Business IT projects · Across Québec Request a quoteFrançais

Guide

What to do after a cyberattack in an SMB?

Short answer

The Canadian Centre for Cyber Security recommends isolating affected systems, preserving evidence, reporting the incident to the police and to the Cyber Centre, then restoring systems. If personal information is involved, the incident goes in the register; notice to the CAI and to the persons concerned is mandatory only if there is a risk of serious injury.

This guide is for information only and is not legal advice.

This guide covers what happens after a cyberattack: ransomware, a hacked email account, unauthorized access to a server. It follows the steps published by the Canadian Centre for Cyber Security and shows where to report the incident according to the official pages. Preparing before an incident (plan, roles, exercises) is covered on the Incident response page, and Law 25 obligations in detail in the guide Quebec Law 25 for SMBs.

Courtier TI does not respond to incidents. If your business is facing an emergency, the Cyber Centre's reporting page says to contact your local police.

1. Isolate affected systems

In its Ransomware playbook (ITSM.00.099), the Canadian Centre for Cyber Security describes the first measures to take:

  • determine which devices and systems are infected;
  • isolate systems and devices, and disconnect infected ones from the Internet and any internal network connection to reduce the risk of the infection spreading;
  • determine what data has been impacted and the likelihood that its confidentiality or integrity has been compromised;
  • deactivate VPNs, remote access servers, SSO resources and cloud-based or public-facing assets as additional containment measures.

The Cyber Centre also recommends assuming that the threat actor is still on your network, and using an alternative communication method they cannot access, for example external email accessed by a device not connected to your network.

2. Document and preserve evidence

The Cyber Centre says to preserve evidence and document the steps taken. These notes support the incident analysis, the police report and, where applicable, the register of confidentiality incidents.

In its checklist for ransomware victims, available in French only, the Sûreté du Québec suggests gathering, if possible with the help of your IT technician, the documents useful for the complaint, for example:

  • a copy of the ransom demand;
  • a copy of the emails exchanged, with the original email header;
  • event logs from servers, the firewall, the VPN or the email service;
  • a network map.

The checklist also suggests identifying and preserving, if possible, the first infected workstation, without handling or resetting it. If preservation is not possible, it suggests making an image copy of one or more infected workstations before restoring them.

Also write down the timeline: when the incident was discovered, by whom, which systems are affected and what measures have been taken.

3. Report the incident

According to the official pages read on October 9, 2026:

  • Canadian Centre for Cyber Security: its "Report a cyber incident" page has a form that tells you where to report. For ransomware, the ITSM.00.099 playbook says to report the attack to the Cyber Centre online via My Cyber Portal.
  • Police: the Cyber Centre says to report ransomware to local law enforcement. The Sûreté du Québec checklist says to file a complaint with your local police service or your local Sûreté du Québec station.
  • Canadian Anti-Fraud Centre: its reporting page asks victims of cybercrime to contact their local police, and also recommends reporting the incident to the Canadian Anti-Fraud Centre. It states that investigating is the role of local police.

The Cyber Centre adds that if you have been infected with a known type of ransomware, you can check whether law enforcement can provide a decryption key.

4. Restore systems

The ITSM.00.099 playbook describes the recovery steps:

  • reset passwords for administrator and user accounts, without changing any credentials required to restore your backup;
  • safely wipe infected devices, reinstall the operating system and reload firmware;
  • run antivirus and antimalware diagnostics on backups before beginning the restore, then restore systems into a clean, network-isolated location;
  • identify how the threat actor entered the network and remediate that point of entry before reconnecting systems to the network or the Internet.

The Cyber Centre describes three options for storing backups, namely online, offline and in the cloud, and states that online backups are vulnerable to ransomware if connected to your systems or networks. The Data backup page describes what a quote should cover to set them up or review them after the incident.

Ransomware: what the Cyber Centre says about the ransom

The Canadian Centre for Cyber Security states that the decision to pay the ransom is up to your organization, and that before you even consider paying, you should contact your local police to report the cybercrime. It explains that paying does not ensure access to your encrypted data or systems, that threat actors may demand more money, retarget your organization or leak data, and that it may be unlawful to pay a ransom under certain laws, including laws against terrorism or money laundering, or sanctions legislation.

If your business holds a cyber security insurance policy, the Cyber Centre mentions that it may provide incident response expertise in the event of a ransomware attack.

Personal information: what Law 25 provides

If the incident involves personal information, the Act respecting the protection of personal information in the private sector applies:

  • Measures (s. 3.5): the business must take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature.
  • Notice to the CAI and to persons (s. 3.5): it is mandatory only if the incident presents a risk of serious injury. In that case, the business must promptly notify the Commission d'accès à l'information and the persons concerned. Notice to the persons may be delayed for as long as it could hamper a police investigation.
  • Risk assessment (s. 3.7): the business considers, among other things, the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for injurious purposes, and consults its person in charge of the protection of personal information.
  • Register (s. 3.8): every confidentiality incident goes in the register, even without a risk of serious injury. A copy is sent to the Commission at its request.

The Regulation respecting confidentiality incidents sets out the content of the written notice to the Commission (s. 3), the content of the notice to the persons concerned (s. 5) and the content of the register (s. 7), which includes the elements that led the business to conclude whether or not there is a risk of serious injury. The information in the register must be kept up to date and kept for at least 5 years after the date or time period when the business became aware of the incident (s. 8).

The guide Quebec Law 25 for SMBs explains these obligations in more detail. The Law 25 assessment page describes a mandate to review your practices. For a legal question, consult a legal advisor.

After the incident

The Cyber Centre recommends identifying the root cause of the incident, evaluating the response and developing lessons learned. It is also the time to prepare or review the incident response plan, as described on the Incident response page.

A quote request after an incident can cover analyzing what happened, restoring systems, backups or preparing a plan. To make it precise, state:

  • what happened, on what date, and the systems affected;
  • the measures already taken and the reports already made;
  • whether personal information is involved;
  • the state of your backups;
  • the people or organizations already involved: insurer, cyber security firm, IT provider;
  • what you expect from the mandate: analysis, restoration, backups, incident response plan.

Frequently asked questions

Do we always have to notify the Commission d'accès à l'information?

No. Under section 3.5 of the Act respecting the protection of personal information in the private sector, notice to the Commission and to the persons concerned is mandatory if the incident presents a risk of serious injury. Every confidentiality incident must still be recorded in the register (s. 3.8).

How long must the incident register be kept?

The Regulation respecting confidentiality incidents states that the information in the register must be kept up to date and kept for at least 5 years after the date or time period when the business became aware of the incident (s. 8).

Where should a cyberattack be reported?

According to their official pages: to your local police, to the Canadian Anti-Fraud Centre and to the Canadian Centre for Cyber Security, whose form tells you where to report. The Sûreté du Québec says to file a complaint with your local police service or your local Sûreté du Québec station.

Should we pay the ransom?

The Canadian Centre for Cyber Security states that the decision is up to your organization, and that before you even consider paying, you should report the cybercrime to your local police. It explains that paying does not ensure access to your data and that paying a ransom may be unlawful under certain laws.

Can Courtier TI step in during a cyberattack?

No. Courtier TI does not respond to incidents. For an emergency, the Canadian Centre for Cyber Security says to contact your local police. For a mandate after the incident, you can describe your needs in a quote request.

Is this guide legal advice?

No. This guide is for information only and is not legal advice. For a question about your obligations, consult a legal advisor.

Sources

  1. Canadian Centre for Cyber Security, Report a cyber incident, read on October 9, 2026
  2. Canadian Centre for Cyber Security, Ransomware playbook (ITSM.00.099), read on October 9, 2026
  3. Canadian Anti-Fraud Centre, Report fraud and cybercrime, read on October 9, 2026
  4. Sûreté du Québec, Dépôt d'une plainte à la police : aide-mémoire pour victime d'un rançongiciel (PDF, in French), read on October 9, 2026
  5. LégisQuébec, Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 3.5, 3.7 and 3.8, read on October 9, 2026
  6. LégisQuébec, Regulation respecting confidentiality incidents (CQLR, c. A-2.1, r. 3.1), sections 3, 5, 7 and 8, read on October 9, 2026

Have an IT project in mind?

Describe your project in a few lines: the team will contact you to clarify your needs and send you a quote.

Get a quote