How to Implement CAN/DGSI:104 in Your Organization

A practical guide to implementing the cybersecurity controls recommended by CAN/DGSI:104, without needing a large internal security team.

Implementing CAN/DGSI:104 does not require building a large internal cybersecurity team. The framework focuses on practical security controls that organizations can adopt to reduce cyber risk and protect their operations.

Most businesses already have some protections in place. The goal is to ensure those protections are implemented consistently and that important security gaps are addressed.

The following steps provide a structured approach for implementing CAN/DGSI:104.

Typical Implementation Timeline

Month 1

Assessment, leadership, governance, and incident response plan

Month 2–3

Patch management, endpoint security, secure configuration, and access controls

Month 3–4

Backups, network defences, and employee training

Month 4–6

Email security, monitoring, and environment-specific controls

Implementation Steps

A Structured Approach to CAN/DGSI:104

These eight steps follow the structure of the CAN/DGSI:104 standard, covering organizational controls (Section 4), baseline technical controls (Section 5), and environment-specific controls (Section 6). Section references are current to the second revision of the standard, published July 2026, which kept this structure intact.

1

Assess Your Current Security Posture

Before implementing new controls, evaluate your existing cybersecurity protections and identify gaps. CAN/DGSI:104 (Section 4.4) requires a formal cyber security risk assessment that considers the threats your organization faces and the potential impact of a breach.

  • Review user account protections, device security, and email defences
  • Assess backup and recovery practices
  • Identify which Section 6 environment-specific controls apply to your organization
  • Document existing gaps and prioritize them by risk

Many organizations discover they already meet some requirements but need improvements in others.

Take the Readiness Assessment
2

Establish Leadership, Governance and Policies

CAN/DGSI:104 requires organizational controls to be in place before technical controls can be effective (Sections 4.1–4.2). Leadership must take ownership of cybersecurity, and clear policies must be documented covering:

  • Acceptable use of systems and devices
  • Password and authentication requirements
  • Data protection and classification practices
  • Incident reporting procedures
  • Roles and responsibilities for cybersecurity

Tip: Keep policies practical and written in plain language. A named senior person must be accountable for cybersecurity — not just the IT team.

3

Develop Your Incident Response Plan

Section 5.1 of CAN/DGSI:104 places the incident response plan as the first baseline control — reflecting that organizations need to know how to respond to incidents before one occurs. A solid plan defines:

  • How incidents are identified and reported internally
  • Who is responsible for responding and making decisions
  • How systems are contained, recovered, and restored
  • How communication with employees, clients, and regulators occurs

Important: Keep a printed copy of the plan. If systems are compromised, you need access to the plan even when technology is unavailable.

4

Patch Systems and Harden Device Configurations

Unpatched software and misconfigured devices are among the most common causes of successful cyber attacks. Sections 5.2–5.4 require organizations to:

  • Enable automatic updates on all operating systems and applications
  • Apply patches to servers, laptops, desktops, tablets, phones, and network equipment
  • Enable security software including antivirus and endpoint detection
  • Harden device configurations based on recognized security benchmarks (such as CIS Controls)

Keeping systems updated closes known vulnerabilities before attackers can exploit them.

5

Protect User Accounts and Access

Compromised credentials are one of the most frequent causes of breaches. Sections 5.5 and 5.8 require strong authentication and access control practices:

  • Enable multi-factor authentication (MFA) for all accounts
  • Enforce strong password policies across all systems
  • Apply the principle of least privilege: grant only the access each role requires
  • Remove or disable unused accounts promptly
  • Restrict administrative privileges to authorized users only

Priority action: Enabling MFA on all email and business application accounts is one of the single most impactful improvements an organization can make.

6

Implement Reliable Backups and Network Defences

Sections 5.6 and 5.7 address data resilience and perimeter security. Organizations should ensure:

  • Critical data is backed up regularly and stored separately from production systems
  • Backup copies are protected from modification or deletion (immutable backups)
  • Backup restoration procedures are tested regularly
  • Firewalls and perimeter controls restrict unauthorized network access
  • Remote access is secured with strong authentication

3-2-1 Backup Rule: Maintain 3 copies of your data, on 2 different types of media, with 1 stored offsite or in the cloud.

7

Address Environment-Specific Controls

Section 6 of CAN/DGSI:104 includes controls that apply depending on how your organization operates. Review which of the following apply to your environment:

  • Mobile devices (6.1): Policies, MDM enrollment, and remote wipe for phones and tablets used for work
  • Cloud and outsourced IT (6.2): Vendor risk assessments and contractual security requirements
  • Websites and web applications (6.3): Awareness of OWASP Top 10 vulnerabilities and regular testing
  • Portable media (6.4): Restrictions on USB drives and encryption requirements
  • Point of sale and financial systems (6.5): Segregation and additional controls for payment environments
  • Log management (6.6): Collecting and reviewing system logs to detect threats early

Many small businesses will need several of these controls. Identifying which apply early prevents gaps from developing.

8

Train Your Team and Build a Security Culture

Section 4.3 of CAN/DGSI:104 requires ongoing cybersecurity awareness training for all staff. People are frequently targeted by phishing, social engineering, and credential theft. Training should cover:

  • How to recognize phishing emails and suspicious messages
  • Safe handling of passwords and sensitive data
  • Acceptable use of company devices and systems
  • How to report a suspected security incident
  • The principle of least privilege and why access is restricted

Regular training — including simulated phishing exercises — significantly reduces the risk of human error enabling attacks.

Note: Training is not a one-time event. The standard requires ongoing awareness as threats evolve and new employees join.

Common Hurdles

Common Implementation Challenges

Organizations implementing CAN/DGSI:104 often encounter the following challenges. Addressing them typically requires a structured strategy, often with the support of a managed security services provider.

Limited Internal Cybersecurity Expertise

Most SMBs don't have a dedicated security team. Implementation often falls to IT generalists or business owners without specialized security knowledge.

Inconsistent Security Practices Across Systems

Organizations that have grown without a formal security program often have different tools and configurations across departments, making a consistent baseline harder to establish.

Lack of Visibility Into Devices and Applications

Many organizations don't have a complete picture of what devices, software, and accounts exist in their environment — a prerequisite for securing them.

Difficulty Prioritizing Security Improvements

With limited time and budget, deciding which controls to tackle first is challenging. Without structure, organizations often focus on visible issues rather than the highest risks.

Budget and Resource Constraints

Security investments compete with other business priorities. CAN/DGSI:104 is designed to be achievable without large budgets, but some controls still require investment in tools or services.

Employee Resistance to New Security Requirements

Controls like MFA, password policies, and acceptable use restrictions can feel burdensome. Building a security culture takes time and consistent support from leadership.

Keeping Up With Ongoing Patching and Updates

Section 5.2 requires patch management across all devices. Mixed environments and legacy systems can make consistent, timely patching operationally demanding — yet it remains one of the most effective defences against known vulnerabilities.

Many organizations address these challenges by partnering with a cybersecurity-focused MSP. MTech Cyber helps Canadian SMBs implement CAN/DGSI:104 controls without needing an in-house security team.

Framework Structure

You Don't Have to Do Everything at Once

Level 1: Foundational

Establishes essential protections such as patch management, employee training, backups, and basic access controls. The right starting point for most organizations.

Level 2: Advanced

Builds on the foundation with stronger monitoring, more formal security processes, and greater visibility across systems. Progress to Level 2 as your program matures.

Learn About Maturity Levels
Getting Started

Next Steps for Implementing CAN/DGSI:104

Organizations that want to improve their cybersecurity posture often begin with a readiness assessment to evaluate existing protections and identify gaps.

📊

Step 1: Assess Your Readiness

Use our free 21-question readiness assessment aligned with Annex B of CAN/DGSI:104 to evaluate your current protections and receive a personalized score with specific recommendations.

Start Assessment

Step 2: Review the Checklist

Work through the detailed CAN/DGSI:104 checklist to identify which controls are in place and which require attention.

View Checklist
🛡

Step 3: Review Each Control

Once gaps are identified, review the detailed controls guide to understand what each control requires and how organizations typically implement it.

View Controls Guide