Law 25 compliance & cyber insurance · Quebec experts

Compliant with Law 25 and your insurer's requirements without losing sleep.

Law 25 is fully in force and your insurer is tightening its terms. We put your controls in place, fix the gaps and prepare your evidence, so you lose neither your coverage nor a contract. In plain language. No surprises.

Gaps fixed, evidence ready Insurer questionnaire support Quebec-based team
The real risk

« Good enough » no longer cuts it

Compliance is no longer a good intention: it's a legal, contractual and insurance requirement. Here's what awaits businesses that wait.

The CAI is now enforcing

After an educational phase, Quebec's access-to-information commission (CAI) is now issuing real penalties. Complaints are rising, and so are inspections.

Fines that hurt

Up to $25M or 4% of worldwide revenue. The CAI can even impose a penalty without going through a court.

Your insurer is tightening terms

Without multi-factor authentication, backups and an incident plan, your premium climbs, your coverage shrinks, or a claim can be denied.

A contract lost for lack of proof

More and more large clients and tenders require proof of compliance. Without it, you're ruled out before you even bid.

No one clearly owns it

Law 25 requires a designated officer, an incident log and a policy. In many SMBs, no one really handles it.

You don't know where you stand

Without a diagnostic, there's no way to know which gaps expose you. The problem is often discovered on the day of the incident, too late.

The question is no longer IF you'll be asked for proof, but WHEN, and whether you'll have it.

The risk in numbers

What inaction costs in Quebec

Compliance is no longer optional. Here's what the data reveals for organizations here.

25 M$

the maximum fine under Law 25 (or 4% of worldwide revenue).
Source: CAI / Law 25, 2026

10 M$

the penalty the CAI can impose directly, without going through a court (or 2% of revenue).
Source: CAI, 2026

6,98 M$

the average cost of a data breach for a Canadian organization.
Source: Ponemon Institute, 2025

Our solution

Compliance, turned into peace of mind

We translate Law 25 and your insurer's requirements into concrete actions, then help you put them in place and document your evidence.

From obligation to evidence

We find your gaps. You leave compliant and ready.

Our Quebec-based experts assess your posture against Law 25, the CIS Controls v8, the NIST framework and your insurer's questionnaire. Every gap becomes a prioritized action, and we support you until it's resolved.

  • A clear picture of your compliance gaps, prioritized by risk
  • A concrete action plan: what to fix, in what order
  • A review of your insurance questionnaire, answers prepared
  • Your evidence documented for the CAI, your clients and insurers
Book my compliance review
What you gain

Concrete results, not a stack of paperwork

Support that protects your business on all three fronts: legal, insurance and commercial.

01

You protect your coverage

You check the boxes your insurer requires, MFA, backups, incident plan, and avoid a denied claim.

02

You avoid penalties

You demonstrate due diligence and reduce the risk of a CAI penalty that can reach millions.

03

You unlock contracts

You provide the proof of compliance large clients and tenders require, and stay in the running.

04

You finally know where you stand

No more fog. You get a clear picture of your gaps and a plan to close them, in plain language.

05

You reassure your clients

Protecting the personal information entrusted to you becomes a selling point, not a source of anxiety.

06

You save time

Stop guessing. Our experts carry the file and tell you exactly what to do, step by step.

Get your business in order before you're asked.

Check my compliance
Our approach

A clear path to compliance, in 4 steps

From the first conversation to your documented evidence, you always know where you stand. Zero jargon, zero surprises.

STEP 01

Scoping & priorities

A call to understand your sector, your sensitive data and your obligations (Law 25, insurer, clients). No obligation.

STEP 02

Gap assessment

We assess your posture against Law 25, the CIS Controls v8 and NIST, and pinpoint what's missing.

STEP 03

Prioritized action plan

You receive a clear plan: what to fix first, why, and the impact on your risk and insurance.

STEP 04

Implementation & evidence

We support you through the fixes and document your evidence for the CAI, your clients and insurers.

Why CyberVision

Compliance that speaks business, not just boxes to tick

Many leave with a theoretical report that gathers dust. With us, you leave compliant, for real.

A typical compliance audit

What too many businesses experience

  • A theoretical report, hard to apply
  • A list of gaps with no priorities or plan
  • No support once the report is delivered
  • You're left alone with the insurance questionnaire
  • A one-time exercise, quickly outdated

The CyberVision 24/7 approach

What you get with us

  • Gaps translated into concrete, prioritized actions
  • A clear plan aligned with Law 25, CIS v8 and NIST
  • Support through the implementation of fixes
  • A review of your insurer questionnaire, answers prepared
  • Ongoing follow-up as your risks evolve

You deserve compliance that holds up in real life.

Book my compliance review
Common questions

« Is this really for us? »

These are the three reactions we hear most. Here's why they deserve a second thought.

« We're a small business, Law 25 doesn't target us »

Law 25 applies to any Quebec organization that collects, uses or stores personal information, SMBs, non-profits and sole proprietors included.

Size doesn't exempt you; it often leaves you less prepared than a large organization with dedicated resources.

« We already have an IT provider and a lawyer »

Your IT provider keeps your systems running; your lawyer knows the law. But Law 25 compliance is technical AND organizational: security controls, incident log, concrete evidence.

We bridge the two and deliver the technical elements neither produces alone.

« We'll deal with it when the CAI comes knocking »

In 2026, the CAI shifted from education to enforcement. Waiting for the inspection means risking a penalty and scrambling to fix everything at once.

Good news: the CAI rewards proactivity. A started effort can reduce penalties, which is why acting now matters.

FAQ

Frequently asked questions about Law 25 and cyber insurance

Everything leaders ask us before getting started.

What is Law 25 and who must comply?

Law 25 modernizes the protection of personal information in Quebec. It applies to any organization that collects, uses, discloses or stores personal information, private businesses, SMBs, non-profits and sole proprietors. All its provisions have been in force since September 22, 2024.

What are the penalties for non-compliance?

The CAI can impose administrative penalties of up to $10M or 2% of worldwide revenue, without going through a court. Penal sanctions can reach $25M or 4% of worldwide revenue, and executives can also be targeted.

How are compliance and cyber insurance connected?

Insurers increasingly require specific controls (multi-factor authentication, backups, EDR, training, an incident plan) before covering, or paying out. A strong compliance posture eases getting coverage, helps contain the premium and prevents a claim from being denied.

How long does becoming compliant take?

It depends on your starting point and how sensitive your data is. A first diagnostic is quick; implementing fixes is phased to your priorities. We set a realistic timeline during the scoping call, with no obligation. To pinpoint your starting point right now, try our free ISO 27001 checklist.

Do you replace an official audit or my insurer?

No. We cover the technical and organizational side of compliance and help you prepare your evidence. We don't replace an independent audit, a certifier or your insurer, the insurer keeps the final decision on your file.

Can our internal team stay involved?

Absolutely. We work alongside your team and advisors. We share our findings in a clear, educational way and support you through implementation.

Another question? Let's talk directly.

Talk to an expert
Free resource

Checklist: 12 controls your insurer will require

Download our free checklist and verify, point by point, whether your business ticks the boxes Law 25 and insurers demand, before you're asked.

Download the checklist
Free review · No obligation

Take stock of your compliance in 30 minutes

Pick a time that works for you. A Quebec-based expert calls you back to assess your Law 25 gaps and tell you what your insurer requires, no obligation.

Book a call

Book your compliance review

Pick the time slot that suits you. A Quebec-based expert calls you back to assess your gaps.

  • 30 minutes, no obligation
  • Video call or phone
  • Quebec-based expert
  • Top priorities identified
24/7514 593-8909