ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

compliance-en

  • Top 5 Cloud Misconfigurations SMBs Make

    8 min read

    Stop hope-based security. Learn the five most common cloud misconfigurations that leave SMBs vulnerable and how to fix them without a CISO.

    Read →

  • How to Run Your First Tabletop Exercise: An SMB Walkthrough

    8 min read

    ISO 27001:2022 controls A.5.24 to A.5.27 require planned, practiced incident response. A tabletop exercise is the cheapest way to test it. Here is how a small IT team runs its first one in 90 minutes, with a ready-to-use scenario.

    Read →

  • How to Read a CVE (and What to Do About It)

    8 min read

    Stop chasing every ‘Critical’ alert. Learn how to decode CVEs and prioritize patches based on actual risk to your SMB environment.

    Read →

  • CPPA Reform 2025 Readiness: What Canadian SMBs Do While Bill C-27 Finishes

    8 min read

    Bill C-27 replaces PIPEDA with the Consumer Privacy Protection Act, adds a data-protection tribunal, and introduces the Artificial Intelligence and Data Act. The exact penalty ceilings and final provisions will be set by the enacted bill — but seven readiness actions are PIPEDA-good today and CPPA-ready tomorrow. A grounded getting-started guide for SMB IT.

    Read →

  • PIPEDA: Consent and Purpose — The Two Principles SMBs Get Wrong

    8 min read

    PIPEDA’s Principles 2 and 3 — Identifying Purposes and Consent — are the two rules SMB IT teams break most. A grounded deep-dive into the statute text: purpose identification at collection, the no-condition rule, express vs implied consent, withdrawal, and the reasonable-person test for appropriate purposes.

    Read →

  • Law 25: SMB Getting-Started Checklist (30-60-90 Days)

    8 min read

    Law 25 imposes twelve obligations across three phases (2022, 2023, 2024). For an SMB starting out, order matters: appoint the officer, stand up the incident register, then build governance. Here is a 30-60-90-day checklist by phase.

    Read →

  • Quebec Law 25: Appointing the Personal-Information Officer

    8 min read

    Law 25 (Article 3.1) requires every private-sector organisation to appoint a personal-information officer and publish their contact details. It is the first obligation, in force since 22 September 2022. Here is the role, the delegation, and how an SMB stands it up.

    Read →

  • Quebec Law 25: Confidentiality Incidents, Register, and Notice Deadline

    8 min read

    Law 25 (Articles 3.5–3.8) requires a register of every confidentiality incident and notice to the CAI and affected individuals when there is a risk of serious prejudice. Unlike GDPR, there is no 72-hour clock — notice is ‘as soon as possible.’ Here is what the Law requires.

    Read →

  • PIPEDA vs Loi 25 vs GDPR: The Cross-Border SMB Compliance Map

    8 min read

    A Canadian SMB that also serves EU or Quebec customers can trigger all three regimes at once. Side-by-side map of PIPEDA, Loi 25, and GDPR — scope, authority, officer, breach clock, access response, impact assessment, portability, transfers, and enforcement — grounded in the statute and regulation text.

    Read →

  • Law 25 and GDPR: Parallelism and a Joint Programme for an SMB

    8 min read

    Law 25 transposes several GDPR elements into Quebec’s private sector: an officer, a PIA, an incident register, portability. An SMB subject to both can fuse the artifacts and run one programme. Here is the correspondence and the divergences.

    Read →