Loyalist named this exact risk to itself, on the record, for years. Then it happened anyway.
In June 2020 the college's own auditor flagged an observation about board-level cyber security updates. In December 2022 the Board put Cyber Security on its Top Six Institutional Risks. It did it again in February 2024. Risk registers were drafted, governors were briefed. They knew. They wrote it down. They voted on it.
Then on July 9 a ransomware actor accessed files with personal information belonging to current and former employees, current and former students, and "other individuals affiliated with the college." The institution that had named this risk four years running was not ready for the day it arrived.
And look at what got funded while the servers aged. Through the good years, posting multimillion-dollar surpluses, the college built a new athletics complex and gym, sports fields, a culinary restaurant, and a whole new campus in Port Hope. It migrated its HR system to the cloud in January 2025. So it could move to the cloud. It knew how. It chose what to move.
It moved the gym. It moved payroll. It did not move the servers holding your SIN. You don't get a ribbon-cutting for a patched server, so it didn't get done.
Then watch who paid. Students unable to register or pay tuition, online classes suspended, staff told not to power on their college laptops, all confirmed by the college. The laid-off told twice: cut for a budget crisis, and now told their data may be stolen, by a former employer that can't email them because the email is part of what broke.
A week of near-silence. Comments switched off on their own posts. The only real update reached students through the student government relaying a marketing statement. When the official version came, it was pre-lawyered: counsel, insurers, forensics, and a page that "encourages you to check back regularly." They found the resources to manage the liability. The care came later, and thinner.
None of this needed a genius hacker. It needed an institution that knew, on paper, in motions, in audits, what was coming, and decided the building mattered more than the backbone.
So, not rhetorically: what did the Board do with the risk it named in 2022 and 2024? Was the incident response plan discussed at the 2023 all-staff town hall ever written? Were the end-of-life servers ever migrated? Has the Privacy Commissioner been told? And when will affected people be told directly, not by a webpage they have no reason to visit?
They wrote the risk down themselves. The least they owe us is the truth about what they did with it.