Monday morning!
It is Monday morning. Your employees can sign in to their computers. The internet works. Email is available. But the outside service you need to run payroll, retrieve client files or send invoices will not load.
Your own network may be working exactly as intended. Your business still has a problem: an essential part of the work happens somewhere else.
Who checks the provider’s status? Who decides whether to switch to a manual process? Can you reach employees if your usual collaboration platform also becomes unavailable? And what can you confidently tell clients?
For Canadian SMBs, cybersecurity planning needs to include these dependencies. A practical starting point is a 30-minute discussion about five services your organization cannot comfortably operate without.
Why a vendor’s problem becomes your business problem
Consider a typical firm in Ottawa, Gatineau or elsewhere in Canada. Microsoft 365 or Google Workspace supports communication. Separate providers handle accounting, payroll, customer relationships, payment processing, document signing and scheduling. A managed service provider manages access, devices or backups.
These services can make a small team more capable. They also create dependencies that a firewall or a well-maintained laptop cannot remove.
A service may become unavailable because of a technical failure, a configuration change, a cyber incident or a protective shutdown. A provider can also suffer a data breach while continuing to operate. Treat availability and the protection of information as separate questions: a working application does not prove that its data is unaffected.
The practical consequence depends on the business process. A payroll interruption close to a submission deadline matters differently from a reporting tool being unavailable for an afternoon. Begin with the work and its deadlines, then identify the technology supporting it.
Recent context: two different dependency risks
On April 11, 2026, Canada Life notified the Government of Canada about a cyber incident, according to Treasury Board briefing material. That is a notification date, not a confirmed intrusion date. Canada Life’s initial statement said regular operations continued. Its subsequent update says it informed affected individuals and relevant advisors and plan sponsors. This Canadian example concerns information and communication, not a claimed service outage.
A separate availability example is the October 19–20, 2025 AWS disruption. Amazon attributed the initial problem to DNS resolution in US-EAST-1 and reported full service recovery on October 20. This was a US-region event, not evidence that every Canadian customer or Canadian cloud region was affected.
The planning lesson is to ask two questions: what will we do if a provider cannot deliver the service, and what will we do if it reports that information was exposed? The answers may involve different people and different decisions.
The dependencies that do not appear on your IT list
Start with the subscription list, but do not stop there. Ask finance about recurring payments and department managers about tools purchased directly. A project team’s file-sharing account or an office manager’s scheduling subscription may have become essential without a formal review. This is often called shadow IT.
Then look beneath the vendor names. Two applications may depend on the same cloud provider. Your backup console and your production systems may use the same sign-in service. Several “alternatives” can therefore share one point of failure.
People and access create dependencies too. If one administrator is the only person who can open a support case, recover an account or approve an emergency purchase, that person’s availability becomes part of the recovery plan. Outsourced IT does not remove the need for an internal business owner.
Record which information the provider holds, whether you can export it, and what those exports actually contain. A spreadsheet of client names may help with calls; it will not recreate a document-management system, its permissions or its audit history.
A 30-minute exercise for your five critical services
Invite an executive, someone from operations or finance, and your IT lead or provider. Use a shared document and a timer. The goal is a useful first pass, with unknowns assigned for follow-up. Do not turn the meeting into a discussion of every subscription.
Minutes 0–5: choose five services
List the external technology services whose loss would most quickly affect safety, client commitments, cash flow or essential work. Include a backup or IT provider if it is necessary to restore another service. Choose actual services, not broad labels such as “the cloud.”
Minutes 5–15: complete the dependency table
Replace the illustrative entries below with your vendors and named internal owners. The suggested workarounds are prompts to validate, not instructions to improvise during an incident.
| Service / vendor | Business process | Data involved | Impact if unavailable | Workaround | Owner |
|---|---|---|---|---|---|
| Payroll provider | Pay employees | Pay and banking details | Missed processing cutoff | Pre-approved contingency with finance | Finance lead |
| Client-file platform | Deliver client work | Confidential records | Files inaccessible | Approved, current essential-file copies | Practice lead |
| Scheduling service | Coordinate appointments | Names and appointments | Bookings cannot be checked | Protected daily schedule and phone process | Office manager |
| Accounting platform | Invoice and collect | Balances and transactions | Billing backlog | Controlled invoice log for later reconciliation | Controller |
| Email / collaboration | Coordinate response | Messages and contacts | Team cannot coordinate | Verified phone tree | Operations lead |
For each row, add maximum acceptable downtime, the provider’s support and escalation contacts, available backups or alternatives, and who needs to be informed. Keep contact details accessible outside the affected service. Never put passwords or recovery codes in this general-purpose worksheet.
Distinguish your business limit from a vendor’s promised restoration time. Also record how much recent work you could afford to lose. Being able to restart tomorrow is different from being able to recover yesterday’s transactions.
Minutes 15–23: test four durations
- One hour: What pauses, and who confirms the incident?
- One day: Which deadlines or client commitments are at risk?
- Three days: Can the workaround handle the growing backlog?
- One week: What must stop, move elsewhere or be renegotiated?
Change the timing once: imagine the outage happens on payroll day, during a closing, or before a major delivery. A service’s importance can change with the calendar. If a workaround requires the same unavailable login, mark it as unproven.
Minutes 23–27: select the three biggest gaps
Prioritize gaps by business consequence and urgency. “No way to reach staff without email” is actionable. “Improve cybersecurity” is not. Other useful findings include an inaccessible emergency contact list, an untested export, or a recovery estimate longer than the business can tolerate.
Minutes 27–30: assign the next action
Give each gap an owner, a due date and evidence of completion. For example: “Operations will test the phone tree with three team leads by Friday and record the results.” Schedule a follow-up to confirm that the three actions worked.
The Cyber Centre’s business-continuity planning guidance provides a broader framework. This short exercise starts the conversation; it does not replace a complete continuity plan.
Five controls worth prioritizing
1. Maintain a vendor inventory with business owners
Connect each critical service to its process, information, renewal date and decision-maker. Review the list when a department adopts a new tool or changes providers. This makes it easier to spot concentration risk and decide where a stronger recovery arrangement is worth the cost.
2. Protect administrator access
Use MFA, preferably phishing-resistant options where supported, and limit administrator privileges. Identify a trained backup administrator and a controlled emergency-access process. Test that process without broadly disabling protection. These measures reduce access risk; MFA alone does not keep a vendor’s service online.
3. Verify that recovery works outside production
Ask which data is backed up, how it is protected from deletion or alteration, and whether recovery depends on the same accounts or provider. Consider isolated or immutable copies where appropriate. Test a small restoration and check that the recovered information is usable.
A backup is not a replacement application. Record the tools, permissions, time and people needed to use it. Measure actual recovery against your business limit rather than relying on a successful backup notification.
4. Prepare communications and manual procedures
Choose an alternate communication channel and keep a protected copy of essential contacts. Define who can activate the plan, approve temporary spending and speak to clients. Prepare a short message stating what is affected, what people should do and when the next update will arrive.
Keep manual records secure and limit the information collected. Plan how to reconcile them when service returns so invoices, appointments or payments are not duplicated.
5. Agree on escalation, then practise it
Review contractual incident-notification terms, support coverage, data-return options and recovery commitments. Check with your insurance broker whether dependent business interruption is covered and which notification conditions apply. Coverage depends on the policy.
Run another tabletop exercise after a major change and on an agreed schedule. Track unresolved actions and retain the test record. The Cyber Centre’s baseline controls are a useful reference for the underlying security programme.
Ten questions for your technology provider
- Which external systems support our most time-sensitive work?
- Which providers hold our most sensitive information?
- Do our critical applications share cloud, identity or network dependencies?
- What can we still do if Microsoft 365, Google Workspace or our main SaaS platform is unavailable?
- Who has administrator access, and who can act if that person is absent?
- How will we receive and verify an incident notification outside normal email?
- What do our contracts require the provider to tell us, and when?
- Can we reach and restore backups if production access is lost?
- What was actually demonstrated in the last recovery test?
- Who has authority to activate our plan and approve client communications?
Ask for examples and evidence. “We have backups” is a starting point; the last test result, its limitations and the next corrective action are more useful.
The same issue looks different across industries
The following are planning scenarios, not reports of incidents at particular organizations.
- Professional services: Law and accounting firms may lose access to client files or filing workflows. Engineering and architecture teams may be unable to retrieve approved drawings. Identify deadline-critical material and how to verify its current version.
- Healthcare clinics: Scheduling and record systems affect different parts of care. A clinical lead should define safe downtime procedures and when appointments must be deferred; a printed schedule alone is not a clinical record.
- Non-profits: A donor or case-management platform may hold the contacts needed to coordinate services. Keep essential continuity information protected and accessible to authorized staff.
- Real estate, mortgage and insurance: Document portals and signing services can delay closings, applications or renewals. Establish approved alternatives and independently verify any changed payment instructions.
- Logistics and transportation: Dispatch, routing and proof-of-delivery tools support daily commitments. Test a limited manual dispatch process and identify the volume at which it becomes unsafe or unmanageable.
- Construction: Site teams may depend on cloud drawings, scheduling and subcontractor portals. Decide how to distribute the latest approved information and stop work when essential safety information cannot be verified.
Your checklist before the next disruption
- Five critical services have named business owners.
- Downtime limits reflect actual deadlines and business consequences.
- Support contacts and response instructions are accessible during an outage.
- Workarounds protect information and have been tried.
- Three priority gaps have owners, due dates and a follow-up.
When an incident occurs, verify information through known provider channels. Preserve notices and decisions. Involve your privacy lead if personal information may be affected, so applicable reporting and notification requirements can be assessed. Do not assume an outage is a breach, or that the provider’s response completes your own responsibilities.
Turn dependency risk into practical priorities
Cyber resilience means understanding what your business relies on and preparing to continue essential work when a dependency fails. You cannot prevent every incident. You can make the next decision easier by agreeing on owners, limits and workable alternatives today.
Not sure which technology dependencies could stop your operations? InnoAxis Solutions Inc. helps Canadian organizations identify cybersecurity, cloud and operational risks and turn them into practical priorities.
Explore the Secure Foundation approach, or book a short conversation about your environment, recovery priorities and next steps.