Cybersecurity FAQ
for Quebec SMBs.
Cybersecurity audits, vulnerability scans, Quebec Law 25, cyber insurance, Microsoft 365, and business continuity: clear answers to help you understand your risks and choose the right type of support. 60 questions and answers in 12 categories.
Content reviewed by Rémi Douville, PMP - President of RDCybersécurité. Last reviewed: July 28, 2026.
Understanding Cyber Risk
Yes. Being small does not make a business invisible. Some attacks are targeted, but many rely on automated campaigns that look for compromised accounts, exposed services, vulnerable software, or weak configurations.
Risk depends more on the systems a business uses, the data it holds, the access available to an attacker, and the consequences of an interruption than on employee count alone.
Start by understanding your actual environment: critical systems, sensitive data, privileged accounts, suppliers, backups, internet-facing services, and operational dependencies.
Early priorities generally include protecting important accounts with appropriate multi-factor authentication, verifying backups and restorations, addressing exposed systems, controlling access, and establishing a clear incident-reporting process. An audit or vulnerability scan can then provide a more structured assessment and help prioritize the next steps.
No. The internal IT team or external IT provider plays an important role, but decisions about risk, budgets, suppliers, legal obligations, and business continuity also belong to leadership.
Cybersecurity also involves human resources, finance, operations, communications, and everyone who uses company systems or handles sensitive information.
The impact depends on the incident and the organization. It may include operational downtime, data loss or disclosure, recovery costs, specialist fees, notification obligations, loss of trust, litigation, or contractual difficulties.
There is no universal cost that applies to every SMB. A credible estimate must consider the affected systems, the duration of the interruption, the data involved, applicable obligations, and the organization’s recovery capabilities.
Choosing the Right Engagement
The right choice depends on the question you need to answer.
- A vulnerability scan looks for known technical weaknesses within an agreed scope.
- An audit provides a broader review of practices, controls, responsibilities, processes, and governance.
- Ongoing advisory support helps the organization follow an action plan, make informed decisions, and improve its security posture over time.
An initial discussion helps clarify the objective, scope, and type of engagement that would be genuinely useful.
A vulnerability scan is primarily technical. It looks for issues such as vulnerable software, exposed services, selected configuration weaknesses, and missing security updates.
An audit is broader. It may review governance, responsibilities, access management, backups, incident response, suppliers, policies, and organizational practices.
A penetration test includes manual testing and authorized exploitation attempts to determine what an attacker could actually achieve within a defined scope.
Penetration testing is generally more targeted and intrusive and requires detailed rules of engagement. The right option depends on the objective, the organization’s maturity, and its contractual requirements.
Source: Canadian Centre for Cyber Security - Choosing the best cyber security solution for your organization ↗# Direct link
A one-time scan provides a snapshot of the environment at the time of the assessment. Recurring monitoring helps track changes in exposure, verify selected improvements, and identify new vulnerabilities during the agreed period.
The scope, frequency, and deliverables must be defined in the engagement. Recurring scanning does not replace day-to-day patch management, operational monitoring, or incident response.
Vulnerability Scanning
A vulnerability scan is a technical assessment designed to identify known weaknesses in the systems included in scope. These may include vulnerable software versions, missing security updates, exposed services, open ports, or selected high-risk configurations.
The results must be reviewed and placed in context. A scanning tool can produce false positives or flag an issue whose significance varies from one environment to another.
The engagement begins by defining the objective, scope, authorized assets, exclusions, and testing windows. Sensitive or fragile systems must be identified before scanning begins.
The scan is then configured and run within the approved scope. Results are reviewed, validated where possible, and presented in a report with recommendations and priorities.
The organization will generally need to provide the list of authorized assets, relevant IP addresses and domains, exclusions, sensitive systems, responsible contacts, testing windows, any required technical accounts, and the communication procedure for urgent findings.
The scope must be approved before work begins to prevent unauthorized testing.
The scan is configured to limit its impact, but no responsible provider should promise zero risk. Older, fragile, industrial, or poorly configured equipment may react unpredictably to network testing.
Sensitive systems should be identified in advance, necessary exclusions should be defined, and an appropriate testing window should be agreed upon. The scan must not intentionally modify systems or delete data.
There is no universal frequency. It depends on the level of risk, internet exposure, rate of change, customer and contractual requirements, insurance requirements, and available resources.
A new scan may be appropriate after a significant change, the introduction of an internet-facing service, a migration, an incident, or a remediation cycle. The frequency should be proportionate to the organization’s risks.
Depending on the approved scope, a scan may cover external IP addresses, servers, workstations, network equipment, virtual machines, and selected cloud environments.
Actual coverage depends on the architecture, available visibility, authorized access, and technical limitations. Web applications, industrial environments, and cloud services may require specialized assessment methods.
A conventional network scan does not automatically assess Microsoft 365. A Microsoft 365 review generally requires a configuration assessment covering areas such as identities, roles, authentication, sharing rules, administrative access, logs, and security policies. This work must be defined separately in scope.
Participation is not always mandatory, but it is often useful. The IT provider can help confirm the architecture, address ranges, sensitive systems, planned changes, and operational constraints.
The provider is also often responsible for implementing some of the corrective actions. The objective is to support effective collaboration while maintaining an independent view of the identified risks.
It depends on the type of assessment. An external or unauthenticated scan can be performed without an administrator account, but it provides less visibility.
An authenticated scan may require a controlled technical account to verify software versions, security updates, and selected configurations more accurately. Access must be limited to what is necessary, protected appropriately, and removed or disabled at the end of the engagement.
It depends on the tool, configuration, and scope. The data may include IP addresses, hostnames, ports, services, software versions, detection results, and other technical information required for the assessment.
Before the engagement begins, the organization should understand which categories of data will be processed, where they will be processed, how long they will be retained, which subcontractors are involved, and which safeguards apply. Do not claim that no data leaves the organization unless this has been verified for the specific solution being used.
Cybersecurity Audits
A cybersecurity audit is a structured assessment of an organization’s security posture. It reviews a defined scope and compares observed practices with agreed criteria, a recognized framework, or specified requirements.
The audit may cover governance, access, assets, backups, incident response, suppliers, policies, configurations, and security awareness. The report presents findings, gaps, risks, and recommended actions.
An engagement will generally include scoping, document collection, interviews, evidence review, selected technical checks, and gap analysis.
The findings are then validated with the relevant stakeholders before the final report is delivered. The exact method depends on the scope, framework, size of the environment, and availability of evidence.
The duration depends on the scope, complexity of the environment, number of stakeholders, availability of documentation, and expected depth of review.
The schedule must be confirmed during scoping. The overall duration of the engagement should be distinguished from the amount of time required from internal teams.
Key stakeholders will generally need to participate in scoping, provide documentation, answer selected questions, and validate findings. Before the audit begins, the schedule should identify the required participants and their expected contributions.
Yes, provided the method is adapted to the organization’s reality. An audit can establish a baseline, identify the most important risks, and help prevent resources from being spread across low-priority initiatives.
The objective is not to penalize an organization for limited maturity. It is to produce a realistic, proportionate improvement plan.
Yes. An audit report often contains sensitive information about systems, access, suppliers, processes, and organizational weaknesses.
The engagement must define confidentiality requirements, authorized recipients, transmission methods, retention, and secure destruction. Results must not be disclosed to a third party without an appropriate contractual or legal basis or proper authorization.
Reports, Priorities, and Remediation
Deliverables must be defined in the engagement. They may include an executive summary, a technical report, a list of findings, a risk assessment, and a prioritized action plan.
The executive summary should explain the potential business consequences and the decisions required. The technical detail should give those responsible for remediation enough information to understand and address each finding.
The Common Vulnerability Scoring System, or CVSS, can help express the technical severity of a vulnerability, but it does not represent business risk on its own.
Prioritization should also consider exposure, the importance of the affected system, evidence of known exploitation, the data involved, compensating controls, patch availability, and potential operational consequences.
No. Some measures require urgent action, while others can be planned.
The decision should consider risk, effort, dependencies, change-related risk, and available resources. When an immediate fix is not possible, temporary or compensating measures may sometimes reduce exposure until a durable solution is implemented.
It depends on the organization and the agreed scope. Remediation may be carried out by the internal team, IT provider, systems integrator, software vendor, or a specialist.
The consultant who prepares the report should clearly explain the recommended actions and may support prioritization. It should not be assumed that every corrective action is included unless this is explicitly stated in the engagement.
The escalation process should be agreed upon before testing begins. If a finding appears to present an urgent risk, the authorized contact should be informed promptly through the agreed channel rather than waiting for the final report.
The finding should be validated as far as reasonably possible before conclusions are drawn. Decisions to remediate, isolate, or suspend a service remain with the organization, supported by its technical and security leads.
Quebec Law 25 and Personal Information
The information in this section is general in nature and does not constitute legal advice.
Law 25 is Quebec legislation that modernized several provisions governing the protection of personal information. It amended, among other statutes, the Act respecting the protection of personal information in the private sector.
It strengthens organizational responsibilities related to governance, transparency, consent, security, privacy incidents, privacy impact assessments, and individual rights.
Source: Commission d’accès à l’information - Key changes introduced by Law 25 (in French) ↗# Direct link
Quebec’s private-sector privacy legislation applies to businesses that collect, hold, use, or disclose personal information in the course of their activities in Quebec, subject to the applicable rules and exceptions.
Company size alone does not create an exemption. Information about customers, employees, candidates, individual suppliers, or users may be covered. The exact scope must be determined based on the organization’s activities and the information it actually processes.
The obligations depend on the circumstances but may include:
- appointing a person in charge of the protection of personal information;
- publishing that person’s title and contact information;
- establishing governance policies and practices;
- managing the collection, use, disclosure, retention, and destruction of personal information;
- protecting information with appropriate safeguards;
- maintaining a privacy incident register;
- responding to individual requests;
- conducting privacy impact assessments where required.
Source: Commission d’accès à l’information - Business responsibilities (in French) ↗# Direct link
Depending on the violation, the Commission d’accès à l’information may impose administrative monetary penalties or initiate penal proceedings.
An administrative monetary penalty may reach $10 million or 2 % of worldwide turnover. Certain penal fines may reach $25 million or 4 % of worldwide turnover. The applicable regime and amount depend on the nature of the violation and the circumstances.
Source: Commission d’accès à l’information - Penalties (in French) ↗# Direct link
When an incident involving personal information presents a risk of serious injury, the organization must notify the Commission d’accès à l’information and the individuals concerned. It must also take reasonable measures to reduce the risk of injury and prevent similar incidents from occurring again.
Privacy incidents must be recorded in a register, even when they do not necessarily present a risk of serious injury.
Source: Commission d’accès à l’information - Privacy incidents and security measures (in French) ↗# Direct link
The obligations are already in force, but beginning a structured compliance effort now is still preferable to waiting for an incident, complaint, or customer request.
The first step is to document the personal information held, its purposes, relevant systems, suppliers, access, retention practices, and existing safeguards. The organization can then identify gaps and prioritize action. A general statement of good faith does not replace the applicable obligations.
A privacy impact assessment may be mandatory in several situations specified by law. These include a project to acquire, develop, or redesign an information system or electronic service involving personal information, as well as certain disclosures of personal information outside Quebec.
The assessment must be proportionate to the sensitivity, purpose, quantity, distribution, and format of the information involved.
Source: Commission d’accès à l’information - Privacy impact assessment guide (in French) ↗# Direct link
Email, Identity, and Microsoft 365
SPF identifies which systems are authorized to send email for a domain. DKIM adds a cryptographic signature that allows a receiving system to verify that a signed message was not altered and is associated with the stated domain. DMARC uses SPF and DKIM results, together with domain alignment, to apply a policy and generate reports.
These mechanisms reduce certain domain-spoofing risks, but they do not stop every form of phishing.
Verification should cover DNS records, syntax, authorized sending sources, DKIM signing, DMARC alignment, and the policy actually being enforced.
The mere presence of a record is not enough. An overly permissive, incomplete, or unmonitored configuration can leave material risks. DMARC reports can help identify legitimate sending sources and attempted unauthorized use.
Identity and access management covers the processes and controls used to create, change, verify, and remove access to systems and data.
It includes employee onboarding, role changes, and departures, as well as administrator accounts, service accounts, supplier access, authentication, and periodic access reviews.
It also applies the principle of least privilege: giving a person, application, or system only the access required to perform its function, and only for as long as required. Access rights should be reviewed regularly, especially for administrators, suppliers, and service accounts.
Multi-factor authentication adds at least one verification factor beyond a password. It significantly reduces the risk created by stolen credentials, but it does not make account compromise impossible.
Some attack techniques can bypass traditional MFA methods. Passkeys, FIDO2 security keys, and other phishing-resistant methods provide stronger protection than SMS codes or simple push approvals.
Source: Canadian Centre for Cyber Security - Phishing-resistant multi-factor authentication ↗# Direct link
The offboarding process should be prepared before the employee’s final day. It should include disabling accounts, revoking sessions and tokens, removing application access, changing shared secrets, recovering company devices, and transferring required business information.
Human resources, the employee’s manager, and IT must coordinate these actions. The level of urgency depends on the circumstances of the departure and the identified risks.
Microsoft protects the infrastructure supporting its service, but the organization remains responsible for its users, access, devices, data, and many configuration decisions.
The actual security posture depends on licensing, authentication, administrative roles, sharing rules, third-party applications, logs, access policies, and tenant-specific settings. Default settings should not be assumed to address every organization’s risks.
Microsoft 365 includes various availability, recycle-bin, retention, and recovery mechanisms. Microsoft also offers a separate service called Microsoft 365 Backup.
These capabilities do not automatically meet every organization’s needs. Before deciding whether an additional solution is required, the organization should define the data to protect, retention requirements, recovery time, loss scenarios, and responsibilities.
Source: Microsoft Learn - Microsoft 365 Backup overview ↗# Direct link
Cyber Insurance
Cyber insurance is a policy that may cover selected costs and services associated with a cyber incident, subject to the coverage, limits, deductibles, and exclusions in the contract.
It may provide access to incident response, forensic, recovery, legal, notification, or communications services. It does not replace preventive measures and does not automatically cover every incident.
Requirements vary by insurer, industry, company size, data held, and the level of coverage requested.
The questionnaire may address multi-factor authentication, backups, updates, endpoint protection, administrative access, network segmentation, training, incident plans, and suppliers. Responses must be accurate, documented, and consistent with the measures actually in place.
An insurer may want to understand the organization’s exposure and safeguards before offering coverage, renewing a policy, or assessing a specific risk.
Confirm the exact document being requested. A technical scan, organizational audit, attestation, and insurance questionnaire are not interchangeable.
There is no general obligation requiring every Quebec SMB to carry cyber insurance.
However, a customer, prime contractor, landlord, partner, or contract may require it. The decision should consider the organization’s risks, financial capacity, proposed coverage, and exclusions.
Incidents, Ransomware, and Business Continuity
Ransomware is malicious software used to make systems or data unavailable, generally to demand payment. Some ransomware operations also steal data and threaten to disclose it.
Backups can support recovery, but they do not necessarily prevent data theft or publication.
Activate the incident response plan and contact the designated people. Affected systems may need to be isolated to limit propagation, but actions should be coordinated to preserve evidence and avoid making the situation worse.
Quickly mobilize the appropriate internal leads, IT provider, incident-response specialist, insurer where relevant, and legal counsel depending on the situation. Avoid improvised actions when their consequences are not understood.
Source: Canadian Centre for Cyber Security - Ransomware playbook ↗# Direct link
Payment does not guarantee data recovery or prevent disclosure. It can support the criminal business model, lead to further demands, and expose the organization to additional risks, including legal risk.
The decision belongs to the organization, but it should not be made in isolation. Before deciding, consult incident-response specialists, legal counsel, the insurer, and the relevant authorities.
Source: Canadian Centre for Cyber Security - Ransomware playbook ↗# Direct link
No. A backup is useful only if it contains the required data, remains available after the incident, and can be restored within an acceptable timeframe.
Backups should be protected against alteration and deletion. Restoration procedures should be tested and documented, priority systems identified, and technical and human dependencies considered.
Source: Canadian Centre for Cyber Security - Tips for backing up your information ↗# Direct link
A business continuity plan describes how the organization will maintain essential operations during a disruption. A disaster recovery plan describes how systems, data, and required capabilities will be restored after the incident.
The two plans must be coordinated. A technical restoration procedure is not enough if the organization does not know how it will operate during the outage.
The recovery time objective, or RTO, is the target time for restoring a service after a disruption.
The recovery point objective, or RPO, is the amount of data loss an organization is prepared to accept, expressed as a period of time. For example, an RPO of several hours means a restoration could return the system to a state from several hours earlier.
These objectives should be based on operational needs and validated through testing.
The frequency depends on system criticality, rate of change, contractual requirements, and risk.
Testing should occur often enough to demonstrate that data can be restored and that procedures remain workable. A test should also be considered after a major change to a system, supplier, architecture, or backup method.
An incident response plan defines roles, contacts, escalation criteria, communication methods, and the principal actions to take when an incident occurs.
It should explain how incidents will be detected, analyzed, contained, eradicated, and recovered from, as well as how decisions will be documented. The plan should be adapted to the organization and tested through exercises.
Source: Canadian Centre for Cyber Security - Developing your incident response plan ↗# Direct link
Training and Awareness
Training is useful when it reflects the participants’ risks and responsibilities. It can help employees recognize suspicious situations, protect their accounts, use company tools correctly, and report an event quickly.
Effective training is clear, practical, and adapted to the organization’s activities. It uses realistic scenarios to explain expected behaviour and the internal reporting process.
Topics may include phishing, passwords, multi-factor authentication, data sharing, mobile devices, remote work, and incident reporting. Regular reminders and exercises are preferable to a single session with no follow-up.
Training does not replace technical controls, governance, or procedures. It is one part of a broader set of complementary safeguards.
RDCybersécurité Advisory Services
Strategic advisory support helps leadership understand risks, prioritize action, track recommendations, and coordinate stakeholders.
It may cover governance, policies, suppliers, customer or insurer requirements, Law 25, incident preparedness, and follow-up on an improvement plan. The scope is adapted to the agreed needs.
An IT provider generally operates and supports the company’s systems. RDCybersécurité contributes specialized expertise in risk, governance, priorities, and security controls.
The roles are complementary. Depending on the engagement, the IT provider may support scoping, provide information, and implement selected corrective actions. RDCybersécurité does not automatically replace the existing provider.
The engagement can also be adapted for a company that relies on an external provider or has limited technical resources.
The organization must still identify who holds the required access, who can approve changes, and who will implement corrective actions. Work outside the agreed scope may require an appropriate technical provider.
RDCybersécurité supports SMBs whose risks and constraints vary based on their operations, data, customers, and contractual obligations.
Before accepting an engagement, the required scope, expertise, and industry-specific considerations are confirmed.
It depends on the type of work, environment, and security constraints. Interviews, document reviews, and selected assessments may be conducted remotely.
An on-site presence may be useful or necessary for certain environments, equipment, workshops, or training activities. The delivery method is confirmed during scoping.
Yes. Some engagements address a one-time need, while others require support over time.
The duration, frequency, scope, deliverables, and responsibilities are defined in the proposal or contract.
CMMC and the Supply Chain
The Cybersecurity Maturity Model Certification program is a U.S. Department of Defense program used to verify the implementation of selected cybersecurity requirements by contractors and subcontractors that handle information related to defence contracts.
The applicable level and assessment type depend in part on the information handled and the requirements included in the contract.
Source: U.S. Department of Defense - CMMC program ↗# Direct link
Yes, if it participates directly or indirectly in an affected supply chain and CMMC requirements are passed down through a contract.
Being located in Quebec neither makes CMMC automatically applicable nor exempts the organization. Review the relevant contracts, customer flow-down clauses, and the categories of information actually handled.
Begin by identifying the relevant contracts, the information handled, the systems in scope, and the requirements that actually apply. Document and address gaps according to the rules currently in force.
As of July 13, 2026, U.S. authorities announced the immediate suspension of Phase II requirements, which had originally been scheduled for November 10, 2026, while Phase I self-assessment requirements remain in place. Information verified on July 28, 2026; it will be reviewed when the authorities publish new guidance.
Source: U.S. Department of Defense - CMMC program and official updates ↗# Direct link
Ask it directly.
Every organization has a different environment, set of constraints, and priorities. A short conversation can clarify your needs and determine whether an engagement would be appropriate.