The Canadian Securities Administrators (CSA) has announced the release of a staff notice detailing the findings of a recent targeted compliance examination sweep of organizations’ cybersecurity practices and updating the regulator’s guidance for organizations to improve their cybersecurity frameworks.
“Cybersecurity risks continue to grow on many fronts, particularly as firms rely more heavily on digital tools, hybrid work arrangements and online platforms to serve clients,” said Stan Magidson, the CSA chair and the Alberta Securities Commission’s chair and chief executive officer, in a news release.
“CSA Staff Notice 33‑322 Review of Registered Firms’ Cybersecurity Practices and Additional Guidance” goes over the cybersecurity practices, policies, and procedures that the CSA observed during its examinations of organizations.
Covering 73 registered firms, the examinations also looked into employee training, risk assessments and controls, oversight of third-party service providers, incident response planning, and gaps, among other areas relevant to cybersecurity.
CSA’s overall findings
In its news release, the CSA made the following overall observations regarding the organizations examined:
- Multiple organizations, especially bigger ones, had robust cybersecurity policies and procedures
- Even for organizations with cybersecurity frameworks implemented, there were still areas for improvement
“While our examinations found that many registered firms have cybersecurity frameworks in place, they also identified areas where some firms could strengthen their practices,” Magidson said in the news release.
The CSA gave compliance feedback to allow organizations to respond to the findings.
“The CSA wants to be clear with registrants that strong cybersecurity practices are not optional in today’s threat environment,” Magidson said.
Guidance for organizations
Apart from the tailored feedback provided, the CSA also offered guidance intended to be practical and scalable for small and medium-sized firms and other organizations.
The guidance aims to acknowledge that different registered firms face varying cybersecurity challenges and have different levels of resources.
“Our guidance is intended to help firms establish and maintain cybersecurity practices that are appropriate to their size and operations, and are responsive to an evolving threat landscape,” Magidson said in the CSA’s news release.
The CSA expressed that it expects organizations to review the notice and the updated guidance, analyze their own cybersecurity practices, ensure that they implement practices that are robust and relevant to the business, find potential deficiencies, and act proactively to fill the gaps and fortify their frameworks, taking into account their current operations.
Enjoy this story? Read the latest technology news on the main page!

