Plain-English guides on website security for Canadian small businesses — how to respond to a hack, WordPress security basics, and two-factor authentication.
Microsoft is retiring texted and phoned sign-in codes for business accounts, with the main cutoff on February 1, 2027. Why SMS codes lost the argument, and how to move your accounts to passkeys first.
Most businesses are not hacked through clever code, they are talked out of their passwords. How phishing, spear phishing, and business email compromise work, the tells to train on, and the defences that survive a bad day.
Most website malware is invisible to the owner and obvious to Google. How infected sites behave, how to confirm an infection, the safe way to clean one, and how to stop it coming back.
A web application firewall filters attacks before they reach your site; DDoS protection keeps you online when someone tries to flood you offline. What both do, why small sites are targeted, and how to get protected without overpaying.
Passkeys have crossed into the mainstream, with five billion in use. Here is what a passkey actually is, why it beats a password and a texted code, and how a Canadian small business can start using them.
HTTPS is now table-stakes. Here's what SSL certificates actually do, why every site needs HTTPS, the different certificate types, and how to set them up correctly.
A clear, step-by-step response plan for Canadian business owners — from spotting the signs and containing the damage, to your breach notification obligations under PIPEDA, and hardening after recovery.
A stolen password is enough to compromise a WordPress site. 2FA stops most credential-based attacks cold. Which method to use, which plugins are reliable, and how to avoid lockouts.