CSA Flags Cybersecurity Gaps in Canadian Securities Firms
Event summary
- CSA examined 73 registered firms' cybersecurity practices in July 2026, identifying gaps despite robust frameworks at larger firms.
- Notice 33-322 provides updated guidance to help firms strengthen cybersecurity frameworks across all sizes.
- Stan Magidson (CSA Chair) emphasized that strong cybersecurity is non-negotiable amid evolving digital threats.
- Examinations covered policies, employee training, risk assessments, third-party oversight, and incident response planning.
The big picture
The CSA's findings reflect growing regulatory scrutiny on cybersecurity in financial services, particularly as digital transformation accelerates. While larger firms show stronger frameworks, smaller registrants face resource challenges in meeting evolving threats. This guidance underscores the need for tailored, scalable solutions across Canada's capital markets.
What we're watching
- Regulatory Enforcement
- How the CSA will monitor firms' responses to identified gaps and whether follow-up actions escalate.
- Cybersecurity Investment
- The pace at which smaller firms adopt scalable cybersecurity measures amid resource constraints.
- Threat Landscape Evolution
- Whether hybrid work and digital tool reliance will further strain firms' cybersecurity frameworks.
Related topics
