TrustCenter

SickKids gets hit through somebody else's software

August 25, 2026. From issue 3 of The Compliance Brief, 2 stories for Canadian companies answering customer security reviews.

Last reviewed 2026-08-25Written by Jacob Masse, TrazTech Inc.

Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. 2 of its 5 stories bear on security reviews, vendor diligence and trust, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: BleepingComputer

Toronto's Hospital for Sick Children disclosed a security incident that exposed personal information belonging to some current and former employees and job applicants. The hospital attributes the exposure to a flaw in third-party software.

Our take, in short

Read that reporting from the other side of the contract, because in a story like this you are the third-party software. Your notification clock, your evidence obligations and your willingness to be named are set by whatever your MSA says today, and most Canadian SaaS contracts I read are vague on all three.

Read the full take on traztech.ca

Defence contractors do not believe their own CMMC scores

Source: Infosecurity

US defence contractors are reporting doubts about the accuracy of their own self-assessment scores under CMMC Phase I. Those scores have reached an all-time high at the same time.

Our take, in short

Self-scoring drifts upward when there is money attached, which is the whole reason assessment phases exist. For Canadian firms this matters twice: if you subcontract to a US prime your inflated score becomes their problem in an audit, and CPCSC is arriving with the same structure at home.

Read the full take on traztech.ca

Also in issue 3

Outside security reviews, vendor diligence and trust, but in the same email:

Older: issue 1 All issues on TrustCenter Newer: issue 4