AI
A 1-Hour IT Checkup for Burnaby Shops in the AI Era
October is Cyber Security Awareness Month in Canada, and the 2026 theme from the federal Get Cyber Safe campaign is "Your best defence is you." It's a nice line. It's also a fair warning, because the campaign page puts AI front and centre: "Cyber criminals use tricks to make scams look real, and AI can make those scams harder to spot" (Get Cyber Safe).
If you run a shop in Burnaby or New Westminster, you probably don't have an IT department. You have a point of sale, a shared inbox, a router nobody has logged into since it was installed, and maybe an AI chatbot or two that staff started using on their own. This is a one hour checkup you can do on a quiet morning. It's built from free Government of Canada guidance, not a sales pitch.
What the numbers actually say
Statistics Canada's release Impact of cybercrime on Canadian businesses, 2023, published October 21, 2024, found that about 1 in 6 (16%) Canadian businesses were impacted by cyber security incidents in 2023. Large businesses were the most likely to be hit, at 30%.
The less comfortable part is what those incidents looked like. Among impacted businesses, 50% dealt with scams and fraud and 31% dealt with identity theft, according to StatCan. Ransomware hit 13%. Those aren't movie style break ins. Mostly, someone got tricked.
Preparation was thin, too. Only 26% of businesses had written cyber security policies in 2023, and just 22% provided formal training, the same release says.
One caveat worth stating plainly: the survey only covers businesses with 10 or more employees. If you're a three person shop, you aren't in these figures at all, so treat them as context rather than a forecast of your own risk.
Why AI changes the checkup
The Canadian Centre for Cyber Security's guidance on generative AI (ITSAP.00.041), dated December 2025, warns that threat actors "can craft targeted spear-phishing attacks more frequently, automatically, and with a higher level of sophistication." The typo filled scam email is fading. A convincing fake invoice from your usual supplier isn't.
The same document flags a risk that sits inside your own business: "Users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries." In a shop, that looks like pasting a customer complaint, name, phone number and order history included, into a free chatbot to draft a reply.
Neither problem needs expensive tools. Both need a few settings and a couple of habits.
The 1-hour checkup
The Cyber Centre publishes a short list called Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035). It's a companion to the longer baseline cyber security controls, which are built around an 80/20 idea: "achieve 80% of the benefit from 20% of the effort." We've pulled out the parts a retail shop can realistically do in an hour. The minute markers are illustrative, and your first run will probably take longer.
- Minutes 0 to 15: turn on MFA where it matters most. Start with email, online banking, your POS admin login, your domain registrar and your ecommerce platform. ITSAP.10.035 says to use two factor or multi factor authentication "wherever possible." Do email first, since whoever controls your inbox can usually reset everything else.
- Minutes 15 to 25: check updates. Confirm automatic updates are on for computers, phones, tablets used as registers, and the router. The Cyber Centre's advice is to "activate automatic patches and updates for all software and hardware."
- Minutes 25 to 35: test one backup. Don't just confirm a backup exists. Restore a single file. The baseline controls say long term backups, such as weekly ones, "must be stored offline," which keeps ransomware from reaching them.
- Minutes 35 to 45: change default passwords and prune accounts. Log into the router and any cameras or terminals with admin panels. ITSAP.10.035 calls out default passwords, "especially administrative passwords." Remove logins for staff who've left, and apply least privilege: cashiers don't need owner access.
- Minutes 45 to 55: write a one page AI and payments rule. Two rules cover most of it. Customer names, card details and staff records don't go into AI tools your business hasn't approved. And any request to change banking details or rush a payment gets confirmed by phone, using a number you already had, never the one in the message.
- Minutes 55 to 60: write down who to call. An incident response plan can start as a single note: who decides, your IT contact, your bank's fraud line, your insurance broker. The baseline controls recommend keeping hard copies, which matters when the computer is the thing that's broken.
If something goes wrong, know which privacy law applies
Most BC shops handling customer information inside the province fall under BC's Personal Information Protection Act (PIPA). The Office of the Privacy Commissioner of Canada's PIPEDA in brief explains that organizations covered by a substantially similar provincial law are generally exempt from the federal PIPEDA for information handled within that province. PIPEDA still applies to personal information that crosses provincial or national borders in commercial activity, and to federally regulated businesses.
The rules differ. For organizations under PIPEDA, the OPC says breaches posing a real risk of significant harm must be reported and affected people notified, and you must "keep breach records of all breaches of security safeguards for two years" (OPC). Under PIPA, the Office of the Information and Privacy Commissioner for BC says private organizations aren't currently required to report breaches to it, but adds: "we strongly recommend that breaches be reported to our office as a best practice" (OIPC BC). An online store shipping across Canada could be dealing with both. If you're unsure, ask a privacy lawyer rather than guessing.
Where this doesn't apply
This checkup has real limits.
It isn't a security audit. It won't find a compromised laptop, a misconfigured cloud account or a hole in your website. If you store card data yourself, run your own servers or handle health information, you need more than an hour and probably a professional.
It won't stop every scam either. The Cyber Centre says an informed workforce "can reduce the likelihood of cyber incidents," but reducing isn't eliminating. Someone will eventually click something, which is why MFA and offline backups carry so much of the load.
And AI isn't the fix here. If a shop doesn't have MFA, updates and a working backup, adding a smarter tool on top won't rescue it. Our honest advice is to hold off on new AI automation until the basics above are done. An AI assistant connected to your inbox or customer records also widens what one stolen password can reach, so it belongs after the checkup, not instead of it.
Finally, the numbers are a snapshot. StatCan's figures describe 2023 and leave out the smallest businesses. We didn't find Canadian data that isolates retail shops in Metro Vancouver, so we haven't invented a figure for them.
Sources
- Government of Canada, Get Cyber Safe. "October is Cyber Security Awareness Month in Canada." 2026. getcybersafe.gc.ca
- Statistics Canada. "Impact of cybercrime on Canadian businesses, 2023." The Daily, October 21, 2024. statcan.gc.ca
- Canadian Centre for Cyber Security. "Generative artificial intelligence (AI) (ITSAP.00.041)." December 2025. cyber.gc.ca
- Canadian Centre for Cyber Security. "Top measures to enhance cyber security for small and medium organizations (ITSAP.10.035)." February 2024. cyber.gc.ca
- Canadian Centre for Cyber Security. "Baseline cyber security controls for small and medium organizations." Version 1.2, 2020. cyber.gc.ca
- Office of the Privacy Commissioner of Canada. "What you need to know about mandatory reporting of breaches of security safeguards." Page modified 2025. priv.gc.ca
- Office of the Privacy Commissioner of Canada. "PIPEDA in brief." Accessed September 2026. priv.gc.ca
- Office of the Information and Privacy Commissioner for British Columbia. "Report a privacy breach." Accessed September 2026. oipc.bc.ca
Want a second set of eyes on your checkup, or help planning AI tools that won't widen your risk? Book a free call with Autana Solutions. We're local to Burnaby and New Westminster, and we'll tell you straight if the right answer is "not yet."
Want an AI employee for your business?
We install a 24/7 AI worker for businesses in Vancouver, Burnaby, and beyond. Book a free Discovery Call.
Book a call →

