The same lesson, aimed at the risk your sector actually carries
A charity, a clinic and a managed service provider are attacked in different proportions, answer to different rules, and have very different amounts of room to absorb a bad day. These pages say what the evidence says about each, and cite it.
62% of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries. That figure is the reason any of this exists. What differs by sector is which part of it lands on you, and what somebody will later ask you to prove.
Every statistic on these pages names its publisher, its date and what it counts, and links to the source so you can check it. Where the best available data is from another country, we say so rather than implying it is Canadian.
Pick the one closest to you
One provider is a shorter path to many companies than many companies are
Security awareness training you can run across every client from one console, on one pool of seats and one invoice.
Read the evidence →Small businessAttackers do not check your headcount first
Security awareness training that costs less than a coffee per person per month, with no seat minimum and nothing to install.
Read the evidence →Non-profitsPhishing is not just one of the risks to your charity. It is very nearly all of them
Security awareness training that costs a few minutes a week, for organisations whose every dollar is accounted for to somebody.
Read the evidence →HealthcareIn healthcare, security awareness training is not advice. It is the wording of the rule
A training programme for every member of the workforce, including management, which is exactly what the regulation asks for.
Read the evidence →Schools & collegesWhen something goes wrong at a school, it is almost always phishing
Security awareness training staff will actually finish, for institutions whose attack surface includes everyone who has ever had a login.
Read the evidence →Card paymentsIf you take cards, phishing training is not optional
Retail, hospitality, clinics, charities taking donations: the same standard applies, and it names the topic by name.
Read the evidence →Public sectorThe sector where the most breaches involve a person, and an unusual share come from inside
Security awareness training for government departments, municipalities and public bodies, whose largest exposure is the sheer volume of correspondence they send.
Read the evidence →Law firmsThe scams that reach a law firm are the ones your insurer already catalogues
Wire redirection, changed banking details and lookalike senders, practised safely by your staff before the real one lands in an inbox.
Read the evidence →Accounting firmsYour firm sits between clients and the CRA, which is exactly where the scams sit
CRA impersonation, changed banking details and tax-season lures, practised by your staff before the real one arrives.
Read the evidence →Everything cited across these pages
12 sources carry every claim we make about who needs this. Two of them argue against parts of our own pitch, and we have kept them in.
- Verizon Business. 2026 Data Breach Investigations Report, Executive Summary. https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.
- CISA, NSA, FBI, NCSC-UK, ACSC, Canadian Centre for Cyber Security, NCSC-NZ. Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131aJoint Cybersecurity Advisory, last revised 11 May 2022. Now marked as archived content by CISA.
- United States Code of Federal Regulations (eCFR). 45 CFR 164.308, Administrative safeguards, (a)(5) Security awareness and training. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308HIPAA Security Rule, quoted from the official codification. eCFR serves the currently effective text; read 5 August 2026.
- PCI Security Standards Council. PCI DSS v4 self-assessment questionnaires, Requirement 12. https://blog.pcisecuritystandards.org/pci-dss-v4-whats-new-with-self-assessment-questionnairesWording quoted from the Council's own published material; read 5 August 2026. The standard itself sits behind a licence agreement we cannot link you through.
- UK Department for Science, Innovation and Technology, and Home Office. Cyber security breaches survey 2025/2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026Official Statistic, published 30 April 2026. United Kingdom only.
- UK Department for Science, Innovation and Technology, and Home Office. Cyber security breaches survey 2025/2026: education institutions findings. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026-education-institutions-findingsOfficial Statistic, published 30 April 2026. United Kingdom only.
- Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice. https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.
- FBI Internet Crime Complaint Center (IC3). 2025 IC3 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdfPublished 2026. 1,008,597 complaints and US$20.877 billion in reported losses for 2025. Figures count complaints the public filed with IC3, so they are self-reported, United States centred, and a floor rather than a total. Figures quoted here were read from the report PDF.
- Competition Bureau Canada. Fraud Prevention Month to bring hidden crime into the spotlight. https://www.canada.ca/en/competition-bureau/news/2026/03/fraud-prevention-month-to-bring-hidden-crime-into-the-spotlight.htmlNews release, 6 March 2026. Loss figures are Canadian Anti-Fraud Centre data, and the release itself carries the caveat that only 5 to 10 per cent of frauds are reported.
- LAWPRO (practicePRO). Current scams, cons, and swindles. https://www.practicepro.ca/2026/06/current-scams-cons-and-swindles/Ontario lawyers' professional liability insurer, last updated 26 June 2026. Case-pattern warnings rather than statistics: LAWPRO publishes no claim counts, which is why no number is quoted from it here.
- Federation of Law Societies of Canada. Model Code of Professional Conduct, commentary to rule 3.1-2 (competence). https://flsc.ca/what-we-do/model-code-of-professional-conduct/interactive-model-code-of-professional-conduct/Commentary [4A] and [4B], quoted from the Federation's own published code; read 13 August 2026. Law societies adopt the Model Code province by province, so check your own society's code for the wording in force where you practise.
- Chartered Professional Accountants of British Columbia (CPABC). 4 CRA-related scams to stay vigilant about this tax season. https://www.bccpa.ca/news-events/cpabc-newsroom/2024/april/4-cra-related-scams-to-stay-vigilant-about-this-tax-season/CPABC newsroom, 16 April 2024. Names the impersonation shapes in circulation rather than publishing totals.