Cyber Threats Outpace Corporate Spending at Canadian Firms, Survey Finds
A new survey suggests some Canadian companies are losing confidence in their cybersecurity budgets’ ability to handle the increasingly frequent and complex threats they face.
The Canadian Internet Registration Authority surveyed 503 people responsible for making cybersecurity decisions and found 76 per cent represented organizations that have increased their cybersecurity budgets over the past year.
Most organizations reported information technology budgets of at least $50,000, though several said they were even more well-capitalized with funding stretching beyond $100,000.
However, most organizations said only five to 15 per cent of those overall IT budgets were dedicated to cybersecurity.
Seventeen per cent thought that amount wasn’t sufficient to keep pace with the threats, sixteen per cent were unsure and one per cent refused to answer.
Sixty-seven per cent believed their cybersecurity budget was enough, which was down from 74 per cent last year.
“The survey reflects what we hear from organizations every day: cybersecurity challenges are increasing while resources are becoming harder to secure,” said Jon Ferguson, vice-president of cyber and domain name system at CIRA.
“Security teams are facing more threats, greater complexity and higher expectations, all amid economic and operational uncertainty.”
Over the last year, many Canadian schools have continued to grapple with a breach of education software they used, while the Hospital for Sick Children in Toronto and Winnipeg’s Health Sciences Centre each warned they had been targeted by cyber attackers.
The CIRA’s survey aimed to look at how organizations are responding to an evolving threat landscape, where artificial intelligence and vast troves of data bought and sold online are being weaponized.
The online survey conducted between June and July found four in ten organizations that were polled experienced a cyber attack in the past year.
Among those that experienced a ransomware attack, 75 per cent said they paid ransom demands. Organizations that paid a ransom typically forked over at least $25,000.
Cybersecurity experts often discourage companies from paying ransoms because they feel it incentivizes attackers to continue breaching organizations.
They instead encourage companies to beef up their security and better train staff to handle threats.
The CIRA survey found 87 per cent of participants had a response plan in place for cybersecurity incidents.
Eighty-two per cent pay for cybersecurity insurance, which is unchanged from last year but up from 59 per cent in 2021.
Two-thirds of organizations surveyed also said they have AI tools integrated into their workflows and operations, but more than eight in 10 cybersecurity decisionmakers are concerned about AI-based threats.
The survey also looked at sovereignty — a hot topic as the trade war rages on and Canada aims to protect its assets and partner with countries other than the U.S.
The CIRA found Canadian ownership and data residency have shifted from a preference to a requirement for many respondents.
Ninety-one per cent said it matters that cyber records are stored and processed in Canada and 89 per cent cared that vendors they partner with are Canadian-owned, headquartered or operating here.
Nearly seven in 10 prioritize data sovereignty over price when selecting a cybersecurity vendor, but four in 10 said they have at least reviewed U.S.-based or other foreign cybersecurity firms in the past year.
Cost and limited availability of Canadian vendors were the primary barriers to choosing a domestic cybersecurity vendor.
The Canadian Research Insights Council, an industry organization that promotes polling standards, says online surveys cannot be assigned a margin of error because they do not randomly sample the population.
This article was first reported by The Canadian Press
Tara Deschamps, The Canadian Press






