Cybersecurity is about small, targeted moves: 20% of the right actions prevent 80% of the risk. Find your 20%: assess your exposure →

Insights & guidance

Cybersecurity analysis and guidance

Cybersecurity, Law 25 compliance, infrastructure: our insights for Quebec SMBs and organizations.

Recorded cases · Canada Published September 17, 2026

Cyberattack in the Education Sector: What It Means for SMEs

A cyberattack reportedly disrupted operations at an education sector organization, to the point of considering a delayed start of the school year. This case is a reminder that no Quebec SME or nonprofit is immune to a similar scenario.

cybersecuritySMEsnonprofits
Recorded cases · Canada Published September 17, 2026

Cyberattack on a Quebec Autism Organization: What It Means for Nonprofits

A cyberattack on a Quebec organization supporting autistic individuals exposed the personal information of nearly 2,000 people. Here is what this incident reveals about nonprofits' obligations regarding personal information protection.

cyberattacknonprofitsLaw 25
Recorded cases · Canada Published September 17, 2026

Data Breach at a Canadian Public Utility: Portal Remains Offline

The online portal of Halifax Water, a Canadian public utility, remains offline following a data breach, according to Radio-Canada. Details remain limited, but the episode shows how a prolonged outage can affect an organization.

data breachbusiness continuitypublic utility
Recorded cases · Canada Published September 17, 2026

Cyberattack on Critical Infrastructure in Canada: What It Means for SMEs

A cyberattack targeted critical infrastructure in Canada, with the affected sector undisclosed, according to Radio-Canada. The incident is a reminder for Quebec SMEs and nonprofits to check their own exposure.

critical infrastructurecyberattackLaw 25
Recorded cases · Canada Published September 17, 2026

Cyberattack Targeting Drinking Water in the Maritimes: A Lesson for SMBs

Drinking water infrastructure in New Brunswick and Nova Scotia was placed under heightened monitoring after a cyberattack in March 2024. Details remain unconfirmed, but the episode is a reminder that no essential system is immune.

critical infrastructurecyberattackindustrial control systems
Recorded cases · Canada Published September 17, 2026

Revolut Data Leak: Quebec Customers Potentially Affected

A data leak has hit neobank Revolut, with European customers affected according to available reports. The impact on Quebec users of the service has not been confirmed at this stage.

Reported casesCanadadata leak
Recorded cases · Quebec Published September 17, 2026

Near-Miss Breach at Communauto: Lessons for Quebec SMBs

A security flaw at Communauto could have exposed some users' personal information, according to La Presse. Here is what this narrowly avoided incident concretely changes for Quebec SMBs and nonprofits.

Reported casesQuebecCommunauto
Recorded cases · Quebec Published September 17, 2026

Communauto Employee Suspected of Data Theft: The Lesson for SMBs

An employee of Communauto is suspected of having extracted data from several customers, according to media reports. This insider case illustrates a risk that any Quebec SMB can face, regardless of size.

Reported casesQuebecinsider threat
Recorded cases · Canada Published September 17, 2026

Canadian Chamber of Commerce: Cybersecurity Is a Small Business Issue Too

The Canadian Chamber of Commerce says cybersecurity is now a shared responsibility, not just a concern for large companies. For Quebec SMEs and nonprofits, this policy reminder echoes legal obligations already in force.

Reported casesCanadaSME cybersecurity
Recorded cases · Quebec Published September 17, 2026

Cyberattacks and Insurance: A Reminder of a Blind Spot for Quebec SMBs

A QUB radio report examines a hacking case where losses reportedly were not covered by the affected company's insurance. It is a reminder that cyber risks are often excluded from standard policies, a reality that also concerns Quebec SMBs and nonprofits.

Reported casesQuebeccyber insurance
Recorded cases · Canada Published September 17, 2026

School cyberattack in France: what it means for Quebec SMBs

A cyberattack recently disrupted the start of the school year at a school in France, forcing it to operate under degraded conditions. RISS Canada looks at this case to draw lessons that apply to Quebec SMBs and nonprofits.

Reported casesCanadacyberattack
Recorded cases · Quebec Published September 17, 2026

AI Giants Sound the Alarm on Cybersecurity: What It Means for Your SME

Leading AI companies are comparing the state of global cybersecurity to a doomsday clock nearing midnight. For Quebec SMEs and nonprofits, this global signal is a reminder to check their own basic protections.

Reported casesQuebeccybersecurity
Recorded cases · Canada Published September 17, 2026

A Cyberattack Disrupts Back-to-School in Canada: What It Means for Your SME

Canadian schools reportedly faced a cyberattack disrupting the start of the school year. Technical details remain unclear, but the incident is a reminder that resource-constrained organizations remain attractive targets.

Reported casesCanadacyberattack
Recorded cases · Canada Published September 17, 2026

AI-Assisted Cyberattacks in Canada: What It Means for Your SME

A Radio-Canada report describes a recent cyberattack in which artificial intelligence techniques reportedly helped automate and conceal the intrusion. Details remain limited, but the trend it illustrates directly concerns Quebec SMEs and non-profits.

Reported casesCanadacyberattack
Recorded cases · Quebec Published September 17, 2026

Data Leak Affecting Quebecers: What Remains to Be Confirmed

A data leak reportedly affected Quebec residents, according to a local media outlet, though the incident's origin and scale remain unconfirmed. The uncertainty is a reminder of the obligations that apply to Quebec organizations regardless of the specific circumstances.

Confirmed casesQuebecdata leak
Recorded cases · Quebec Published September 17, 2026

Data Breach Affecting 414,000 Quebecers: What It Means for Your SMB

A data breach reportedly exposed the personal information of 414,000 Quebecers, according to available reports. This incident is a reminder that data protection obligations apply to SMBs and nonprofits as well, not only to large organizations.

Documented casesQuebecdata breach
Recorded cases · Quebec Published September 17, 2026

Cyberattack on a Quebec Healthcare Facility: Lessons for SMEs and Nonprofits

A Quebec healthcare facility was reportedly targeted by a cyberattack, according to press reports. Technical details remain unclear, but the incident is a reminder that IT security concerns every organization.

Recorded incidentsQuebeccybersecurity

Key points

  • Analysis of real events, not raw threat feeds: what the event changes for you.
  • Every figure published carries its body, its publication and its year.
  • Our own engagement measurements are presented as such, never as third-party data.
  • Five themes: ransomware, Law 25, supply chain, AI and fraud, technical foundations.

What do you publish, and why?

Analysis of real events, chosen because they change something for a smaller Quebec organization. Every article follows the same structure: the verifiable facts, what actually happened technically, then the applicable lesson. Sources are cited and figures carry their origin.

We do not publish raw threat feeds. A list of copied alerts helps nobody decide: what executives lack is not information but the translation of information into a consequence for their organization. A ransomware attack on a pharmacy chain in Western Canada only matters to a manufacturer in Saint-Hyacinthe if someone explains what it reveals about their own backups.

That requirement has a cost: we publish less often than an automated feed. It also has a consequence we state publicly in our analyses, namely that certain figures widely repeated in this market are unverifiable, and that we prefer to drop them rather than repeat them to fill space.

Which themes do you follow?

Five, chosen because they are the five places smaller Quebec organizations actually get caught. They match the blog categories and also serve as the thread running through our assessments.

  • Ransomware and extortion. The business model, double extortion, what an operational shutdown really costs, and the controls that intercept most scenarios.
  • Law 25 compliance and personal information. Obligations in force, the incident register, notification to the Commission d'accès à l'information, disclosures outside Quebec.
  • Data leaks and the supply chain. The risk that arrives through your suppliers, particularly through the remote administration tools used by IT providers.
  • AI, deepfakes and fraud. What generative artificial intelligence changes about executive impersonation and phishing, and how to govern the AI your teams already use.
  • Technical foundations. Access and authentication, genuinely tested backups, patch management and internet-facing systems.

How do you read an analysis without wasting time?

Every article opens with dated, sourced facts, then explains the mechanism, then closes with the applicable lesson. If you are short of time, the two sections that matter are "the facts" and "the lesson for your organization".

The structure is deliberately repetitive. It lets you skim an article whose subject does not concern you and dive into the one that touches your situation, without having to read in order to discover whether it is relevant.

Analyses covering a reported case always name their press or institutional source. Those covering a vulnerability give the CVE number, the fixed version and, where it exists, the listing in CISA's catalogue of actively exploited vulnerabilities, which is the best available signal for judging urgency.

What use is an analysis if you are not a client?

Acting on it yourself. Our articles end with measures you can apply without us: check a version, test a restore, enable an authentication method, put a precise question to your IT provider. That is useful even if you never contact us.

The choice is deliberate and the commercial logic is simple: an organization that has applied the basic measures becomes someone you can work with seriously. Conversely, a readership kept in ignorance in order to sell it advice eventually buys from whoever is cheapest, because it cannot tell the difference.

The best way to use the blog, if the subject is new to you, is to start with the technical foundations category. Those analyses cover the controls with the best ratio of effort to risk reduction, and none of them requires a budget to begin.

Sources

Frequently asked questions

On no fixed schedule. We publish when an event justifies a useful analysis, and we do not publish to maintain a rhythm. That means dense periods, typically around a major vulnerability or a regulatory decision, and quiet ones. A steady flow of interchangeable articles would take less effort and serve you less well: we accept the irregularity.

No, everything is public and will stay that way. Articles end with measures applicable without us, and that is intentional: an organization that has applied the basic controls is a better counterpart, for itself as much as for us. The Law 25 white paper is the only content whose full file requires a form, and the page presenting it remains freely readable.

They are produced by the RISS Canada team and published under the editorial responsibility of Olivier Guidici, president. That means an identifiable person stands behind what is written, and any factual error can be reported and corrected. We amend published articles when necessary, including to remove a figure whose source does not hold up.

Yes, citing the source and linking to the original. We have no interest in restricting the spread of content whose purpose is to get basic measures applied. For full republication in a trade publication or an association newsletter, simply write to us: we can supply a version adapted to the format and check that the figures cited are still current.

An email distribution exists for receiving the analyses. It meets the consent requirements of Law 25 and of Canada's anti-spam legislation: explicit consent, stated purpose, and unsubscription available in every message. We do not use that list for commercial prospecting unrelated to the published analyses.

Is your infrastructure ready for the next threat?

An initial assessment, free and without commitment, to evaluate your security posture.

Home Expertise RISS 360 PME Assess