A press report mentions a cyberattack in Canada, without specifying the sector affected or the extent of the damage. This uncertainty is a useful reminder of the obligations Law 25 places on Quebec organizations in this kind of situation.
cyberattackLaw 25SMEs
Recorded cases · Quebec Published September 17, 2026
Collège du Mont Notre-Dame, in Quebec's Eastern Townships, has confirmed a cyberattack that compromised personal information. The exact scope of the data affected remains unclear, based on information currently available.
cyberattackeducation sectorLaw 25
Recorded cases · Canada Published September 17, 2026
A cyberattack reportedly disrupted operations at an education sector organization, to the point of considering a delayed start of the school year. This case is a reminder that no Quebec SME or nonprofit is immune to a similar scenario.
cybersecuritySMEsnonprofits
Recorded cases · Canada Published September 17, 2026
A cyberattack on a Quebec organization supporting autistic individuals exposed the personal information of nearly 2,000 people. Here is what this incident reveals about nonprofits' obligations regarding personal information protection.
cyberattacknonprofitsLaw 25
Recorded cases · Canada Published September 17, 2026
The online portal of Halifax Water, a Canadian public utility, remains offline following a data breach, according to Radio-Canada. Details remain limited, but the episode shows how a prolonged outage can affect an organization.
data breachbusiness continuitypublic utility
Recorded cases · Canada Published September 17, 2026
A cyberattack targeted critical infrastructure in Canada, with the affected sector undisclosed, according to Radio-Canada. The incident is a reminder for Quebec SMEs and nonprofits to check their own exposure.
critical infrastructurecyberattackLaw 25
Recorded cases · Canada Published September 17, 2026
Drinking water infrastructure in New Brunswick and Nova Scotia was placed under heightened monitoring after a cyberattack in March 2024. Details remain unconfirmed, but the episode is a reminder that no essential system is immune.
critical infrastructurecyberattackindustrial control systems
Recorded cases · Canada Published September 17, 2026
A data leak has hit neobank Revolut, with European customers affected according to available reports. The impact on Quebec users of the service has not been confirmed at this stage.
Reported casesCanadadata leak
Recorded cases · Quebec Published September 17, 2026
A security flaw at Communauto could have exposed some users' personal information, according to La Presse. Here is what this narrowly avoided incident concretely changes for Quebec SMBs and nonprofits.
Reported casesQuebecCommunauto
Recorded cases · Quebec Published September 17, 2026
An employee of Communauto is suspected of having extracted data from several customers, according to media reports. This insider case illustrates a risk that any Quebec SMB can face, regardless of size.
Reported casesQuebecinsider threat
Recorded cases · Canada Published September 17, 2026
The Canadian Chamber of Commerce says cybersecurity is now a shared responsibility, not just a concern for large companies. For Quebec SMEs and nonprofits, this policy reminder echoes legal obligations already in force.
Reported casesCanadaSME cybersecurity
Recorded cases · Quebec Published September 17, 2026
A QUB radio report examines a hacking case where losses reportedly were not covered by the affected company's insurance. It is a reminder that cyber risks are often excluded from standard policies, a reality that also concerns Quebec SMBs and nonprofits.
Reported casesQuebeccyber insurance
Recorded cases · Canada Published September 17, 2026
A cyberattack recently disrupted the start of the school year at a school in France, forcing it to operate under degraded conditions. RISS Canada looks at this case to draw lessons that apply to Quebec SMBs and nonprofits.
Reported casesCanadacyberattack
Recorded cases · Quebec Published September 17, 2026
A data theft affecting roughly 350,000 workers at the Commission de la construction du Québec has been reported in the press. Here is what this incident concretely means for personal information management at Quebec SMEs and nonprofits.
Reported casesQuebecdata theft
Recorded cases · Quebec Published September 17, 2026
Leading AI companies are comparing the state of global cybersecurity to a doomsday clock nearing midnight. For Quebec SMEs and nonprofits, this global signal is a reminder to check their own basic protections.
Reported casesQuebeccybersecurity
Recorded cases · Canada Published September 17, 2026
Canadian schools reportedly faced a cyberattack disrupting the start of the school year. Technical details remain unclear, but the incident is a reminder that resource-constrained organizations remain attractive targets.
Reported casesCanadacyberattack
Recorded cases · Canada Published September 17, 2026
A Radio-Canada report describes a recent cyberattack in which artificial intelligence techniques reportedly helped automate and conceal the intrusion. Details remain limited, but the trend it illustrates directly concerns Quebec SMEs and non-profits.
Reported casesCanadacyberattack
Recorded cases · Quebec Published September 17, 2026
A data leak reportedly affected Quebec residents, according to a local media outlet, though the incident's origin and scale remain unconfirmed. The uncertainty is a reminder of the obligations that apply to Quebec organizations regardless of the specific circumstances.
Confirmed casesQuebecdata leak
Recorded cases · Quebec Published September 17, 2026
A data breach reportedly exposed the personal information of 414,000 Quebecers, according to available reports. This incident is a reminder that data protection obligations apply to SMBs and nonprofits as well, not only to large organizations.
Documented casesQuebecdata breach
Recorded cases · Canada Published September 17, 2026
A water treatment plant in Ontario was targeted by a cyberattack, according to Radio-Canada. The incident is a reminder that essential infrastructure, even on a small scale, remains a strategic target.
Reported incidentsCanadacyberattack
Recorded cases · Quebec Published September 17, 2026
A cyberattack affected the municipality of Saint-Noël, Quebec, according to reporting by Radio-Canada. Here is what this incident reveals about the exposure of small Quebec organizations to current cyber threats.
Recorded casesQuebeccyberattack
Recorded cases · Quebec Published September 17, 2026
A Quebec healthcare facility was reportedly targeted by a cyberattack, according to press reports. Technical details remain unclear, but the incident is a reminder that IT security concerns every organization.
Recorded incidentsQuebeccybersecurity
Recorded cases · Quebec Published September 17, 2026
An incident in Quebec remains difficult to classify: external cyberattack or insider action? This ambiguity is a reminder that SMEs must prepare to respond before they even know what caused an anomaly.
A ransomware attack affected access controls and ventilation systems at a Winnipeg hospital, illustrating the risks facing essential infrastructure.
Reported casesCanadaransomware
Key points
Analysis of real events, not raw threat feeds: what the event changes for you.
Every figure published carries its body, its publication and its year.
Our own engagement measurements are presented as such, never as third-party data.
Five themes: ransomware, Law 25, supply chain, AI and fraud, technical foundations.
By Olivier Guidici, President, RISS Canada Inc.Updated 2026-09-16
What do you publish, and why?
Analysis of real events, chosen because they change something for a smaller Quebec organization. Every article follows the same structure: the verifiable facts, what actually happened technically, then the applicable lesson. Sources are cited and figures carry their origin.
We do not publish raw threat feeds. A list of copied alerts helps nobody decide: what executives lack is not information but the translation of information into a consequence for their organization. A ransomware attack on a pharmacy chain in Western Canada only matters to a manufacturer in Saint-Hyacinthe if someone explains what it reveals about their own backups.
That requirement has a cost: we publish less often than an automated feed. It also has a consequence we state publicly in our analyses, namely that certain figures widely repeated in this market are unverifiable, and that we prefer to drop them rather than repeat them to fill space.
Which themes do you follow?
Five, chosen because they are the five places smaller Quebec organizations actually get caught. They match the blog categories and also serve as the thread running through our assessments.
Ransomware and extortion. The business model, double extortion, what an operational shutdown really costs, and the controls that intercept most scenarios.
Law 25 compliance and personal information. Obligations in force, the incident register, notification to the Commission d'accès à l'information, disclosures outside Quebec.
Data leaks and the supply chain. The risk that arrives through your suppliers, particularly through the remote administration tools used by IT providers.
AI, deepfakes and fraud. What generative artificial intelligence changes about executive impersonation and phishing, and how to govern the AI your teams already use.
Technical foundations. Access and authentication, genuinely tested backups, patch management and internet-facing systems.
How do you read an analysis without wasting time?
Every article opens with dated, sourced facts, then explains the mechanism, then closes with the applicable lesson. If you are short of time, the two sections that matter are "the facts" and "the lesson for your organization".
The structure is deliberately repetitive. It lets you skim an article whose subject does not concern you and dive into the one that touches your situation, without having to read in order to discover whether it is relevant.
Analyses covering a reported case always name their press or institutional source. Those covering a vulnerability give the CVE number, the fixed version and, where it exists, the listing in CISA's catalogue of actively exploited vulnerabilities, which is the best available signal for judging urgency.
What use is an analysis if you are not a client?
Acting on it yourself. Our articles end with measures you can apply without us: check a version, test a restore, enable an authentication method, put a precise question to your IT provider. That is useful even if you never contact us.
The choice is deliberate and the commercial logic is simple: an organization that has applied the basic measures becomes someone you can work with seriously. Conversely, a readership kept in ignorance in order to sell it advice eventually buys from whoever is cheapest, because it cannot tell the difference.
The best way to use the blog, if the subject is new to you, is to start with the technical foundations category. Those analyses cover the controls with the best ratio of effort to risk reduction, and none of them requires a budget to begin.
On no fixed schedule. We publish when an event justifies a useful analysis, and we do not publish to maintain a rhythm. That means dense periods, typically around a major vulnerability or a regulatory decision, and quiet ones. A steady flow of interchangeable articles would take less effort and serve you less well: we accept the irregularity.
No, everything is public and will stay that way. Articles end with measures applicable without us, and that is intentional: an organization that has applied the basic controls is a better counterpart, for itself as much as for us. The Law 25 white paper is the only content whose full file requires a form, and the page presenting it remains freely readable.
They are produced by the RISS Canada team and published under the editorial responsibility of Olivier Guidici, president. That means an identifiable person stands behind what is written, and any factual error can be reported and corrected. We amend published articles when necessary, including to remove a figure whose source does not hold up.
Yes, citing the source and linking to the original. We have no interest in restricting the spread of content whose purpose is to get basic measures applied. For full republication in a trade publication or an association newsletter, simply write to us: we can supply a version adapted to the format and check that the figures cited are still current.
An email distribution exists for receiving the analyses. It meets the consent requirements of Law 25 and of Canada's anti-spam legislation: explicit consent, stated purpose, and unsubscription available in every message. We do not use that list for commercial prospecting unrelated to the published analyses.
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.
This site uses no advertising cookies and no analytics trackers. Only strictly necessary cookies (security, admin session) may be set : no consent required. Learn more.