Networking, cybersecurity, cloud and sovereign AI: RISS Canada supports organizations and SMBs across Quebec throughout the lifecycle of their critical environments.
Our services cover the design, deployment and operation of your networking, cybersecurity and cloud systems, with a constant focus on compliance (Law 25) and data sovereignty. Every service line is delivered by a certified team following a proven method, from the initial audit to continuous improvement. Explore our areas of expertise and our latest insights below.
A press report mentions a cyberattack in Canada, without specifying the sector affected or the extent of the damage. This uncertainty is a useful reminder of the obligations Law 25 places on Quebec organizations in this kind of situation.
cyberattackLaw 25SMEs
Recorded cases · Quebec Published September 17, 2026
Collège du Mont Notre-Dame, in Quebec's Eastern Townships, has confirmed a cyberattack that compromised personal information. The exact scope of the data affected remains unclear, based on information currently available.
cyberattackeducation sectorLaw 25
Recorded cases · Canada Published September 17, 2026
A cyberattack reportedly disrupted operations at an education sector organization, to the point of considering a delayed start of the school year. This case is a reminder that no Quebec SME or nonprofit is immune to a similar scenario.
cybersecuritySMEsnonprofits
Key points
Six distinct engagements, each with a written deliverable and a scope agreed in advance.
Our first recommendation is sometimes not to buy what you asked for.
We resell no licences, so no tool earns us more than another.
An orientation table further down says what to do based on your situation.
By Olivier Guidici, President, RISS Canada Inc.Updated 2026-09-16
Where do you start with no IT team?
With a factual review, never with a tool. Buying a solution before knowing your exposure is like choosing a medication before the diagnosis. Three questions are enough to set the direction, and they can be answered in an hour of conversation.
The organizations that contact us almost always arrive with a request already phrased as a solution: "we need a new firewall", "we want a penetration test", "our insurer is asking for an audit". Those requests are legitimate, but they skip a step. In roughly half of cases, the genuinely useful engagement is not the one that was requested.
What would stop you tomorrow morning? Identify the system whose unavailability would prevent you from invoicing, producing or serving clients. That is what gets protected first, not the one most talked about.
What are you already paying for without using? In many organizations, security features included in existing licences are simply not enabled. The first gain is often free.
Who holds you to account? A client, an insurer, a regulator. The answer determines what must be documented, and therefore the shape of the deliverable.
What are your six engagements?
An assessment to establish where you stand, a compliance engagement, an upgrade of the technical foundations, preparation for insurance questionnaires, team awareness training, and continuously managed security. Each has a written deliverable.
Cybersecurity assessment. The factual review of your exposure: internet-facing assets, access and authentication, backups and real restore capability, outstanding patches. Deliverable: a roadmap prioritised by risk reduction, readable by a management team. See the assessment.
Governance and Law 25 compliance. Incident register, privacy and retention policies, designation of the privacy officer, notification procedure, privacy impact assessments. Deliverable: a file that holds up under review. See Law 25 compliance.
IT security foundations. Multi-factor authentication, tested backups, patch management, access review. These are the controls that intercept most successful attacks on smaller organizations. See the foundations.
Cyber insurance readiness. Underwriting questionnaires ask precise questions about your patching timelines and your access controls. An inaccurate answer can compromise coverage at the moment you need it. See cyber insurance.
Phishing awareness and simulation. Successful attacks almost always begin with a person, not a machine. See awareness training.
Managed security: RISS 360. For when the question is no longer what to do, but who does it day to day. See RISS 360.
How does an engagement unfold?
In four stages, in this order: assessment, prioritised plan, deployment in reversible waves, then continuous management or handover to your teams. Each stage produces a document, and each stage can be the last if you decide so.
01. Assessment. A conversation, then a technical review. We recommend nothing before looking.
02. Prioritised plan. Actions ranked by the ratio between impact and effort, separating what is urgent from what can wait for a future budget cycle.
03. Deployment. In waves, each with its rollback window. A smaller organization cannot afford a security project that interrupts its operations.
04. Continuous management or handover. Either we operate, or we train your teams and document so they can. Both are valid outcomes.
Which service fits which situation?
The table below answers the question the way executives actually ask it. It is deliberately readable without knowing us, and without technical vocabulary.
Your situation
The right engagement
Why that one
We have never had our security assessed
Cybersecurity assessment
Draw the map before digging, so you do not fund work that reduces nothing
A client or insurer has sent us a questionnaire
Cyber insurance readiness
Answer factually, find the blocking gaps, build the correction plan
We handle personal information and Law 25 worries us
Governance and Law 25 compliance
The obligation applies with no size threshold, and documentation is what demonstrates diligence
Our backups exist but have never been restored
IT security foundations
An untested backup is an assumption, not a control
An employee clicked a suspicious link
Awareness and simulation
What teams can recognise, they do not fall for
We have a plan and nobody to hold it day to day
RISS 360
Monitoring and compliance are continuous activities, not projects
Will you work with our current IT provider?
Yes, and that is the most common case. We are not a managed IT services provider and we are not looking to replace yours. Our role is analysis, advice and oversight, which includes clarifying what their contract ought to guarantee.
This separation of roles matters. A provider who deploys the tools, sells them and then verifies their own installation has a conflict of interest, even in good faith. We earn nothing from the choice of a product, which lets us assess what is already in place and say when a contractual commitment is missing.
In practice, we regularly help executives put to their provider the questions they lacked the technical means to ask: what patching timelines are committed to, what scope the contract actually covers, and how quickly you would be notified of an incident at their end.
No single price can be published honestly, because scope depends entirely on your context: number of users and sites, what your licences already cover, applicable regulatory obligations, the real cost of an hour of downtime, the level of handover you want, and your clients' and insurer's requirements. Two organizations of the same headcount receive very different proposals for those reasons. We set out each variable on the page about building a proposal, and the first conversation exists precisely to establish them.
No, and trying is the surest way to finish nothing. The sequence we recommend is ordered: assess, fix the foundations, then validate with a technical exercise. Many organizations progress across several budget cycles, handling each year whatever reduces the most risk for the funds available. A staged plan that is actually followed beats an ambitious programme abandoned in the first quarter.
Yes. The initial assessment is free, carries no commitment, and the written summary of your principal exposure stays yours even if you do not proceed. That is a deliberate position: an organization that leaves with a clear view of its risks and decides to handle them itself has still gained something, and we prefer that to an engagement sold before it was understood.
Yes. We are based in Montérégie and work in Greater Montreal and throughout Quebec, on site and remotely. Technical reviews and most governance work are done remotely; physical infrastructure surveys, wireless coverage studies and awareness workshops happen on site. For Europe, our engagements are run with our partner RISS Consulting in France.
Say so explicitly in your message or by phone: those requests go ahead of everything else. The first hours determine a great deal, and decisions taken under pressure without a written procedure are often the ones people regret. If you have no support in place, two immediate reflexes: do not power off the affected machines, which destroys useful evidence, and write down the time and nature of what you observe.
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.
This site uses no advertising cookies and no analytics trackers. Only strictly necessary cookies (security, admin session) may be set : no consent required. Learn more.