RESOURCES / PRACTICAL GUIDANCE
Cybersecurity Resources for Quebec Professionals and Small Businesses
Understand the security decisions behind Microsoft 365, endpoints, patching, backup, recovery, privacy incidents and cyber-insurance—without fear-driven noise.
Protected. Patched. Backed up. Recoverable. Documented.
Loi 25 technical safeguards
A practical guide is being prepared for publication. No download is offered until the content is complete.
Draft / no download yet
KNOWLEDGE CENTRE
Start with the decision you need to make.
These topic introductions are available now; substantive guides and downloadable assets will be linked only when published.
Loi 25 Technical Safeguards
Understand where technical controls, evidence and incident readiness can support a broader privacy program.
Microsoft 365 Security
Review MFA, account protection, administration, sharing, device access and backup.
Backup & Recovery
Move from “we have backups” to monitored backups, restore procedures and validated recovery.
Ransomware Readiness
Connect endpoint protection, patching, detection, isolation, backups and recovery planning.
Cyber-Insurance Controls
Understand common questions about MFA, EDR, encryption, patching and evidence.
Account Compromise
Know the structured first steps for suspicious sign-ins, sessions, mailbox rules and escalation.
COMING RESOURCES
Useful substance before download links.
Microsoft 365 Security Hardening Guide
A practical review of MFA, privileged accounts, forwarding, sharing, devices and recovery.
Ransomware Readiness Checklist
Questions to answer about detection, isolation, backups, recovery dependencies and escalation.
Loi 25 Technical Safeguards
A plain-language view of identity, endpoint, backup, evidence and incident-readiness controls.
Backup & Recovery Validation Worksheet
A structure for covered systems, backup state, restore history, dependencies and gaps.
KNOWLEDGE CENTRE
Browse practical security guidance.
All materials below are clearly marked drafts until final publication.

Microsoft 365 security hardening
A practical review of identities, administration, sharing and device access.
Publication link will be added when complete.
Ransomware readiness checklist
Questions for protection, isolation, backups and recovery dependencies.
Publication link will be added when complete.
Loi 25 technical safeguards
A calm technical view of identity, endpoint, backup and evidence controls.
Publication link will be added when complete.
Backup and recovery validation
Map covered systems, backup health, restore history and operational gaps.
Publication link will be added when complete.
Phishing and account compromise
Recognize the signals and coordinate a structured first response.
Publication link will be added when complete.
Incident response planning
Structure contacts, decisions, evidence and recovery responsibilities.
Publication link will be added when complete.
Securing remote work
Connect people, devices, identities and cloud services without excess complexity.
Publication link will be added when complete.
Audit-readiness evidence
Organize recurring status, exceptions, actions and recovery evidence.
Publication link will be added when complete.TOOLS & LEARNING
Useful materials are being prepared for responsible publication.
Loi 25 gap review
Draft — no download yetIncident-response worksheet
Draft — no download yetEmployee awareness poster
Draft — no download yetPassword policy starter
Draft — no download yetVendor-security review
Draft — no download yetRansomware readiness for small organizations
A practical session is being scoped. No date or registration is published yet.

RESPONSIBLE PUBLICATION
Useful guidance should be accurate, scoped and ready to apply.
CyberQC resources are prepared as working material first, then reviewed before a live destination or download is published.
- Start with a concrete operating question
- Separate general guidance from environment-specific advice
- Review claims, links and bilingual terminology
- Publish only when the destination is complete
- 01Draft
- 02Review
- 03Localize
- 04Publish

FAQ
Questions, answered clearly.
Defined scope and realistic expectations are part of good security.
Is this legal advice?
No. CyberQC resources focus on technical security and operational practices. Consult qualified legal or privacy advisors for legal conclusions.
Do checklists guarantee security?
No. They organize a review, but actual risk depends on implementation, monitoring, people, data and threats.
What should Microsoft 365 users review first?
Start with account protection, MFA, privileged administration, device access, external sharing and backup.
Can CyberQC implement the recommendations?
Yes. A Strategy Call can translate the relevant recommendations into a managed plan or scoped intervention.
A PRACTICAL NEXT STEP
Turn security knowledge into an operating plan.
A checklist is a useful start. A managed monthly process is what turns recommendations into a security program.
