FAQ
Answers, plain and simple.
Answers to common questions about our IT services, pricing, and how we work.
Services & Support
What does managed IT services include?
Our managed IT plans include 24/7 monitoring, patch management, helpdesk support, cybersecurity protection, backup management, and regular technology reviews. We proactively maintain your systems so issues are caught before they cause downtime.
Every plan is tailored to the size and complexity of your environment — there's no one-size-fits-all package.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think
How quickly do you respond to support requests?
We start work on a critical issue within one hour at any hour, on any day, at no extra charge — that is the response-time guarantee in the agreement. Our operational targets are to acknowledge a critical incident within 15 minutes and give hourly progress updates; those communication targets are separate from the response-time guarantees in your signed agreement. Standard tickets are started within 4 business hours. High-priority tickets are started within 2 business hours. We also publish resolution targets: 2 business days on a high-priority ticket, 5 on a standard one, and 10 on a service request (additions, moves and changes are excluded from the contractual response-time guarantee), with the clock pausing while we wait on a vendor, on parts, or on a decision from you. 24/7 intake is available through our AI assistant, online ticketing, a toll-free line, and live chat. Critical and high-priority issues must be reported by phone, which is what the response-time guarantee in the service agreement requires.
A critical incident is worked within one hour at any hour, on any day, at no extra charge. Non-critical work you ask us to do outside business hours is billed at C$250/hour. You can reach us by phone, email, or through the client portal.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think.
Do you offer on-site support?
Yes. While most issues are resolved remotely within minutes, on-site visits are available for Thunder Bay area clients. Hardware installs, network cabling, server deployments, and hands-on troubleshooting all include on-site service.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think.
Do you support remote and hybrid offices?
Absolutely. We manage remote workstations, VPNs, cloud applications, and mobile devices. Many of our Northern Ontario clients have staff working from multiple locations — our tools and processes are built for distributed teams.
Read more: BYOD Security Without Killing Productivity: A Practical Guide for Northern Ontario Businesses
Can you help with one-time projects instead of ongoing support?
Yes. We take on project-based work including network upgrades, server migrations, office moves, security assessments, and cloud deployments. No ongoing contract required — though most project clients end up staying.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think.
What is a virtual CIO and is it included?
A virtual CIO provides strategic IT planning, quarterly technology reviews, and a roadmap that aligns your technology investments with your business goals. Many of our managed IT plans include vCIO services — giving small businesses access to executive-level IT strategy without hiring a full-time CIO.
Read more: What a Virtual CIO Actually Does — And Why Growing Businesses Need One
How much does IT downtime cost a small business?
Industry estimates put small business downtime costs at hundreds of dollars per minute. Combined with ransomware incidents averaging $25,000–$50,000 per incident according to Canadian cybersecurity reports, unmanaged IT represents a significant financial risk — even for small organizations.
Read more: Why Small Businesses Need Managed IT
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
Pricing & Contracts
How is managed IT priced?
Managed IT starts with a C$500 monthly base fee, plus a bundle for each user. The base covers helpdesk labour, remote monitoring and management, and operational tooling.
Each user's bundle includes:
- Microsoft 365 licensing suited to their role
- Endpoint detection and response (EDR)
- Identity threat detection and response (ITDR)
- DNS filtering and web protection
- Microsoft 365 mailbox backup
Bundle rates: Business Basic C$30.64, Business Standard C$42.04, Business Premium C$55.00 per user per month, each covering up to 3 devices. Other Microsoft subscriptions are quoted separately. Your organization can mix subscriptions across users. Infrastructure and additional services are billed separately at cost plus 20%; project labour and after-hours support at published hourly rates. Prices exclude HST.
See published pricing, build your quote for an itemized estimate, or contact us for a written proposal.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think
What is the difference between per-user and per-device pricing?
Per-user pricing covers each employee rather than each machine. At DVG Systems one user bundle covers up to 3 devices for that person — desktop, laptop, and phone — at one rate. Per-device charges for every managed device separately, which gets complicated when staff use multiple devices.
Per-user is the more common modern model and scales more cleanly. It's the model we use at DVG Systems: a C$500 base fee plus one bundle per user, priced by that user's Microsoft 365 subscription.
Read more: How Much Does Managed IT Cost?
Is managed IT cheaper than hiring an in-house IT person?
In most cases, yes. A single in-house IT employee in Ontario costs roughly $88,000–$128,000 per year including salary, benefits, training, and tools. For the same investment, a managed IT provider gives you a full team — helpdesk technicians, network engineers, security specialists, and strategic planning — with no single point of failure.
In Northern Ontario, the IT talent pool is smaller than the GTA, making hiring and retention even harder. Managed IT solves both the cost and the talent problem.
Read more: How Much Does Managed IT Cost?
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think
What hidden costs should I watch for in managed IT quotes?
Most MSPs (DVG Systems included) bill some things outside the monthly retainer — projects, onsite visits, hardware. The question is whether the rates are written down before you need them. Surprises at invoice time mean those rates weren't disclosed up front.
Ask any provider for: onboarding fee structure, project hourly rate, onsite visit rate, hardware markup percentage, and contract minimums.
DVG Systems publishes ours: project work C$150/hr, onsite visits C$175/hr, infrastructure and hardware at cost plus 20%, non-critical work requested after hours C$250/hr. A P1 critical incident carries no after-hours charge.
Read more: How Much Does Managed IT Cost?
What is the minimum monthly engagement?
Every managed IT plan starts with the C$500 monthly base fee, which covers helpdesk labour, remote monitoring and management, and operational tooling. Each supported user then adds one per-user bundle.
Small teams are welcome. The base fee is the same whether you have two users or twenty. Use build your quote to tell us your team size and subscriptions, and we'll send an itemized proposal.
Read more: How Much Does Managed IT Cost?
Is Microsoft 365 Business Premium included for everyone?
Microsoft 365 licensing is assigned by user role. One organization can mix Business Basic (C$30.64 bundle), Business Standard (C$42.04) and Business Premium (C$55.00) users. Your quote identifies each user's licence, the applicable rate, and the features available to them. Every bundle carries the same DVG protection.
Business Basic users do not automatically receive Business Premium features such as desktop Office apps, Intune device management, or Defender for Business. See what's included for the two editions side by side.
Is endpoint and identity protection an optional add-on?
No. Endpoint detection and response (EDR) and identity threat detection and response (ITDR) are included in every user bundle. They are part of the bundle price, not add-ons.
Is backup included?
Mailbox backup is included in the user bundle. Server backup is a separate service. Your proposal specifies the protected systems, data, retention, and recovery scope.
Read more: Why Your Microsoft 365 Data Needs Backup
How are Azure and additional products billed?
Azure and separately quoted products are billed at cost plus 20%. Your proposal identifies these charges separately from the managed IT base fee and user bundles.
Azure consumption is billed monthly in arrears from your prior-month usage, so the line moves with what you actually run.
Read more: Canadian Data Sovereignty: What Ontario Businesses Need to Know About US Cloud.
Do you charge for hardware procurement?
Hardware is sourced at our cost plus 20%, which covers sourcing, configuration, asset tagging, and warranty registration. The markup is disclosed on every hardware quote.
You can see the underlying vendor invoice on request.
What should I ask when evaluating a managed IT provider?
Key questions to ask any provider:
- What is the response time SLA — in writing?
- Is the rate card published — including project hourly, onsite, hardware markup, and after-hours?
- Do they offer proactive monitoring, or just break-fix?
- Are they local enough for on-site support when needed?
- Do they understand your industry's compliance requirements?
- Can you talk to a current client?
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think
Do you require long-term contracts?
Our managed IT agreements are month-to-month. Microsoft 365 licences inside the user bundle carry their own subscription terms, so licence reductions follow the applicable subscription commitment and renewal dates rather than taking effect immediately. Your proposal states the term for each subscription.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think.
Are there extra charges for after-hours support?
A critical incident — a site down, a core system unavailable, or a confirmed security incident — is worked within one hour at any hour, on any day, at no extra charge. If you ask us to work a non-critical ticket outside business hours, that is billed at C$250/hour. Planned out-of-hours work such as a migration or a cutover is quoted at the project rate in advance, not the emergency rate.
Read more: How Much Does Managed IT Cost?
Getting Started
How does onboarding work?
Initial go-live — monitoring agents, backups, and the support portal — typically takes 2–4 weeks. The full 120-day process covers hardening, staff training, and optimization:
- Discovery — We audit your current environment, document systems, and identify risks.
- Proposal — You receive a detailed plan with transparent pricing.
- Deployment — We install monitoring agents, configure backups, and set up your support portal.
- Handoff — Your team gets a walkthrough of how to reach us and what to expect.
You have a named onboarding lead for the duration of onboarding, and you deal with the same small team throughout.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think.
Can you take over from our current IT provider?
Yes — we handle provider transitions regularly. We'll coordinate with your outgoing provider (or work independently if needed), ensure no service gaps, and document everything properly from day one.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think.
What areas do you serve?
We're based in Thunder Bay and serve businesses across Northwestern Ontario — including Nipigon, Marathon, Geraldton, Timmins, Kirkland Lake, Matheson, and surrounding communities.
Most support is delivered remotely, with on-site visits available in the Thunder Bay area.
Read more: Why Small Businesses Need Managed IT.
Security & Compliance
How do you protect our data?
We deploy business-grade security tools including endpoint protection, DNS filtering, email security, and network firewalls. All managed systems are monitored 24/7 for threats.
We follow security best practices including multi-factor authentication enforcement, least-privilege access, and encrypted backups.
Read more: Zero Trust Security for Small Business: What It Actually Means (and What It Doesn't)
Can you help with compliance requirements?
Yes. We work with clients in healthcare, legal, and nonprofit sectors who have specific compliance needs (PHIPA, PIPEDA, CRA requirements). We help implement the technical controls required and provide documentation for audits.
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
Read more: Should Canadian Businesses Be Worried About Storing Data in U.S. Cloud Services?
What happens if we experience a cyberattack?
Managed clients have an incident response plan in place before anything happens. Response has four separate activities: monitoring (Huntress and our RMM raise the alert), containment (affected devices or accounts are isolated as quickly as the situation allows), investigation (we establish what was accessed and how), and recovery (systems and data are restored from backup where needed). Each stage is communicated to you as it happens.
No provider can promise to contain every attack instantly. What we promise is a defined process and clear communication.
Read more: Cybersecurity for SMBs
Read more: How to Build an Incident Response Playbook Your Team Will Actually Use
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
What should I do if I think my Microsoft 365 account has been compromised?
Take these steps immediately:
- Stop using the affected device
- Contact your IT team or provider
- Reset the compromised account's password and revoke all active sessions
- Review sent email for messages the attacker may have sent on your behalf
- Notify any contacts who may have received fraudulent messages
- Contact your bank if financial information was exposed
Read more: Device Code Phishing: The M365 Attack That Bypasses MFA
Read more: How One Compromised Inbox Leads to a Six-Figure Wire Fraud
What are Conditional Access Policies in Microsoft 365?
Conditional Access Policies control who can sign in to your Microsoft 365 environment and under what conditions — restricting by location, device compliance, and risk level. They are a critical layer of defence against token theft and phishing attacks that bypass MFA.
Read more: Zero Trust Security for Small Business: What It Actually Means (and What It Doesn't)
Does my business need cyber insurance?
Cyber insurance is increasingly recommended for businesses of all sizes, but the policy is only as good as the security posture behind it. Most cyber insurance applications now require specific controls — multi-factor authentication, endpoint protection, email filtering, and an incident response plan — before they'll issue a policy.
Your MSP should be able to help you meet these requirements and provide documentation for your application. The real value of cyber insurance is covering costs that security controls can't prevent entirely: legal fees, notification costs, business interruption, and forensic investigation after a breach.
Read more: Cybersecurity for SMBs: Cyber Insurance and Your MSP
Read more: How to Build an Incident Response Playbook Your Team Will Actually Use
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
What are SPF, DKIM, and DMARC, and does my business need them?
SPF, DKIM, and DMARC are three email authentication controls that prevent attackers from spoofing your business domain — sending emails that appear to come from you but don't. Without them, anyone can send phishing emails using your domain name to your clients, staff, and suppliers.
SPF defines which mail servers are authorized to send on your behalf. DKIM adds a cryptographic signature verifying the email hasn't been tampered with. DMARC ties them together with an enforcement policy. Google and Yahoo now require DMARC for bulk senders. Your MSP should have all three configured and actively monitored.
Read more: Why Your Business Email is Probably Being Spoofed Right Now
What is DNS filtering and does my business need it?
DNS filtering blocks malicious websites, phishing pages, and malware downloads before they ever reach your devices — at the DNS query level, before any connection is established. One in every 174 DNS requests is malicious according to DNSFilter's 2025 report.
Unlike antivirus which catches threats after they arrive, DNS filtering prevents the connection from happening in the first place. It covers every device on your network, catches threats that email filters miss (phishing links from Teams, SMS, or search results), and can stop ransomware from communicating with its command servers. It's one of the highest-value security controls an MSP can deploy.
Why every MSP doesn't include it: DNS filtering runs roughly $2 per user per month but requires ongoing tuning — allow-lists, reporting review, and coverage for remote devices via agent. Many break-fix or reactive providers skip it because it's invisible when it works. DVG Systems includes DNS filtering and web protection in every user bundle, so it is never an add-on.
Read more: DNS Filtering Explained
What is Microsoft Defender for Business and do we need it?
Microsoft Defender for Business is an enterprise-grade endpoint protection platform designed for businesses with up to 300 users. It goes far beyond basic antivirus — it includes Endpoint Detection and Response (EDR), automated investigation and remediation, vulnerability management, and attack surface reduction rules.
It covers Windows, macOS, iOS, and Android devices. It's available as a standalone add-on for $4.10 CAD per user per month, or included at no extra cost with Microsoft 365 Business Premium. If your business runs Microsoft 365, this is the endpoint protection your MSP should have deployed.
Read more: Microsoft Defender for Business: Is the Built-In EDR Good Enough?
Is Microsoft Defender for Business the same as Windows Defender?
No. Windows Defender is the basic antivirus built into Windows 10 and 11 — it scans for known malware. Microsoft Defender for Business is a full endpoint protection platform that includes behavioural threat detection (EDR), automated remediation, device isolation during attacks, vulnerability scanning, and attack surface reduction rules.
It uses the same detection engine that earned Microsoft recognition as a Gartner Magic Quadrant Leader for six consecutive years and achieved 100% detection coverage in the 2024 MITRE ATT&CK Evaluations. They share a name but are fundamentally different products.
Read more: Microsoft Defender for Business: Is the Built-In EDR Good Enough?
If we already pay for Microsoft 365 Business Premium, do we need to buy extra endpoint protection?
No. Defender for Business is included in Microsoft 365 Business Premium. If you're on Business Basic or Standard, standalone Defender for Business is about $4.10 CAD per user per month.
But owning the licence is not the same as having it deployed — it needs onboarding, policy configuration, and attack-surface-reduction rules turned on to actually protect you. DVG Systems handles this as standard for managed clients.
Read more: Microsoft Defender for Business: Is the Built-In EDR Good Enough?
Is Zero Trust realistic for a 20-person business, or is it only for enterprises?
It's realistic. Zero Trust is a security model, not a product, and most small businesses running Microsoft 365 Business Premium already own the core tools — Conditional Access, Intune, Entra ID, and Defender.
Start with MFA everywhere (Microsoft's own data shows MFA blocks 99.2% of account-compromise attacks), then add Conditional Access policies and Intune device compliance. That's most of the value for most SMBs.
Read more: Zero Trust Security for Small Business: What It Actually Means (and What It Doesn't)
Is my Canadian client data safe in Microsoft 365 even though Microsoft is an American company?
For most Canadian SMBs, yes — if your tenant is configured for Canadian data residency, core Microsoft 365 data (Exchange, SharePoint, OneDrive, Teams) lives in the Toronto and Quebec City datacentres.
The U.S. CLOUD Act can compel Microsoft to produce data, but requires a valid warrant with probable cause, and Microsoft has publicly committed to challenging CLOUD Act requests that conflict with Canadian law. Regulated industries should verify residency in the Microsoft 365 Admin Centre and consider the Advanced Data Residency add-on.
Read more: Should Canadian Businesses Be Worried About Storing Data in U.S. Cloud Services?
What is the difference between PIPEDA and PHIPA, and which applies to my business?
PIPEDA is Canada's federal private-sector privacy law and covers personal information used in commercial activity. PHIPA is Ontario's Personal Health Information Protection Act and governs personal health information held by health information custodians (clinics, physicians, pharmacies, long-term care).
A clinic is usually under PHIPA for patient records and PIPEDA for everything else; a non-clinical business is under PIPEDA only. Both laws require specific safeguards and impose breach-notification duties.
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses.
Data Breach & Class-Action Risk
Does my Ontario business have to report small breaches to the Privacy Commissioner?
Only breaches with a "real risk of significant harm" (RROSH) must be reported to the Office of the Privacy Commissioner of Canada and to affected individuals under PIPEDA.
But you must keep an internal record of every breach of security safeguards for at least 24 months regardless — the OPC can request them at any time. PHIPA custodians in Ontario have an equivalent notice obligation with additional reporting to the Ontario Information and Privacy Commissioner (IPC) for significant breaches.
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
Can my business be sued in a class action after a data breach?
Yes. Jones v. Tsige (Ontario Court of Appeal, 2012) established the intrusion-upon-seclusion tort in Ontario, and Canadian breach-related class actions have grown since — Desjardins settled for $201M, LifeLabs litigation is ongoing.
Even unsuccessful class actions typically cost $500,000–$2M in defence fees alone, which is why cyber insurance with regulatory-defence coverage matters as much as technical controls do.
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
Phishing & Email Security
Does MFA protect against phishing?
MFA stops stolen password attacks, credential stuffing, and password spraying. But it's not enough on its own.
Advanced techniques like device code phishing and adversary-in-the-middle (AiTM) attacks can intercept MFA tokens in real time. That's why we recommend a layered approach: MFA + security awareness training + email filtering + DNS protection + identity threat monitoring like Huntress ITDR.
Read more: Device Code Phishing: The M365 Attack That Bypasses MFA
Read more: 5 Social Engineering Tactics Hitting Northern Ontario Businesses Right Now
What is device code phishing?
Device code phishing directs you to Microsoft's real, legitimate login page (microsoft.com/devicelogin) and asks you to enter a code. When you authenticate, you're unknowingly authorizing the attacker's device to access your account. Because the login page is genuinely Microsoft's, most users don't think twice — and because the attacker gets an OAuth token, standard MFA doesn't stop it.
Rule of thumb: If anyone asks you to go to microsoft.com/devicelogin and enter a code, stop and verify with IT first.
Read more: Device Code Phishing: The M365 Attack That Bypasses MFA
What is adversary-in-the-middle (AiTM) phishing?
AiTM phishing captures not just your password but your active session token when you authenticate through a fake login page. The attacker replays that token to access your account without completing MFA again.
This is why MFA alone is not sufficient — you also need identity threat monitoring (like Huntress ITDR) and Conditional Access Policies.
Read more: Device Code Phishing: The M365 Attack That Bypasses MFA
Are AI-generated phishing emails a real threat?
Yes. Current phishing campaigns use AI to generate personalized, well-written emails with no spelling mistakes or awkward phrasing. Traditional "look for bad grammar" training is becoming obsolete.
Businesses need technical controls like identity monitoring and email filtering alongside updated security awareness training.
Read more: 5 Social Engineering Tactics Hitting Northern Ontario Businesses Right Now
What is phishing-resistant MFA (FIDO2 / Windows Hello)?
FIDO2 security keys and Windows Hello are authentication methods that are immune to token theft attacks. Unlike standard MFA (text codes or authenticator app approvals), these methods are cryptographically bound to the legitimate site, so they cannot be intercepted by an attacker-in-the-middle.
Read more: Device Code Phishing: The M365 Attack That Bypasses MFA
What is Huntress ITDR?
Huntress Identity Threat Detection and Response monitors your Microsoft 365 tenant 24/7 for suspicious sign-ins, impossible travel, and token abuse. When threats are identified, Huntress can automatically deploy Conditional Access Policies and block attacker infrastructure before your organization is compromised.
Identity threat detection and response is part of every DVG Systems user bundle — it's not an add-on.
Read more: Cybersecurity for SMBs
Are construction companies being targeted by phishing scams?
Yes. A targeted phishing campaign across Canada is hitting construction firms with fake Microsoft login pages. Attackers pose as project managers or suppliers, capture credentials and session tokens in real time, and can bypass MFA entirely.
Once inside, they intercept payment instructions, impersonate staff, and redirect funds. Construction is targeted because of the high-value transactions and volume of external communication.
Read more: Construction Industry Phishing Scam
Read more: How One Compromised Inbox Leads to a Six-Figure Wire Fraud
Read more: 5 Social Engineering Tactics Hitting Northern Ontario Businesses Right Now
Why does my business need a password manager?
Reused passwords are the most common way businesses get breached. A password manager generates strong, unique passwords for every account, stores them in an encrypted vault, and auto-fills them for your team.
For businesses, look for one with a centralized admin console, shared vaults for team credentials, dark web monitoring, and proper offboarding controls so you can rotate credentials when employees leave.
Read more: The Business Case for a Password Manager
Is Chrome or Edge's built-in password manager good enough for business?
No. Browser password managers lack centralized admin control, shared vaults, dark web monitoring, and proper offboarding controls. When an employee leaves, their saved passwords go with them — or stay on a device you can't control.
A dedicated business password manager gives IT visibility and control over all credentials.
Read more: The Business Case for a Password Manager
How do you offboard an employee's passwords when they leave?
A business password manager with an admin console shows you exactly which credentials a departing employee had access to, so you can rotate them systematically. Without one, you have no central record of which vendor portals, banking logins, social media accounts, or Wi-Fi passwords they knew.
Read more: When Employees Leave
Should employees have admin rights on their work computers?
In most cases, no. Local admin rights let users install software and change system settings — but they also let malware do the same thing. The difference between a contained incident and a full network compromise often comes down to whether the affected user had admin rights.
We deploy standard user accounts by default and handle software installs centrally. Elevation requests are handled remotely, usually within minutes.
Read more: Should Employees Have Admin Rights?
What happens when employees have admin rights and malware strikes?
When an admin user clicks a malicious link, the malware can install itself system-wide, disable antivirus, create new accounts, and spread across the network. When a standard user does the same, the damage is contained to what that user account can access.
Read more: Should Employees Have Admin Rights?
How do you handle software install requests without giving admin rights?
Pre-approved software is deployed centrally through our management tools. When a legitimate need arises — a new printer driver or niche application — we handle the installation remotely in minutes with an audit trail. In rare cases like developer roles, time-limited elevation with logging can be granted.
Read more: Should Employees Have Admin Rights?
Are email disclaimers legally required in Canada?
No Canadian law requires a disclaimer on every business email. However, CASL requires specific content in commercial/marketing emails: your business name, mailing address, contact info, and a working unsubscribe mechanism. Penalties are up to $10 million per violation.
For regulated professions (legal, healthcare, accounting), professional body rules effectively make confidentiality disclaimers necessary.
Read more: Email Disclaimers in Microsoft 365
What does CASL require in commercial emails?
Canada's Anti-Spam Legislation requires every commercial or marketing email to include: your business name, a valid mailing address, a phone number or email or website, and a working unsubscribe mechanism that stays active for at least 60 days. Penalties are up to $10 million per violation.
Read more: Email Disclaimers in Microsoft 365.
How do I set up email disclaimers in Microsoft 365?
You can use Microsoft 365's built-in mail flow rules (Exchange Admin Center > Mail flow > Rules) for basic disclaimers. These work but have limitations — disclaimers stack in threads, formatting can break on mobile, and you can't vary them by department.
For more complex needs, third-party tools like Exclaimer or CodeTwo offer per-department disclaimers, consistent formatting, and audit logging.
Read more: Email Disclaimers in Microsoft 365
A supplier just emailed new banking details for their invoice — how do we verify it's legitimate?
Phone the supplier using a number you already have on file — not one from the email or their signature — confirm the change verbally, and document who you spoke to.
Once a fraudulent wire transfer clears, recovery rates are under 30% and the window to act is often just 24–48 hours. Standing policy for every organization: any change to payment instructions must be verified through a separate, pre-agreed channel.
Read more: How One Compromised Inbox Leads to a Six-Figure Wire Fraud
Business Continuity
What happens to my business when IT goes down?
IT downtime affects more than just email. When systems go down, staff can't access files, phones may stop working, payment processing halts, and customer-facing services go offline. Industry estimates put small business downtime costs at hundreds of dollars per minute.
The businesses that recover quickly are the ones that planned for it — with tested backups, documented recovery procedures, and an MSP that knows their environment. A business continuity plan doesn't prevent outages, but it determines whether a disruption costs you an hour or a week.
Read more: What Happens When Your IT Goes Down?
Read more: How to Build an Incident Response Playbook Your Team Will Actually Use
Read more: Your Backups Are Useless If You've Never Tested Them
Backup & Data Protection
Does Microsoft 365 back up my data?
No. Under Microsoft's Shared Responsibility Model, they manage the infrastructure but you're responsible for your data. Their own Services Agreement (clause 6B) recommends you back up with a third-party. Default deleted item retention in Exchange Online is just 14 days — extendable to a maximum of 30 days via PowerShell, but most businesses never configure this. After that window, the data is gone.
That's why we include Dropsuite cloud backup for every managed client.
Read more: Why Your Microsoft 365 Data Needs Backup
Read more: Your Backups Are Useless If You've Never Tested Them
What is Microsoft's Shared Responsibility Model?
Microsoft manages the infrastructure — uptime, data centre security, physical redundancy. But you are responsible for your data. Their Services Agreement (clause 6B) explicitly recommends backing up with a third party. Default deleted item retention in Exchange Online is only 14 days.
Read more: Why Your Microsoft 365 Data Needs a Backup
Read more: Your Backups Are Useless If You've Never Tested Them
What is eDiscovery and does my backup include it?
eDiscovery lets you search across historical email and files for legal matters, regulatory inquiries, or internal investigations. Dropsuite includes eDiscovery as a built-in feature with no add-on licensing — search all backed-up mailboxes, apply date ranges and keyword filters, and export results.
Read more: Why Your Microsoft 365 Data Needs Backup.
What does Dropsuite back up and how often?
Dropsuite is capable of backing up your wider Microsoft 365 (and Google Workspace) environment:
- Email — 12 times per day (every 2 hours)
- SharePoint, Teams, and Groups — 3 times daily
- OneDrive, Calendars, Contacts, and Tasks — once daily
- Email Archiving — real-time (not on a schedule)
That is what the platform is capable of. What the DVG user bundle includes is Microsoft 365 mailbox backup. Backup of OneDrive, SharePoint and Teams content, and server backup, require the applicable separately agreed scope and are quoted in your proposal.
Read more: Why Your Microsoft 365 Data Needs Backup
Read more: Your Backups Are Useless If You've Never Tested Them
Is there a storage limit on Dropsuite backups?
The backup platform itself imposes no storage cap and supports retention policies from 30 days to 11 years at the mailbox or individual file level, so your backup grows alongside your data. The retention period contracted for your organization is set in your proposal and service agreement.
Read more: Why Your Microsoft 365 Data Needs Backup.
Can I delete old backup data if I need to?
Yes. Dropsuite's archival tool lets you trim and purge data — something no other backup vendor on our line card offers. Most backup solutions are write-only. Dropsuite gives you full lifecycle control over your backed-up data.
Read more: Why Your Microsoft 365 Data Needs Backup.
How is backup data secured?
All backups are protected with AES-256 bit encryption — both in transit and at rest. Dropsuite also includes built-in eDiscovery for legal and compliance searches across historical email and files, with no add-on licensing required.
Read more: Why Your Microsoft 365 Data Needs a Backup
Read more: Should Canadian Businesses Be Worried About Storing Data in U.S. Cloud Services?
How often should we actually test our backups?
Minimum cadence:
- Full system restore — quarterly
- Individual file restore — monthly
- Application-level restore — quarterly
- RTO/RPO validation — semi-annually
According to Sophos's 2024 State of Ransomware report, 94% of ransomware attacks try to compromise backups and 57% succeed — so immutable or air-gapped copies are non-negotiable. DVG Systems includes restore testing as part of our Dropsuite-backed managed service.
Read more: Backup Testing: The Most Neglected Step in Business Continuity
Cloud & Migration
Why should my business move to the cloud?
On-premise servers are hard to secure with remote workers, create unpredictable costs, don't scale easily, and have risky disaster recovery. Cloud platforms like Microsoft 365 and Azure solve all of these with predictable monthly costs, built-in security, and access from anywhere.
Read more: Cloud Migration in 2026
Read more: Should Canadian Businesses Be Worried About Storing Data in U.S. Cloud Services?
What is the difference between CAPEX and OPEX for IT spending?
On-premise IT is a capital expense (CAPEX) — you buy servers, licences, and hardware up front, then refresh every few years. Cloud IT shifts this to a predictable monthly operating expense (OPEX).
For small businesses where cash flow matters, this shift to predictable monthly costs is often the deciding factor.
Read more: Cloud Migration in 2026: Why Northern Ontario Businesses Are Making the Move.
How does cloud IT handle disaster recovery compared to on-premise?
On-premise disaster recovery is expensive, complicated, and most small businesses have plans that have never been tested. Cloud infrastructure like Microsoft Azure is built with redundancy at every level — backup power, redundant networking, and geographic replication.
Your data doesn't depend on a single box in a single building. For businesses in Northern Ontario, where power outages and severe weather are real risks, this is practical risk management.
Read more: What Happens When Your IT Goes Down?
Read more: Your Backups Are Useless If You've Never Tested Them
How does cloud IT compare in cost to on-premise servers?
On-premise IT is a capital expense game — buying servers, licenses, maintenance, and hardware refresh cycles. Cloud IT flips this to a predictable monthly operating expense. No hardware refreshes, no server room electricity bills, and easier budgeting.
Read more: Cloud Migration in 2026
Read more: Should Canadian Businesses Be Worried About Storing Data in U.S. Cloud Services?
Do I have to migrate everything to the cloud at once?
No. A good cloud migration is planned, phased, and tailored to your business. We start with a free assessment of your current environment to understand what you're running, what it's costing, and what a cloud-first approach would look like.
Read more: Cloud Migration in 2026: Why Northern Ontario Businesses Are Making the Move.
What is Microsoft Intune and why does it matter for remote teams?
Microsoft Intune gives you centralized control over every device that connects to your environment — corporate or personal. You can enforce security policies, push updates, and wipe lost devices remotely without physical access.
It's especially valuable when your team is distributed across multiple communities in Northern Ontario.
Read more: BYOD Security Without Killing Productivity: A Practical Guide for Northern Ontario Businesses
Can my team access their work from anywhere?
Yes. Microsoft 365 gives your team access to their full work environment — SharePoint for files, Teams for communication, OneDrive for storage — from any device, anywhere, without a VPN. This is especially valuable in Northern Ontario where staff may be at job sites or working remotely across communities.
Read more: BYOD Security Without Killing Productivity: A Practical Guide for Northern Ontario Businesses.
Cloud Desktops
What is the difference between Windows 365 and Azure Virtual Desktop?
Windows 365 gives each user a dedicated cloud PC with fixed monthly pricing (~$49–$248/user/month CAD). No Azure expertise needed — managed through the Microsoft 365 admin center. Ideal for teams of 5–25.
Azure Virtual Desktop (AVD) uses shared infrastructure with pay-as-you-go pricing. More flexible and potentially cheaper at scale (25+ users), but requires Azure administration expertise and Microsoft 365 Business Premium licences.
Read more: Windows 365 vs Azure Virtual Desktop
How much does a Windows 365 cloud PC cost?
Windows 365 Business (Microsoft list, CAD per user/month):
- Basic — 2 vCPU / 4 GB / 128 GB → $42.90
- Standard — 2 vCPU / 8 GB / 128 GB → $55.20 (most popular)
- Premium — 4 vCPU / 16 GB / 128 GB → $85.90
For higher-spec workloads, Windows 365 Enterprise reaches roughly $248/user/month for 8 vCPU / 32 GB configurations.
Most Northern Ontario offices land on the Premium tier (~$86/user). For a 15-person office on that tier, expect roughly $1,200–$1,500/month. Higher-spec Enterprise configurations push the same office toward $3,000–$3,750/month.
Pricing is fixed monthly with no variable usage charges. MSP-resold retail adds deployment, image management, and ongoing operations on top of these list prices.
Read more: Windows 365 vs Azure Virtual Desktop
Can cloud desktops handle AutoCAD or Revit?
Yes. Windows 365 at the 4 vCPU / 16 GB RAM tier handles AutoCAD, Revit, and most demanding applications well for day-to-day work. For complex 3D rendering or simulation, Azure Virtual Desktop offers custom GPU-enabled VMs at higher cost.
For most Northern Ontario firms running design software, Windows 365 is the practical choice.
Read more: Windows 365 vs Azure Virtual Desktop
Do cloud desktops work offline?
No. Both Windows 365 and Azure Virtual Desktop require an internet connection. Windows 365 handles brief disconnections more gracefully by preserving session state, but neither works offline.
If your team regularly works at remote job sites without reliable internet, cloud desktops may not be the right fit for those users.
Read more: Windows 365 vs Azure Virtual Desktop
Nonprofit Licensing
Are there cloud discounts for nonprofits?
Yes. Microsoft provides free Microsoft 365 Business Basic licences (up to 300 users) to qualifying registered nonprofits, with discounts of up to 75% on upgraded plans like Business Premium. We help nonprofits across Northern Ontario with the application, migration, and ongoing management.
Learn more on our nonprofit IT support page.
Read more: Microsoft 365 Nonprofit Licence Changes
What does Microsoft 365 Business Basic include for nonprofits?
The free Business Basic plan includes:
- Exchange Online — 50 GB mailbox, professional email
- Microsoft Teams — meetings, chat, calls
- OneDrive — 1 TB cloud storage per user
- SharePoint — shared document libraries
- Web and mobile versions of Word, Excel, PowerPoint, and Outlook
Up to 300 licences per organization. Does not include desktop Office apps, Intune, Defender for Business, or Conditional Access.
Read more: Microsoft 365 Nonprofit Licence Changes.
What security features do nonprofits lose moving from Business Premium to Basic?
Moving from Premium to Basic means losing:
- Microsoft Intune — device management
- Defender for Business — endpoint security
- Advanced Threat Protection — enhanced email and identity protection
- Conditional Access — granular sign-in controls
These are significant gaps for organizations handling sensitive data. The 75% nonprofit discount on Premium helps offset this cost.
Read more: Microsoft Defender for Business: Is the Built-In EDR Good Enough?
What changed with Microsoft nonprofit licensing in July 2025?
Microsoft retired the free grants for Microsoft 365 Business Premium and Office 365 E1 effective July 1, 2025. Business Basic remains free (up to 300 users).
If your organization was on a free Premium or E1 grant, you'll need to either move to Business Basic or take advantage of the 75% nonprofit discount on upgraded plans. We can audit your licences and handle the transition.
Read more: Microsoft 365 Nonprofit Licence Changes
AI Policy & Copilot Usage
Should our business have an AI use policy?
Yes. Your staff are almost certainly already using AI tools — ChatGPT, Microsoft Copilot, Google Gemini, browser extensions. Without a written policy, you are absorbing the risk blindly.
A practical AI policy covers approved tools, data classification, human review requirements, and accountability. It fits on one or two pages and is part of your PIPEDA compliance posture.
Read more: AI Policy and Compliance for SMBs.
What data can my staff safely put into ChatGPT or Microsoft Copilot?
It depends on the tool and the data tier:
- Public (website copy, press releases, published pricing) — any approved AI tool is fine.
- Internal and Confidential (internal memos, client contracts, financials, HR records) — enterprise-tier only: Microsoft 365 Copilot in your tenant, ChatGPT Enterprise/Team, or Gemini for Workspace Business.
- Restricted (PHI, Social Insurance Numbers, financial account numbers, privileged legal communications) — keep out of general-purpose AI entirely.
Read more: A 4-Tier Data Classification Guide for AI.
Is Microsoft 365 Copilot safe for confidential business information?
Microsoft 365 Copilot runs inside your Microsoft 365 tenant, inherits your access controls and permissions, and contractually does not train on your data.
For most SMBs, that makes it appropriate for Confidential business information — provided it is deployed with sensitivity labels, proper permissions, and staff training. Consumer tools like free ChatGPT do not offer these protections.
Read more: What Data Is Safe for ChatGPT & Copilot?
What is "shadow AI" and should I be worried about it?
Shadow AI is AI tools, browser extensions, and third-party integrations your staff use without IT approval — free ChatGPT accounts, AI summarizer extensions, meeting-notes tools connected to Microsoft 365 via OAuth.
It is nearly universal in SMBs and creates real data exposure. The fix is not prohibition — it is giving staff a good sanctioned alternative, auditing OAuth grants monthly, and running occasional amnesty conversations.
Read more: Shadow AI: The Tools Your Employees Are Using.
Can employees use free ChatGPT on a work device for work tasks?
For Public data only — published marketing copy, competitor research, public website text — yes. For anything Internal, Confidential, or Restricted, free ChatGPT should not be used on a work device.
The consumer tier retains prompts and may use them for model training. Use an enterprise AI tool instead, or stick to public information only.
Read more: AI Policy and Compliance for SMBs.
Do AI tools like ChatGPT train on the data I paste in?
Consumer and free AI tools typically do. Enterprise tiers — Microsoft 365 Copilot, ChatGPT Enterprise/Team, Gemini for Workspace Business — contractually do not train on customer data.
Always check the current terms at purchase, as they can change. If your business handles personal or regulated information, assume consumer tools train on input and choose tools accordingly.
Read more: A 4-Tier Data Classification Guide for AI.
What should I do if an employee accidentally pastes client data into ChatGPT?
Treat it like any privacy incident:
- Stop the activity immediately.
- Document what was shared and when.
- Notify your MSP and your privacy officer.
- Assess whether the exposure qualifies as a reportable breach under PIPEDA or PHIPA. Depending on the data type and jurisdiction, notification to the Office of the Privacy Commissioner and affected individuals may be required.
Prevention — classify data and approve tools in advance — is much easier than remediation.
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
Does PIPEDA apply to how my staff use AI tools?
Yes. Under PIPEDA, your business is accountable for personal information under your control, including when it is processed by third-party AI tools your staff use. If an employee pastes customer information into a consumer AI tool, your PIPEDA obligations still apply.
An AI policy is part of your PIPEDA compliance posture — not a separate initiative.
Read more: AI Policy and Compliance for SMBs
Read more: What Actually Happens After a Data Breach — The Financial and Legal Reality for Ontario Businesses
Does PHIPA allow AI tools for patient data?
PHIPA governs how personal health information is handled in Ontario. PHI should not be entered into general-purpose AI tools.
Purpose-built, vetted healthcare AI tools with appropriate data processing agreements are the only appropriate path — and even those require careful review before deployment. Consumer AI tools and browser extensions are a hard no for any PHI.
Read more: AI Policy and Compliance for SMBs
Is AI-generated content reliable enough to send directly to clients?
Not without human review. Generative AI hallucinates — it invents facts, citations, regulations, and statistics with complete confidence. Hallucinations do not look like errors; they look like the rest of the work.
Every piece of AI-assisted content that leaves your business needs a human reviewer to verify factual claims, check tone, and confirm the output matches the intent. Review effort should scale with risk — light for internal notes, thorough for contracts and regulated output.
Read more: Why Every AI Output Needs a Human Reviewer.
How do I roll out Microsoft 365 Copilot without losing control of data?
Start with a readiness assessment — what data lives where, who has access, and what sensitivity labels are in place. Configure Microsoft 365 permissions, sensitivity labels, and DLP policies before enabling Copilot. Train staff on data classification and an approved-tool list.
DVG Systems handles this as a structured Copilot rollout that includes configuration, team training on prompting, and ongoing review.
Read more: AI Policy and Compliance for SMBs
What is the fastest way to get my team writing better AI prompts?
Teach the GCSE framework:
- Goal — what outcome you want
- Context — why and for whom
- Source — what information to draw from
- Expectations — format, length, tone, and constraints
Fill all four slots every time. That single habit outperforms 90% of AI prompting in one afternoon of training. We run a 90-minute team workshop as part of our Copilot rollouts.
Read more: The GCSE Prompting Framework.
How do I find out what AI tools my staff are already using?
Three quick checks:
- Audit OAuth grants in Microsoft Entra ID or Google Workspace Admin — look for unfamiliar apps with access to your tenant.
- Sample browser extensions on a few company devices.
- Hold an amnesty conversation: no consequences, just ask the team what they are using so you can make the sanctioned path better.
That conversation surfaces more shadow AI than any audit tool.
Read more: Shadow AI: The Tools Your Employees Are Using That You Don't Know About.
Can DVG Systems help us build and enforce an AI policy?
Yes. We help small and mid-sized businesses across Northern Ontario with:
- AI readiness assessments
- Policy drafting and data classification
- Microsoft 365 Copilot deployment with sensitivity labels
- Staff training on prompting and safe tool use
- OAuth audits and shadow AI discovery
- Ongoing review as tools evolve
Book a free assessment to find out where your AI exposure is today.
Read more: AI Policy and Compliance for SMBs.
AI Governance & Tenant Hygiene
Every time a new AI model launches, should we be changing our IT setup?
No. The honest triggers are narrow: a vendor you use changes its data-handling terms, your regulator issues new guidance, a new capability gets enabled by default in a platform you already deploy, or an actual incident is publicly attributed to the model.
Model intelligence alone is not a trigger — focus on identity, data classification, and incident readiness. Every frontier launch is a good prompt to review those fundamentals, not to restructure your stack.
Read more: Seven Questions Ontario SMBs Should Ask Their MSP Every Time a Major AI Model Launches
How do I audit which AI tools and OAuth integrations my Microsoft 365 tenant has already granted access to?
Go to the Microsoft Entra admin centre → Applications → Enterprise applications. You'll see every third-party app holding persistent permissions, with their scopes and last-used dates visible.
These grants survive staff turnover unless actively revoked. DVG Systems runs this review quarterly for managed clients as part of the AI governance cadence.
Read more: Shadow AI: The Tools Your Employees Are Using That You Don't Know About
Before we turn on Microsoft 365 Copilot company-wide, what do we need to clean up first?
SharePoint and OneDrive permissions. Copilot inherits each signed-in user's access, so accumulated over-permissions become discoverable at machine speed — the sales team suddenly sees the HR site they were never supposed to know about.
Microsoft's own deployment guidance treats a permissions review as a prerequisite, not optional. DVG Systems includes this review in every Copilot rollout.
Read more: Seven Questions Ontario SMBs Should Ask Their MSP Every Time a Major AI Model Launches
What should a Northern Ontario IT provider do between launches or incidents to earn their monthly fee?
A good MSP is continuously reviewing enterprise-app OAuth grants, maintaining Conditional Access policies, keeping an inventory of AI tools staff actually use, updating your acceptable-use policy when vendor terms or Ontario laws change, and briefing you only when something real changes.
If the only time you hear from your MSP is when something breaks, that's break-fix with a retainer — not managed IT.
Read more: The Break-Fix Trap: Why Reactive IT Support Is Costing Your Business More Than You Think
Password & Credential Management
Is it okay to share a Microsoft 365 or software licence between two employees to save money?
No. SaaS licences — Microsoft 365, Google Workspace, QuickBooks Online, Adobe, and most line-of-business software — are one-user-per-licence by contract. Sharing is a breach of vendor terms and can trigger retroactive billing for up to 12 months plus penalties on audit.
It also breaks MFA, destroys your audit trail, and can void cyber insurance coverage. The apparent savings are typically $30–$75/month; the downside on audit or incident is often five or six figures.
Read more: Why "One Login for the Team" Is a Six-Figure Risk.
What are the real risks of sharing business software logins?
Six things happen when logins are shared across staff:
- Contract breach with the vendor, with back-billing on audit
- Loss of audit trail — you cannot tell who did what
- MFA collapse — shared credentials cannot enforce per-user MFA
- Impossible offboarding — disabling a shared account locks out everyone else
- Poor password hygiene — shared passwords are weaker, reused, and leak faster
- Cyber insurance exposure — shared logins often violate policy conditions and can lead to denied claims
Read more: Password Sharing at Work
How should I safely share passwords with my IT provider or MSP?
The best answer is don't share at all — use delegated admin models like Microsoft GDAP so your MSP signs in as themselves with their own MFA. Each technician's actions are audit-logged against a named person.
When you must share a credential, use a business password manager with secure sharing (Bitwarden Business, 1Password Business, Keeper Business) or a one-time encrypted link (Bitwarden Send). Rotate the credential after the handoff.
Never share passwords by email, SMS, Teams/Slack chat, sticky notes, or shared documents.
Read more: A Handoff Playbook for Sharing Passwords With Your IT Provider.
What is GDAP and why does it matter?
GDAP stands for Granular Delegated Admin Privileges. It is Microsoft's modern model for how a managed IT provider accesses a client's Microsoft 365 tenant.
Under GDAP, each technician signs in with their own identity, own MFA, and a specific time-bound role — not a shared Global Admin password. Every action is audit-logged against a named person, and access can be revoked in one click.
Microsoft began auto-migrating existing DAP relationships to GDAP in May 2023 and ended DAP for new reseller relationships in October 2023. If your MSP still asks for the Global Admin password, that is a 2019-era practice and should be updated.
Read more: How to Safely Share Passwords With IT
Should my MSP have our Microsoft 365 Global Admin password?
No. In 2026 your MSP should hold delegated admin access through GDAP — with named technicians, their own MFA, and role-scoped access that can be revoked instantly.
You should also keep a client-held break-glass account — a single emergency admin login whose credentials live in your own password manager, with MFA on an owner or executive device. That is your insurance policy if you ever need to regain control.
Read more: How to Safely Share Passwords With IT
Is it safe to email my password to IT support?
No. Emailed passwords persist in your sent folder, the recipient's inbox, intermediate mail servers, and backup archives — often for years. A single future mailbox compromise anywhere in that chain exposes every password you ever sent.
The same applies to SMS, Teams, Slack, sticky notes, and general-purpose shared documents. Use a business password manager's secure-sharing feature or an encrypted one-time link instead, and rotate the credential immediately after the recipient confirms access.
Read more: How to Safely Share Passwords With IT
How do I verify an IT support call is legitimate before sharing credentials?
Three habits:
- Hang up and call back on a number you already have on file — not one the caller provides
- Never approve an MFA prompt you did not personally initiate
- Confirm there is an open ticket for the request before sharing anything
Help-desk vishing is one of the fastest-growing attack vectors for SMBs. The 2023 MGM Resorts breach, which cost over $100 million, started with a ten-minute call to MGM's help desk impersonating an employee. A legitimate IT provider will never be offended by a verification step.
Read more: How to Safely Share Passwords With IT
Read more: 5 Social Engineering Tactics Hitting Northern Ontario Businesses Right Now
What is a business password manager and do we need one?
A business password manager (Bitwarden Business, 1Password Business, Keeper Business, Dashlane Business) is an encrypted vault that stores credentials, shares them securely between team members, and logs every access.
It is the foundation for safe credential handling in an SMB — the place you store genuinely-shared credentials, hand off passwords to your MSP, manage offboarding, and produce an audit trail for your cyber insurer. For any business handling personal information under PIPEDA, a business password manager is no longer optional.
Read more: The Business Case for a Password Manager.
Are passkeys actually more secure than a strong password plus MFA?
Yes. The UK's National Cyber Security Centre (NCSC) published a technical report in April 2026 concluding that passkeys are at least as secure — and generally more secure — than pairing the strongest password with two-step verification, including SMS codes.
The main reason is that passkeys are phishing-resistant by design: a passkey is cryptographically tied to the exact domain it was registered with, so a lookalike site can't trick your device into authenticating. There's no shared secret an attacker can phish, intercept, or replay.
Read more: Passkeys vs Passwords: Why UK Cyber Chiefs Just Called Time on the Password.
Microsoft is auto-enabling passkey profiles in our Entra tenant — what does that mean?
Per Microsoft Message Center notice MC1221452, Microsoft Entra ID is rolling out passkey profiles to General Availability across worldwide public cloud tenants. Tenants that already had FIDO2 enabled but did not opt in are being automatically migrated between early May 2026 and late June 2026.
Microsoft moves your existing FIDO2 configuration into a default passkey profile and preserves your current restrictions and user targeting. Greenfield tenants that never enabled FIDO2 are not in scope.
The defaults aren't dangerous, but they may not match your risk appetite — opt in deliberately and configure passkey profiles before the auto-migration applies them for you.
Read more: Passkeys vs Passwords: NCSC + Microsoft Entra ID 2026.
What happens if a user loses the device with their passkey?
It depends on whether the passkey is synced or device-bound:
- Synced passkeys (stored in iCloud Keychain, Google Password Manager, or a third-party credential manager) are available on the user's other signed-in devices, so a single device loss is recoverable.
- Device-bound passkeys are not — you'll need a backup authentication method, a hardware security key kept in a safe, or an administrator-assisted recovery path.
Recovery planning should be documented before any rollout, especially for executives and admins.
Read more: Passkeys vs Passwords: What SMBs Should Do Before the June 2026 Migration.
Do I still need a business password manager if we move to passkeys?
Yes — for the foreseeable future. Not every website and line-of-business application supports passkeys yet, and until they do, a business password manager remains the right tool for those gaps.
The NCSC's own guidance is the same: where a service supports passkeys, use them; where it does not, use a password manager to generate strong unique passwords and keep using two-step verification. Passkeys and password managers coexist — they don't replace each other.
Read more: Passkeys vs Passwords: NCSC + Microsoft Entra ID 2026.
Read more: The Business Case for a Password Manager.
Should our admins use synced passkeys or hardware security keys?
For privileged accounts — Global Administrators, break-glass accounts, finance approvers — we generally recommend hardware-backed, attested passkeys (FIDO2 security keys) rather than synced passkeys.
The trade-off is convenience: synced passkeys are easier for users because they roam between their devices, while hardware keys require physical possession but offer stronger assurance and resistance to credential cloud-sync compromises.
Most SMBs run a mix — synced passkeys for general staff, hardware keys for the small number of privileged accounts that need stricter rules.
Read more: Passkeys vs Passwords: NCSC + Microsoft Entra ID 2026.
Does my cyber insurance application actually ask about staff security training?
Yes. Beazley's cyber insurance questionnaire asks whether your organization regularly provides cybersecurity awareness training — including anti-phishing awareness — to all users with access to your network or confidential data. Optional questions about simulated phishing testing can earn premium discounts.
Chubb Canada bundles up to $28,000 of complimentary user-security education into its first-year Cyber Stack for SMBs with 100 employees or fewer. Coalition launched its own training platform (Coalition Security Awareness Training) inside Coalition Control on July 16, 2024.
Saying "yes" on the application without a documented training platform is how claims get denied.
Is staff cybersecurity training required by Canadian privacy law?
PIPEDA does not name a specific training cadence in statute, but the Office of the Privacy Commissioner of Canada explicitly identifies "regular staff training" as an organizational safeguard required under Principle 4.7. The OPC's 2025 Staples Canada investigation (PIPEDA Findings #2025-004) recommended that Staples improve its training program and ensure all employees handling personal data complete training before doing so. The practitioner standard is annual minimum with role-specific refreshers.
For Ontario healthcare custodians, PHIPA goes further — administrative monetary penalties of up to $50,000 for individuals and $500,000 for organizations have been available to the IPC since January 1, 2024. Penalty calculations explicitly consider whether a custodian could have prevented the contravention — which is where missing training cuts the deepest.
Read more: Your Cyber Insurance Application Asks About Staff Training.
Will security awareness training actually lower our cyber insurance premium?
It can. Beazley's questionnaire treats simulated phishing testing as an optional item where satisfactory responses result in premium discounts. Chubb Canada includes a free year of training and phishing simulation (via KnowBe4 and GLS) for sub-100-employee SMB cyber policyholders — up to $28,000 in services. Coalition policyholders get integrated training inside Coalition Control.
The exact discount depends on your broker comparing quotes side by side, but the direction is consistent: documented training lowers underwriting risk and price.
Read more: Your Cyber Insurance Application Asks About Staff Training.
What does a defensible employee security training programme actually look like?
Four components, in order of importance:
- A real platform with completion records. Spreadsheets and email reminders are not evidence. When a broker, the OPC, or the IPC asks, the export takes thirty seconds.
- A baseline curriculum every staff member completes annually — phishing recognition, MFA hygiene, PIPEDA/PHIPA handling, social engineering, secure remote work. Refreshers when major shifts occur (e.g. the 2026 NCSC passkeys recommendation).
- Simulated phishing tests with remediation routing, not gotcha. The point is identifying training gaps, not embarrassing staff who click.
- Productivity training combined with security training — Microsoft 365, Teams, Outlook, Copilot — in one platform. Lowers helpdesk burden and breach risk on the same subscription.
DVG Systems deploys this stack as part of every full managed IT engagement.
Read more: Your Cyber Insurance Application Asks About Staff Training.
What security awareness training platform does DVG Systems use?
For SMB managed IT engagements we deploy BiggerBrains, a video-based platform that bundles Microsoft 365 productivity training (Outlook, Excel, Teams, OneDrive, Copilot) with cybersecurity awareness modules in one subscription. The productivity-plus-security combination is unusual in the category and addresses both the cyber-insurance question and the helpdesk-ticket reduction in the same monthly per-user fee.
For larger clients past 100 staff or in highly regulated industries, we deploy KnowBe4 instead. Other platforms we evaluate against include Hook Security, Phin Security, Coalition Security Awareness Training, and Microsoft Attack Simulator.
Read more: KnowBe4's MSP Program Has a 101-User Minimum. Here's What We Use for Smaller Northern Ontario Clients.
Why doesn't DVG Systems use KnowBe4 for every client?
KnowBe4's MSP partner program requires a 101-user minimum per client, with no ability to aggregate user counts across multiple managed clients. For Northern Ontario SMBs averaging 8–60 staff, the math doesn't work — most of our clients individually fall below the threshold, and KnowBe4 doesn't allow MSPs to pool small clients to qualify.
We use KnowBe4 for the small share of clients past 100 staff or in regulated industries where SecurityCoach risk scoring and PhishER's enterprise phishing-simulation depth materially matter. For everyone else, BiggerBrains is the better fit — same compliance value, no user minimum, and productivity training included.
Read more: KnowBe4's MSP Program Has a 101-User Minimum. Here's What We Use for Smaller Northern Ontario Clients.
IT Policy, AUP & Workplace Privacy
Does my Ontario business need an IT Acceptable Use Policy?
If you employ 25 or more people in Ontario as of January 1 of any year, you are legally required under the Working for Workers Act, 2022 (in force since October 11, 2022) to have a written electronic monitoring policy and to provide it to every employee — new hires within 30 days. An Acceptable Use Policy (AUP) is the standard way to meet that requirement.
Below 25 employees the law does not strictly apply, but cyber insurance underwriters, auditors, and professional regulators increasingly expect one regardless. It also strengthens your position in any HR or privacy dispute.
Read more: The IT Acceptable Use Policy Every Small Business Should Have.
What should an IT Acceptable Use Policy cover?
A practical AUP is 2 to 4 pages and covers eight areas:
- Authorized use of company systems
- Account security — passwords, MFA, no credential sharing
- Company-issued devices (laptops, desktops, phones) — MDM enrollment, patch compliance, lost/stolen reporting within one hour
- Personal use and BYOD rules
- Email, internet, and messaging standards
- Data handling tied to your classification tiers
- Monitoring and privacy — what is logged, why, and retention
- Reporting obligations and consequences
Every employee signs and dates it at hire, and re-signs annually or on material change.
Read more: IT Acceptable Use Policy
Read more: BYOD Security Without Killing Productivity: A Practical Guide for Northern Ontario Businesses
Why does every employee need to sign an Acceptable Use Policy?
A signed AUP gives you three things an unsigned or verbal one cannot:
- Evidentiary value — if an employee is terminated for misuse, the signature proves they were informed of the rule
- Legal standing — wrongful-dismissal cases often turn on whether the employer established and communicated clear expectations
- Compliance defensibility — cyber insurance questionnaires, PIPEDA investigations, and professional audits all ask whether staff have agreed to acceptable-use terms
An AUP your staff never signed, or signed once in 2021 and never revisited, is drifting toward obsolete.
Read more: IT Acceptable Use Policy
What can my employer actually see on my work computer and browser?
Considerably more than most people assume. On a managed company device, an employer can typically see:
- Every website domain you visit (even in incognito, even over HTTPS)
- Every email and calendar event on your corporate account, including metadata
- Every file created, opened, shared, or downloaded through company systems
- Every application installed or used
- Login activity — time, device, location, MFA method, success/failure
- Device inventory — OS version, patch status, installed software, encryption state
What is usually not visible is the specific content within a webpage (just the domain), or anything on a truly personal device that never touches company accounts.
Read more: What Can My Employer See on My Browser and Work Computer?
Does incognito or private browsing hide my activity from IT?
No. Incognito only prevents the browser itself from saving your history and cookies locally. It does nothing at the network level.
Your company's DNS resolver, firewall, and web filtering service log every domain your device contacts — in incognito or not, over HTTPS or not. The specific page content is usually encrypted, but the domain is visible. A personal VPN may itself be a policy violation on a company device.
Practical rule: if you would not be comfortable with your employer seeing it in a disclosed audit, do not do it on a work device or work network.
Read more: Workplace Privacy and Employee Monitoring
Can my employer read emails I have deleted?
In most modern Microsoft 365 and Google Workspace environments, yes. Deleting a message removes it from your view, not from compliance archives.
Admins can recover emails, Teams or Slack messages, and files long after the user has deleted them — typically 90 days to 7 years depending on retention policy. This is by design: it supports incident investigation, legal hold, PIPEDA breach response, and regulatory requests.
Read more: Workplace Privacy and Employee Monitoring
What is Ontario's Working for Workers Act electronic monitoring policy requirement?
Ontario's Working for Workers Act, 2022 (Bill 88) requires employers with 25 or more employees as of January 1 of any year to have a written policy on the electronic monitoring of employees. The requirement has been in force since October 11, 2022.
The policy must describe whether, how, and in what circumstances the employer electronically monitors employees, and the purposes for which the resulting information may be used. It must be provided to every current employee and to new hires within 30 days of being hired.
An Acceptable Use Policy with a monitoring section satisfies the requirement.
Read more: Workplace Privacy and Employee Monitoring
If we enroll my personal phone in Intune for work email, can my employer wipe my personal photos?
No. Intune Mobile Application Management (MAM) protects only company data in company apps — Outlook, Teams, OneDrive. A "selective wipe" removes your work data and leaves personal photos, contacts, and apps untouched.
Full Mobile Device Management (MDM), which can wipe the whole device, is only used for company-owned hardware. If you're enrolling a personal phone for work email, MAM is almost always the correct model — and it's designed exactly so your employer can't touch your personal content.
Read more: BYOD Security Without Killing Productivity
VoIP & Business Phones
Do you handle business phones, or should we go to a separate VoIP provider?
DVG Systems runs a dedicated VoIP division — DVGVoIP — offering 3CX hosted PBX, SIP trunking, and number porting. Managed IT clients get a single point of accountability across phones, network, and Microsoft 365.
For detailed VoIP questions including pricing, softphone setup, and Ontario compliance topics like PIPEDA/PHIPA call recording and CRTC 911 obligations, see dvgvoip.com.
Read more: DVG Systems VoIP services overview.
Can our clinic use VoIP with patient calls and stay compliant with PIPEDA and PHIPA?
Yes when configured correctly — DVGVoIP offers Canadian data-hosting, TLS/SRTP encrypted call paths, role-based access to call recordings, and audit logs. The full checklist of obligations (consent language, data-residency questions, access controls) is in the DVGVoIP Canadian Clinic VoIP Compliance Checklist.
Read more: DVG Systems Healthcare IT services.