Threat intelligence · Report LT-Q3-2026-CA-001

State of Canadian Owner-Run Firm Cybersecurity, Q3 2026

What 1,460 outside assessments of Canadian owner-run firms found about email, domains, exposed services and staff credentials.

Report LT-Q3-2026-CA-001Region CanadaPeriod Q3 2026Published 8 Jul 2026By LeakTrace Intelligence Desk
The period in figures

What the assessments found.

1,460
Canadian owner-run firms assessed from outside, before any engagement
93.0
Average external Rating, of 100. A lower rating is better.
98.4%
Rated Critical or High

Source: LeakTrace assessments, of 1,460 firms assessed, Q3 2026.

Summary

LeakTrace assessed the public surface of 1,460 Canadian owner-run firms in Q3 2026: email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl, lookalike domains and keys left in website code. The average external Rating across those 1,460 firms was 93.0 of 100, and 98.4% of them were rated Critical or High.

Separately, the owner or principal email address of 163 of those firms was checked against monitored breach databases; 25.2% of the 163 appeared in at least one breach record.

This report gives the sector and regional breakdowns, the method, and the mitigation steps that apply across sectors. Every firm in the population was assessed from outside, before any engagement, using public data only.

Findings at a glance

25.2%
Owner or principal address in at least one monitored breach database
Source: LeakTrace assessments, of 163 firms whose owner address was checked, Q3 2026
98.8%
Infrastructure misconfigurations
Source: LeakTrace assessments, of 1,460 firms assessed, Q3 2026
65.8%
Registered typosquat domains
Source: LeakTrace assessments, of 1,460 firms assessed, Q3 2026

External exposure

How the 1,460 firms assessed fall across the four severity bands, from outside checks of email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl and software versions.

Severity bandShare of 1,460
Critical
84.9%
High
13.5%
Moderate
1.1%
Low
0.4%

Credential exposure

Bands for the 163 firms whose owner address was checked against monitored breach databases. Passwords and financial data weigh more than personal identifiers, which weigh more than usernames alone.

BandShare of 163
Severe
11.7% (19)
Moderate
13.5% (22)
Minor
0% (0)
None identified
74.8% (122)

How firms were exposed

Share of the 1,460 firms assessed where each condition was found, most common first.

ConditionShare of 1,460
Infrastructure misconfigurationsDNS, TLS/SSL, DMARC, SPF, or DKIM configurations flagged as high-risk during external scanning.98.8%
Registered typosquat domainsLook-alike domain variants already registered by third parties, brand impersonation and BEC infrastructure.65.8%
JavaScript secret exposureAPI keys, tokens, or credentials embedded in front-end JavaScript bundles reachable from the homepage.63.3%
Vulnerable JavaScript librariesFront-end libraries with known CVEs loaded on production pages, direct client-side outside exposure.25.9%
WordPress user enumerationWordPress installations leaking usernames through unauthenticated REST endpoints, enables targeted credential-stuffing.23.6%
Exposed configuration endpointsPublicly-accessible admin panels, config files, or unprotected API endpoints identified via non-invasive probing.11.1%
Sensitive open portsInternet-facing ports exposing services with known CVEs or authentication concerns, per public internet indexes.5.8%
Cloud storage exposurePublicly-listable S3/GCS/Azure buckets associated with the domain, data exfiltration risk.5.5%

By sector

“Firms” is the number assessed in each sector as stored; the Rating runs from 0 to 100, and a lower rating is better. Owner-credential rates are not broken out by sector because the counts are too small to publish.

SectorFirmsRatingCritical or High
Financial Services57496.9100.0%
Legal554100.0100.0%
Dental17693.298.3%
Construction6291.7100.0%
Manufacturing3395.5100.0%
Other2393.1100.0%
Healthcare1998.6100.0%
Accounting1993.2100.0%

By province

“Firms” is the number assessed there. Differences reflect the mix of firms as much as their upkeep.

ProvinceFirmsRatingCritical or High
Ontario103392.898.4%
Manitoba31291.294.3%
British Columbia9494.1100.0%
Alberta8093.398.7%
Quebec4895.0100.0%
Nova Scotia2092.8100.0%
Saskatchewan7100.0100.0%

Recommended mitigations

For Canadian owner-run firms in this monitoring population:

  1. Immediate
    Outside exposure remediation

    With an average external threat surface risk score of 93.0/100 and 98.4% of businesses classified as Critical or High risk, outside exposure reduction is the highest-leverage single investment. Priorities: enable DMARC enforcement, remediate SSL/TLS misconfigurations, retire exposed administrative interfaces, and review subdomain sprawl.

  2. Immediate
    Force password rotation for owner/executive accounts

    With 14.1% of businesses in our monitoring showing password-class breach exposure, credential stuffing attacks are a realistic near-term threat. Rotating passwords + enabling MFA closes this vector immediately.

  3. Near-term (30 days)
    Deploy business email compromise (BEC) monitoring

    Owner email addresses in breach databases enable BEC / whaling attacks where attackers pose as the executive. Monitoring for spoofed sender activity + implementing DMARC enforcement mitigates this.

  4. Near-term (30 days)
    Employee awareness training

    With 3.1% of businesses showing financial-data exposure and the elevated infrastructure risk profile, staff awareness training is the highest-leverage human-factor investment. Focus on recognizing phishing, verifying wire requests, and reporting suspicious contact.

  5. Quarterly
    Repeat the exposure check

    Breach databases update daily and infrastructure changes affect risk scores. Quarterly re-checking is standard threat intelligence hygiene.

  6. Strategic
    Cyber insurance review

    With the combined infrastructure + credential exposure profile observed across the Canadian owner-run firm landscape, cyber insurance policies should be reviewed for adequate coverage. Current premiums assume active mitigation programs; documented mitigation reduces premiums.

Sources and method

Visibility

LeakTrace maintains an ongoing threat intelligence pipeline monitoring Canadian owner-run firms across sectors including healthcare, legal, financial services, dental, and professional services. Our monitoring combines public data sources with proprietary discovery workflows and covers firms assessed before any engagement.

Coverage dimensions

  • Infrastructure, outside exposure checks covering DNS security posture, TLS/SSL configuration, exposed administrative interfaces, subdomain sprawl, and vulnerable framework detection.
  • Credential exposure, matching owner and executive email addresses against monitored breach databases and data-class exposure classification.
  • Public web exposure, open-source intelligence aggregation covering code repository leaks, paste site mentions, and publicly-indexed disclosure activity.

Sources

  • Monitored breach databases
  • Supplementary monitored breach databases
  • Open-source intelligence aggregation of publicly-indexed web content
  • Publicly-available corporate registry data and business directories
  • outside exposure checks across DNS, TLS, subdomain, and framework layers

Methodology

For each business in our monitoring pipeline, we run parallel exposure checks across the coverage dimensions above. Infrastructure risk scores are computed on a 0-100 scale where higher indicates greater exposure surface. Credential exposure scores are classified by data class weight (passwords + financial > PII > usernames only). Severity bands are harmonized across dimensions.

Limitations

  • Public data only, no dark web or non-licensed sources
  • Credential coverage limited to owners/executives whose emails are publicly discoverable
  • Infrastructure reading is non-invasive, passive external observation only
  • Severity indicates exposure surface, not active threat targeting

No firm is named. Every firm was assessed from outside, before any engagement, from public data only.

Share on LinkedIn

The outside watch for your firm: see what is open before anyone else does, with the proof for the lead finding. Check my firm →