11 min read
Cyber Security Awareness Month 2026: A Four-Week Playbook for Canadian SMBs
Adrian Ghira
:
September 3, 2026
Every year in late September, a familiar email goes out at thousands of Canadian businesses. It has a phishing infographic attached, a subject line about October being Cyber Security Awareness Month, and a closing line asking everyone to stay vigilant. It is opened by about a third of the staff, read by fewer, and remembered by nobody. The following October, the same email goes out again.
We are not being cynical about the intent. The intent is good. The problem is that awareness delivered as a broadcast does not change behaviour, and behaviour is the entire point. When we audit client environments after a year of that approach, we find the same pattern: the same three or four people click every simulated phishing email, nobody in the finance function has ever practised verifying a banking change request out loud, and the leadership team has never sat through the training it approved for everyone else.
October is Cyber Month in Canada, coordinated by the Communications Security Establishment through its Get Cyber Safe campaign. For a business with 20 to 200 users, it is the single best window in the year to run a security program that people will actually pay attention to, because the calendar gives you a reason to talk about it that does not feel like a reaction to something going wrong.
This playbook is what we run with clients. It is structured across the four weeks of October, it can be delivered entirely with internal resources, and it does not require a new licence or a new vendor. If you already have a training platform, it will make better use of it. If you do not, you can still run all four weeks.
There is also a business reason to take this seriously in 2026 that has nothing to do with security posture. Canadian cyber insurance underwriters have moved security awareness training from a soft recommendation to a line item on the application. Several carriers now ask for the name of your training platform and the results of your most recent phishing simulation. An absent or undocumented program can produce a premium increase or, more damaging, a social engineering exclusion, which removes coverage for precisely the attack type most likely to hit a business of your size. If you have been looking for a way to justify the time, your renewal date is it.
Why Most SMB Awareness Programs Fail
Before the playbook, it is worth naming the specific failure modes, because most programs contain at least two of them.
They measure attendance instead of behaviour. A completion rate of 100% on an annual training module tells you that people clicked through a video. It tells you nothing about whether they would report a suspicious email or verify a payment change. Completion is an administrative metric that has been mistaken for a security metric.
There is no follow-up path. In most organizations, a person who fails a phishing simulation receives an automated notice and nothing else. The people who most need help get the least. A program without a remediation path for repeat clickers is not a program; it is a measurement exercise.
Leadership exempts itself. Executives are the highest-value targets in the company and frequently the least trained. When the leadership team is excluded from simulations, either formally or through quiet intervention, the entire staff notices, and the program is understood as something done to employees rather than something the company does.
The finance function is trained generically. Everyone gets the same phishing content, when the specific attack that costs Canadian SMBs the most money is a fraudulent payment or banking change request aimed at two or three people in the finance function. Generic training does not prepare those people for the actual scenario they will face.
It happens once a year. Behaviour built in one session in October has decayed by February. Attackers do not run an annual campaign.
The playbook below is designed to address each of these directly.
Before October: Three Things to Set Up in September
Establish a baseline. Run one phishing simulation in September, before any training. Do not announce it. You need to know where you actually stand, and you need a number to compare against in November. Record two figures: the click rate and, more importantly, the report rate. If you have no simulation platform, a carefully constructed internal test coordinated with your IT provider will do for a baseline.
Get leadership committed in writing. Not approval. Commitment. The leadership team participates in the simulations, attends the same sessions, and one executive opens the first week. A single sentence from the owner or CEO at the start of October is worth more than an hour of content from anyone else.
Plan the communication, not just the content. Decide who sends each week’s material, on what day, through which channel, and how long each activity takes. Fifteen minutes a week that actually happens beats a two-hour session that gets rescheduled twice and then cancelled.
Week 1: Accounts and Identity
The first week covers the layer where most compromises begin.
Passphrases and password managers. The message worth landing is not complexity rules, which people work around, but reuse. A password reused across a personal shopping account and a work login is the single most common route into a business account, because the shopping site is the one that gets breached. Deploy or promote a password manager during this week if you have one; if you do not, this is the week to make the business case.
Multi-factor authentication that resists phishing. Most staff now have MFA on their work account and believe that settles the matter. It does not. Attacker-in-the-middle phishing kits routinely defeat SMS codes and basic app approvals by relaying the code in real time. The practical message for staff is about approval fatigue: an authentication prompt you did not initiate is an incident, not an inconvenience, and it needs to be reported rather than dismissed. On the technical side, this is the week to review whether your organization is on number matching, passkeys, or hardware tokens for privileged and finance accounts. Insurers are asking.
Credential stuffing, explained from the user’s side. Staff do not need the term. They need to understand why a login attempt on their account from another country at 3 a.m. is a normal Tuesday for attackers, and why that is not a reason to panic but is a reason to report.
The personal and work crossover. Signing into work email on a personal device, using a work address for personal services, storing work documents in a personal cloud account. Name these plainly and give people the sanctioned alternative rather than only a prohibition.
Week 2: Devices and the Physical Layer
Updates and deferred restarts. The most common technical gap we find in SMB environments is not missing patch management. It is patch management that reports success while a meaningful number of endpoints have deferred the restart that completes the update. The staff-facing message is simple: the update is not applied until the machine restarts. Give people a predictable window when restarts are expected.
Mobile devices and bring your own device. Which devices are allowed to access company email and files, what happens to company data if the device is lost or the employee leaves, and what the organization can and cannot see on a personal phone. The last point matters more than most employers realize. Uncertainty about employer visibility is the main reason staff resist mobile device management, and clarity resolves most of it.
Removable media and physical access. Less relevant than it was, still relevant in manufacturing, healthcare, and field environments. Cover it briefly and move on.
Home and hybrid network hygiene. Router firmware, default admin credentials, and separating work devices from the smart home equipment sharing the same network.
Lost device reporting without punishment. This is the week to make explicit that reporting a lost laptop or phone within the hour is the expected behaviour and will not result in blame. Organizations that punish the report get delayed reports, and the delay is where the damage happens.
Week 3: Phishing and Payment Fraud
This is the week that matters most, and it needs two separate tracks.
The all-staff track: a simulation that teaches rather than humiliates. The design principles we use: simulate a scenario that plausibly targets your business rather than a generic prize notification; deliver the teaching moment immediately on click, in a tone that assumes competence rather than carelessness; never publish or circulate the names of people who clicked; and celebrate reports rather than only tracking clicks. A rising report rate is a better indicator of a healthy program than a falling click rate, because reporting is an active behaviour and not clicking can simply mean not reading.
The finance track: the payment verification drill. Set aside 30 minutes with the two to five people who can move money or change vendor banking details. Walk through the actual scenario: an email arrives from a known supplier, on a thread that already exists, advising that banking details have changed for this month’s payment. Then practise the response out loud. Call the supplier on the number you already have on file, not the number in the email. Speak to a person you have spoken to before. Document the verification. Do this as a live exercise, not as a policy document, because under deadline pressure people fall back on what they have practised rather than what they have read.
Invoice and vendor change fraud patterns. Attackers rarely invent a fake supplier. They insert themselves into a real thread with a real supplier, often after compromising the supplier’s mailbox rather than yours. Staff should understand that the message being genuinely from the supplier’s address does not make the instruction genuine.
Voice and video impersonation. Synthetic voice requests are no longer an enterprise-only problem. The defence is procedural rather than perceptual: an urgent request to move money, arriving by voice, from an executive, gets verified through a second channel regardless of how convincing it sounds. Tell your staff that the CEO will never be annoyed at being called back. Then make sure that is true.
Week 4: Habits That Outlast October
The reporting path. Every employee should be able to answer one question without looking it up: what do I do when something looks wrong? One route, one button or address, and a response that thanks them whether or not the report was a real threat.
A leadership tabletop. Ninety minutes with the leadership team walking through a ransomware scenario. Not a technical exercise. Who decides to shut systems down. Who talks to clients. Who calls the insurer, and do you know the number. What you say publicly on day one. Most SMB leadership teams discover during this session that three or four decisions nobody owns.
Convert October into a cadence. The most valuable output of Cyber Month is a schedule for the rest of the year: a simulation each quarter, a short module for new hires during onboarding, one finance drill every six months, and an annual tabletop. Put the dates in the calendar before October ends, because they will not be added in November.
The 30-Minute Leadership Session
Run this in the first week. Cover four things: the specific attack types most likely to hit a business of your size and sector, the two or three controls that would prevent most of them, what your cyber insurance actually requires of you, and the decisions leadership would need to make in the first hour of an incident.
The purpose is not to train executives on phishing. It is to make the rest of the month land. When staff see that leadership went first and is participating in the same simulations, uptake changes measurably. When they see leadership exempted, no amount of content compensates.
What to Measure
Report rate. The percentage of recipients who reported the simulated phishing message. This is your primary metric. It is an active behaviour, it is unambiguous, and it improves with a functioning program.
Time to first report. How long between delivery and the first report. In a healthy organization this drops to minutes, which is the difference between containing an incident and investigating one.
Repeat clicker trend. Not a list of names. A count, tracked quarterly, of people who clicked in consecutive simulations. If that count is not falling, your remediation path is not working.
Click rate. Useful, but secondary and easy to misread. A low click rate on an easy simulation means nothing.
Metrics to ignore: training completion percentage, hours of training delivered, and any single-month click rate presented without a trend.
Using the Free Get Cyber Safe Resources Well
Get Cyber Safe is the Government of Canada’s public awareness campaign, led by the Communications Security Establishment with guidance from the Canadian Centre for Cyber Security. It publishes free Cyber Month material each year: weekly themes, social assets, banners, and templates, along with generic resources for organizations that would rather not follow the annual theme. Organizations can also register as champions.
Two practical notes. First, the annual theme is usually announced in late September, so build your program to work without it and layer the theme in once it is published. Second, the material is written for a general Canadian audience, which means it needs a layer of your own context to work internally. Pair each government-produced asset with one specific sentence about your business: the systems you actually use, the suppliers you actually pay, the client data you actually hold. That single sentence is what makes it feel relevant rather than institutional.
What This Looks Like at a 60-Person Company
To make it concrete, here is the total time cost of the full playbook for a 60-person business: one baseline simulation in September, roughly two hours of coordination; a 30-minute leadership session in week one; four weekly staff communications at fifteen minutes of reading each; one 30-minute finance drill in week three; one 90-minute leadership tabletop in week four; and roughly three hours of administration across the month.
That is under two hours per employee for the year, plus about six hours of management time. It produces a documented program, a measurable baseline and improvement, an evidence package for your insurer, and a leadership team that has rehearsed the decisions it would otherwise make badly under pressure.
GAM Tech Differentiators: Security Awareness for Canadian SMBs
GAM Tech has supported Canadian businesses with 20 to 200 users since 2012, from nine markets across Alberta, British Columbia, Ontario, and Quebec, with bilingual support in Ottawa and Montreal.
On awareness programs specifically, our managed engagement covers phishing simulation platform management and campaign design tailored to your sector, live role-based training rather than generic video modules, the finance-specific payment verification drill delivered as a facilitated exercise, quarterly reporting formatted for a board or an insurance application, and the remediation path for repeat clickers that most programs never build.
We are SOC2 certified, B Corp certified, and our support team is internal and never outsourced, with a 5-minute response commitment delivered on 99%+ of tickets. Project packs are included in our managed services agreement, so the policy and program work described in this article is not a separate scoping exercise every time.
Our pricing is straightforward: Silver plans start at $110 per managed device per month with a $1,000 monthly minimum. Gold plans add the layered cybersecurity stack, including managed awareness training and simulation.
Frequently Asked Questions
How often should employees receive security awareness training? Quarterly is the practical standard for a Canadian SMB, with a short module during onboarding for new hires and one focused finance drill every six months. Annual-only training decays well before the year is out and is increasingly treated as insufficient by cyber insurance underwriters.
Do phishing simulations actually work? Yes, when they are designed to teach and paired with a remediation path. Report rates rise measurably within two or three campaigns. Simulations run purely to generate a click statistic, with no follow-up and no teaching moment, produce resentment and very little behaviour change.
What should we do about an employee who keeps failing simulations? Treat it as a training gap rather than a discipline matter, at least initially. A short one-on-one session is far more effective than an escalating series of automated notices. If the pattern persists after direct coaching, and the person holds access to financial systems or sensitive data, then it becomes an access question rather than a training question.
Is annual training enough for cyber insurance? Increasingly, no. Carriers are asking for the platform name, the training frequency, and recent simulation results. Documented quarterly activity is a stronger position than an annual completion certificate.
How much does security awareness training cost for a Canadian SMB? Platform licensing for simulation and training typically runs a few dollars per user per month. The larger cost is the coordination and follow-up, which is where most self-managed programs quietly stop. For GAM Tech clients, managed awareness training is included in Gold plans.
What is Cyber Month and do we have to participate? October is Cyber Security Awareness Month in Canada, coordinated by the Communications Security Establishment through Get Cyber Safe. There is no obligation to participate. The reason to do it is practical: the calendar provides a reason to talk about security that is not a reaction to an incident, and the free material lowers the effort.
Should leadership be included in phishing simulations? Yes, without exception. Executives are the highest-value targets in the organization, and excluding them undermines the credibility of the entire program with staff.
What is the single highest-value training topic for a small business? Payment and banking change verification, delivered to the specific people who can move money. Business email compromise produces the largest direct financial losses for Canadian SMBs, and the control that stops it is a phone call to a known number.
How do we train volunteers and contractors? Include them, scoped to their access. Anyone with a login to your systems is part of your attack surface, and volunteers and contractors are frequently excluded from training while retaining access long after their engagement ends.
How do we know whether the training is working? Track report rate, time to first report, and the quarterly trend in repeat clickers. If report rate is rising and repeat clickers are falling, the program is working. Completion percentages tell you nothing.
Can we run this ourselves or do we need a provider? The playbook in this article is designed to be run internally, and many businesses do. A provider adds value in three places: simulation design and platform management, the facilitated finance drill and leadership tabletop, and the reporting that supports insurance applications and board oversight.
Make October Count This Year
You get one month a year where security has the organization’s attention without an incident forcing it. Four weeks, structured, with leadership going first and a measurement baseline set in September, produces a different company than a forwarded infographic does.
If you would like help running it, or you want to see how your current program would look to an underwriter, GAM Tech offers a security awareness assessment across all nine of our Canadian markets. Contact us to arrange one before October.