Some outages go unnoticed until the day you need the service. On November 10, 2025, tens of thousands of residents across Greater Montreal unknowingly stopped being reachable in case of an emergency.
Key points
- The municipal alert platform CodeRED was taken offline by a cyberattack.
- The affected cities were not the target; they were hit by a ripple effect.
- Law 25 requires a written contract governing any subcontractor that processes your data.
- Your responsibility cannot be outsourced, even when the incident originates with your vendor.
What happened with CodeRED?
On November 10, 2025, the municipal alert platform CodeRED, operated by Crisis24, was taken offline following a cyberattack. Personal information belonging to registered residents, including names, addresses, emails, phone numbers and associated passwords, was stolen.
The scale is real: in Ville Mont-Royal, more than five thousand people were registered; in Kirkland, at least eleven thousand. Several municipalities had to suspend the service and scramble to migrate to other solutions.
What makes this case instructive is not the attack itself, but the position it puts cities in: they must manage an incident they neither caused, nor could have prevented, nor even detected.
Why does an organization that was never attacked end up exposed?
Because the vendor is a point of concentration. A single breach upstream exposes every downstream client at once. The affected cities were not hacked; their shared provider was, and they inherited its incident without having made any mistake of their own.
You likely entrust data to third parties too: payroll software, cloud hosting, an IT provider, a booking platform. Their security is part of your own, and a weak link in your vendor chain can expose you even when you have done nothing wrong.
The second effect, less visible, is losing control of the timeline. The vendor decides when to inform you, what it discloses, and how quickly it restores service. Your own obligations, however, start running the moment you know.
What obligations does Law 25 impose on your subcontractors?
The disclosure of personal information to a subcontractor must be governed by a written contract specifying the protection measures expected. This is not an administrative formality; it is your legal safety net for the day your vendor stumbles.
- A written contract, not terms of service accepted online. It must name the protection measures in place, limit use to the assigned mandate, and provide for data destruction at the end of the contract.
- A notification obligation, measured in hours. An executive who learns of an incident from the media before hearing from their vendor is already in breach on this point.
- A map of your dependencies. The useful question: which third parties hold or can reach our data, and through what access. Many leadership teams discover at this stage remote access points they didn’t know existed.
- A “what if it’s them” scenario. Your response plan must cover the case where the incident occurs at a third party, because you will then control neither the information nor the timeline.
At RISS, we help Quebec SMEs map their dependencies, govern vendor access, and prepare for the scenario where the incident originates elsewhere.
FAQ
Our vendor refuses to amend its contract. What can we do?
This is common with large software vendors, whose terms are largely non-negotiable. Three levers remain available. Ask for an independent attestation of their security posture, which they generally provide. Document your request and their refusal in writing, which establishes your due diligence. And reduce your exposure by limiting the data you entrust to them, which is often possible without losing the service.
Are we responsible for an incident that occurs at our provider?
Under the regulation, your organization remains responsible for the personal information it entrusted to others. In practice, it is your incident register that must be updated, your business that assesses the risk of serious harm, and the quality of your contractual oversight that will be examined. The provider has its own obligations, but they do not replace yours.
How do we find out which third parties hold our data?
Through an inventory conducted department by department rather than from a list of invoices. Forgotten access points tend to hide in the corners: a remote maintenance box that shipped with a piece of equipment, access granted to an integrator for a project that has since closed, a tool a team adopted without going through leadership. This mapping is the first deliverable in our vendor risk assessments, and it almost always turns up surprises.
Sources
- Journal Métro · CodeRED alert system data breach, November 2025
- Commission d’accès à l’information du Québec (Quebec’s access to information commission) · disclosure of personal information to a third party and notification obligations
- Loi sur la protection des renseignements personnels dans le secteur privé (RLRQ, c. P-39.1) (Act respecting the protection of personal information in the private sector) · current official text