Cyber Security Blog

OSFI Guideline B-13

As financial institutions become increasingly dependent on digital technologies, cloud computing, third-party service providers, and interconnected systems, technology risk has become one of the most significant challenges facing the financial sector. Cyberattacks, system outages, operational disruptions, ransomware incidents, and third-party failures can have severe financial, operational, and reputational consequences for organizations while also impacting customers and the broader financial system.   To address these growing risks, regulators...

Read More
NIS2

Detecting a cyber security incident is only the first step. Under NIS2 incident reporting requirements, organizations must also determine whether the incident is reportable, notify the appropriate authority within strict timelines, and continue providing updates as investigations progress.   Meeting these obligations requires more than knowing the reporting deadlines. Security, IT, compliance, legal, and management teams need clear processes for classifying incidents, coordinating investigations, gathering evidence, and...

Read More
OECD AI Principles

Artificial Intelligence (AI) is transforming industries at an unprecedented pace. From healthcare and finance to manufacturing, retail, and government services, AI is helping organizations automate processes, improve decision-making, and unlock new opportunities for innovation. However, as AI becomes more powerful and widespread, it also introduces significant challenges related to transparency, fairness, accountability, privacy, security, and human rights.   Organizations today are under increasing pressure to ensure that...

Read More
NIS2

Cyber security risk management used to mean updating an Excel tracking sheet once or twice a year, taking a few screenshots of your cloud setup, and emailing back and forth with external auditors.   Under the NIS2 Directive, that approach is no longer viable.   The Directive mandates proactive, risk-proportionate cyber security measures, backed by strict management oversight and rapid incident reporting. When auditors or national authorities evaluate your...

Read More
National AI Risk Management Framework

Artificial intelligence is transforming industries at an unprecedented pace. Organizations are using AI to automate operations, improve customer experiences, strengthen decision-making, detect fraud, optimize supply chains, and accelerate innovation. While these technologies create enormous opportunities, they also introduce new risks that traditional governance and cyber security programs were never designed to address.   AI systems can generate biased outcomes, expose sensitive information, make decisions without transparency, introduce...

Read More
Digital Operational Resilience Act DORA

Financial institutions rely on cloud providers, software vendors, managed service providers, payment processors, and other ICT partners to deliver critical services. While these relationships support innovation and operational efficiency, they also introduce risks that can affect business continuity, cyber security, regulatory compliance, and customer service.   DORA places significant emphasis on ICT third-party risk management and requires financial institutions to establish controls throughout the vendor lifecycle. Organizations...

Read More