Law 25 Breach Notification: Your First 72 Hours, Step by Step
An hour-by-hour breach response plan for Quebec SMBs: containment with Defender, the serious injury test, CAI notices and the register you must keep.
Your bookkeeper clicks a convincing link at 9:12 on a Tuesday morning. By 9:40, someone on the other side of the world is reading her mailbox and forwarding client invoices to an outside address. Under Quebec law, that is a confidentiality incident, and your Law 25 breach notification duties are now live. What you do in the next 72 hours decides whether this stays a rough week or becomes a file at the Commission d'accès à l'information (CAI).
Our guide to Law 25 and Microsoft 365 security covered prevention. This one covers the day prevention fails. Here's the hour-by-hour playbook we run with Quebec SMBs: contain, assess, notify, document.
Key Takeaways
- Law 25 requires notifying the CAI "with diligence", meaning promptly. The famous 72-hour deadline belongs to GDPR, not Quebec.
- You notify the CAI and affected individuals only when an incident presents a risk of serious injury.
- Every confidentiality incident, reportable or not, must be recorded in your incident register.
- Contain before you investigate: isolate devices, revoke sessions, reset credentials, kill forwarding rules.
- Microsoft Defender and Sentinel cut containment from hours to minutes and preserve the evidence the CAI may request.
72 Hours Is a Working Window, Not a Legal Deadline
Let's clear up the most common misconception first. GDPR, the European regime, imposes a 72-hour deadline for notifying its regulators. Law 25 does not. Quebec's law says you must notify "with diligence", which means promptly, without unjustified delay. No number of hours appears in the statute.
So why frame your response around 72 hours? Because it works. Three days is roughly how long you have before evidence degrades, logs roll over, the attacker digs in deeper and clients hear the news from someone other than you.
Once an incident hits, the law asks three things of you:
- Take reasonable measures to reduce the risk of injury and to prevent similar incidents from recurring.
- If the incident presents a risk of serious injury, notify the CAI and every affected individual with diligence.
- Record the incident in a register, whether it was reportable or not.
A confidentiality incident is broader than most owners assume: any unauthorized access, use or communication of personal information, or its loss. A stolen laptop counts. A client list emailed to the wrong recipient counts. Ransomware is just one scenario among many.
Hours 0 to 8: Contain the Incident
Containment beats investigation in the first hours. Every minute of attacker access widens the scope you'll have to assess later. Work in this order:
- Isolate the affected devices. In Microsoft Defender for Business, isolation takes one click and keeps the machine reachable for forensics while cutting it off from everything else.
- Disable the compromised account and revoke sessions. In Entra ID, block sign-in and revoke all active sessions so stolen tokens die immediately.
- Reset credentials and re-register MFA. Assume the attacker harvested the password and may have added their own authentication method.
- Hunt for persistence. Check inbox rules, mail forwarding, new OAuth app consents and freshly created admin accounts.
- Preserve, don't purge. Don't wipe the machine or delete suspicious messages. You'll need them as evidence, and possibly for the CAI.
If you don't have security staff in house, this is the moment to call your provider. A managed cybersecurity team that already runs Defender in your environment can execute all five steps remotely, often within the first hour.
Hours 8 to 24: Assess the Risk of Serious Injury
With the attacker locked out, the legal question begins: does this incident present a risk of serious injury? Law 25 gives you three factors to weigh:
- Sensitivity of the information. A social insurance number, health record or banking detail weighs far heavier than a business phone directory.
- Anticipated consequences of its use. Could someone commit fraud, steal an identity or damage a reputation with what was taken?
- Likelihood of injurious use. Data exfiltrated by a criminal group is far more likely to be misused than a file briefly opened by the wrong employee.
This assessment belongs to your person in charge of the protection of personal information (by default, your highest-ranking officer). Write down the conclusion and the reasoning while everything is fresh.
You can't assess what you can't see, which is why scoping matters. Which mailboxes were opened? Which SharePoint files were downloaded? Microsoft Purview audit logs and Sentinel hunting queries answer those questions in minutes. Guesswork never does.
Law 25 Breach Notification: The CAI and Affected Individuals
If you conclude there is a risk of serious injury, two notifications become mandatory, and both must happen with diligence.
Notifying the CAI. The Commission publishes an official incident report form on its website. Quebec's confidentiality incident regulation spells out what the notice must contain: a description of the personal information involved, the circumstances and date of the incident, the number of people affected, the measures you've taken and a contact person.
Notifying affected individuals. Each affected person must be told directly, with enough detail to protect themselves: what was exposed, when, what you're doing about it and what they can do. Public notice is allowed in limited cases, for instance when reaching people one by one would cause undue hardship.
Law 25 also lets you share information with any person or body that could reduce the risk, a credit bureau for example, without the consent of the individuals concerned.
Resist the temptation to stay quiet. The CAI can impose administrative monetary penalties reaching $10 million or 2% of worldwide turnover, and penal fines climb higher still. A late or missing notification is one of the easiest failures for a regulator to prove.
Hours 24 to 72: Evidence, the Incident Register and Recovery
The register is not optional. Every confidentiality incident goes in, including those that presented no serious risk. The regulation sets its content (description of the incident, information involved, dates, people affected, your risk assessment, measures taken) and requires keeping that information for five years after you become aware of the incident. The CAI can demand a copy at any time, and an empty register after a known breach makes a terrible impression.
Preserve your evidence now. Export the Defender incident timeline, Sentinel incident records, Entra sign-in logs, audit searches and message traces while they're still within retention. Store the exports outside the compromised environment.
Then recover. Clean or rebuild affected machines, restore altered or deleted data and confirm the attacker's changes are fully reversed. This step is painless when backup and recovery is already in place; our comparison of Microsoft 365 Backup and Dropsuite shows what point-in-time restore looks like for M365 data. And remember the law's other demand: reasonable measures to prevent a repeat. Fix the root cause, not just the symptom.
How Defender and Sentinel Speed Up Every Step
Microsoft's security stack kept showing up above. That's no accident.
- Containment. Defender's automatic attack disruption can isolate a device and disable a compromised account before a human even opens the alert.
- Scoping. Sentinel pulls sign-in logs, audit events and endpoint telemetry into one timeline, so "what did they touch?" becomes a query instead of a week of archaeology.
- Evidence. Sentinel retains security data beyond the default portal windows, which matters when an incident surfaces weeks after the initial compromise.
Our post on Sentinel and Defender as an SMB SOC describes how we run this stack for small businesses. The tooling that stops the breach is the same tooling that builds your CAI file.
Write the Plan Before the Breach
Every hour above goes twice as fast when it has been rehearsed. A one-page incident response plan for an SMB needs named roles (who contains, who decides on serious injury, who talks to clients), out-of-band contact methods in case email is compromised, the CAI form bookmarked and your provider's emergency number. Run a tabletop exercise twice a year; thirty minutes around a conference table exposes most of the gaps.
FAQ
Does Law 25 require me to notify the CAI within 72 hours?
No. Law 25 requires notification "with diligence", meaning promptly and without unjustified delay, when an incident presents a risk of serious injury. The 72-hour deadline people often cite comes from Europe's GDPR. Treat 72 hours as a sound operational target, not a legal rule.
What counts as a confidentiality incident under Law 25?
Any access, use or communication of personal information not authorized by law, and any loss of personal information. That includes hacked mailboxes, stolen laptops, misdirected emails and employees browsing files they have no business opening. Ransomware is only one scenario among many.
Do I have to report every incident to the CAI?
No. You notify the CAI and affected individuals only when the incident presents a risk of serious injury, weighed against the sensitivity of the information, the anticipated consequences and the likelihood of misuse. Every incident must still be recorded in your internal incident register.
How long must I keep my incident register?
Quebec's confidentiality incident regulation requires the information in the register to be kept up to date and retained for at least five years after the date you become aware of the incident. The CAI can request a copy of the register at any time.
What penalties can follow a mishandled breach under Law 25?
The CAI can impose administrative monetary penalties of up to $10 million or 2% of worldwide turnover, whichever is greater. Penal proceedings can reach $25 million or 4% of worldwide turnover. Failing to notify, or notifying late without justification, is among the clearest violations to sanction.
A breach at 9:12 on a Tuesday shouldn't be the day you learn all of this. If you'd like a clear picture of how your Microsoft 365 environment would hold up, and whether you could produce a CAI-ready file within 72 hours, book a free IT assessment and we'll walk through it together.
Related Articles
Law 25 Enforcement in 2026: Ready for a CAI Inspection?
Law 25 enforcement is ramping up in 2026. Learn how to map each obligation to concrete Microsoft 365 controls before a CAI inspection lands.
IT Budget Planning 2027: Costs and Grants for Quebec SMBs
IT budget planning 2027 for Quebec SMBs: Microsoft 365 renewals, Windows 10 ESU, backup, security and ESSOR grants. Learn how to build yours.
Windows 10 ESU Ends October 13, 2026: Your 10-Week Plan
Windows 10 ESU Year 1 ends October 13, 2026. Learn how to audit your fleet with Intune and finish your Windows 11 migration in 10 weeks.