ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

Cybersecurity

  • PIPEDA: Consent and Purpose — The Two Principles SMBs Get Wrong

    8 min read

    PIPEDA’s Principles 2 and 3 — Identifying Purposes and Consent — are the two rules SMB IT teams break most. A grounded deep-dive into the statute text: purpose identification at collection, the no-condition rule, express vs implied consent, withdrawal, and the reasonable-person test for appropriate purposes.

    Read →

  • Quebec Law 25: Appointing the Personal-Information Officer

    8 min read

    Law 25 (Article 3.1) requires every private-sector organisation to appoint a personal-information officer and publish their contact details. It is the first obligation, in force since 22 September 2022. Here is the role, the delegation, and how an SMB stands it up.

    Read →

  • GDPR Data Subject Rights and the 72-Hour Breach Clock

    8 min read

    GDPR gives data subjects eight rights, and it gives you one month to answer them — and 72 hours to report a breach. Here is what each right requires, the response clock, and the breach-notification contents an SMB must assemble in three days.

    Read →

  • PCI DSS Self-Assessment Questionnaire Guide: Pick the Right SAQ

    8 min read

    The SAQ you file is determined by how you handle card data. Pick the narrowest one that fits and your validation is a short form, not a full audit. Here is how an SMB chooses among the PCI DSS SAQs — and how scope reduction changes the answer.

    Read →

  • PCI DSS Scope Reduction: 12 Controls That Shrink Your Audit Footprint

    8 min read

    PCI DSS v4.0.1 applies to the cardholder data environment and everything with unrestricted connectivity to it. Shrink the CDE and you shrink the audit. Here are 12 scope-reduction controls an SMB can apply, each tied to the standard’s scoping rules.

    Read →

  • PCI DSS 6.4.3 and 11.6.1 Explained: Stopping Payment-Page Skimming

    8 min read

    PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 target Magecart-style payment-page skimming. 6.4.3 manages the scripts; 11.6.1 detects when they are tampered with. Here is what each requires and how an SMB implements both.

    Read →

  • ISO 42001 and the EU AI Act: Where the Standard Meets the Regulation

    8 min read

    The EU AI Act regulates AI by risk tier; ISO 42001:2023 is the management system that helps an SMB demonstrate it meets those requirements. Here is where the two overlap, where 42001 falls short, and what to do for each tier.

    Read →

  • PCI DSS v4.0.1 pour les PME : Pourquoi agir maintenant

    8 min read

    Une introduction pragmatique à PCI DSS v4.0.1 pour les administrateurs IT seuls ou en petite équipe — les mandates du 31 mars 2025, les contrôles 6.4.3 et 11.6.1, le scoping SAQ, la TRA et une feuille de route sur 90 jours.

    Read →

  • Loi 25 pour les PME : Pourquoi maintenant

    8 min read

    Une introduction pragmatique à la Loi 25 (Québec) pour les administrateurs TI de PME — amendes jusqu’à 25 M$ / 4 % du chiffre d’affaires mondial, calendrier par phases 2022-2024, responsable de la protection des RP, EFVP, droits des personnes, notification d’incident en 72 h et feuille de route sur 90 jours.

    Read →

  • Comment animer votre premier exercice de simulation : un parcours PME

    8 min read

    Les contrôles ISO 27001:2022 A.5.24 à A.5.27 exigent une réponse aux incidents planifiée et répétée. Un exercice de simulation est le moyen le moins cher de la tester. Voici comment une petite équipe IT mène le premier en 90 minutes, avec un scénario prêt à l’emploi.

    Read →