1 of 18

2 of 18

Cybersecurity Expert:

  • Electrical Engineering Diploma - University of Ottawa, Canada
  • Master in Information Security - Lulea University of Technology, Sweden
  • Current Role: Enterprise Architect in Montreal

Passion: Cybersecurity

  • Current Study: Ph.D. student in IT Security at Polytechnique Montreal

Cristian Bucur Background

3 of 18

WHY DO WE NEED CYBERSECURITY

  • The main goal of Cybersecurity is to protect your business.
  • There are many potential threats, from outside but also from inside.
  • A cybersecurity incident can be extremely expensive for a small business.
  • Small businesses are targets.

?

4 of 18

SOME STATS

5 of 18

COMMON CYBERSECURITY THREATS�

  • Phishing attacks: Emails or text messages that try to trick you into clicking on a malicious link or opening an attachment.
  • Malware: Malicious software that can damage your computer system or steal your data.
  • Ransomware: A type of malware that encrypts your data and demands a ransom payment to decrypt it.
  • Denial-of-service (DoS) attacks: Attacks that flood your website or network with traffic, making it unavailable to legitimate users.

?

6 of 18

PROTECT YOUR DATA

  • Regularly back up your data to a secure location.
  • There are two main types of data backups: full backups and incremental backups.
  • Full backups back up all of your data, while incremental backups only back up the data that has changed since the last full backup.

?

7 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • A small physiotherapy clinic with five employees, uses Electronic Medical Record (EMR) or Electronic Health Record (EHR) to manage patient information.
  • This EPR system stores sensitive data such as names, addresses, diagnoses, and treatment plans.
  • What steps needs this company to take in order to protect its data.

?

8 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • Strong Passwords & Multi-Factor Authentication (MFA):
  • Enforce a policy requiring employees to use strong, unique passwords for all accounts, exceeding 12 characters with a mix of upper and lowercase letters, numbers, and symbols.
  • Implement MFA for all logins to the EPR system, adding an extra layer of security beyond just a password. This could involve a code sent via text message or a security token.

?

9 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • Software Updates & Security Software:
  • Ensure all devices used at the clinic, including computers, tablets, and smartphones, have the latest operating system and software updates installed. These updates often include security patches that fix vulnerabilities.
  • Install and maintain reputable antivirus and anti-malware software on all devices to detect and prevent malicious software infections.

?

10 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • Strong Passwords & Multi-Factor Authentication (MFA):
  • Enforce a policy requiring employees to use strong, unique passwords for all accounts, exceeding 12 characters with a mix of upper and lowercase letters, numbers, and symbols.
  • Implement MFA for all logins to the EPR system, adding an extra layer of security beyond just a password. This could involve a code sent via text message or a security token.

?

11 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • Data Backups & Encryption:
  • Regularly back up patient data to a secure offsite location, such as a cloud storage service with strong encryption. This ensures data recovery in case of a cyberattack or hardware failure.
  • Consider encrypting patient data at rest and in transit. Encryption scrambles the data, making it unreadable even if intercepted by a cybercriminal.

?

12 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • Employee Training:
  • Train all employees on cybersecurity best practices, including identifying phishing emails, creating strong passwords, and avoiding suspicious links and attachments.
  • Educate them about the importance of data privacy and patient confidentiality.

?

13 of 18

USE CASE: PHYSIOTHERAPY CLINIC

  • Incident Response Plan:
  • Develop a plan for responding to a cyberattack. This plan should outline steps to take in case of a data breach, such as notifying patients, law enforcement, and relevant authorities.

?

14 of 18

BEST PRACTICES FOR CYBERSECURITY��

  • Implement a strong password policy and require employees to use multi-factor authentication.
  • Install and keep antivirus and anti-malware software up to date.
  • Regularly back up your data and store it offsite.
  • Secure your Wi-Fi network with a strong password and encryption.
  • Educate your employees about cybersecurity threats and best practices.
  • Have a plan for incident response in case of a cyberattack.

?

15 of 18

WHAT IS BILL C-27

  • Three Proposed Acts: The bill proposed to enact three new pieces of legislation:
  • Consumer Privacy Protection Act (CPPA): This act would give Canadians more control over how their personal information is collected, used, and disclosed by organizations.
  • Personal Information and Data Protection Tribunal Act (Tribunal Act): This act would establish a new tribunal to hear and decide on matters related to access to and correction of personal information.
  • Artificial Intelligence and Data Act (AI Act): This act would set out rules for the development, use, and oversight of artificial intelligence systems in Canada.
  • Current Status: It's important to note that Bill C-27 did not pass and is no longer under consideration in its current form.

?

16 of 18

BILL 25 IN QUEBEC – LA LOI 25

  • Key Aspects: It introduces new requirements for organizations that handle personal information of Quebec residents. These requirements include:
  • Enhanced Transparency: Organizations must be more transparent about how they collect, use, and disclose personal information.
  • Stronger Consent: Individuals have greater control over their personal information and can withdraw consent at any time.
  • Increased Security Measures: Organizations are obligated to implement appropriate safeguards to protect personal information from unauthorized access, use, disclosure, or loss.
  • Data Breach Notification: Organizations must report data breaches to the authorities and affected individuals.
  • Designation of a Privacy Officer: Businesses may need to designate a person responsible for overseeing compliance with the law.

?

17 of 18

CONCLUSION

  • By following the best practices outlined in this presentation, you can help to keep your business safe from cyber attacks.
  • Cybersecurity is an ongoing process, but by taking steps to protect your business, you can reduce your risk of a cyberattack.
  • Don't hesitate to contact professional companies.

?

18 of 18

THANK YOU