What four years of incidents reported to Quebec's Commission d'accès à l'information (CAI) reveal about the threat in Quebec, sector by sector.
In 2025-2026, phishing doubled in the incidents reported in Quebec. For the first time in four years, it outweighs ransomware.
More than six in ten reported incidents now cite an attack, and nearly nine in ten in manufacturing. Here are the five findings that matter, and what to do about them.
Five measures, in the order we would put them in place. They are our recommendations, not findings from the register: each responds to a measured finding, shown on the left, and aligns with the public recommendations of the Canadian Centre for Cyber Security. None requires an in-house security team; several can be entrusted to a service provider.
What about training?
It remains useful. Errors or accidents appear in 25.9% of 2025-2026 notices, and awareness also helps people recognize phishing. It does not replace technical measures: it only takes one person being fooled once. That is why phishing-resistant authentication comes first.
In surveys, Quebec businesses often say they are ready, but most have no plan if ransomware strikes. The Commission's register does not record organization size, so this section draws on other sources and sets out what they can and cannot say about small and medium-sized businesses (SMEs).
Quebec had 1,024,273 active businesses in December 2025, including 278,816 with at least one employee. Of these, 72.0% have fewer than ten employees and 99.7% fewer than 500. The four sectors with the most employer businesses are construction (13.7%), retail trade (11.8%), health care and social assistance (11.3%) and professional, scientific and technical services (10.7%).5
Three of these four sectors are among those with the highest malicious share of notices over four fiscal years (section 04): construction 83.3%, retail trade 79.9%, professional services 73.1%. This comparison describes the incident profile of sectors where small businesses are numerous. It does not say that notices in these sectors come from SMEs, nor that a given SME faces a particular risk there. In health care, which mixes large public institutions and small clinics, the error-dominated profile may mostly reflect the large reporters; the register cannot verify this.
A Quebec-specific measure of incidence exists. Two researchers at the Université de Montréal analyzed Statistics Canada's cybersecurity survey for the roughly 2,800 Quebec businesses in its sample: 15.5% of them report experiencing an incident in 2023, versus 16.4% in 2021; the share of incidents aimed at stealing money or obtaining a ransom rose from 19.8% to 39.9%; and 44.9% of businesses have no employee assigned to cybersecurity.6
These figures cover only businesses with 10 or more employees, excluding public administration, like the entire survey.7 They therefore do not cover the 72% of Quebec employer businesses with fewer than ten. And having no employee assigned to cybersecurity does not mean no one handles it: across Canada, the reason most often cited by businesses without dedicated staff is relying on consultants or contractors (47%).
A KPMG survey of 154 Quebec businesses, in September 2023, gives a glimpse of their preparedness: 58% had no plan to deal with ransomware, 65% said they lacked the skilled staff to manage cybersecurity, and 74% felt their legacy systems made them vulnerable.8 These businesses all report more than $10 million in annual revenue, up to $1 billion: they are mid-sized firms, not the small businesses that make up most of Quebec's economy. The survey relies on an opt-in panel, with no published margin of error. Its rates of businesses “attacked” (63%) and having paid a ransom (60% over three years) are comparable neither with the register nor with the Statistics Canada survey, for lack of a common definition; we do not use them as a measure of the threat. The shortage of skilled staff, however, matches the IMC2 finding.
Two other surveys point the same way, with similar caveats. KPMG repeated the exercise in September 2024 with 350 Quebec businesses, larger still on average (47% report $500 million to $1 billion in revenue): 73% had no plan to deal with ransomware, and only 39% strongly agreed that cybersecurity is a priority for their business.9 The two samples differ too much to read a trend between 58% and 73%. On the SME side, the Quebec software publisher Devolutions has published a portrait since 2022. In the 2022 edition (151 IT professionals and decision-makers, a survey by the firm SOM), half of respondents said they had experienced a cyber incident in the past year, 54% had implemented two-factor authentication, and 18% had no formal policy for revoking former employees' access. In the 2024-2025 edition, 50% say they experienced at least one cyberattack in 2024; 71% say they are confident they could respond to a major incident, but only 13% consider their posture advanced, and 25% have no process for managing privileged access.10 These samples are small, recruited by a software publisher, and the size of the 2024-2025 sample is not published: they describe self-reported preparedness, not how often incidents occur.
What we draw from it. Large or small, the Quebec businesses surveyed often say they are confident, but few have a response plan or structured access management. This gap between confidence and preparedness underpins three of our recommendations: protecting access (1), preparing for a leak (3) and monitoring valid access (4).
Sector is the only information the register gives about the reporting organization. The gaps between sectors are clear: find yours to see which type of cause dominates the notices reported there.
Malicious share and error share, by sector
For each sector, share of notices citing a malicious cause (orange) and share citing an error or accident (blue). Four fiscal years combined, from the sector with the highest malicious share to the one with the lowest.
| Business sector | Notices (4 yrs) | Dominant profile | Malicious cause | Error or accident | Access abuse |
|---|---|---|---|---|---|
| Manufacturing | 129 | Attack | 91.5% | 9.3% | 7.8% |
| Wholesale trade | 41 | Attack | 85.4% | 4.9% | 12.2% |
| Construction | 36 | Attack | 83.3% | 11.1% | 11.1% |
| Accommodation and food services | 32 | Attack | 81.2% | 9.4% | 15.6% |
| Retail trade | 149 | Attack | 79.9% | 10.7% | 13.4% |
| Mining, oil and gas extraction | 22 | Attack | 77.3% | 13.6% | 13.6% |
| Professional services | 223 | Attack | 73.1% | 20.6% | 10.8% |
| Information industries | 52 | Attack | 67.3% | 23.1% | 25.0% |
| Other services | 146 | Attack | 63.7% | 21.2% | 21.2% |
| Transportation and warehousing | 32 | Attack | 62.5% | 18.8% | 12.5% |
| Real estate and rental | 37 | Mixed | 59.5% | 27.0% | 13.5% |
| Arts, entertainment and recreation | 46 | Mixed | 52.2% | 32.6% | 19.6% |
| Finance and insurance | 275 | Mixed | 45.8% | 30.2% | 23.6% |
| Educational services | 132 | Error | 31.1% | 59.8% | 12.9% |
| Health care and social assistance | 251 | Error | 25.9% | 56.6% | 15.5% |
| Public administration | 113 | Error | 23.0% | 52.2% | 23.0% |
Base: CAI register, four fiscal years combined, 1,716 notices in the 16 sectors with at least 20. The last three columns are the share of the sector's notices citing at least one cause of that type; since a notice can carry several causes, they do not add up to 100%. “Attack” profile: at least 60% of notices cite a malicious cause. “Error”: the share of notices citing an error or accident exceeds the malicious share. “Mixed”: all other cases. These thresholds are ours.
In education, health care, finance and public administration, the share of notices citing a malicious cause rises in 2025-2026. Volumes are small, from 29 to 94 notices per sector and fiscal year, and finance had already reached 53.6% in 2023-2024. These increases are a signal to confirm next year, not an established trend.
Malicious share in four sectors, by fiscal year
Share of the sector's notices citing at least one malicious cause, by fiscal year.
In 2025-2026, phishing became the second most cited cause in notices, ahead of ransomware. It is the first time in the four fiscal years.
Share of notices by family of reported causes
Share of the fiscal year's notices citing at least one cause from the family. Since a notice can carry three causes, it can count in several families.
| Cause family | 2022-2023 | 2023-2024 | 2024-2025 | 2025-2026 |
|---|---|---|---|---|
| Malicious attack | 55.5% | 55.4% | 50.7% | 62.8% |
| Error or accident | 30.3% | 30.4% | 35.1% | 25.9% |
| Access abuse | 9.2% | 16.2% | 16.1% | 19.2% |
| Data theft | 11.0% | 13.1% | 19.0% | 17.3% |
In 2025-2026, 37 notices report both a cyberattack and unauthorized access, versus 8 a year earlier. This combination, rare until then, became the fourth most frequent in the register. It describes an intrusion during which data was viewed, and it deserves to be tracked. It does not, however, measure compromised accounts: the register says neither how the intruder got in nor whether credentials were stolen.
“Unauthorized access” reported with a cyberattack
Number of notices carrying both causes at once.
What the register measures
37 notices cite both a cyberattack and unauthorized access in 2025-2026, versus 8 in 2024-2025, 5 in 2023-2024 and 1 in 2022-2023. These 37 notices come from many sectors, with at most 6 in any one sector. Seventeen cite only these two causes, eleven add data theft, four add phishing. Over the same period, notices citing unauthorized access without an attack cause remained stable or declined: 39, 39 and then 33 from 2023-2024 to 2025-2026.
Our proposed interpretation
The combination describes an intrusion during which data was viewed. It is consistent with an intruder who used valid access, for example credentials obtained through phishing, to read what was accessible.
Other compatible scenarios
An intrusion through a vulnerability, followed by viewing of the data. Organizations that now describe the consequence of an intrusion as “unauthorized access,” through better knowledge of the categories or a change in instructions: cause vocabulary changes from one fiscal year to the next (section 06). Or several notices stemming from a single incident at a shared supplier, which the register cannot link.
What other sources describe
The Canadian Centre for Cyber Security detected more than one hundred “adversary-in-the-middle” phishing campaigns targeting Microsoft Entra ID accounts between 2023 and early 2025. These campaigns capture the user's session at the moment of sign-in, second factor included when it is not phishing-resistant.3 In France, ANSSI, the national cybersecurity agency, describes the role of credential-stealing malware (infostealers) and of brokers who resell access.11 In its incident response work in Canada, KPMG also reports business email compromise that bypasses multi-factor authentication.1 These mechanisms exist; the register cannot say what share of the 37 notices they explain.
What cannot be concluded
That these notices correspond to compromised accounts. What share of the increase stems from how notices are filled out rather than from the incidents. Nor that the increase will continue: it covers a single fiscal year.
What Flare sees, from Montreal
Flare, a Montreal threat intelligence company, monitors the logs of credential-stealing malware (infostealers) that circulate in the criminal ecosystem. In its February 2026 report, based on 18.7 million logs collected in 2025, the share of infections containing enterprise credentials (single sign-on or identity provider) rose from about 6% in early 2024 to nearly 14% by late 2025. Microsoft Entra ID appears in 79% of these logs, and 1.17 million of them contain both enterprise credentials and session cookies.2
What we draw from it. Flare's data are global and say nothing about Quebec in particular. Yet they describe the raw material of the scenario we propose for the 37 notices: valid access stolen in growing numbers, then used to view data. The register cannot say how many of the 37 notices stem from it; the two series point the same way.
Put another way: in 2025-2026, 74.1% of notices cite only attack, abuse or theft causes, with no error, accident or failure, versus 64.1% a year earlier. Conversely, notices citing only errors, accidents or failures fell from 31.3% to 20.8%.
Ransomware is cited in 47, 97, 111 and then 103 notices depending on the fiscal year. Its share of notices stays close to 21.6% for three fiscal years, then falls to 17.7% in 2025-2026. Among notices citing a malicious cause, its share went from 38.8%, 39.4% and 42.5% to 28.1%. Data theft went from 19.0% to 17.3% of notices the same year. These series show that ransomware weighs less among reported causes in 2025-2026. On their own, they do not show that attackers have replaced encryption with something else: the decline covers one fiscal year, and data theft is not rising in parallel.
| Reported cause | 2022-2023 | 2023-2024 | 2024-2025 | 2025-2026 | Over 4 years | One-year change |
|---|---|---|---|---|---|---|
| Cyberattack | 33.5% | 35.8% | 31.3% | 34.8% | ▲ +3.5 pts | |
| Phishing | 11.5% | 7.4% | 9.7% | 19.0% | ▲ +9.3 pts | |
| Ransomware | 21.6% | 21.8% | 21.6% | 17.7% | ▼ −3.9 pts | |
| Data theft | 11.0% | 13.1% | 19.0% | 17.3% | ● −1.7 pts | |
| Accidental disclosure | 4.6% | 12.8% | 19.4% | 15.3% | ▼ −4.1 pts | |
| Unauthorized access | 7.8% | 10.1% | 10.7% | 13.4% | ▲ +2.7 pts | |
| Human error | 19.3% | 13.7% | 21.7% | 13.0% | ▼ −8.7 pts | |
| Social engineering | 1.8% | 1.1% | 2.9% | 3.1% | ● +0.2 pts | |
| Technical failure | 6.4% | 3.6% | 1.9% | 2.9% | ● +1.0 pts |
Base: CAI register, 218, 444, 515 and 583 notices depending on the fiscal year. Share of the fiscal year's notices, causes ranked by 2025-2026; since a notice can carry up to three causes, columns exceed 100%. The change is in percentage points between 2024-2025 and 2025-2026: ▲ rising the cause is cited in a larger share of notices, ▼ falling in a smaller share, ● stable the gap is under two points. The “over 4 years” curve is scaled to each cause.
From 254 notices in 2022-2023 to 583 in 2025-2026, growth is slowing: +75%, +16% and then +13%. The data cannot separate what is due to more incidents from what is due to better compliance with the reporting obligation.
Confidentiality incident notices received by the Commission
Quebec fiscal year, April 1st to March 31.
In 2021-2022, the last full year of the voluntary regime, the Commission received 78 reports. It described the incidents handled as follows: external intrusions 67%, human error 24%, other incidents 9%.12 These categories are not those of the register, and the organizations that reported voluntarily are not the same population as those reporting under the obligation. These 67% therefore cannot be compared with the 55.5% of notices citing a malicious cause in 2022-2023 as if they were the same measure. One can only note that, from 2022-2023 on, the mandatory register contains a large share of errors and accidents (30.3% of notices). The simplest hypothesis is that the obligation brings in incidents that were previously not reported; the data cannot verify it.
Other series help put the notice curve in context, without settling the question. Police-reported cybercrime in Quebec went from 4,004 incidents in 2018 to 11,902 in 2024, then 11,547 in 2025; more than half of police-reported cybercrime in Canada is fraud, mostly targeting individuals.13 At the federal level, where breach reporting has been mandatory since 2018, the Office of the Privacy Commissioner of Canada (OPC) receives a stable volume: 681, 693 and then 686 reports from 2022-2023 to 2024-2025.14 These observations are consistent with a Quebec increase driven partly by a recent reporting regime. They do not show how large that part is.
Method. We searched for incidents affecting Quebec organizations made public between April 1st, 2022 and September 23, 2026, in French and English, in the press, organizations' press releases and specialized sites. A case is included only if at least one consulted page confirms the facts; a figure that appears only in an inaccessible source is not used. The search produced thirty main cases and a dozen more in reserve. This review is not a representative sample: what becomes public depends on the organization's size, its public or listed status, and press interest. The nine cases below are illustrations, chosen to cover a range of sectors and situations. The last column is our reading, not a fact established by the source.
| When | Organization | Facts reported by the source | Our reading |
|---|---|---|---|
| Aug. 2022 | BRP, Valcourt Manufacturing | Ransomware. Head office and plant shut down for more than a week; about 30 GB stolen, including employees' passports and driver's licences. InCyber, August 30, 2022 | A production shutdown of more than a week is a cost in itself, regardless of any ransom. |
| Nov. 2023 | Town of Lac-Mégantic Public administration | Ransomware. All servers encrypted, backups included; data recovered in December with the help of outside firms. La Tribune, Dec. 22, 2023 | Backups reachable from the affected network can be encrypted along with everything else; an isolated copy reduces this risk. |
| May 2024 | Pharmascience, Montreal Manufacturing | Unauthorized access beginning in early May, discovered on June 1st, reported to the Commission on June 6. Employees' personal, financial and medical information exfiltrated. Cyberswat, July 2024, citing the Commission | According to the source, about a month passed between the start of the access and its discovery. |
| Mar. 2025 | Cablevision, Val-d'Or Information industries | Exfiltration and sale of 66.8 GB: about 35,000 customers, banking data for fewer than one in ten; four years of credit monitoring offered. Radio-Canada, March 18, 2025 | The measures offered to affected customers, here four years of credit monitoring, are part of the cost of an incident. |
| Mar. 2025 | Groupe Qualinet, Quebec City Administrative and support services | Data theft with extortion, identity documents put up for sale; second incident after 2021; class action application filed. Le Soleil, March 3, 2025; Droit-inc, March 11, 2025 | An incident can lead to legal proceedings; here, a class action application. |
| Jul. 2025 | Groupe Colabor, Saint-Bruno Wholesale trade | Cyberattack on internal systems, disruptions until early August; employee data possibly compromised; Commission and police notified, credit monitoring for all employees. Press release, August 7, 2025 | The company made public the incident, its notifications to the Commission and the police, and the measures offered to employees. |
| Nov. 2025 | Crisis24 (CodeRED), Montreal Supplier to municipalities | Ransomware with data theft at the supplier; passwords compromised; about 6,000 Brossard residents notified, other cities too. Le Courrier du Sud, Dec. 2, 2025 | An incident at a supplier forces its clients to notify their own users. |
| Jan. 2026 | CIUSSS du Centre-Sud-de-l'Île-de-Montréal Health care | Error. A payroll file accidentally shared with about a hundred colleagues for more than six years; more than 20,000 current and former employees, with bank account numbers. Radio-Canada, January 2026 | A sharing error can last for years if file access rights are not reviewed. |
| Aug. 2026Outside the data period | Commission de la construction du Québec Construction-sector body | Ransomware with theft of client and employee information; online and phone services down until September 8; credit monitoring offered. Already hit in 2023 by the MOVEit vulnerability at a subcontractor. CCQ, Sept. 4, 2026; CCQ, 2023 | Businesses and workers can be affected by an incident at a body that holds their information, without having been attacked themselves. |
Public cases are not part of any calculation in this report. The August 2026 case postdates March 31, 2026, the end of the period covered by the register. The numbers of people affected are those given by the open source; higher figures circulating in the press were not used for lack of a verifiable page.
Three observations concern this review itself. They do not generalize to all incidents.
Ransomware is common among public cases. Thirteen of the thirty main cases are ransomware, which halts operations and is visible from outside. Phishing is almost never named as the entry point in the sources consulted. For this cause, the register is the only measure available to us.
Public cases do not reflect the register's sector distribution. Nineteen of the thirty cases involve public bodies, health care or education, which issue press releases. We found no Quebec construction contractor, hotel or restaurant publicly named, even though these sectors are among those with the highest malicious share of notices. This gap shows what the review cannot see; it says nothing about these businesses' practices.
Eight of the thirty cases go through a third party: a subcontractor, a platform, a polling firm, a fundraising service provider. This proportion is a property of the review, not a measure of all incidents. It points to a question the register cannot address (section 07).
Reporting regimes differ in their threshold, categories and scope: their volumes and shares are not directly comparable, and no ranking is possible. Four comparisons nonetheless shed light on specific questions.
Do incident responders see the same shift? KPMG in Canada has published reviews of its incident response work for 2023 and for 2024. In its cases, the share of ransomware fell from 77% in 2023 to 46% in 2024, business email compromise rose from 15% to 32%, and unauthorized access and insider threats from 8% to 22%. KPMG also describes multi-factor authentication bypass and the use of Canadian VPN addresses to blend in with legitimate traffic.1 These figures cover KPMG's clients across Canada, by calendar year, and the number of cases is not published: they do not measure all incidents. Yet they point the same way as the register, through an independent method: less ransomware, more incidents that go through an account or an access.
Is ransomware declining elsewhere? In France, ANSSI writes in its Panorama de la cybermenace 2025 [Cyber Threat Landscape 2025] that “the number of ransomware attacks is slightly down compared with 2024,” while “the number of data exfiltration incidents known to ANSSI has increased significantly”: 128 ransomware compromises and 196 exfiltrations in 2025.11 In Canada, CIRA's annual survey shows the share of organizations reporting a successful ransomware attack falling from 28% in 2024 to 24% in 2025.15 Conversely, the Canadian Centre for Cyber Security notes that ransomware incidents brought to its attention have grown by an average of 26% per year since 2021.16 These sources do not measure the same thing. The decline observed in Quebec concerns the share of notices and a single fiscal year; it does not mean that ransomware groups are less active.
Is Quebec's malicious share unusual? In Australia, where reporting is also mandatory when there is a risk of serious harm, 59% of notifications in the first half of 2025 are attributed to a malicious or criminal attack.17 Quebec, at 62.8% in 2025-2026 by our grouping, is of the same order of magnitude. The two measures do not rest on the same categories.
Is unauthorized access rising elsewhere? At the federal level, the share of breaches reported to the OPC that are attributed to unauthorized access rose from 66% in 2022-2023 to 81% in 2024-2025.14 The federal category is broader than the combination studied above: it points the same way without confirming it.
The figures in this report come from the register of confidentiality incident notices held by Quebec's Commission d'accès à l'information, obtained through an access-to-information request.18 A confidentiality incident, under Quebec's Law 25, is personal information accessed, used, disclosed or lost without authorization, whether through an attack or an error. One row per notice: the organization's sector and up to three causes, with no name or date. In total, 1,760 notices, from April 2022 to March 2026.
For 2025-2026, the register counts 583 notices. The Commission, whose annual report for that year has not yet been published, estimated 579 in June 2026; the gap is under 1%.19 The other sources cited in the notes serve to put these figures in context.
Sector profiles combine the four fiscal years; changes compare 2024-2025 and 2025-2026. A “malicious cause” means a notice citing a cyberattack, ransomware, phishing or social engineering: this grouping is ours. Because a notice can carry three causes, percentages by cause add up to more than 100%.
The recalculated counts were checked against the Commission's published figures: 444 rows for 444 notices in 2023-2024, 515 for 514 in 2024-2025; sector breakdowns match to within one unit. For 2025-2026, the five-year report of June 11, 2026 put forward an estimate of 579 notices, the compilation not being complete; the register, extracted on August 27, 2026, counts 583. The 2025-2026 annual report will settle the matter.
Figure 1 and the figure of 583 notices rest on the Commission's official totals; all analyses of causes and sectors rest on the row-by-row register. The two differ for two fiscal years.
| Fiscal year | Official total | Register rows | Explanation of the gap |
|---|---|---|---|
| 2022-2023 | 254 | 218 | The Commission provided only the notices received after the obligation came into force on September 22, 2022. |
| 2023-2024 | 444 | 444 | No gap. |
| 2024-2025 | 514 | 515 | One row more than the official total. The register carries no name or date, so the extra row cannot be identified. It is kept; percentages for this fiscal year are calculated on 515, which shifts them by at most 0.2 points. |
| 2025-2026 | 583 | 583 | No gap with the register. The Commission's five-year report puts forward an estimate of 579 (see above). |
| Total | 1,795 | 1,760 | Each figure and table states its own base. |
Fiscal years run from April 1st to March 31; the Commission extracted its register on August 27, 2026, five months after the end of 2025-2026. A cause is counted once per notice. The average number of causes per notice went from 1.32 in 2022-2023 to 1.61 in 2024-2025, then 1.51 in 2025-2026: cause combinations depend partly on how notices are filled out. The cause “divulgation accidentelle” (accidental disclosure), cited 19 to 22 times a year until 2024-2025, no longer appears in 2025-2026. The public cases in section 05 run until September 2026 and are not part of any calculation.
The 20 sector categories used by the Commission are those of the North American Industry Classification System (NAICS).20 The register follows them in 97.7% of cases: 41 rows out of 1,760 carry a spelling variant or a subsector absent from the list. These discrepancies are concentrated in the first two fiscal years and then disappear, which makes recent years more reliable than the early ones.
Four pieces of information are missing from the register, and each one prevents a useful question from being answered.
Organization size. Nothing distinguishes an incident at a five-person SME from one at a 5,000-employee company. It is therefore impossible to say whether Quebec SMEs are over-represented.
The technical entry vector. The “cyberattack” category does not distinguish stolen credentials from an exploited vulnerability. This is what prevents direct measurement of account compromise (section 05). A category separating “compromised legitimate access” from “exploited vulnerability” would make it possible.
Third-party origin. The register does not indicate whether the incident occurred at a supplier. In our review of public cases, eight out of thirty went through a third party: the question arises, but nothing allows its scale to be measured. The CodeRED case shows how a single incident at a service provider ripples through to its clients.
The date. The register provided carries no incident or reporting date. Any analysis of seasonality, detection time or coordinated campaigns is out of reach.
Add to this a loss of transparency. On May 27, 2025, the Commission stopped publishing the list of organizations that reported an incident, while committing to continue releasing statistical data.21 The commitment has been kept, but the published statistics remain two separate breakdowns, with no cross-tabulation and no historical series.
We found no other comparable public series for Quebec. Quebec's Ministry of Cybersecurity and Digital Affairs publishes no count of the incidents handled by its network of cyber defence operations centres in its annual management reports.22 The Sûreté du Québec replied to two access requests, in 2023 and again in 2025, that its systems cannot isolate complaints related to cybercrime.23 We found no published results from the Institut de la statistique du Québec, Quebec's statistical agency, on incidents affecting businesses, and Statistics Canada does not publish a provincial breakdown of its survey.
The Commission's register shows what organizations report. It does not say how large the organization is, how the attacker got in, or what stays below the reporting threshold. For the next edition, we want to add what is happening on the ground.
Over the coming months, and throughout the year, we will run an anonymous survey of Quebec businesses of all sizes, including the smallest ones, which no public survey covers today. It will run in short waves, each focused on one theme (access and authentication, incidents experienced, suppliers, preparedness), to gather precise information without asking for more than a few minutes at a time. Answers will never be linked to your identity or your business, and we will publish the questionnaire and the sample size with the results.
You can now ask to be invited to upcoming waves, to receive the 2027 edition by email when it comes out, or both. Your address will be used only for these emails: it will never be shared with third parties or used for sales outreach, and you will be able to unsubscribe in one click.
Notes and sources
The Commission classifies each reporting organization in one of the 20 sectors of the North American Industry Classification System. It publishes no definitions; the descriptions below summarize the scope of each sector as set out in Statistics Canada's NAICS 2022.
| Sector | Code | What it covers |
|---|---|---|
| Agriculture, forestry, fishing and hunting | 11 | Farms, logging operations, fisheries and support services |
| Mining, quarrying, and oil and gas extraction | 21 | Mines, quarries, energy extraction and drilling services |
| Utilities | 22 | Generation and distribution of electricity, gas and water, wastewater treatment |
| Construction | 23 | General and specialty contractors, building, civil engineering |
| Manufacturing | 31-33 | Food processing, metals, wood, transportation equipment, pharmaceuticals |
| Wholesale trade | 41 | Sales to retailers, businesses or institutions, rather than to consumers |
| Retail trade | 44-45 | Sales to consumers, in store and online |
| Transportation and warehousing | 48-49 | Road, rail, air and marine transportation, couriers, warehousing |
| Information and cultural industries | 51 | Publishing, software, film, broadcasting, telecommunications, data hosting |
| Finance and insurance | 52 | Banks, credit unions, insurers, brokers, fund managers |
| Real estate and rental and leasing | 53 | Real estate brokerage and management, rental of housing, equipment and vehicles |
| Professional, scientific and technical services | 54 | Law and accounting firms, consulting engineering, architecture, advertising, IT, research |
| Management of companies and enterprises | 55 | Head offices and holding companies that manage other entities in their group |
| Administrative and support, waste management and remediation services | 56 | Employment agencies, call centres, private security, maintenance, waste management |
| Educational services | 61 | Schools, school service centres, CEGEPs, universities, vocational training |
| Health care and social assistance | 62 | Hospitals, clinics, long-term care homes (CHSLD), professional offices, child care and social services |
| Arts, entertainment and recreation | 71 | Performance venues, sports clubs, museums, parks, fitness centres |
| Accommodation and food services | 72 | Hotels, campgrounds, restaurants, bars, caterers |
| Other services (except public administration) | 81 | Repair and maintenance, personal care, funeral services, religious organizations, non-profits |
| Public administration | 91 | Government departments, public agencies, municipalities, police and protective services |
Two consequences of this classification are worth keeping in mind. A sector can bring together very different organizations: health care covers a hospital centre as well as a two-person practice. And an organization is classified by its main activity, so a commercial Crown corporation does not appear under public administration but in its economic sector.