Compliance

Ransomware in an SMB: the first 72 hours, and what Law 25 requires of you

September 9, 2026
Xavier PeichBy Xavier Peich

Ransomware is a confidentiality incident under Law 25. What to do hour by hour and day by day, and why the 72-hour legal deadline doesn't exist here.

Ransomware in an SMB: the first 72 hours, and what Law 25 requires of you

Friday, 4 p.m., and the billing clerk's screen is showing a ransom note. Nobody in the company has been through this before, and the next two days will turn on decisions made in the first twenty minutes. It's the one part of our summary of Law 25 obligations for SMBs that fires under pressure, in the middle of a technical crisis.

So this article is a timeline rather than a lecture. Hour zero, day 1, days 2 and 3, the week after: at each step, what the Canadian Centre for Cyber Security says, and what Quebec law stacks on top. One clarification up front: the "72 hours" in the title is our working frame, not a deadline written into the law.

The short answer, for the busy

Ransomware becomes a confidentiality incident under Law 25 as soon as it touches personal information, even with no proof of data theft: section 3.6 covers loss and any other breach of the protection of such information. No 72-hour deadline exists in Quebec law. Section 3.5 requires that you "promptly" notify the Commission d'accès à l'information when the incident presents a risk of serious injury, and that you notify each affected person as well. In order: isolate the infected systems and cut remote access, report the crime to your local police and the Canadian Anti-Fraud Centre, call your insurer, then establish what information was touched. The risk assessment is done with your privacy officer and weighs the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for injurious purposes. Every incident, reportable or not, goes into the register.

The 72-hour deadline doesn't exist, and you want to know that before the crisis

Plenty of Quebec business owners carry a 72-hour clock in their head. It comes from Europe's General Data Protection Regulation, not from here. The Quebec text is shorter and vaguer: section 3.5 of the Act respecting the protection of personal information in the private sector says to notify the Commission d'accès à l'information "promptly" (the French original reads "avec diligence"). No counter, no business days, no threshold.

The absence of a number is not permission to drag your feet, it's the opposite. A fixed deadline gives you an alibi until it expires; "promptly" gets judged after the fact, against what you knew and when. We keep 72 hours as an internal discipline because that's roughly how long it takes an SMB to go from chaos to a clear picture.

Hour zero: isolate, switch channels, and don't pay on reflex

The Canadian Centre for Cyber Security's Ransomware playbook (ITSM.00.099, effective 11 December 2025) opens with the instruction SMBs follow least: assume the threat actor is still on your network and knows what's happening on it. So coordinate your response over a different channel, off the compromised network, or you're writing your recovery plan under the eyes of the person attacking you.

Then containment. Identify the infected devices, isolate them, disconnect them from the internet and from internal networks, and disable VPNs, remote access servers, single sign-on and exposed cloud assets. The playbook acknowledges that cutting your infrastructure off temporarily disrupts operations, and maintains that it is the single most important step. Then reset administrator and user passwords, without revoking the credentials you'll need to restore your backups.

Report the crime to your local police, the Canadian Anti-Fraud Centre and the Cyber Centre. This isn't a formality: for a known ransomware variant, law enforcement sometimes has a decryption key. Call your insurer too, who will often put an external incident response team at your disposal.

On payment the playbook is measured: the decision is yours, but paying guarantees nothing. Some groups deploy a wiper that permanently destroys files after the transfer, others come back for more, publish the data anyway or attack again. Payment can also be illegal under anti-terrorism, anti-money-laundering, criminal organization financing or sanctions legislation. That's why the call to the police comes before the decision, not after.

Day 1: what was touched, and the serious injury test

Once the bleeding stops, the Quebec obligation takes over. The question is no longer "are our systems running", it's "what personal information was touched".

Watch for the most common line of reasoning: "they only encrypted it, they didn't steal anything, so there's nothing to report". Section 3.6 defines a confidentiality incident as access, use or communication of personal information not authorized by law, or its loss or "any other breach of the protection of such information". An encrypted payroll server fits the definition without a single byte leaving, and the Commission d'accès à l'information lists ransomware among its own examples of an incident, alongside phishing.

The risk assessment follows section 3.7: sensitivity of the information, anticipated consequences of its use, likelihood that it will be used for injurious purposes. It has to be done with your privacy officer, which the law requires and many companies forget. A client list with names and emails, an employee file with social insurance numbers and a server full of shop drawings do not produce the same answer.

All of it goes into your confidentiality incident register, including when you conclude there is no serious risk. The register gets filled in during the incident, not from memory three weeks later.

Days 2 and 3: notify without lying, and without knowing everything

If the test lands on a risk of serious injury, two notices go out. The one to the Commission is made in writing, on its official form, whose content is set by the Regulation respecting confidentiality incidents: eleven items, including a description of the information involved, the circumstances, the date of the incident and the date you became aware of it, the number of people affected and how many of them live in Quebec. The form also warns that certain information, including your organization's name and the fact that an incident occurred, could be made public.

The usual objection at this stage is that you don't know everything yet. The regulation answers it: the organization must promptly transmit, as it goes, any element it learns after sending the notice. You report what you know, then you complete it. Waiting for a perfect picture is the wrong call, legally included.

The notice to affected individuals is shorter and more useful: what information, what circumstances, when, what you're doing, what they should do to protect themselves, and who to contact. A public notice replaces the individual one in only three situations, notably when you don't have people's contact details. This is where the temptation to round off the edges is strongest: the real penalty risk under Law 25 has far more to do with how you handle the aftermath than with the theoretical size of the fines.

The week after: restoring from backups you already tested

Recovery turns on a decision made months earlier. The federal playbook recommends running anti-malware diagnostics on the backup before restoring, rebuilding systems in a clean location isolated from the network, then bringing everything to the latest patch level. A backup restored without checking often reinstalls the backdoor along with the files, and the company gets encrypted a second time.

Plan for the duration too: the playbook warns that nearly every recovery process requires a long period disconnected from the internet in order to evict the threat actor, downtime most SMBs have never costed.

The prevention that changes the odds, and what it actually costs

The Cyber Centre names three main ways in: attacks on authentication mechanisms (password guessing), exploitation of software vulnerabilities, and phishing. All three close with the measures we detail in our article on website security for SMBs: multifactor authentication everywhere, patches applied fast, accounts cut back to least privilege, offline backups whose restore has been tested. Microsoft's study of Azure Active Directory accounts showing suspicious activity measured a 99.22% reduction in compromise risk with multifactor authentication: nothing else on the list comes close on effort versus result.

The human side deserves better than an annual training session. The Canadian Anti-Fraud Centre files under "spear phishing" the mechanic SMBs call CEO fraud: an email that appears to come from the boss demanding an urgent wire transfer, or a fake supplier message announcing a change of banking details. A compromised mailbox makes those messages credible, because they quote your real invoices. The habit worth installing costs nothing: every change of banking details gets confirmed by phone, at a number known in advance.

Cyber insurance: what it covers, what it demands

A cyber policy covers items ordinary business insurance ignores: forensic investigation, legal counsel, notifying affected individuals, data restoration, income disruption and cyber extortion. The Insurance Bureau of Canada and the federal Get Cyber Safe program make the same point: it is one component of a strategy, never a substitute for cyber resilience.

The market has hardened. According to the Insurance Bureau of Canada, cyber liability premiums went from $18 million in 2015 to $550 million in 2023, with a combined ratio averaging 153% between 2019 and 2023, meaning $1.53 paid in claims and expenses for every dollar earned. Insurers responded by tightening underwriting and requiring stringent security controls. The basics now determine your insurability and your premium. One last counterintuitive warning from the Cyber Centre: keep your policy documents out of reach, because an attacker who knows your coverage limit negotiates the ransom accordingly.

The number of ransomware incidents known to the Cyber Centre has grown by an average of 26% a year since 2021, and the agency considers it almost certain that the real number is higher, because so many go unreported. None of these measures assumes an in-house security team. The bill arrives when, at 4 p.m. on a Friday, nobody knows who calls the police, who calls the insurer, or where the backups are.

→ Let's talk about your situation, or see how we handle security in our web services.

This article explains legal obligations to help an SMB ask the right questions; it is not legal advice. The text of the Act respecting the protection of personal information in the private sector, the Regulation respecting confidentiality incidents and the positions of the Commission d'accès à l'information govern: for your specific situation, consult a lawyer.

Xavier Peich

Written by

Xavier Peich