The Canadian Securities Administrators (CSA) has published Staff Notice 33-322, Review of Registered Firms' Cybersecurity Practices and Additional Guidance, following a compliance examination of 73 registered firms' cybersecurity practices. The examinations covered cybersecurity policies and procedures, employee training, risk assessments and controls, oversight of third-party service providers, and incident response planning. The CSA found that a number of firms, particularly larger ones, had robust cybersecurity frameworks in place, but also identified gaps where firms could strengthen their practices. Compliance feedback has been provided to the relevant firms to address the findings, and the notice sets out scalable guidance intended to apply to firms of all sizes, recognizing that cybersecurity risks and resources vary across registrants. Stan Magidson, CSA Chair and Chair and CEO of the Alberta Securities Commission, said the CSA wants to be clear with registrants that strong cybersecurity practices are not optional in today's threat environment. "Our guidance is intended to help firms establish and maintain cybersecurity practices that are appropriate to their size and operations, and are responsive to an evolving threat landscape," he said. Magidson added that cybersecurity risks continue to grow on many fronts as firms rely more heavily on digital tools, hybrid work arrangements, and online platforms to serve clients, and that while the examinations found many firms have frameworks in place, they also identified areas where some firms could strengthen their practices. Staff expect firms to have cybersecurity practices relevant to their business and are encouraging registrants to review the notice and assess whether their own practices can be strengthened. The CSA's findings land alongside a wider push across Canadian financial regulators to tighten cyber expectations, one that increasingly touches the insurance sector directly. The Office of the Superintendent of Financial Institutions, which regulates federally regulated insurers alongside banks, has its own Guideline
CSA <b>cybersecurity</b> review finds gaps at registered firms, issues updated guidance
Read the original article
insurancebusinessmag.com →