Hey there, this week's edition has a theme, and it's not subtle: patching. A record-breaking IBM breach report, two separate SharePoint flaws exploited in the same month, and a bug with no fix at all all trace back to the same root cause: software that didn't get updated fast enough. On the AI side, the rulebook for business AI use just got a lot thicker, on both sides of the Atlantic. Let's get into it.
🗞️ STORY OF THE WEEK
The Average Data Breach in Canada Just Hit a Record $7.11 Million
IBM's annual Cost of a Data Breach report landed this week, and the number for Canadian organizations is the highest it's ever recorded: an average of $7.11 million per breach. That's not a hypothetical. It's the measured, real-world cost of forensic investigators, lawyers, regulatory fines, lost business, and the long slog of rebuilding customer trust after something goes wrong.
Two other numbers in the report explain why the total keeps climbing. The average breach now takes 205 days to fully contain, nearly seven months of a company living with an active security incident. And the average breach now exposes 28,500 records, up 8% from last year. Bigger breaches that take longer to fix cost more money: not a complicated equation, but a brutal one.
There's a bright spot buried in the data, though. Organizations that used AI extensively in their security operations, for things like spotting unusual activity or automating parts of incident response, cut their average breach cost by about $3.41 million compared to those that didn't. That's not a reason to buy AI tools blindly, but it is a reason to ask what "AI-assisted detection" actually looks like for a business your size.
Why it matters to you: For a small business, a $7.11M breach isn't a rounding error. It's existential. Most SMBs don't have the cash reserves to absorb a breach that size, which is exactly why breach costs are becoming a business continuity question, not just an IT one. Ask yourself: if we had an incident tomorrow, could we actually afford six-plus months of cleanup?
What you can do right now: This week, ask your IT provider or managed security partner one direct question: "What would our first 72 hours look like if we had a breach, and do we have cyber insurance that would actually cover it?" If you don't have a clear answer, that's your starting point.
⚡THE RIPPLE EFFECT - Three stories, and what they actually mean for your business
A Widely Used Coding Library Has No Fix, and Hackers Already Know It
A component called Fastjson, buried inside many business applications built on Java, has a serious flaw that lets attackers break in without needing a password. There's no patch (the software is officially discontinued), and confirmed victims already include organizations in Canada, the US, and Singapore. Federal cybersecurity agencies are treating it as urgent.
What it means for you: If your business runs custom or older Java-based software, ask your developer or IT vendor this week whether Fastjson is buried inside it. Since there's no patch, the only fix is a workaround or migration.
Microsoft SharePoint Has Been Hit Twice in One Month
SharePoint, Microsoft's document-sharing platform, had two separate serious flaws actively exploited by hackers in July alone: one let attackers steal long-term access to servers, and a second, patched just this week, lets attackers escalate their access without even logging in. Microsoft has fixed both, but only for organizations that install the updates.
What it means for you: If your business runs its own SharePoint server (rather than Microsoft's cloud version), confirm with IT that July's security updates are installed. This is exactly the kind of opening ransomware crews look for.
The Rules for Business AI Use Are Multiplying Fast
Europe's major AI law formally took effect this month, and in the US, 19 new AI-related laws passed across states and Congress in a single two-week stretch in June. A new US executive order can now require advance government notice before certain powerful AI systems are released. The takeaway: "wait and see" is no longer a safe AI governance strategy.
What it means for you: If your business uses AI tools anywhere (HR, customer service, marketing), start a simple list of what you use and where your customers' data lives, so you're ready when a rule lands that applies to you.
40%
Undisclosed ransomware attacks (the ones that never make headlines or a regulatory filing) rose 40% year-over-year in Q2 2026. The breaches you read about in the news are only a fraction of what's actually happening; most ransomware attacks on small and mid-sized businesses never become public.
✅ ONE THING TO DO THIS WEEK
Do a 10-Minute Patch Check With Your IT Provider
Three of this week's biggest stories (the SharePoint flaws, the Fastjson bug, and a separate flaw in a popular AI-powered business platform) all boil down to the same root cause: software that wasn't patched fast enough. Attackers usually aren't hacking anyone in the clever, movie-plot sense; they're reading the same patch notes IT teams get, then racing to hit anyone who hasn't applied them yet.
This week, send one email to whoever manages your IT, whether that's an in-house person or an outside provider, and ask: "Are we current on all critical security patches as of this week, and how do we know?" It's a simple question, but you'd be surprised how often the honest answer is "not sure."
Most breaches don’t start with a genius hacker. They start with a patch nobody got around to installing.
📌 QUICK BITES
A major beverage company's dairy subsidiary landed on a ransomware gang's leak site. The Anubis ransomware group claimed it breached Fairlife, Coca-Cola's dairy production arm, part of a wider ransomware wave running about 20% above last year's pace. If your business shares systems or data with suppliers or subsidiaries, it's worth checking how well-separated those connections really are.
Canadian law enforcement took down ransomware infrastructure this week. It's a good reminder that domestic enforcement action is happening, and reporting an incident promptly can genuinely help investigators trace and disrupt these networks, not just create paperwork.
A popular business platform's AI features had a serious security hole, and criminals found it fast. Within days of the vendor shipping a fix for a flaw in its AI-powered service platform, attackers were already exploiting it on systems that hadn't updated yet. If your business uses this kind of platform for IT or HR workflows, confirm with your provider that you're on the latest version.
US regulators want mandatory guardrails for AI that takes actions on its own. A new push from US Homeland Security officials would require businesses using "agentic" AI (tools that can act autonomously, not just answer questions) in critical systems to document human-oversight procedures. If you're piloting AI agents anywhere in your operations, start writing down how a human can step in and override them.
💬 PARTING THOUGHT
Every story this week has the same quiet lesson underneath it: resilience isn't about being unhackable, it's about being current. The businesses that got hurt this month weren't the ones with the most sophisticated attackers. They were the ones a patch or two behind. That's a solvable problem, and a far less intimidating one than "stop a nation-state hacker."
The same goes for the AI rulebook piling up on both sides of the border. You don't need to master every new law the moment it passes. You just need a simple, current list of where AI touches your business, so you're never caught flat-footed when a rule finally applies to you.
Small, boring habits (patch checks, a running list, one good question to your IT provider) are what actually keep businesses out of next year's breach report.
See you next Friday and stay
TryberResilient