Five points. One page. No jargon.
Most awareness material is written for the people who already care. These are written for everyone else — the person who is about to reply to an urgent message from someone claiming to be the CFO. Print them, pin them by the kettle, drop them into an all-staff email or a Teams channel. They are free, there is nothing to fill in, and we do not ask who you are.
AI-powered scams: pause, check, protect
Voices can be cloned, writing styles can be copied, and the message naming your finance director may not have come from your finance director. The instruction staff actually need is not technical: slow down, and confirm the request a second way before acting on it.
- Why urgency, authority and emotion are the warning signs
- Confirming an unusual request through a channel the sender did not choose
- What must never be pasted into a public AI tool
- Reporting quickly, without fear of being blamed
PIPEDA: handle personal information with care
No member of your staff is ever going to read PIPEDA. This is the part of it that touches their day: what they may collect, who they may pass it to, and what to do in the first ten minutes after something goes to the wrong person.
- Collecting only what a clear, stated purpose needs
- Consent that is meaningful rather than buried
- Not reusing information for a purpose nobody approved
- Reporting loss, wrong recipients and unauthorised access straight away
Quebec Law 25: privacy by default
If you hold information about people in Quebec, Law 25 reaches you whether or not you have an office there. It is stricter than PIPEDA in the places staff touch daily: settings start closed, privacy is consulted before the project ships, and every confidentiality incident gets reported.
- Privacy by default, and access only where the role requires it
- Bringing in the privacy officer before new technology or a transfer outside Quebec
- Handling access, correction, withdrawal and portability requests
- Reporting every confidentiality incident, not only the serious ones
Strong passwords, safer accounts
Weak and reused passwords are still how most account takeovers start, and no amount of policy fixes a password that also unlocks someone’s personal email. This is the version of the advice that people can act on without being told off first.
- Length beats complexity — four unrelated words, fifteen characters or more
- Why one breach anywhere should not unlock everything
- Using an approved password manager rather than a notebook
- Multi-factor codes are never shared, and unexpected prompts get rejected
- When a password actually needs changing, and when it does not
Need one we have not made yet?
Tell us the behaviour you are trying to change — passwords written on desks, invoices paid without a second check, files shared out of the wrong folder — and if it is a problem other Canadian organisations share, we will make the poster and put it here free.
We build them in English and French. No charge, and you do not have to be a client.
Suggest a posterFree to use, in your name
Print them, email them, put them on the screen in reception. You do not need to credit us and you do not need to ask. The only thing we ask is that you do not resell them or present them as a product of your own. If you would rather they carried your logo alongside ours, say so and we will send you that version at no charge.
A poster is awareness. It is not a control.
The first poster tells staff to use only approved AI tools. Most organisations have never written down which tools those are — so the poster asks a question the business cannot yet answer. Our AI acceptable use policy template answers it, and the control set shows where awareness sits among the thirty-six things a Canadian board is expected to be able to evidence.