HireACISO

Ottawa is looking at how a breach was disclosed, not only how it happened

September 29, 2026. From issue 8 of The Compliance Brief, 2 stories for founders and executives who own security.

Last reviewed 2026-09-29Written by Jacob Masse, TrazTech Inc.

Issue 8 of The Compliance Brief went to subscribers on September 29, 2026. 2 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: The Record

Canada's federal privacy regulator opened an investigation into IDScan following a data breach. The probe covers the company's security practices and, separately, whether the notifications sent to affected individuals met the requirements of the federal private-sector privacy law.

Our take, in short

Notification adequacy being named as its own line of inquiry is the detail to take away. Almost every incident response plan I review has a solid technical section and two vague sentences about telling people, with no template, no owner and no defined clock.

Read the full take on traztech.ca

A stolen OAuth token from a former employee's laptop

Source: Dark Reading

CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. The token used was an OAuth token stolen from a former employee's computer through the TanStack npm supply chain compromise earlier this year.

Our take, in short

Offboarding at most companies this size disables the account and stops there, leaving OAuth grants, personal access tokens and CI credentials alive behind it. Pull the list of third-party OAuth apps authorised against your GitHub organisation this week and see how many you recognise.

Read the full take on traztech.ca

Also in issue 8

Outside breaches, incidents and security leadership, but in the same email:

Older: issue 7 All issues on HireACISO