Cybersecurity Checklist for Squamish, Whistler & Vancouver Small Businesses: 10 Things to Fix Before You Get Hacked
Small businesses across the Sea-to-Sky corridor and Metro Vancouver are increasingly a target for cybercriminals — not because they're high-value, but because they're easy. Attackers run automated scans looking for the weakest lock on the block, and most small businesses haven't checked their locks in years.
Whether you're running a retail shop in Vancouver, a hotel or rental property business in Whistler, or a service company in Squamish, here are the 10 things worth fixing before they become an expensive problem.
1. Multi-Factor Authentication (MFA) Everywhere
If email, banking, or admin logins don't require a second factor beyond a password, that's the single highest-leverage fix available. Enable MFA on email, cloud storage, accounting software, and any admin panel.
App-based MFA (like an authenticator app) is a solid baseline, but it's not phishing-proof — a convincing fake login page can still trick someone into handing over a one-time code. For business owners and anyone with admin access to financial systems, a physical security key like a YubiKey is a meaningful step up. It plugs into USB or taps via NFC, requires physical possession to log in, and can't be phished the way codes and SMS messages can. Most major platforms — Google Workspace, Microsoft 365, banking portals, and password managers — support them directly. For a small business, the practical approach is usually two keys per critical account: one in daily use, one stored securely as a backup.
2. Wi-Fi Network Segmentation (VLANs)
Guest Wi-Fi, staff devices, and point-of-sale systems should never sit on the same network. A compromised guest device shouldn't have a path to your payment terminal or file server. VLAN segmentation is one of the most common gaps found during audits — and one of the more overlooked fixes for hospitality businesses in Whistler where guest Wi-Fi is a daily reality.
The starting point is separate SSIDs for separate purposes — a "Guest" network, a "Staff" network, and, where applicable, a dedicated network for POS/payment hardware. Each SSID should be tied to its own VLAN with firewall rules that block traffic between them by default, not just a different Wi-Fi password on the same flat network. A common setup looks like:
- VLAN 10 — Staff/Corporate: work laptops, staff phones, internal file shares and printers. Full access to business systems.
- VLAN 20 — Guest: internet-only access for customers, hotel guests, or visitors, with no visibility into any other VLAN and typically a bandwidth cap.
- VLAN 30 — POS/Payments: card terminals and payment hardware only, isolated from every other device on the network — this is often a PCI compliance requirement, not just a best practice.
- VLAN 40 — IoT/Building systems: smart locks, cameras, thermostats, and other connected devices, which are frequently the weakest-secured devices on a network and shouldn't have a path to anything sensitive.
This is typically configured at the router/firewall level with a managed switch and access points that support VLAN tagging — most modern business-grade equipment (Ubiquiti, TP-Link Omada, and similar) supports this without a major hardware overhaul. Done properly, a stolen guest laptop or infected customer phone has no route to anything that matters to the business, even though it's technically on the same physical Wi-Fi hardware.
3. Employee Phishing Awareness
Most breaches start with a convincing email, not a sophisticated exploit. A short annual training session and a habit of double-checking unusual payment or login requests goes further than most security software.
4. A Real, Tested Backup Strategy
Backups that have never been tested for restoration aren't backups — they're guesses. Follow the 3-2-1 rule: three copies, two different media types, one offsite. Ransomware recovery hinges entirely on this.
5. Point-of-Sale and Payment Security
Retail and hospitality businesses handling card payments need PCI-compliant systems and regularly updated POS software. An outdated payment terminal is a common entry point.
6. Patch Management
Unpatched software is one of the most common ways attackers get in. Set a recurring schedule to apply updates to operating systems, routers, and business software rather than waiting for a prompt.
7. Public Wi-Fi Risk for Tourism-Sector Businesses
Whistler and Vancouver businesses that operate across multiple locations or rely on staff working from cafes and shared spaces should use a VPN (like WireGuard or Tailscale) for any connection back to business systems.
8. Physical Device Security
Laptops and POS terminals left unlocked or unattended are a bigger risk than most owners assume, especially in high-foot-traffic retail and hospitality settings common in Vancouver's downtown core and Whistler Village.
9. An Incident Response Plan
Knowing who to call, what to shut down, and how to communicate with customers before an incident happens saves hours during the moment it matters most.
10. A Professional Security Audit
Most of the above can be self-assessed, but a proper audit catches the gaps you don't know to look for — misconfigured firewalls, exposed ports, weak admin credentials, and outdated network hardware.
Need help getting your new business online? Let's talk about your website, email and domain setup.
Get a free quote