The Canadian Securities Administrators (CSA) have published CSA Staff Notice 33-322 Review of Registered Firms’ Cybersecurity Practices and Additional Guidance (The Staff Notice).
The Staff Notice follows a focused compliance examination sweep of 73 registered firms’ cybersecurity practices and sets out observed practices, identified gaps, and updated guidance to support firms in strengthening their cybersecurity frameworks.
The examinations covered a range of areas, including cybersecurity policies and procedures, employee training, risk assessments and controls, oversight of third-party service providers and incident response planning.
Overall, the CSA found that of the firms examined, particularly the larger firms, had robust cybersecurity policies and procedures. However, the CSA also identified gaps where firms could strengthen their cybersecurity practices. Compliance feedback has been provided to relevant firms for them to address the findings. In addition, the Staff Notice aims to provide practical, scalable guidance to firms of all sizes – including small and medium-sized firms – recognizing that cybersecurity risks and resources vary across registrants.
CSA staff advise that they expect firms to have robust cybersecurity practices in place that are relevant to the firm’s business. Registered firms are encouraged to review the notice and assess whether their cybersecurity practices can be strengthened, considering their current operations.
CSA Staff Notice 33-322 Review of Registered Firms’ Cybersecurity Practices and Additional Guidance is available for download from the websites of the participating jurisdictions.
For more information, please call Barbara Hendrickson at BAX Securities Law (647) 403-4606.
This publication is not intended to constitute legal advice. No one should act on it or refrain from acting on it without consulting with a lawyer. BAX does not warrant or guarantee the accuracy or currency or completeness of the publication. No part of this publication may be reproduced without the prior written permission of BAX Securities Law.