Cyber incidents are hitting businesses twice as often as they did five years ago, even though cybersecurity budgets keep growing. The 2026 Cyber Claims Report from Coalition reveals why throwing more technology at the problem isn’t enough. Email scams alone caused 58% of cyber insurance claims last year, showing that your team’s awareness can be just as crucial as your IT tools. Read on to learn how managed IT services in Edmonton can help you protect your business from these rising threats.
Understanding the Real Cyber Threat Landscape
When we talk with business owners across Edmonton and Alberta, the conversation about cyber threats often focuses on the big headline breaches. You know the ones: major corporations losing millions of records, hospitals shut down by ransomware, or government agencies compromised by sophisticated hackers. But here’s what the data tells us: those aren’t the stories that matter most to your business.
Coalition’s 2026 Cyber Claims Report analyzes actual insurance claims from more than 100,000 organizations worldwide. This isn’t speculation or theory. These are real losses experienced by real businesses, many of them just like yours. The findings reveal something that might surprise you: the cyber threats keeping business owners up at night aren’t always the ones they should be worried about.
In case you missed it, we’ve made the video recording of our recent webinar available for you to revisit at your convenience. The webinar dives deep into the findings of the Coalition 2026 Cyber Claims Report and explores real-world cyber incident case studies. You can watch the full recording here to gain insights into the latest cybersecurity strategies and how they can be applied to protect your business. Feel free to share the link with your team to enhance their understanding and awareness of current cyber threats.
The Cyber Protection Paradox
We’re seeing something interesting happen in the business world right now. Companies are spending more on cybersecurity than ever before. Budgets are increasing year over year. New tools are being purchased and deployed. Security awareness training is becoming standard practice. And yet, cyber incidents are happening twice as frequently as they did five years ago.
This is what Coalition calls the “Cyber Protection Paradox.” More spending doesn’t automatically equal better protection. As an IT consulting provider in Edmonton, we see this firsthand. Businesses come to us frustrated because they’ve invested in security tools, but they’re still experiencing breaches, compromises, and losses.
The problem isn’t that the technology doesn’t work. The problem is that technology alone can’t solve a problem that’s fundamentally about people and processes.
Email: Still Your Biggest Vulnerability
If you’re running a business, you probably check your email dozens of times a day. Your team does too. Email is how we communicate with clients, coordinate with vendors, manage projects, and run our operations. It’s also the number one way cybercriminals are getting into businesses.
According to the report, Business Email Compromise (BEC) accounted for 31% of all cyber insurance claims in 2025. Funds Transfer Fraud (FTF) represented another 27%. Put those together, and you’re looking at 58% of all claims starting with email-based attacks.
How Business Email Compromise Works

Let me walk you through a typical scenario we’ve seen with businesses here in Edmonton. An attacker gains access to an employee’s email account. Maybe they fell for a phishing email. Maybe they used a weak password. Maybe they reused a password that was compromised in a breach at another service.
Once the attacker is in, they don’t immediately start causing chaos. Instead, they watch. They read emails. They learn about your business relationships, your vendors, your payment processes, and your internal communications. They’re looking for opportunities.
Then they strike. Maybe they send an email to your accounting team that looks like it came from your CEO, requesting an urgent wire transfer. Maybe they intercept a legitimate invoice from a vendor and change the banking details before forwarding it to your accounts payable team. Maybe they contact one of your customers pretending to be you and provide new payment instructions.
The average loss from these attacks? Over $141,000 USD. For many small and medium businesses, that’s a devastating hit.
Why Social Engineering Works
Here’s what makes these attacks so effective: 71% of Funds Transfer Fraud incidents involved social engineering. That means the attacker didn’t need to hack through firewalls or exploit complex vulnerabilities. They simply convinced someone to do what they wanted.
They create urgency. They impersonate authority. They exploit trust. They rely on the fact that your team is busy, juggling multiple priorities, and trying to be responsive to requests from leadership and clients.
As a Managed IT Service provider Edmonton businesses trust, we can implement all the technical controls in the world, but if your team doesn’t know how to spot these tactics, you’re still vulnerable.
The Evolution of Ransomware Threats
Ransomware gets a lot of attention, and for good reason. It represented 21% of all claims in the report, and the average ransom demand exceeded $1 million in 2025. That’s a 47% increase from the previous year.
But ransomware has changed in ways that make it even more dangerous than it used to be.
From Encryption to Dual Extortion

Five years ago, a ransomware attack was relatively straightforward. Criminals would break into your network, encrypt your files, and demand payment for the decryption key. If you had good backups, you could restore your systems and avoid paying the ransom.
Cybercriminals adapted. Now, most ransomware attacks involve what’s called “dual extortion.” Before they encrypt your files, they copy your data and take it out of your network. Then they hit you with two threats:
-
Pay the ransom or you won’t get the decryption key to recover your systems.
-
Pay the ransom or we’ll publicly release your sensitive data.
This creates pressure from multiple directions. You’re dealing with operational downtime. You’re facing potential regulatory penalties if customer data is exposed. You’re worried about legal liability. You’re concerned about reputational damage.
The Good News About Ransomware
Here’s something encouraging from the report: 86% of ransomware victims refused to pay the ransom demand. Organizations with tested backups, solid incident response plans, and proper recovery procedures were able to restore operations without funding criminal activity.
This is where working with an IT company Edmonton businesses can rely on makes a real difference. We help clients build resilient infrastructure that can withstand and recover from these attacks. We test backups regularly. We create and practice incident response plans. We implement security controls that make it harder for attackers to gain the initial access they need.
If you do find yourself in a situation where paying a ransom seems necessary, never do it alone. Work with your cyber insurance provider and their breach counsel. They have experience negotiating with these groups. They can verify whether the group is on any sanctions lists. They can often reduce the ransom demand significantly. Coalition reports achieving a 68% reduction in ransom payments through professional negotiation.
Industry-Specific Risk Factors

Cyber risk isn’t distributed equally across different types of businesses. The report shows significant variation in both claim frequency and severity across industries.
Information Technology organizations experienced the highest average claim severity at approximately $182,000 USD. Healthcare organizations averaged more than $130,000 USD per claim. Manufacturing, construction, engineering, and materials industries also saw elevated claim frequency due to their operational complexity and reliance on critical systems.
What does this mean for your business? Generic cybersecurity advice isn’t enough. You need to understand the specific risks that apply to your industry, your operations, and your business model.
As an Edmonton based IT solutions provider, we take the time to understand your business before we make recommendations. We don’t believe in one-size-fits-all approaches. What works for a law firm doesn’t necessarily work for a construction company. What makes sense for a healthcare provider might not be right for a manufacturing business.
The Growing Threat of Third-Party Incidents
Here’s something that caught my attention in the report: Coalition is seeing an increase in claims related to losses that resulted from an incident at a vendor or service provider.
Think about the services your business relies on every day. Your accounting software. Your CRM system. Your payment processor. Your cloud storage provider. Your IT support partner. What would happen to your operations if one of those providers experienced a major cyber incident?
The report shows that these third-party incidents are causing real, measurable losses for businesses. You might have excellent security practices in your own organization, but you’re still exposed to risk through your supply chain.
This is why vendor risk management needs to be part of your cybersecurity strategy. When you’re selecting technology partners or service providers, ask questions about their security practices:
-
Do they follow recognized frameworks like NIST or CIS Controls?
-
What cyber insurance coverage do they carry?
-
Do they have an incident response plan?
-
How do they protect customer data?
-
What would their recovery process look like if they experienced a breach?
Five Essential Security Controls for Every Business
Let me shift gears and give you some practical steps you can take right now to improve your security posture. These are foundational controls that every business should have in place:

1. Multi-Factor Authentication
Multi-factor authentication (MFA) requires users to provide two or more verification factors to gain access to an account or system. Even if an attacker gets your password, they can’t get in without the second factor.
Enable MFA on every system that supports it, especially email, financial systems, and remote access tools. This single control can prevent the majority of account compromise attacks.
2. Regular Backups with Testing
Having backups isn’t enough. You need to test them regularly to make sure they actually work when you need them. We’ve seen too many businesses discover during a crisis that their backups were incomplete or corrupted.
Follow the 3-2-1 rule: keep three copies of your data, on two different types of media, with one copy stored offsite or in the cloud. Test your restoration process at least quarterly.
3. Email Security and User Training
Deploy email filtering and protection tools to catch phishing attempts and malicious attachments before they reach your users. But don’t stop there. Train your team to recognize social engineering tactics.
Teach them to verify unusual requests, especially those involving financial transactions or sensitive data. Create a culture where it’s okay to double-check, even if it means questioning a request from leadership.
4. Patch Management
Keep your systems and software up to date. Many successful attacks exploit known vulnerabilities that have patches available. If you’re not applying those patches promptly, you’re leaving the door open.
This is one area where managed IT services businesses can really help. We monitor for updates and apply them systematically, reducing your exposure window.
5. Access Controls and Least Privilege
Not everyone in your organization needs access to everything. Implement the principle of least privilege: give users only the access they need to do their jobs, nothing more.
When employees change roles or leave the company, remove their access immediately. Review permissions regularly to make sure they’re still appropriate.
Beyond Security: Building Cyber Resilience
I want to make an important distinction here. Cybersecurity is about trying to prevent incidents from happening. Cyber resilience is about acknowledging that even the best organizations will likely experience some type of cyber incident, and preparing to respond effectively when it happens.
Resilient organizations:
-
Have documented incident response plans that everyone knows about
-
Practice their response procedures regularly through tabletop exercises
-
Maintain relationships with incident response providers and legal counsel before they need them
-
Communicate transparently with stakeholders when incidents occur
-
Learn from every incident and continuously improve their defenses
This mindset shift is important. If you’re only focused on prevention, you’re setting yourself up for a crisis when (not if) something gets through. If you’re focused on resilience, you’re prepared to handle incidents in a way that minimizes their impact on your business.
What This Means for Edmonton Businesses
If you’re running a business in Edmonton or anywhere in Alberta, these findings should inform your approach to cybersecurity. The threats are real, they’re growing, and they’re targeting businesses of all sizes.
But here’s the good news: you don’t have to face these challenges alone. Working with the managed service provider Edmonton businesses trust can give you access to expertise, tools, and resources that would be difficult to build in-house.
At Tier 3 IT Solutions, we help businesses build stronger security postures without getting overwhelmed by complexity. We focus on practical, effective controls that fit your business and your budget. We explain things in plain language, not technical jargon. We take the time to understand your operations so we can provide recommendations that make sense for you.
The Four Pillars of IT Success
Our approach is built on what we call the Four Pillars of IT Success:
Strategy: Aligning your technology with your business goals, not just buying tools because they’re popular.
Security: Protecting your business with layered defenses and building resilience to handle incidents when they occur.
Support: Providing responsive, knowledgeable assistance when you need it, whether that’s through our IT helpdesk Edmonton team or proactive monitoring.
Systems: Building reliable infrastructure that supports your operations and scales with your growth.
When all four pillars are strong, your business is positioned to leverage technology as a competitive advantage rather than viewing it as a necessary expense or a source of risk.
Taking Action on These Insights
Reading about cyber threats can feel overwhelming. The numbers are big. The attacks are sophisticated. The risks seem to be everywhere. But remember: the goal isn’t to achieve perfect security. The goal is to be prepared, protected, and resilient.
Start with the basics. Make sure you have those five essential controls in place. Review your cyber insurance coverage to understand what’s protected and what gaps exist. Talk to your team about security awareness. Consider working with a partner who can help you build a comprehensive program.
If you’d like to have a conversation about your specific situation, we’re here to help. We offer complimentary security assessments for businesses throughout Edmonton and Alberta. We’ll look at your current setup, identify areas of concern, and provide practical recommendations you can act on.
The businesses that come out ahead aren’t necessarily the ones with the biggest security budgets. They’re the ones who take a strategic, business-focused approach to managing cyber risk. They’re the ones who recognize that computer security isn’t just an IT issue, but a business priority that deserves attention from leadership.
Moving Forward with Confidence
The 2026 Cyber Claims Report gives us valuable insights into the real-world cyber threats facing businesses today. Email-based attacks are the most common threat. Ransomware continues to be disruptive and expensive. Third-party incidents are creating new exposure. Industry-specific factors affect your risk profile.
But armed with this knowledge, you can make informed decisions about how to protect your business. You can prioritize the controls that will have the biggest impact. You can build resilience that will help you weather incidents when they occur.
Whether you’re looking for comprehensive managed IT services, focused cybersecurity Edmonton support, or strategic IT consulting Edmonton businesses depend on, the key is finding a partner who understands your business and can help you build solutions that work for you.
Your business is unique. Your challenges are specific to your industry, your operations, and your goals. You deserve an approach to technology and security that reflects that. You deserve a partner who takes the time to understand what matters to you and helps you build systems that support your success.
If you’re ready to take the next step in strengthening your cyber resilience, we’d love to talk with you. Reach out to Tier 3 IT Solutions today to schedule a conversation about how we can help protect and support your business with outsourced IT services Edmonton companies trust.
Your technology should work for you, not against you. Let’s make that happen together.
Additional Resources:
-
Watch our full webinar recording breaking down the Coalition 2026 Cyber Claims Report
-
Download the complete 2026 Cyber Claims Report from Coalition
-
Learn about our Cyber Readiness Program
-
Contact us to discuss your cybersecurity needs

