FREQUENTLY ASKED QUESTIONS
Straight answers on managed IT, cybersecurity and compliance for Canadian businesses.
80 questions we hear from business owners and IT leads in Toronto, the GTA and across Ontario, answered in plain language by the specialists at Tuor, a Canadian owned managed IT services provider headquartered in Toronto since 2003. Whether you are comparing providers, budgeting for IT, facing a cyber insurance renewal or making sense of PIPEDA, Law 25 and Copilot, start here.
Last updated September 2026. We revise this page as Canadian law, Microsoft licensing and the threat landscape change.
Section 01
About Tuor
Who we are, where we work and how to reach a real person.
12 questions
What is Tuor?
Tuor is a Toronto based managed IT services provider (MSP) founded in 2003. We deliver managed IT, cybersecurity, cloud services and IT consulting to small and mid sized businesses across Ontario and Canada, most of them between 10 and 100 employees, for one flat monthly rate. We are 100% Canadian owned and operated, and every specialist who works on your environment is based in Canada. You may also see us referred to as Tuor Networks. Same company, shorter name.
What does the name Tuor mean?
Tuor is Latin for to protect, to watch over and to uphold, which is a fair summary of the job. It is pronounced like the word tour. It is not a reference to the Tolkien character, although we get that question more often than you might think.
Where is Tuor located and which areas do you serve?
Our head office is at 130 King Street West, Suite 1900 in downtown Toronto. From there we support businesses across the Greater Toronto Area including Mississauga, Brampton, Vaughan, Markham, Richmond Hill, Oakville, Burlington and Hamilton, across Ontario including Ottawa, Kitchener Waterloo, London, Barrie and Niagara, and at client locations across Canada. Most support is delivered remotely by our Canadian team. When work needs hands on site, our own field specialists cover the GTA and a vetted partner network that we manage for you covers everywhere else.
How long has Tuor been in business?
Tuor was founded in Toronto in 2003, so we have been running IT for Canadian businesses for more than twenty years. Along the way we were named Varnex Partner of the Year for Central Canada in 2020, have been on the list of Canada's 50 Best Managed IT Companies every year since 2024, and were named to the 2026 MSP 501, the global ranking of top performing managed service providers, in our first year applying.
Is Tuor Canadian owned?
Yes. Tuor is 100% Canadian owned and operated, headquartered in Toronto, with a Canada based support team. That matters for practical reasons. Your data and documentation are handled by a company that answers to Canadian law, your support is delivered in your time zone by people who know your environment, and you will never be routed to an overseas call centre. With more Canadian businesses asking who ultimately controls their systems and data, Canadian ownership has moved from a nice to have to a real evaluation criterion.
What size of business does Tuor work with?
Our sweet spot is organizations with 10 to 100 employees, and we also support larger and multi site businesses. If you have outgrown the one person IT shop but are not ready to hire and manage a full internal team, that is exactly the gap we fill. You get the capabilities of a complete IT department, from a service desk to systems and network administrators to a solutions architect and project manager, without carrying that headcount.
Which industries does Tuor serve?
We work with professional services firms, financial services and insurance, legal, architecture and engineering, associations and not for profits, healthcare, and logistics companies, among others. Many of our clients operate in regulated environments where privacy obligations, audit evidence and cyber insurance requirements are part of daily life, so our security baseline and documentation are built with that in mind.
What certifications and partnerships does Tuor hold?
Tuor is a Microsoft Solutions Partner and has renewed that designation three years running. We are also an Anthropic partner, supporting safe AI adoption with Claude alongside Microsoft Copilot. Our security practice is aligned to the CIS Controls and the NIST Cybersecurity Framework. On the recognition side, Tuor was named to the 2026 MSP 501 and has been one of Canada's 50 Best Managed IT Companies for three consecutive years.
How do I contact Tuor?
Call 1-833-599-TUOR (8867) toll free or 416-599-8867 locally, email sales@tuor.ca, or use the contact form on our homepage to book a free 30 minute Discovery Call. Existing clients reach the service desk at support@tuor.ca or by phone. Our office hours are 8 a.m. to 6 p.m. Eastern, Monday to Friday, and monitoring and alerting run 24/7 on every plan.
What does Real IT. Real People. Real Accountability. actually mean?
It is our tagline and the standard we grade ourselves against. Real IT means a complete, properly run environment rather than patched together fixes. Real People means you reach a specialist who knows your business, with no phone trees and no tier one runaround. Real Accountability means every ticket is reviewed daily against our service levels and stays open until you confirm the work is done. If we miss on any of the three, we want to hear about it.
Do you support businesses in Mississauga, Vaughan, Markham, Oakville and the rest of the GTA?
Yes. The Greater Toronto Area is our home market. We support businesses in Mississauga, Brampton, Vaughan, Markham, Richmond Hill, Scarborough, Etobicoke, Oakville, Burlington, Milton and Hamilton every day, with remote support as the first line and our own field specialists for on site work across the region.
Can Tuor support remote and hybrid teams with staff in other provinces?
Yes. Hybrid work is the norm for our clients and our model was built for it. Devices are managed and protected wherever they connect, identity and multifactor authentication travel with the user, and support is a phone call or a ticket away regardless of location. Staff in Ottawa, Calgary or Halifax get the same service as staff in Toronto, and our national partner network covers on site needs when they arise.
Section 02
Managed IT services explained
The basics of working with an MSP, in plain language.
13 questions
What is a managed service provider (MSP)?
A managed service provider is a company that takes ongoing responsibility for running your IT for a fixed monthly fee. Instead of calling someone when something breaks, an MSP monitors your systems continuously, keeps them patched and secure, supports your staff through a service desk, and plans ahead with you. Tuor is an MSP based in Toronto. In practice we operate as your IT department, with the added benefit of a full bench of specialists rather than one or two people.
What does a managed IT services provider actually do day to day?
On a typical day an MSP is monitoring servers, computers, network equipment and cloud services for problems, applying security updates, answering service desk requests from your staff, onboarding and offboarding users, backing up data and testing that the backups restore, watching for security threats, and documenting everything. Behind the scenes there is also account management, quarterly planning and vendor coordination. Most of this work is invisible when it is done well, which is the point.
What is included in Tuor's managed IT services?
Every Tuor plan includes the same complete baseline. Unlimited helpdesk support, 24/7 monitoring and alerting, on site support when needed, and quarterly business reviews with a roadmap. Computer and server management, firewall and network management, backup monitoring, mobile device management, asset and lifecycle tracking, documentation of your environment, vendor management, and hardware and software procurement.
The security layer is included too, not sold separately. A CIS and NIST aligned security stack, endpoint detection and response with 24/7 threat hunting, advanced patch management, DNS and web protection, email protection and cloud backup, staff security training, network vulnerability scanning and cloud security posture monitoring. Our Advanced and Premium plans add deeper detection and response on top of that.
What is the difference between break-fix and managed IT?
Break-fix IT is reactive. Something stops working, you call, someone fixes it and sends an invoice, and the provider makes more money the more often things break. Managed IT is proactive. A flat monthly fee covers monitoring, maintenance, security and support, so the provider is financially motivated to prevent problems rather than bill for them. For most businesses with more than about ten employees, managed IT costs less over a year once downtime is counted, and it is far less stressful.
Should a small business outsource IT or hire someone in house?
For most businesses under 50 to 75 employees, a managed IT provider delivers more coverage and more skills than a single in house hire, usually for less money. One full time IT generalist in Ontario costs roughly $90,000 to $110,000 a year once salary, benefits and tools are included, and that person still takes vacation, still gets sick, and cannot be an expert in networking, security, cloud and support at the same time. An MSP gives you a whole team for a predictable monthly fee. Larger organizations often keep an internal IT lead and pair them with an MSP in a co-managed arrangement.
What is co-managed IT and does Tuor offer it?
Co-managed IT is when your internal IT staff and an MSP share responsibility for your environment. Your team keeps the work it wants to own, and the MSP provides the tooling, monitoring, security operations, after hours coverage and specialist depth that are hard to staff internally. Yes, Tuor supports co-managed arrangements. We agree in writing on who does what, your team gets visibility into every ticket, and nothing depends on a single person's calendar.
What is a vCIO and do I need one?
A virtual CIO is a senior IT advisor who gives you executive level technology leadership without a full time executive salary. At Tuor, vCIO work shows up as quarterly business reviews, a multi year roadmap tied to your budget and risk, and vendor neutral advice on projects and platforms. If you have ever bought technology without a plan, renewed a contract you did not understand, or been surprised by an IT expense, you would benefit from one. It is included in every Tuor plan.
What happens when I call Tuor for support?
You reach a person, not a phone tree, and that person is a specialist rather than a script reader. Every request becomes a ticket so nothing gets lost. A service coordinator routes it to the right specialist the first time, you get updates on the record as work happens, and if the issue needs senior help it is escalated quickly. The ticket stays open until you confirm it is actually resolved, and our service quality team reviews every open ticket daily against our service levels.
How quickly does Tuor respond to support requests?
Response and resolution targets are defined in your service agreement and are based on priority, so a company wide outage is handled very differently from a printer question. What makes us different is how we manage against those targets. Our service quality team reviews open work every day against a live SLA schedule, and anything at risk gets flagged and escalated before it slips rather than after. We are happy to share our actual performance numbers on a Discovery Call.
Does Tuor provide on site support?
Yes. Most day to day support is handled remotely because it is faster for you, but when a job needs hands on site, whether that is an installation, a hardware replacement or a cutover, our field specialists come to you. On site support is included in every plan when it is needed. Outside the GTA we manage a vetted partner network so clients in other Ontario cities and other provinces get the same coverage.
What hours is support available?
Our service desk is staffed during business hours in the Eastern time zone, and monitoring and alerting run 24 hours a day, every day, on every plan. After hours emergency coverage is defined in your agreement so you know exactly what happens at 2 a.m. before you ever need it. Premium plan clients also have a 24/7 Canadian based human security operations centre watching for threats around the clock.
How does onboarding work when we switch to Tuor?
Onboarding starts with discovery and documentation. We inventory your users, devices, network, cloud services, vendors and passwords, then deploy our management and security tooling, apply the security baseline, and confirm backups are working and restorable. Your staff get a short introduction to how support works and who to call. We coordinate the handover with your outgoing provider so there is no gap in coverage. Most onboardings complete within the first few weeks, with the heaviest lifting in the first few days.
What is the difference between an MSP and an MSSP?
An MSP manages your IT. An MSSP, or managed security service provider, focuses specifically on security monitoring and response. Historically businesses hired one of each, which meant two vendors pointing at each other during an incident. Tuor delivers both under one agreement. Every plan includes a full security stack with 24/7 threat hunting, our Advanced plan adds SIEM and XDR with automated response, and our Premium plan adds a 24/7 Canadian based human SOC, so the people who run your systems and the people who defend them are the same team.
Section 03
Pricing and plans
What managed IT costs in Ontario and how Tuor's flat rate works.
8 questions
How much do managed IT services cost in Toronto and Ontario?
Fully managed IT for a small or mid sized business in the Greater Toronto Area typically costs between $120 and $250 per user per month in 2026, and Canada wide guides put the range at roughly $100 to $300 depending on scope. Plans below about $100 per user usually cover monitoring only, with support billed hourly on top, which is where surprise invoices come from. Plans above $250 generally involve heavy compliance requirements or complex multi site infrastructure.
Tuor prices per user with a flat monthly rate that includes unlimited helpdesk and the complete security baseline, so the number you see is the number you pay. Because every environment is different we quote after a short discovery conversation, and we publish an honest breakdown of what drives cost on our blog.
How does Tuor's flat rate pricing work?
You pay one predictable monthly fee based on the number of users we support. That fee covers unlimited service desk requests, monitoring, maintenance, security tooling, on site support when needed and quarterly planning, and it moves up or down as your headcount changes. Project work that falls outside normal operations, such as an office move or a server migration, is scoped and quoted separately in advance so you always know what you are approving. No hourly meters and no surprise invoices.
What plans does Tuor offer?
Tuor offers three managed plans, Fundamental, Advanced and Premium, all built on the same complete baseline of managed IT and cybersecurity. Fundamental is complete managed IT with the core protection stack every modern business needs. Advanced adds SIEM and XDR with automated threat response, dark web monitoring, external penetration testing and cloud identity backup for businesses ready to level up their security. Premium adds a 24/7 Canadian based human security operations centre, annual NIST and CIS assessments with governance reviews, application allowlisting, priority vulnerability remediation and email archiving for compliance.
Which Tuor plan is right for my business?
Fundamental fits most growing businesses that want a complete, secure IT department without the noise. Advanced is the right call if you handle sensitive client data, operate in a regulated industry, or your cyber insurer is asking harder questions every renewal. Premium is for organizations that need round the clock human security monitoring and a formal governance program, often because clients or auditors require evidence of it. We recommend the tier that matches your actual risk, and it is fine to start at one level and move up as you grow.
Is hardware and software licensing included in the monthly fee?
Procurement and vendor management are included, meaning we research, quote, order, configure and manage the lifecycle of your hardware and licences. The products themselves, such as laptops, firewalls and Microsoft 365 subscriptions, are billed transparently at the quoted price. Bundling everything into a single hidden number usually costs businesses more, so we keep the service fee and the product costs visible and separate.
Does Tuor require a long term contract?
Our agreements are written in plain language and we walk through term length, what is included and how an exit works before you sign anything. Managed IT works best as a partnership over years, but that should be because the service earns it, not because a contract traps you. You always retain ownership of your data, your documentation and your administrative credentials.
What affects the price of managed IT services?
The biggest factors are how many users you have, how many servers and locations we manage, the security tier you need, any compliance requirements such as PIPEDA, PHIPA or Quebec's Law 25, and whether you need extended hours or on site coverage beyond the norm. Remote and hybrid teams add little cost because most support is remote anyway. Legacy equipment and unsupported software tend to increase cost because they create more work and more risk, which is why we build a refresh roadmap into every plan.
How should a 25, 50 or 100 person company budget for IT?
Start with a per user managed services fee multiplied by headcount, then add Microsoft 365 or equivalent licensing, cyber insurance, and a hardware refresh budget that replaces laptops every four to five years and network equipment roughly every five to seven. For a 50 person Ontario business that usually lands somewhere between $8,000 and $15,000 a month all in, depending on the security tier and how current your equipment is. The advantage of managed IT is that the largest line becomes predictable, and a quarterly business review keeps the rest from surprising you.
Section 04
Cybersecurity for small and mid sized businesses
What actually protects a business in 2026, without the fear marketing.
12 questions
What cybersecurity does a small business in Ontario actually need in 2026?
Seven controls stop the vast majority of attacks on small businesses. Multifactor authentication on every account, especially email, remote access and administrator accounts. Endpoint detection and response on every computer and server rather than traditional antivirus. Backups that are immutable or offline and are tested with a real restore. Email security including sender authentication such as SPF, DKIM and DMARC. Automatic patching of operating systems and applications. Security awareness training with phishing simulations. And a written incident response plan that names who does what.
This list lines up with the Canadian Centre for Cyber Security baseline controls for small and medium organizations and with what cyber insurers now require before they will quote a policy. Tuor's baseline covers the technical controls on this list, and we help you write and test the incident response plan.
What is EDR and how is it different from antivirus?
Traditional antivirus looks for known malicious files. Endpoint detection and response (EDR) watches behaviour, so it can spot an attacker who is using legitimate tools, stealing credentials or moving between machines, and it can isolate a compromised device automatically. EDR also records what happened so an investigation is possible afterwards. Cyber insurers stopped accepting antivirus alone several years ago. Every Tuor plan includes EDR with 24/7 threat hunting on every managed device.
Do I need 24/7 security monitoring or a SOC?
Attacks do not wait for business hours, and many ransomware attacks are launched overnight, on weekends and on holidays when nobody is watching. Every Tuor plan includes 24/7 monitoring and endpoint detection with continuous threat hunting. Our Advanced plan adds SIEM and XDR with automated response, and our Premium plan adds a 24/7 Canadian based human security operations centre, where analysts investigate alerts and act in real time. Whether you need the human SOC depends on your risk profile, your data and what your clients, auditors or insurer expect.
What is the difference between vulnerability scanning and penetration testing?
Vulnerability scanning is automated and continuous. It checks your systems against a database of known weaknesses and tells you what needs patching or reconfiguring. Penetration testing is a human led exercise where a tester actively tries to break in, chaining weaknesses together the way a real attacker would. Scanning is included in every Tuor plan. External network penetration testing is included in our Advanced and Premium plans, and it is increasingly requested by enterprise clients and insurers.
How does Tuor protect businesses against ransomware?
Ransomware defence is layered. Email and DNS protection block most malicious links and attachments before anyone clicks. Multifactor authentication and identity protection stop stolen passwords from being enough. Endpoint detection and response with 24/7 threat hunting catches attackers who get through and isolates the device. Patching closes the holes they exploit. And image based backups with local and cloud copies, tested regularly, mean that even in the worst case you restore rather than pay. Staff training closes the loop, because people are the most common entry point.
What is the difference between backup and disaster recovery?
Backup is a copy of your data. Disaster recovery is the tested plan and technology for getting your business running again after something goes badly wrong, whether that is ransomware, a failed server, a flood or a fire. Two measures matter. Recovery time objective, how long you can afford to be down, and recovery point objective, how much recent data you can afford to lose. We help you set both based on business risk, build image based backups with local and cloud tiers to match, and run test restores so the plan works when it counts.
Is Microsoft 365 backed up automatically?
Not in the way most people assume. Microsoft operates on a shared responsibility model. It keeps the service running and offers retention features, but protecting and restoring your own data is your responsibility, and Microsoft does not provide a true independent backup of your mailboxes, OneDrive, SharePoint and Teams content that you can restore after a deletion, a ransomware event or a compromised account. Every Tuor plan includes email protection and cloud backup for Microsoft 365, and our Advanced plan adds cloud identity backup for your Microsoft Entra configuration.
What should I do if I think my business has been hacked?
Call your IT provider immediately, and if you are a Tuor client call the service desk at any hour. Do not turn off or wipe affected machines, because evidence and recovery options live on them. Disconnect them from the network if you can. Change passwords from a device you trust, starting with email and administrator accounts, and alert your bank if payments could be affected. Write down what you saw and when. If personal information may have been exposed, PIPEDA requires you to assess whether there is a real risk of significant harm and to report and notify accordingly, and your cyber insurer will want to be notified promptly. The faster the first hour goes, the smaller the incident stays.
Does security awareness training actually work?
Yes, when it is ongoing rather than a once a year video. Phishing remains the most common way attackers get in, and organizations that run regular short training with realistic phishing simulations see click rates drop sharply over the first year. Training is included in every Tuor plan, and we report results so leadership can see the trend. It is also a control that cyber insurers and frameworks like CyberSecure Canada expect to see.
What is zero trust and does it apply to a 30 person company?
Zero trust is a simple idea. Never assume a user or device should be trusted just because it is inside the office or has a password. Verify identity with multifactor authentication, check that the device is healthy and managed, grant only the access a person needs, and reassess continuously. For a 30 person company this is not a big project. It is mostly configuration in Microsoft 365 and on your endpoints, and it dramatically reduces the damage a single compromised account can do. Tuor applies zero trust principles as part of the standard baseline.
What is dark web monitoring?
Dark web monitoring watches criminal marketplaces and data dumps for your company's email addresses, passwords and domains. When an employee's credentials show up in a breach of some other service, which happens constantly, you find out quickly and can reset passwords before an attacker reuses them to get into your systems. It is included in Tuor's Advanced and Premium plans.
What security frameworks does Tuor follow?
Our security stack and processes are aligned to the CIS Controls and the NIST Cybersecurity Framework, the two most widely referenced frameworks for organizations of our clients' size. They also map cleanly to the Canadian Centre for Cyber Security baseline controls that underpin the CyberSecure Canada certification. Premium plan clients receive an annual NIST and CIS assessment with governance reviews, which doubles as evidence for insurers, auditors and enterprise customers.
Section 05
Cyber insurance, privacy law and compliance in Canada
The Canadian rules that apply to your business, updated for 2026.
13 questions
What do cyber insurers require from small businesses in 2026?
Canadian cyber insurance applications have grown to anywhere from eight to twenty five pages and they read like a security audit. Most carriers now require multifactor authentication on every account, endpoint detection and response on every device, immutable or offline backups with a recent tested restore, a written and tested incident response plan, security awareness training, email authentication such as DMARC, and a documented patching process. Missing MFA is the single most common reason a business cannot get a quote at all.
The other trap is accuracy. The application is a legal attestation, and claims are being denied when forensics find a control that was declared but not fully in place. That is why insurers increasingly favour businesses with a managed provider who can prove the controls are deployed everywhere and kept that way.
Can Tuor help us complete a cyber insurance application or renewal?
Yes, and we recommend involving us before you sign anything. We review the questionnaire with you, confirm each control is actually deployed across your whole environment rather than mostly, and provide the evidence underwriters ask for, such as MFA coverage, EDR deployment, backup test results and training records. Because these controls are part of our standard baseline, our clients generally move through renewals with fewer surprises and better terms. Give yourself 60 to 90 days before renewal for a clean process.
Is cyber insurance mandatory for businesses in Canada?
No Canadian law requires most businesses to carry cyber insurance. It is often required by contract, by a lender, or by a larger customer's vendor terms, and it is strongly advisable given that a single ransomware incident can cost far more than years of premiums. Separately from insurance, PIPEDA legally requires you to report serious breaches and keep records of all of them, so a legal duty exists whether or not you are insured.
Which privacy law applies to a business in Ontario?
For most private sector businesses in Ontario the answer is PIPEDA, the federal Personal Information Protection and Electronic Documents Act, because Ontario does not have its own general private sector privacy law. If you handle personal health information you are also subject to Ontario's PHIPA. If you have customers or employees in Quebec, British Columbia or Alberta, those provinces have their own private sector laws, with Quebec's Law 25 being the strictest. And if you sell to government or the public sector, contract terms usually import additional requirements. We help clients map which rules apply to which data before an auditor or a breach forces the question.
What are PIPEDA's breach reporting requirements?
Under PIPEDA, if a breach of security safeguards creates a real risk of significant harm to an individual, you must report it to the Office of the Privacy Commissioner of Canada, notify the affected individuals, and notify any other organization that could reduce the harm, all as soon as feasible. You must also keep a record of every breach, including the ones that do not meet the reporting threshold, for at least two years. Knowingly failing to report, notify or keep records is an offence that can lead to fines. Good logging, EDR and backups are what make it possible to answer the question of what actually happened.
What is Bill C-36 and will it replace PIPEDA?
Bill C-36, tabled on June 15, 2026, would replace the privacy portions of PIPEDA with the Protecting Privacy and Consumer Data Act. It is the federal government's third attempt at reform after Bills C-11 and C-27 failed. Key changes include a new regulator, the Digital Safety and Data Protection Commission of Canada, mandatory documented privacy management programs, new rules on automated decision systems and de-identified data, and administrative penalties of up to $25 million or 5% of global revenue for serious offences. As of September 2026 it has had first reading only, with Parliament returning on September 21, so it is not yet law. Organizations that document their privacy practices now will be well positioned whatever the final text looks like.
Does Quebec's Law 25 apply to my Ontario business?
It can, even if you have no office in Quebec. Law 25 applies to private organizations that collect, use or hold personal information about people in Quebec, so a single Quebec customer list or remote employee is enough to bring you into scope. Requirements include naming a person in charge of protecting personal information, keeping a register of confidentiality incidents and reporting serious ones to the Commission d'accès à l'information, conducting privacy impact assessments before sending personal data outside Quebec, and clear consent practices. Penalties can reach $25 million or 4% of worldwide turnover. It is the most common compliance gap we find in Ontario businesses that assumed it did not apply to them.
What is Bill C-8 and does the Critical Cyber Systems Protection Act affect small businesses?
Bill C-8 became law when it received Royal Assent in June 2026. It amends the Telecommunications Act, which took effect immediately, and creates the Critical Cyber Systems Protection Act, which will impose mandatory cybersecurity programs, supply chain risk management and incident reporting on designated operators in federally regulated sectors such as banking, telecommunications, energy and transportation. Those obligations phase in through regulations that have not yet been set. Most small businesses are outside its direct scope, but if you supply services to a bank, a utility or a telecom you should expect the requirements to flow down through vendor questionnaires and contract clauses over the next couple of years.
What is CyberSecure Canada and should we get certified?
CyberSecure Canada is the federal government's voluntary cybersecurity certification for organizations with 1 to 499 employees. It is assessed against the 13 baseline controls published by the Canadian Centre for Cyber Security, covering incident response, patching, MFA, training, backups, secure cloud and outsourced IT, access control and more, and it is administered by the Standards Council of Canada. Certification lasts two years and is increasingly referenced in government and enterprise procurement. If your customers are asking about your security posture, it is a much lighter lift than ISO 27001. Tuor's baseline already implements the controls, so certification is mostly documentation and an assessment.
What is SOC 2 and does a small business need it?
SOC 2 is an audit report on a service organization's controls for security, availability, confidentiality, processing integrity and privacy, produced by an independent CPA firm. Most small businesses do not need one unless their customers require it, which is common if you sell software or handle other companies' data. When you are choosing IT and cloud vendors, asking for their SOC 2 report or an equivalent description of controls is a reasonable due diligence step, and we help clients review them.
What is the difference between data residency and data sovereignty?
Data residency is where your data is physically stored. Data sovereignty is which country's laws govern who can access it. They are not the same thing. A Canadian data centre run by a US headquartered company gives you residency, but the provider remains subject to US law including the CLOUD Act, which can compel US companies to produce data regardless of where it sits.
For most Ontario businesses the practical approach is to know which systems hold your most sensitive data, choose Canadian regions where they are available, understand who controls the encryption keys, and work with Canadian owned providers for the services where control matters most. Tuor is Canadian owned, and we help clients document residency and sovereignty for each system so the answer is ready when a client or regulator asks.
Can our Microsoft 365 and Azure data be stored in Canada?
Yes. Microsoft operates Canadian regions, Canada Central in Toronto and Canada East in Quebec City, and Microsoft 365 tenants for Canadian organizations store core customer data such as Exchange, SharePoint, OneDrive and Teams content in Canada. Azure workloads can be deployed to the Canadian regions as well. That satisfies residency requirements and is what most Canadian privacy assessments expect. It does not by itself remove US jurisdiction over Microsoft as a US company, which is why we treat residency as one control among several rather than the whole answer.
What is PHIPA and does it apply to my business?
PHIPA is Ontario's Personal Health Information Protection Act. It governs health information custodians such as clinics, pharmacies, dental and physiotherapy practices, and it also reaches the service providers who handle that information on their behalf, including IT providers, who act as agents of the custodian. PHIPA requires safeguards, breach notification to the Information and Privacy Commissioner of Ontario in certain cases, and annual statistical reporting of breaches. If your business handles health information, your IT provider should be able to explain in writing how they meet PHIPA obligations.
Section 06
Cloud and Microsoft 365
Licensing, migrations, Copilot and what changed in 2026.
8 questions
Which Microsoft 365 plan should a small business choose?
Most small businesses land on a mix. Microsoft 365 Business Basic covers email, Teams and web apps for roughly $7 USD per user per month. Business Standard adds the desktop Office apps for about $14. Business Premium, at $22, adds the security and device management layer including Intune, Defender for Business and Entra ID P1, which is where insurers and auditors want you to be. The July 2026 price change narrowed the gap between Standard and Premium, so we recommend Premium for anyone who handles sensitive data and a role based mix for everyone else. Tuor is a Microsoft Solutions Partner and manages licensing for clients.
Did Microsoft 365 prices go up in 2026?
Yes. Microsoft's first commercial price increase since 2022 took effect on July 1, 2026. Business Basic moved from $6 to $7 USD per user per month, Business Standard from $12.50 to $14, Microsoft 365 E3 from $36 to $39, and Frontline plans rose by as much as a third. Business Premium and Office 365 E1 stayed flat. Existing subscriptions move to the new price at their next renewal after July 1, so most businesses feel it at renewal rather than immediately. The best response is a licence review, since unused seats, departed users still licensed and duplicate third party tools usually cover the increase.
Should we buy Microsoft 365 licences through Tuor or directly from Microsoft?
The product is identical either way. Buying through Tuor as a Microsoft Solutions Partner means your licences, billing, support and security configuration are managed by the same team that runs your environment, so adding or removing a user is one request rather than a login and a separate invoice. We handle renewals, right size seats before they renew, and act as your escalation path into Microsoft. Pricing is competitive with buying direct, and you get accountability that a portal does not offer.
What is Azure and when does a small business need it?
Azure is Microsoft's cloud platform for running servers, applications, databases and backups without owning hardware. A small business typically reaches for Azure when an old on premises server needs replacing, when a line of business application needs to be reachable from anywhere, or when it wants cloud backup and disaster recovery with Canadian data residency. Not everything belongs in Azure, and unmanaged cloud spend can climb quickly, so we design right sized hybrid or cloud architectures and monitor cost as part of the service.
Can Tuor migrate us to Microsoft 365 from on premises servers or Google Workspace?
Yes. We plan and run migrations from on premises Exchange and file servers, from Google Workspace, and from other hosted email platforms to Microsoft 365, including mail, calendars, contacts, files and Teams setup. The plan is built to minimize downtime, usually with the cutover happening outside business hours, and it includes identity setup, the security baseline, and training for your staff on the new tools. Migration is a good moment to fix permissions and retire old data, so we build that in.
What is Microsoft 365 Copilot and is it worth it for a small business?
Microsoft 365 Copilot is an AI assistant built into Word, Excel, Outlook, Teams and the rest of Microsoft 365 that can draft, summarize and analyze using your own business data. The full add on lists at about $30 USD per user per month, while lighter Copilot Chat capabilities are now included in business plans. It is worth it for roles that live in documents, email and meetings, and the returns depend on two things. Sequenced adoption with training, and cleaning up oversharing in SharePoint and OneDrive first, because Copilot surfaces whatever a user already has access to. Our AI Governance service handles both.
What happened with Windows 10 end of support?
Microsoft ended free support for Windows 10 on October 14, 2025. Devices still on Windows 10 no longer receive security updates unless they are enrolled in Microsoft's paid Extended Security Updates program, which is a temporary bridge rather than a plan. Unsupported operating systems are also a red flag on cyber insurance applications. If you still have Windows 10 machines, we recommend a Windows 11 refresh roadmap that replaces incompatible hardware over the coming budget cycles rather than all at once.
Is the cloud more secure than on premises servers?
It can be, but it is not automatic. Microsoft and other major providers invest more in physical security, redundancy and patching than any small business can, so the platform is typically more secure than a server in a closet. The risk shifts to configuration and identity. Weak MFA, oversharing, unmanaged devices and misconfigured tenants are the leading causes of cloud breaches. The cloud is more secure when someone owns the configuration, monitors it continuously and backs up the data, which is what a managed provider does.
Section 07
AI for business
Adopting AI safely, whether that is Copilot, Claude or ChatGPT.
6 questions
Is it safe for employees to use ChatGPT, Copilot or Claude at work?
It is safe when three things are true. You use business or enterprise tiers, which contractually exclude your data from model training, rather than free consumer accounts. You have a short written policy that says which tools are approved and what data may never be pasted into them. And you have visibility into which AI apps are connected to your Microsoft 365 tenant. Most AI risk in small businesses comes from well meaning staff using free tools with client data, not from the technology itself.
What is AI governance and why does a 40 person company need it?
AI governance is the set of policies, controls and reviews that let your business use AI productively without leaking data or breaking privacy law. For a smaller company it means an approved tools list, an acceptable use policy, discovery of shadow AI already in use, data loss prevention and sensitivity labels so confidential files stay protected wherever they go, oversharing cleanup before you turn on Copilot, and periodic reviews of connected apps and agents. The Canadian Centre for Cyber Security has published guidance on generative AI risks, and privacy regulators expect PIPEDA obligations to apply to AI use just as they do to any other processing.
How does Tuor help businesses adopt AI?
Our AI Governance and Security service covers the full path. AI readiness and risk assessments including shadow AI discovery and data exposure reviews, Microsoft Purview deployment with sensitivity labels and data loss prevention tuned for AI, SharePoint and Microsoft 365 oversharing cleanup, Microsoft 365 Copilot enablement done securely, AI acceptable use policies and staff training, and ongoing governance with an inventory of agents and apps and quarterly reporting. Tuor is a Microsoft Solutions Partner and an Anthropic partner, so we can help you deploy Copilot, Claude or both with the right guardrails.
Which is best for a small business, Microsoft Copilot, ChatGPT or Claude?
There is no single winner, and the model matters less than the governance around it. Microsoft 365 Copilot inherits your existing tenant security, works inside the apps your staff already use and is the natural default for most Microsoft based businesses. Claude is particularly strong for long document analysis, writing and reasoning, and Claude for Work offers business data protections. ChatGPT is the most widely known and its business tiers add similar protections. A common pattern is Copilot as the primary tool with a small pool of Claude seats for specialists who do heavy document and analysis work. We help you choose based on your data, your workflows and your compliance obligations.
Does Canada have an AI law?
Not a standalone one. Canada released the AI for All national strategy in June 2026 and chose to address AI risk through targeted legislation, principally privacy reform, rather than a dedicated AI act like the European Union's. Bill C-36, the proposed replacement for PIPEDA, includes obligations around automated decision systems and de-identified data, and existing privacy law already applies to how AI tools process personal information. Regulated sectors have additional expectations from their own regulators. In practice, good AI governance today is mostly good privacy and security governance.
How many Canadian businesses are actually using AI?
Adoption has accelerated sharply. Statistics Canada reported that about 19% of Canadian businesses used AI to produce goods or deliver services in the twelve months to mid 2026, up from roughly 6% two years earlier, with professional services and finance leading. The productivity gains are real for businesses that adopt intentionally, with a plan, training and governance, and largely absent for those who buy licences and hope. That gap is why we treat AI adoption as a managed project rather than a checkbox.
Section 08
Choosing or switching an IT provider
How to evaluate an MSP, and what to expect if you move to Tuor.
8 questions
How do I choose a managed IT provider in Toronto?
Focus on how they actually operate rather than the sales deck. Ask whether they are Canadian owned and where support is delivered from. Ask whether cybersecurity is included in the base fee or sold as an upsell. Ask for their service levels in writing and how they measure themselves against them. Ask about the ratio of specialists to users, how after hours issues are handled, whether they can dispatch on site across the GTA, how they support cyber insurance renewals, and what the exit process looks like. Then ask for references in your industry and call them.
What questions should I ask an MSP before signing a contract?
A short list that separates strong providers from average ones. What exactly is included in the monthly fee and what is billed extra. What are your response and resolution targets by priority, and can I see last quarter's numbers. Who owns my data, documentation and administrator credentials. How do you handle an after hours emergency. What security controls are included and do they meet cyber insurance requirements. How do you back up my data and when did you last test a restore. How many technicians support how many users. What does onboarding involve and how long does it take. What is the contract term and how does an exit work. Can I speak to three current clients of similar size.
A confident provider welcomes every one of these. A vague or defensive answer is your answer.
What are the red flags when evaluating an IT provider?
Watch for break-fix habits dressed up as managed services, such as hourly billing for routine support. Vague or missing service levels. Security sold as a separate product or brand with no integration. Support delivered only offshore with no Canadian escalation. No regular reporting or business reviews. One or two person shops where everything lives in someone's head. Contracts with no clear exit, or with the provider holding your administrator credentials. And any reluctance to let you speak with current clients.
How does switching IT providers work and will there be downtime?
A well run switch has little or no downtime. We start by collecting documentation and credentials from your outgoing provider, ideally with a defined transition period where both parties have access. We deploy our monitoring and security agents alongside theirs, verify backups, and take over the service desk on an agreed date. Their tools are then removed. Your staff notice a new phone number and a new face, not an outage. The most common friction is an outgoing provider dragging their feet on handover, which is why the exit terms in your current contract matter.
What if my current IT provider will not hand over passwords or documentation?
You own your data, your licences and the administrator credentials to your systems, and a provider withholding them is a serious problem, but it is a situation we know how to handle. Start by requesting them in writing with a deadline, referencing your agreement. In parallel, we can regain administrative control of Microsoft 365, domains and network equipment through vendor recovery processes if needed. Most providers cooperate once they realize you have a plan. The lesson for the next agreement is to require that credentials and documentation are always held in a system you can access.
How do I know if my current IT provider is doing a good job?
Ask a few questions and see how quickly the answers arrive. When was our last successful backup restore test. What percentage of our devices have MFA and EDR. Which of our systems are out of support. When was our last business review and what did we decide. If you are not getting patch reports, if the same problems keep recurring, if you dread the cyber insurance questionnaire every year, or if you cannot name your account manager, the relationship is reactive rather than managed. A second opinion is free and takes 30 minutes.
What is the MSP 501 and what is Canada's 50 Best Managed IT Companies?
The MSP 501 is a global annual ranking of the top performing managed service providers based on audited financial and operational data. Canada's 50 Best Managed IT Companies is a Canadian program that recognizes MSPs on business excellence, service quality and customer focus. Tuor was named to the 2026 MSP 501 in our first year applying and has been on the Canada's 50 Best list for three consecutive years. Awards are not a substitute for references, but they do indicate a provider that runs its business seriously.
Does Tuor offer a free consultation?
Yes. We offer a free 30 minute Discovery Call where we learn about your business, your current IT setup and what is frustrating you, and we answer your questions honestly, including the ones that end with us not being the right fit. If it makes sense to continue, we follow up with a plain language proposal and clear pricing. No pressure and no commitment. Call 1-833-599-TUOR or use the form on our homepage.
Still have a question?
Bring it to a free 30 minute Discovery Call. Real specialists, no phone trees, no pressure, just straight answers.