Compliant with Law 25 and your insurer's requirements without losing sleep.
Law 25 is fully in force and your insurer is tightening its terms. We put your controls in place, fix the gaps and prepare your evidence, so you lose neither your coverage nor a contract. In plain language. No surprises.
« Good enough » no longer cuts it
Compliance is no longer a good intention: it's a legal, contractual and insurance requirement. Here's what awaits businesses that wait.
The CAI is now enforcing
After an educational phase, Quebec's access-to-information commission (CAI) is now issuing real penalties. Complaints are rising, and so are inspections.
Fines that hurt
Up to $25M or 4% of worldwide revenue. The CAI can even impose a penalty without going through a court.
Your insurer is tightening terms
Without multi-factor authentication, backups and an incident plan, your premium climbs, your coverage shrinks, or a claim can be denied.
A contract lost for lack of proof
More and more large clients and tenders require proof of compliance. Without it, you're ruled out before you even bid.
No one clearly owns it
Law 25 requires a designated officer, an incident log and a policy. In many SMBs, no one really handles it.
You don't know where you stand
Without a diagnostic, there's no way to know which gaps expose you. The problem is often discovered on the day of the incident, too late.
The question is no longer IF you'll be asked for proof, but WHEN, and whether you'll have it.
What inaction costs in Quebec
Compliance is no longer optional. Here's what the data reveals for organizations here.
the maximum fine under Law 25 (or 4% of worldwide revenue).
Source: CAI / Law 25, 2026
the penalty the CAI can impose directly, without going through a court (or 2% of revenue).
Source: CAI, 2026
the average cost of a data breach for a Canadian organization.
Source: Ponemon Institute, 2025
Compliance, turned into peace of mind
We translate Law 25 and your insurer's requirements into concrete actions, then help you put them in place and document your evidence.
We find your gaps. You leave compliant and ready.
Our Quebec-based experts assess your posture against Law 25, the CIS Controls v8, the NIST framework and your insurer's questionnaire. Every gap becomes a prioritized action, and we support you until it's resolved.
- A clear picture of your compliance gaps, prioritized by risk
- A concrete action plan: what to fix, in what order
- A review of your insurance questionnaire, answers prepared
- Your evidence documented for the CAI, your clients and insurers
Concrete results, not a stack of paperwork
Support that protects your business on all three fronts: legal, insurance and commercial.
You protect your coverage
You check the boxes your insurer requires, MFA, backups, incident plan, and avoid a denied claim.
You avoid penalties
You demonstrate due diligence and reduce the risk of a CAI penalty that can reach millions.
You unlock contracts
You provide the proof of compliance large clients and tenders require, and stay in the running.
You finally know where you stand
No more fog. You get a clear picture of your gaps and a plan to close them, in plain language.
You reassure your clients
Protecting the personal information entrusted to you becomes a selling point, not a source of anxiety.
You save time
Stop guessing. Our experts carry the file and tell you exactly what to do, step by step.
Get your business in order before you're asked.
Check my complianceA clear path to compliance, in 4 steps
From the first conversation to your documented evidence, you always know where you stand. Zero jargon, zero surprises.
Scoping & priorities
A call to understand your sector, your sensitive data and your obligations (Law 25, insurer, clients). No obligation.
Gap assessment
We assess your posture against Law 25, the CIS Controls v8 and NIST, and pinpoint what's missing.
Prioritized action plan
You receive a clear plan: what to fix first, why, and the impact on your risk and insurance.
Implementation & evidence
We support you through the fixes and document your evidence for the CAI, your clients and insurers.
Compliance that speaks business, not just boxes to tick
Many leave with a theoretical report that gathers dust. With us, you leave compliant, for real.
A typical compliance audit
What too many businesses experience
- ✕A theoretical report, hard to apply
- ✕A list of gaps with no priorities or plan
- ✕No support once the report is delivered
- ✕You're left alone with the insurance questionnaire
- ✕A one-time exercise, quickly outdated
The CyberVision 24/7 approach
What you get with us
- Gaps translated into concrete, prioritized actions
- A clear plan aligned with Law 25, CIS v8 and NIST
- Support through the implementation of fixes
- A review of your insurer questionnaire, answers prepared
- Ongoing follow-up as your risks evolve
You deserve compliance that holds up in real life.
Book my compliance review« Is this really for us? »
These are the three reactions we hear most. Here's why they deserve a second thought.
« We're a small business, Law 25 doesn't target us »
Law 25 applies to any Quebec organization that collects, uses or stores personal information, SMBs, non-profits and sole proprietors included.
Size doesn't exempt you; it often leaves you less prepared than a large organization with dedicated resources.
« We already have an IT provider and a lawyer »
Your IT provider keeps your systems running; your lawyer knows the law. But Law 25 compliance is technical AND organizational: security controls, incident log, concrete evidence.
We bridge the two and deliver the technical elements neither produces alone.
« We'll deal with it when the CAI comes knocking »
In 2026, the CAI shifted from education to enforcement. Waiting for the inspection means risking a penalty and scrambling to fix everything at once.
Good news: the CAI rewards proactivity. A started effort can reduce penalties, which is why acting now matters.
Frequently asked questions about Law 25 and cyber insurance
Everything leaders ask us before getting started.
What is Law 25 and who must comply?
Law 25 modernizes the protection of personal information in Quebec. It applies to any organization that collects, uses, discloses or stores personal information, private businesses, SMBs, non-profits and sole proprietors. All its provisions have been in force since September 22, 2024.
What are the penalties for non-compliance?
The CAI can impose administrative penalties of up to $10M or 2% of worldwide revenue, without going through a court. Penal sanctions can reach $25M or 4% of worldwide revenue, and executives can also be targeted.
How are compliance and cyber insurance connected?
Insurers increasingly require specific controls (multi-factor authentication, backups, EDR, training, an incident plan) before covering, or paying out. A strong compliance posture eases getting coverage, helps contain the premium and prevents a claim from being denied.
How long does becoming compliant take?
It depends on your starting point and how sensitive your data is. A first diagnostic is quick; implementing fixes is phased to your priorities. We set a realistic timeline during the scoping call, with no obligation. To pinpoint your starting point right now, try our free ISO 27001 checklist.
Do you replace an official audit or my insurer?
No. We cover the technical and organizational side of compliance and help you prepare your evidence. We don't replace an independent audit, a certifier or your insurer, the insurer keeps the final decision on your file.
Can our internal team stay involved?
Absolutely. We work alongside your team and advisors. We share our findings in a clear, educational way and support you through implementation.
Another question? Let's talk directly.
Talk to an expertChecklist: 12 controls your insurer will require
Download our free checklist and verify, point by point, whether your business ticks the boxes Law 25 and insurers demand, before you're asked.
Download the checklist12 controls your insurer requires
One closed door isn't enough
Cybersecurity is a chain. Here are other ways we protect businesses here.
Take stock of your compliance in 30 minutes
Pick a time that works for you. A Quebec-based expert calls you back to assess your Law 25 gaps and tell you what your insurer requires, no obligation.
Book your compliance review
Pick the time slot that suits you. A Quebec-based expert calls you back to assess your gaps.
24/7514 593-8909