A press report mentions a cyberattack that occurred in Canada, without specifying the exact nature of the incident or its scope. Even incomplete, this kind of news is a useful occasion to revisit what Quebec regulation expects from organizations in this type of situation.
Key points
- A cyberattack was reported in Canada by the press, with no details on the method used or the extent of the damage.
- Many incidents affecting SMEs never make the news, which does not reduce the real risk.
- In Quebec, Law 25 requires organizations to keep an incident register and, in some cases, to notify the Commission d’accès à l’information.
- The Canadian Centre for Cyber Security recommends baseline measures that any organization can apply, regardless of size.
What do we actually know about this incident?
Based on the information available, the press reports that a cyberattack occurred in Canada, without specifying the type of attack, the sector affected, the extent of the damage, or the identity of the organizations involved. No technical details have been made public at this stage, which limits the analysis to general observations rather than a precise account of the facts.
We do not have access to information that would allow us to identify the victim, the method of intrusion, or the precise consequences of this event. It would therefore be inaccurate, and unhelpful to our readers, to add details the source does not provide. What this type of report does allow, however, is a reminder of the framework within which every Quebec organization, SME or nonprofit alike, must now assess its exposure and its ability to respond.
Why does this lack of detail not change the need for vigilance?
The lack of public detail on this incident does not reduce the real risk: ransomware and email fraud affect organizations of all sizes across Canada, including SMEs and nonprofits, often without ever making national headlines.
Many incidents affecting smaller organizations never receive detailed media coverage, either because there is insufficient public interest or because the affected organization chooses not to communicate publicly. That does not mean such incidents are rare. A vague report like this one is mainly a useful reminder: the question is not whether this kind of event can happen, but whether your organization would be able to respond to it in a structured way.
What must a Quebec organization do in the event of a confidentiality incident?
Law 25 requires every Quebec organization to keep a register of confidentiality incidents and, when there is a risk of serious harm, to notify the Commission d’accès à l’information as well as the individuals concerned, regardless of the organization’s size.
The Act respecting the protection of personal information in the private sector, known as Law 25, governs how Quebec organizations must respond to an incident involving personal information. Among other things, it requires organizations to keep a register of confidentiality incidents, regardless of how serious they may appear. These obligations apply to SMEs and nonprofits just as they do to large organizations, which still surprises some business owners who assume this kind of rule mainly targets big companies.
What baseline measures reduce exposure to this type of scenario?
The Canadian Centre for Cyber Security recommends measures within reach of any organization: regular updates, tested backups, strong authentication, and staff awareness training. These measures do not eliminate risk, but they make an intrusion or fraud attempt considerably harder to carry out.
None of these measures, taken alone or even combined, can support a claim that an organization is immune: no cyberattack can be entirely ruled out, and any claim suggesting otherwise should be treated with caution. The realistic goal is to significantly reduce exposure and limit the consequences if an incident occurs despite the precautions taken.
FAQ
Does this incident concern our industry?
We cannot say precisely, since the available source does not specify the sector affected or the nature of the attack. What is verifiable, however, is that ransomware and email fraud strike organizations across every sector in Canada, regardless of size. An SME or nonprofit should not wait for an incident to directly affect its own sector before assessing its exposure. The useful question is not whether your sector is targeted by this specific event, but whether your organization has the recommended baseline measures in place and a plan to respond if an incident occurred.
Does Law 25 require us to report every incident?
Not systematically. Law 25 requires organizations to keep a register for every confidentiality incident, even minor ones, but notification to the Commission d’accès à l’information and to the individuals concerned is only required when there is a risk of serious harm, an assessment that depends on the sensitivity of the information involved and the possible consequences for the people affected. This assessment must be documented regardless of the conclusion reached. An organization that has never formalized this process risks discovering, in the middle of a crisis, that it has to improvise a procedure the law has expected of it since it came into force.
Can a service provider guarantee us total protection against this type of attack?
No, and any claim promising total protection or zero risk should be treated with caution: no serious provider can make that kind of promise, since information security relies on continuously reducing exposure, never on eliminating it entirely. What is realistic is putting recognized measures in place, such as regular updates, tested backups, and staff awareness training, which make an intrusion considerably harder to carry out and limit the consequences if an incident occurs despite these efforts. Structured support helps prioritize these measures according to each organization’s specific context, rather than applying a generic template.
Sources
- La Presse, via Google News · press report, 2026
- Commission d’accès à l’information du Québec (Quebec’s oversight body for access to information and privacy) · obligations, incident register and notification
- Canadian Centre for Cyber Security: Baseline cyber security controls for small and medium organizations · baseline control checklist