A practical guide to implementing the cybersecurity controls recommended by CAN/DGSI:104, without needing a large internal security team.
Implementing CAN/DGSI:104 does not require building a large internal cybersecurity team. The framework focuses on practical security controls that organizations can adopt to reduce cyber risk and protect their operations.
Most businesses already have some protections in place. The goal is to ensure those protections are implemented consistently and that important security gaps are addressed.
The following steps provide a structured approach for implementing CAN/DGSI:104.
Assessment, leadership, governance, and incident response plan
Patch management, endpoint security, secure configuration, and access controls
Backups, network defences, and employee training
Email security, monitoring, and environment-specific controls
These eight steps follow the structure of the CAN/DGSI:104 standard, covering organizational controls (Section 4), baseline technical controls (Section 5), and environment-specific controls (Section 6). Section references are current to the second revision of the standard, published July 2026, which kept this structure intact.
Before implementing new controls, evaluate your existing cybersecurity protections and identify gaps. CAN/DGSI:104 (Section 4.4) requires a formal cyber security risk assessment that considers the threats your organization faces and the potential impact of a breach.
Many organizations discover they already meet some requirements but need improvements in others.
Take the Readiness AssessmentCAN/DGSI:104 requires organizational controls to be in place before technical controls can be effective (Sections 4.1–4.2). Leadership must take ownership of cybersecurity, and clear policies must be documented covering:
Tip: Keep policies practical and written in plain language. A named senior person must be accountable for cybersecurity — not just the IT team.
Section 5.1 of CAN/DGSI:104 places the incident response plan as the first baseline control — reflecting that organizations need to know how to respond to incidents before one occurs. A solid plan defines:
Important: Keep a printed copy of the plan. If systems are compromised, you need access to the plan even when technology is unavailable.
Unpatched software and misconfigured devices are among the most common causes of successful cyber attacks. Sections 5.2–5.4 require organizations to:
Keeping systems updated closes known vulnerabilities before attackers can exploit them.
Compromised credentials are one of the most frequent causes of breaches. Sections 5.5 and 5.8 require strong authentication and access control practices:
Priority action: Enabling MFA on all email and business application accounts is one of the single most impactful improvements an organization can make.
Sections 5.6 and 5.7 address data resilience and perimeter security. Organizations should ensure:
3-2-1 Backup Rule: Maintain 3 copies of your data, on 2 different types of media, with 1 stored offsite or in the cloud.
Section 6 of CAN/DGSI:104 includes controls that apply depending on how your organization operates. Review which of the following apply to your environment:
Many small businesses will need several of these controls. Identifying which apply early prevents gaps from developing.
Section 4.3 of CAN/DGSI:104 requires ongoing cybersecurity awareness training for all staff. People are frequently targeted by phishing, social engineering, and credential theft. Training should cover:
Regular training — including simulated phishing exercises — significantly reduces the risk of human error enabling attacks.
Note: Training is not a one-time event. The standard requires ongoing awareness as threats evolve and new employees join.
Organizations implementing CAN/DGSI:104 often encounter the following challenges. Addressing them typically requires a structured strategy, often with the support of a managed security services provider.
Most SMBs don't have a dedicated security team. Implementation often falls to IT generalists or business owners without specialized security knowledge.
Organizations that have grown without a formal security program often have different tools and configurations across departments, making a consistent baseline harder to establish.
Many organizations don't have a complete picture of what devices, software, and accounts exist in their environment — a prerequisite for securing them.
With limited time and budget, deciding which controls to tackle first is challenging. Without structure, organizations often focus on visible issues rather than the highest risks.
Security investments compete with other business priorities. CAN/DGSI:104 is designed to be achievable without large budgets, but some controls still require investment in tools or services.
Controls like MFA, password policies, and acceptable use restrictions can feel burdensome. Building a security culture takes time and consistent support from leadership.
Section 5.2 requires patch management across all devices. Mixed environments and legacy systems can make consistent, timely patching operationally demanding — yet it remains one of the most effective defences against known vulnerabilities.
Many organizations address these challenges by partnering with a cybersecurity-focused MSP. MTech Cyber helps Canadian SMBs implement CAN/DGSI:104 controls without needing an in-house security team.
Establishes essential protections such as patch management, employee training, backups, and basic access controls. The right starting point for most organizations.
Builds on the foundation with stronger monitoring, more formal security processes, and greater visibility across systems. Progress to Level 2 as your program matures.
Organizations that want to improve their cybersecurity posture often begin with a readiness assessment to evaluate existing protections and identify gaps.
Use our free 21-question readiness assessment aligned with Annex B of CAN/DGSI:104 to evaluate your current protections and receive a personalized score with specific recommendations.
Start AssessmentWork through the detailed CAN/DGSI:104 checklist to identify which controls are in place and which require attention.
View ChecklistOnce gaps are identified, review the detailed controls guide to understand what each control requires and how organizations typically implement it.
View Controls Guide