You walk into the office one morning and nothing works. Your files are encrypted, and a message on the screen demands a ransom to get your data back. This scenario isn’t reserved for large corporations. Small and medium businesses in Quebec City, Trois-Rivieres, and across the province have become prime targets for ransomware gangs.
Here’s what you need to know about the threat, and more importantly, how to protect your business against it.
Quick answer: To protect a small business against ransomware, combine tested offline backups, multi-factor authentication, regular updates, EDR antivirus, and employee training. A recovery plan lets you get back up and running without paying the ransom.
1. What exactly is ransomware?
What this means for your business
Ransomware is malicious software that infiltrates your network, encrypts your files, and demands payment to restore access to your data.
What makes this threat especially dangerous in 2026 is the double extortion tactic used by most criminal groups: they encrypt your data AND steal it. If you refuse to pay, they threaten to publish or sell it.
- Data encryption: your files become inaccessible within minutes of the intrusion
- Data theft: customer information, financial data, and HR records are exfiltrated before encryption
- Time pressure: a countdown timer often appears to push you into a rushed decision
- Rapid spread: a single infected device can compromise the entire network within hours
Keep in mind: paying the ransom doesn’t guarantee you’ll get your data back. According to the Canadian Centre for Cyber Security, victims who pay don’t always recover all of their files.

2. Why small businesses in Quebec City and Trois-Rivieres are targeted
What this means for your business
You might assume cybercriminals mostly go after large corporations. That’s not the case. According to the National Cyber Threat Assessment 2025-2026 from the Canadian Centre for Cyber Security, businesses with fewer than 50 employees make up the majority of ransomware victims in Canada.
The reasons are straightforward:
- Fewer IT resources: small businesses rarely have a dedicated cybersecurity team
- Valuable data: customer information, financial records, health data, contracts
- Pressure to pay: a small business can’t afford to be shut down for weeks
- Automated attacks: AI tools let attackers target hundreds of small businesses at once
The hardest-hit sectors in Quebec include professional services (accountants, notaries, lawyers), medical and dental clinics, manufacturing companies, and engineering firms. Sectors well represented in both Quebec City and Trois-Rivieres.
According to the CCCS, ransomware incidents in Canada increased by an average of 26% per year between 2021 and 2024. The trend isn’t slowing down.
3. How an attack actually unfolds
What this means for your business
Understanding the stages of an attack means understanding where to stop it. Here’s how ransomware typically gets into a small business:
- Step 1: Phishing. An employee receives an email that looks legitimate and clicks a link or opens an attachment. This is the entry point in 60% of cases in Canada, according to the CCCS
- Step 2: Silent intrusion. The malware installs itself quietly and stays dormant for days or weeks while mapping your network
- Step 3: Privilege escalation. Attackers work to gain administrator access so they can reach your most important data
- Step 4: Exfiltration. Your data is copied and sent to external servers before the attack is triggered
- Step 5: Encryption. Within minutes, all accessible files are encrypted and the ransom note appears
The problem with unprotected backups: if your backups are connected to the same network, they get encrypted right along with your primary data. That’s why your backup strategy matters just as much as prevention.
4. Five concrete measures to protect your business
The good news: most successful attacks could have been prevented with basic measures applied properly. Here’s what the Canadian Centre for Cyber Security and Microsoft recommend.
- 1. Turn on multi-factor authentication (MFA) for every account: Microsoft confirms that MFA blocks 99.9% of account attacks. It’s the most effective measure and the easiest to roll out
- 2. Apply updates quickly: most intrusions exploit known vulnerabilities for which patches already exist
- 3. Train your employees to spot phishing: an alert employee is your first line of defense. Regular phishing simulations cut the risk significantly
- 4. Follow the 3-2-1 backup rule: 3 copies of your data, on 2 different types of storage, with 1 copy off site or in the cloud (Azure Backup, for example). Test your restores regularly
- 5. Deploy EDR (Endpoint Detection and Response): unlike traditional antivirus, EDR detects suspicious behavior in real time and can stop an attack before it spreads

5. What to do if you’re attacked
If you fall victim to ransomware, every minute counts. Here are the immediate actions recommended by the Canadian Centre for Cyber Security:
- Isolate right away: disconnect infected machines from the network (Wi-Fi and cable) to stop the spread
- Don’t shut down your servers: important forensic evidence can be lost. Contact an expert before taking action
- Don’t pay the ransom without consulting someone first: payment doesn’t guarantee you’ll recover your data, and it can expose you to legal consequences
- Report the incident: to the Canadian Centre for Cyber Security (cyber.gc.ca) and your local police
- Contact your cyber insurer: if you have coverage, activate it right away
Having a documented incident response plan in place before an attack happens makes a huge difference in how quickly you recover. It’s one of the things a vCIO or an IT partner like OKTO Solutions puts in place for you.

6. Not sure where you stand? Start here
The first step is an audit of your current security posture. This exercise quickly identifies your most critical vulnerabilities so you can address them in order of priority, without overhauling everything at once.
Small and medium businesses in Quebec City and Trois-Rivieres that work with OKTO Solutions get an assessment of their Microsoft 365 environment, their backup strategy, and their access controls. We identify what’s at risk and put together a concrete, realistic action plan.
Discover our cybersecurity services or contact us for a security posture assessment. It’s better to act before an attack forces the decision.
– Canadian Centre for Cyber Security: National Cyber Threat Assessment 2025-2026
– Canadian Centre for Cyber Security: Ransomware – How to prevent and recover (ITSAP.00.099)
– Microsoft Learn: Protecting against ransomware
– Canadian Centre for Cyber Security: Ransomware Threat Overview 2025-2027