xero provides granular role-based access controls that most clients never configure. The principle: every user should have the minimum access required to perform their specific function. A bookkeeper does not need access to payroll. An accounts payable clerk does not need bank account details. An employee with read-only access cannot approve payments or modify bank account numbers. Bronte Bay configures Xero access controls for every new client — assigning specific roles and requiring 2FA on all accounts. If your Xero has multiple users all set to “Standard” or “Adviser” access, your access controls need immediate review.
5. Maintain Offsite Backups of Critical Business Data
Ransomware works by encrypting all data accessible from an infected device — including mapped network drives and connected cloud storage. The only protection is a recent backup stored in a location that is not accessible from the primary network at the time of the attack. For incorporated businesses using Xero, Hubdoc, and cloud software, most data is already backed up by the platforms themselves. The gap is typically: local files on employee computers, email archives, client contracts, and custom templates stored on shared drives. Back these up to an isolated, encrypted cloud location weekly. Verify the backup by restoring a test file quarterly.
6. Secure Your CRA My Business Account
Your CRA My Business Account contains your corporation’s complete tax history, HST account, payroll account, and authorized representative list. It is a high-value target — access to it allows a criminal to change banking information for tax refunds, file fraudulent returns, or remove your CPA’s authorization. Secure it immediately: enable 2FA on CRA My Account, review the list of authorized representatives (Level 1 and Level 2) and remove anyone who should no longer have access, and set up email and text notifications for any changes to your account. Do not access CRA My Account on public Wi-Fi or shared devices.
7. Get Cyber Liability Insurance
Standard commercial general liability (CGL) insurance does not cover cybersecurity incidents. A standalone cyber liability policy covers: breach response costs (forensic investigation, legal notification, credit monitoring for affected clients), business interruption during system restoration, ransom payments if you choose to pay, and third-party liability if client data is compromised. For most incorporated Canadian professional services firms, cyber liability coverage costs $1,500–$5,000 per year depending on revenue, data sensitivity, and existing security controls. Insurers increasingly require documented security practices — including 2FA, backup procedures, and employee training — as a condition of coverage. Insurers can deny claims if basic controls were not in place.
8. Create a Simple Incident Response Plan
An incident response plan does not need to be a 50-page document. For an incorporated business, it needs four things: (1) the name and phone number of your IT support contact, your CPA, and your cyber insurance provider; (2) the steps to immediately contain a breach — disconnect affected devices from the network, change passwords on all business accounts, contact your IT support; (3) the PIPEDA breach assessment process — who determines if the breach creates a real risk of significant harm and within what timeframe; and (4) a communication plan — who notifies affected clients and in what form. Write it down, store it somewhere accessible without an internet connection, and review it annually.
Protecting Your Financial Data in Xero and Hubdoc

Xero and Hubdoc contain the most financially sensitive data in most incorporated businesses — complete bank transaction history, all supplier invoices and payment details, client billing records, payroll data, and HST filings. Here is how Xero protects that data at the platform level, and what you must do at the user level:
Xero Platform Security
| Security Feature | What It Does |
|---|---|
| 256-bit AES encryption at rest | All data stored in Xero is encrypted — unreadable without the decryption key |
| TLS 1.2 encryption in transit | All data moving between your browser and Xero is encrypted |
| AWS data centers | SOC 1 and SOC 2 compliant — independently audited security controls |
| Two-factor authentication | Available for all users — required by Bronte Bay for all client accounts |
| Activity audit log | Every login, change, and export is logged — reviewable by the account owner |
| Role-based access controls | Adviser, Standard, Invoice Only, Read Only — assign minimum required access |
| Bank feed encryption | Bank connections use read-only access — Xero cannot initiate transfers |
What You Must Do at the User Level
- Enable 2FA on every Xero user account — go to Xero → My Xero → Profile → Security. Use an authenticator app, not SMS. Make it mandatory for every user who has access to your organization.
- Review and restrict user access roles — go to Xero → Settings → Users. Every user should have only the role required for their function. Remove former employees and contractors immediately — Xero user access does not expire automatically.
- Review connected apps — go to Xero → Settings → Connected Apps. Remove any app you no longer use. Every connected app has access to your Xero data under the permissions granted at connection.
- Monitor the Xero audit trail — available under Accounting → Reports → Audit Trail. Review monthly for any unexpected exports, user additions, or bank account changes.
- Never share your Xero login credentials — invite additional users through Xero → Settings → Users. Each person should have their own login so activity is traceable to an individual account.
Government Financing for Cybersecurity — BDC LIFT and CSBFP
Cybersecurity investment — endpoint protection software, identity management systems, secure backup infrastructure, staff training programs, and cyber liability insurance — is a legitimate business expense that can also be partially financed through government programs.
| Program | What It Covers | Who Qualifies |
|---|---|---|
| BDC LIFT | Repayable financing for cybersecurity, AI, digital transformation, ERP — up to $500M available | Incorporated businesses with at least $1M annual revenue and strong financials |
| Canada Small Business Financing Program (CSBFP) | Government-guaranteed loans up to $1.15M — covers eligible intangible assets including software | Incorporated businesses with under $10M annual revenue |
| SR&ED | 35% refundable tax credit on eligible R&D — if cybersecurity work involves technological advancement | CCPCs with qualifying R&D activity — rare for standard cybersecurity but possible for custom security development |
| CCCS Free Resources | Free cybersecurity guidance, assessment tools, and incident reporting — specifically for Canadian businesses | All Canadian businesses — no revenue requirement |
Cybersecurity software and services purchased for the corporation are fully deductible business expenses — reducing taxable corporate income at the 12.2% SBD rate (Ontario) or 11% (BC). Speak to Bronte Bay before making a significant cybersecurity investment to ensure it is structured correctly — deducted as an operating expense where possible, or capitalized under the correct CCA class where required.
What to Do If Your Incorporated Business Is Breached — The PIPEDA Response Process

If your incorporated business experiences a data breach — whether through ransomware, unauthorized access, or accidental disclosure — the following steps apply under PIPEDA:
- Contain immediately — disconnect affected devices from the network, change passwords on all business accounts starting with email, banking, Xero, and CRA My Account. Call your IT support.
- Determine what was compromised — identify which systems were accessed, what data was stored there, and which individuals’ personal information may have been exposed. Document everything.
- Assess the risk of harm — under PIPEDA, reporting is required if the breach creates a “real risk of significant harm” to affected individuals. This includes financial harm, identity theft, reputational damage, or physical harm. If in doubt, report.
- Report to the Office of the Privacy Commissioner (OPC) — submit a breach report to the OPC as soon as feasible after the determination that a real risk of significant harm exists. The report must describe: what happened, what personal information was involved, the number of individuals affected, and what steps you have taken to contain the breach.
- Notify affected individuals — directly and as soon as feasible — by the most effective means available (direct contact where possible, not just a website notice).
- Record the breach — regardless of whether the breach was reportable, maintain a record for a minimum of 24 months. The OPC can request your breach records at any time.
- Notify your cyber insurer — contact your cyber liability insurance provider immediately. Most policies have strict notification timelines — typically 24–72 hours after discovery. Missing the notification deadline can void coverage.
⚠️ CRA Account Warning: If your CRA My Business Account credentials are compromised, contact the CRA’s Business Enquiries line immediately at 1-800-959-5525. Ask them to place a fraud flag on your account, review recent activity for unauthorized filings or banking changes, and note the date and name of the CRA agent you spoke with. Your CPA can also take action as your authorized Level 2 representative.
Cybersecurity Quick Reference — Incorporated Canadian Business 2026
| Action | Cost | Time to Implement | Priority |
|---|---|---|---|
| Enable 2FA on all business accounts | Free | 30 minutes | 🔴 Do today |
| Deploy a password manager (all users) | $5–$8/user/month | 1 hour | 🔴 Do this week |
| Review Xero user access roles | Free | 30 minutes | 🔴 Do this week |
| Secure CRA My Business Account (2FA + representative review) | Free | 20 minutes | 🔴 Do this week |
| Phishing awareness training for all employees | $10–$30/user/month (KnowBe4, Proofpoint) | 1 week to deploy | 🟡 This month |
| Offsite backup verification | $10–$50/month (cloud backup) | 1 day to configure | 🟡 This month |
| Get cyber liability insurance | $1,500–$5,000/year | 1–2 weeks | 🟡 This quarter |
| Write a one-page incident response plan | Free | 2 hours | 🟡 This quarter |
Frequently Asked Questions
“Subhash is always able to advise us and share his insightful experience. He has an abundance of business experience and knowledge across industries and jurisdictions.”
— Managing Director, Lyra Marketing · Read full review on Clutch →
Is Your Business Financial Data Protected?
Bronte Bay configures Xero security controls, reviews CRA account access, and identifies cybersecurity risk as part of the annual Virtual CFO review for every incorporated client. Book a consultation to review your current financial data security position.
Toronto: 5000 Yonge Street, Suite 1901, North York, ON M2N 7E9 · Vancouver: 600-1285 West Broadway, BC V6H 3X8 · +1 416-439-4648
Related reading: Virtual CFO & Business Advisory · Bookkeeping for Incorporated Businesses · Early Warning Signs of Insolvency · Canadian Business Tax Deadlines 2026 · Smart Spending for Incorporated Businesses