HireACISO

SickKids gets hit through somebody else's software

August 25, 2026. From issue 3 of The Compliance Brief, one story for founders and executives who own security.

Last reviewed 2026-08-25Written by Jacob Masse, TrazTech Inc.

Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. One of its 5 stories bears on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: BleepingComputer

Toronto's Hospital for Sick Children disclosed a security incident that exposed personal information belonging to some current and former employees and job applicants. The hospital attributes the exposure to a flaw in third-party software.

Our take, in short

Read that reporting from the other side of the contract, because in a story like this you are the third-party software. Your notification clock, your evidence obligations and your willingness to be named are set by whatever your MSA says today, and most Canadian SaaS contracts I read are vague on all three.

Read the full take on traztech.ca

Also in issue 3

Outside breaches, incidents and security leadership, but in the same email:

Older: issue 1 All issues on HireACISO Newer: issue 4