BadgerQuest
Play a roundWhy it sticksFor managersWho it's forLearnDocsPricingSign in
Who it is for

The same lesson, aimed at the risk your sector actually carries

A charity, a clinic and a managed service provider are attacked in different proportions, answer to different rules, and have very different amounts of room to absorb a bad day. These pages say what the evidence says about each, and cite it.

62% of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries. That figure is the reason any of this exists. What differs by sector is which part of it lands on you, and what somebody will later ask you to prove.

Every statistic on these pages names its publisher, its date and what it counts, and links to the source so you can check it. Where the best available data is from another country, we say so rather than implying it is Canadian.

Start free, no cardTalk to us

Pick the one closest to you

MSPs

One provider is a shorter path to many companies than many companies are

Security awareness training you can run across every client from one console, on one pool of seats and one invoice.

Read the evidence →
Small business

Attackers do not check your headcount first

Security awareness training that costs less than a coffee per person per month, with no seat minimum and nothing to install.

Read the evidence →
Non-profits

Phishing is not just one of the risks to your charity. It is very nearly all of them

Security awareness training that costs a few minutes a week, for organisations whose every dollar is accounted for to somebody.

Read the evidence →
Healthcare

In healthcare, security awareness training is not advice. It is the wording of the rule

A training programme for every member of the workforce, including management, which is exactly what the regulation asks for.

Read the evidence →
Schools & colleges

When something goes wrong at a school, it is almost always phishing

Security awareness training staff will actually finish, for institutions whose attack surface includes everyone who has ever had a login.

Read the evidence →
Card payments

If you take cards, phishing training is not optional

Retail, hospitality, clinics, charities taking donations: the same standard applies, and it names the topic by name.

Read the evidence →
Public sector

The sector where the most breaches involve a person, and an unusual share come from inside

Security awareness training for government departments, municipalities and public bodies, whose largest exposure is the sheer volume of correspondence they send.

Read the evidence →
Law firms

The scams that reach a law firm are the ones your insurer already catalogues

Wire redirection, changed banking details and lookalike senders, practised safely by your staff before the real one lands in an inbox.

Read the evidence →
Accounting firms

Your firm sits between clients and the CRA, which is exactly where the scams sit

CRA impersonation, changed banking details and tax-season lures, practised by your staff before the real one arrives.

Read the evidence →

Everything cited across these pages

12 sources carry every claim we make about who needs this. Two of them argue against parts of our own pitch, and we have kept them in.

  1. [1]Verizon Business. 2026 Data Breach Investigations Report, Executive Summary. https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.
  2. [2]CISA, NSA, FBI, NCSC-UK, ACSC, Canadian Centre for Cyber Security, NCSC-NZ. Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131aJoint Cybersecurity Advisory, last revised 11 May 2022. Now marked as archived content by CISA.
  3. [3]United States Code of Federal Regulations (eCFR). 45 CFR 164.308, Administrative safeguards, (a)(5) Security awareness and training. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308HIPAA Security Rule, quoted from the official codification. eCFR serves the currently effective text; read 5 August 2026.
  4. [4]PCI Security Standards Council. PCI DSS v4 self-assessment questionnaires, Requirement 12. https://blog.pcisecuritystandards.org/pci-dss-v4-whats-new-with-self-assessment-questionnairesWording quoted from the Council's own published material; read 5 August 2026. The standard itself sits behind a licence agreement we cannot link you through.
  5. [5]UK Department for Science, Innovation and Technology, and Home Office. Cyber security breaches survey 2025/2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026Official Statistic, published 30 April 2026. United Kingdom only.
  6. [6]UK Department for Science, Innovation and Technology, and Home Office. Cyber security breaches survey 2025/2026: education institutions findings. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026-education-institutions-findingsOfficial Statistic, published 30 April 2026. United Kingdom only.
  7. [7]Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice. https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.
  8. [8]FBI Internet Crime Complaint Center (IC3). 2025 IC3 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdfPublished 2026. 1,008,597 complaints and US$20.877 billion in reported losses for 2025. Figures count complaints the public filed with IC3, so they are self-reported, United States centred, and a floor rather than a total. Figures quoted here were read from the report PDF.
  9. [9]Competition Bureau Canada. Fraud Prevention Month to bring hidden crime into the spotlight. https://www.canada.ca/en/competition-bureau/news/2026/03/fraud-prevention-month-to-bring-hidden-crime-into-the-spotlight.htmlNews release, 6 March 2026. Loss figures are Canadian Anti-Fraud Centre data, and the release itself carries the caveat that only 5 to 10 per cent of frauds are reported.
  10. [10]LAWPRO (practicePRO). Current scams, cons, and swindles. https://www.practicepro.ca/2026/06/current-scams-cons-and-swindles/Ontario lawyers' professional liability insurer, last updated 26 June 2026. Case-pattern warnings rather than statistics: LAWPRO publishes no claim counts, which is why no number is quoted from it here.
  11. [11]Federation of Law Societies of Canada. Model Code of Professional Conduct, commentary to rule 3.1-2 (competence). https://flsc.ca/what-we-do/model-code-of-professional-conduct/interactive-model-code-of-professional-conduct/Commentary [4A] and [4B], quoted from the Federation's own published code; read 13 August 2026. Law societies adopt the Model Code province by province, so check your own society's code for the wording in force where you practise.
  12. [12]Chartered Professional Accountants of British Columbia (CPABC). 4 CRA-related scams to stay vigilant about this tax season. https://www.bccpa.ca/news-events/cpabc-newsroom/2024/april/4-cra-related-scams-to-stay-vigilant-about-this-tax-season/CPABC newsroom, 16 April 2024. Names the impersonation shapes in circulation rather than publishing totals.
BadgerQuest by CyberBadger
Who it's forLearnDocsAPIHelpCheck a certificatePrivacyTermsMade in Canada