When cybersecurity becomes a competitive advantage
This project effectively demonstrates how a cybersecurity culture can transform a vulnerable SME, exposed to cyber threats and non-compliance risks, into a resilient and proactive organization capable of protecting its sensitive data while strengthening the trust of its partners and clients.
Sector
Tourism industry.
Challenge
An IT infrastructure vulnerable to cyberattacks.
An IT infrastructure vulnerable to cyberattacks, requiring the adoption of a strong cybersecurity culture. Discover the strategic challenges of cybersecurity for Quebec businesses.
Solutions
Implementation of comprehensive protection to transform a high-risk environment into a secure and resilient system.
Results
Within a few months, the organization implemented a cybersecurity culture, achieved compliance with Law 25, and stopped an incident in real-time thanks to the vigilance of our experts.

Vulnerabilities impossible to ignore
With the arrival of new requirements under Law 25, a major player in Quebec’s tourism sector realized that its IT infrastructure had serious flaws, compromising the security of its sensitive data.
Major cybersecurity challenges
- Employees with low awareness of phishing risks.
- Faulty access control, exposing confidential files.
- Lack of continuous monitoring for IT threats.
- Incomplete compliance with Law 25 requirements.
- High reputational risk in case of a security incident.
Impacts in case of a cyberattack
- Loss of credibility with government institutions and partners.
- Significant penalties for non-compliance with Law 25.
- High risk of sensitive data leaks.
Thanks to Grav-ITI’s support, we were able to structure our work environment while strengthening our cybersecurity. The deployment of continuous training and phishing tests allowed us to equip our employees and implement a true security culture. Today, security is an integral part of our practices, and we are fully compliant with Law 25.
Solutions implemented by our experts
The organization decided to structure its cybersecurity strategy to better protect its critical assets. The first step was to start with a structured IT audit.
Deployment of Sentinelles
To secure the organization’s IT infrastructure, our experts implemented Sentinelles, our cybersecurity solution designed to offer proactive protection tailored to the needs of SMEs.
- Continuously monitor suspicious activities on servers (24/7)
- Strengthen authentication with mandatory MFA
- Effectively control access to critical systems
Employee awareness
Users represent the first line of defense against cyberattacks. To reinforce good practices and encourage constant vigilance, we implemented a continuous training program adapted to the organization’s challenges.
- Quarterly phishing simulations
- Interactive training adapted to the challenges of the tourism sector
- Performance reports to adjust practices and strengthen team resilience.
Compliance with Law 25 and response to cyberattacks
To minimize the impact of potential security incidents and meet regulatory requirements, we have:
- Deployed the necessary measures for compliance with Law 25.
- Developed a disaster recovery plan (DRP).
- Implemented rapid intervention protocols in case of intrusion.
- Integrated an access logging and traceability policy.
The result? A secure IT environment
Since the deployment of Sentinelles, the results are tangible! Employees are now more aware of phishing risks, and the cybersecurity culture is now well-established, valued at all levels of the organization.
reduction in phishing-related incidents
unauthorized access blocked
Workstations protected
An attack thwarted in less than 2 minutes!
It all starts with an email, seemingly innocuous. An official, well-worded request sent to an employee of the organization.
But this time, the phishing attempt did not go unnoticed. Thanks to recurring training, the aware employee quickly spotted the fraud attempt and reported it.
Less than two minutes later, our team neutralized the cyberattack before it could reach the organization’s systems.
This simple reflex, made possible by a well-established cybersecurity culture, saved the organization a lot of headaches.

Are you ready to secure your IT infrastructure?
Thanks to the support of our experts, our client not only secured their sensitive data but also implemented a true internal cybersecurity culture.
This project demonstrates that with a personalized approach and human support, it is possible to build an effective cybersecurity strategy capable of supporting your compliance and the growth of your business.
Are you ready to protect your SME? Contact our experts for a free consultation.