2026-07-15
Added · Updated
The Canadian Securities Administrators (CSA) published Staff Notice 33-322 following a compliance examination of 73 registered firms, identifying gaps in cybersecurity practices and providing updated guidance. The notice outlines expectations for robust cybersecurity policies, employee training, risk assessments, third-party oversight, and incident response planning tailored to firm size. Registered firms are expected to review the guidance, assess their current practices against identified gaps, and take proactive steps to strengthen their cybersecurity frameworks.