Skip to main content
← Back to Insights
CybersecurityLeadershipIndigenous Perspectives

Beyond Compliance: Cybersecurity as Indigenous Stewardship

Reframing cybersecurity from a compliance burden to a modern form of stewardship that protects community trust and long-term sustainability for Indigenous businesses.

CISM, CISA, CRISC, CISSP, PMP
Winter 2023·4 min read·Updated: Jan 1, 2023
AI Summary

For Indigenous entrepreneurs, cybersecurity is often framed as a compliance obligation or a technical burden. This article, originally featured in the CCIB Aboriginal Business Report (Formerly CCAB), reframes that entirely: protecting business data is a form of stewardship, an extension of the responsibility to safeguard community trust and long-term sustainability. It covers four early-stage pillars - MFA, default passwords, password managers, and holistic assessments - along with later-stage guidance on cybersecurity roadmaps and partnership risk. It closes with the Indigenous context shaping all of this: disproportionate cyber impacts, connectivity gaps in northern and remote regions, and a framework for incorporating your Nation's values into how you manage digital risk.

Beyond Compliance: Cybersecurity as Indigenous Stewardship

In the lifecycle of an entrepreneur, cybersecurity is often pushed to the bottom of the to-do list. However, neglecting this vital aspect of digital security can put your business, your partners, and even your clients at risk. At Nitap Technologies, we believe in reframing this conversation: cybersecurity shouldn't be a source of fear. It should be viewed as a modern form of stewardship.

The Holistic View

Moving beyond a narrow "cyber lens" allows organizations to incorporate broader business objectives into their security posture. For Indigenous entrepreneurs, this means understanding that protecting business data is an extension of safeguarding community trust and long-term sustainability.

The Four Pillars of Digital Hygiene

As discussed in the Canadian Council for Indigenous Business (CCIB, formerly CCAB) feature, I recommend focusing on four critical areas:

  • Leveraging MFA: Using multi-factor authentication to confirm identity security across all accounts and access points.

  • Default Passwords: Moving away from factory defaults to harden perimeter security on routers, firewalls, and any network device.

  • Password Managers: Utilizing tools to manage unique, complex credentials without relying on memory or reuse.

  • Holistic Strategies: Integrating assessments (such as web application assessments) to identify and remediate vulnerabilities early - before attackers do.

Already Past the Early Stage? It's Not Too Late

If you're a few years into running your business and haven't worked through those four pillars, don't panic. You can loop back and enable MFA across your accounts, rotate out default credentials, and put a password manager in place at any time. Once the basics are in hand, there are two further areas that matter as the business grows:

  • Build a cybersecurity roadmap. A roadmap is more than a checklist - it's a business enabler, an insurance policy, and a defense strategy tied to where your organization is headed. Knowing your current posture and your next few objectives makes every security decision cheaper and faster.

  • Manage partnership and supplier risk. Many Indigenous entrepreneurs grow through joint ventures, contractors, and specialized service providers. Each of those relationships is also a path into your data. Sharing a simple cybersecurity plan with partners, and asking about theirs, keeps you from inheriting someone else's exposure.

An Indigenous Approach

The true value of cybersecurity for Indigenous businesses lies in incorporating your Nation's views into how you manage business risk. This matters even more given the realities the sector faces: Indigenous businesses and communities experience disproportionate cybersecurity impacts, compounded by gaps in reliable broadband and cellular coverage across many northern, rural, and remote regions of Canada. While frameworks like NIST or ITSG-33 provide the technical foundation, there is a profound opportunity to weave in cultural practices and language to create a truly meaningful security posture.

Security done well isn't about checking boxes for auditors. It's about protecting the people, relationships, and knowledge your community has built - and making sure that protection reflects your values.

Related Reading

Follow Our Insights

New articles on cybersecurity strategy, Indigenous digital sovereignty, and governance, delivered when we publish.

Subscribe via RSS to get new articles in your feed reader.

Terms and Legal Notice

By reading this article, you agree to our terms and legal conditions in theLegal and Privacy page.

The views shared in this article are the author's own and do not reflect the views of any other organization or employer.

Dustyn Martin-Ross, Principal Consultant and founder of Nitap Technologies

Dustyn Martin-Ross

CISM, CISA, CRISC, CISSP, PMP, MBA (IT Management)

Principal Consultant and founder of Nitap Technologies. 4+ years at Deloitte leading cybersecurity assessments and governance consulting. Expertise in ITSG-33, PBMM compliance, risk management, and Indigenous data sovereignty.