Safeguards & Checklists

Verification steps you can use today, before a payment goes out, when banking details change, when you set up a home network, and in the first hour of an incident.

The rule behind every checklist

Verify on a second channel, using contact details you already hold. Nearly every successful fraud against an organization depends on one person acting alone, in a hurry, on information the sender supplied.

Home Wi-Fi & Device Setup

0/6 complete

A one-evening pass over the router, phones, and smart devices that sit on your home network.

Personal Account Recovery Plan

0/6 complete

Set this up while you still have access, so losing a phone or a password is an inconvenience, not a crisis.

Travel & Public Networks

0/6 complete

What to do before and during a trip, in airports, hotels, cafes, and conference halls.

If Your Accounts or Card Are Compromised

0/7 complete

The order to work in when a card, an account, or your identity details have been taken.

Reporting an Incident

If your organization has been targeted or hit, report it. Reporting supports recovery and helps other Atlantic organizations see what's coming.

Emergency: Call 911

If anyone is in immediate danger, or a crime is in progress at your workplace, call 911.

911

Your Bank's Commercial Fraud Desk

Call first if money has already left. Ask for a wire or EFT recall and have the payment frozen, the first 24 to 48 hours decide whether funds can be recovered.

Use the number on your account statement

Canadian Anti-Fraud Centre (CAFC)

Report business fraud, invoice redirection, business email compromise and wire fraud. Your report feeds the RCMP and the National Cybercrime Coordination Centre.

Canadian Centre for Cyber Security

Report ransomware, intrusions and account compromises affecting your organization, and get national guidance on containment and recovery.

Cyber Incident Reporting Portal

Submit a formal cyber incident report for your organization, and upload logs, emails or files related to the incident.

Office of the Privacy Commissioner

If employee or client personal information was exposed, a breach of security safeguards posing a real risk of significant harm must be reported under PIPEDA, and affected people notified.

Local Police or RCMP Detachment

File a local report for the loss. Insurers and banks usually require a police file number before they will process a claim or a recall request.

Spam Reporting Centre

Report the unwanted or spoofed commercial email your staff received, where no financial loss or criminal act occurred.

National Security Concerns (CSIS)

Report suspected espionage, foreign interference, or cyber tampering affecting critical infrastructure or sensitive research.

These checklists are educational. Always involve local law enforcement and your financial institution if you believe your organization has been defrauded.