Safeguards & Checklists

Verification steps you can use today, before a payment goes out, when banking details change, when you set up a home network, and in the first hour of an incident.

The rule behind every checklist

Verify on a second channel, using contact details you already hold. Nearly every successful fraud against an organization depends on one person acting alone, in a hurry, on information the sender supplied.

Payment & Wire Verification

0/6 complete

Work through this before any transfer, wire, or unusual payment leaves the organization.

Vendor Bank Detail Changes

0/6 complete

Use this every time a supplier, contractor, or employee asks to change where money is sent.

Urgent Requests From Leadership

0/6 complete

For any unexpected instruction that appears to come from an owner, executive, or manager.

The First 60 Minutes of an Incident

0/7 complete

What non-technical staff should do when ransomware or an account compromise is suspected.

Reporting an Incident

If your organization has been targeted or hit, report it. Reporting supports recovery and helps other Atlantic organizations see what's coming.

Emergency: Call 911

If anyone is in immediate danger, or a crime is in progress at your workplace, call 911.

911

Your Bank's Commercial Fraud Desk

Call first if money has already left. Ask for a wire or EFT recall and have the payment frozen, the first 24 to 48 hours decide whether funds can be recovered.

Use the number on your account statement

Canadian Anti-Fraud Centre (CAFC)

Report business fraud, invoice redirection, business email compromise and wire fraud. Your report feeds the RCMP and the National Cybercrime Coordination Centre.

Canadian Centre for Cyber Security

Report ransomware, intrusions and account compromises affecting your organization, and get national guidance on containment and recovery.

Cyber Incident Reporting Portal

Submit a formal cyber incident report for your organization, and upload logs, emails or files related to the incident.

Office of the Privacy Commissioner

If employee or client personal information was exposed, a breach of security safeguards posing a real risk of significant harm must be reported under PIPEDA, and affected people notified.

Local Police or RCMP Detachment

File a local report for the loss. Insurers and banks usually require a police file number before they will process a claim or a recall request.

Spam Reporting Centre

Report the unwanted or spoofed commercial email your staff received, where no financial loss or criminal act occurred.

National Security Concerns (CSIS)

Report suspected espionage, foreign interference, or cyber tampering affecting critical infrastructure or sensitive research.

These checklists are educational. Always involve local law enforcement and your financial institution if you believe your organization has been defrauded.