Skip to content

Security for portfolio managers and dealers

You hold client wealth, identity documents and the authority to move money — under a regulator that already asks what you do about cyber security.

What it actually looks like when it happens

A phishing email went to everyone at an Alberta wealth management firm. One person opened it, and the attacker took the client contact file — names, social insurance numbers, account numbers, and each client's assets under management. 767 people were affected. As for how long it takes anyone to notice: at another Alberta firm an advisor clicked a link in December and nothing happened until February, when the mailbox began sending phishing mail to clients. A client told them.

Read both decisions, and what was taken →

Documented cases at portfolio managers

Cases →

Anyone on the internet can send an email that looks exactly like it came from your firm — 69% of Canadian portfolio managers with a website publish nothing that tells a receiving mail server to refuse it. This is the exposure your regulator already asked about — from 2026, your CCO personally certifies your firm’s cybersecurity answers.

It is one of the first things the free Snapshot checks — from the outside, nothing to install.

See what we’d find on your domain — get the free Security Snapshot →

The controls they check for

The rulebook below says what you owe. It does not say what to have. Your insurer does — in writing, on the form you fill in before it will quote you. These four come up on every one of them, and putting them in and keeping them there is most of what the retainer is.

Multi-factor authentication, enforced

Not offered — enforced, and separately on each of email, remote access and privileged accounts. It is the first control on the Canadian questionnaire and the one an insurer is most likely to check after a claim.

An Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. The rollout had started; it had not finished.

Backups you have restored from

At least weekly, covering all sensitive or business-critical data, and held where an intruder inside your network cannot reach them. A backup nobody has restored from is an assumption, not a control.

Patching what faces the internet

Anything reachable from outside — the mail service, the remote-access gateway, the portal — carries known, published weaknesses within days of their disclosure. Insurers ask whether you actively manage and install critical patches across those systems.

An incident-response plan you have tested

Who is called, in what order, with what authority to disconnect something. Written down and rehearsed before the morning you need it, not drafted during it.

And the one no form asks about: knowing it happened at all. Most of the duties below start running when you find out — and in almost every case we document, no system caught the intruder; the firm learned of it from someone else, weeks or months later. Cases →

Our Service →

What you are already required to do

Ontario Securities Commission · CIRO

If you cannot show the evidence behind Question G10, a named officer has already certified answers your firm cannot support.

The rule Who it binds If you don’t Source
The cybersecurity question is asked directly Every OSC-registered firm Your answer is on record with the regulator OSC 2026 Risk Assessment Questionnaire, general section
And an officer certifies it personally The Chief Compliance Officer A named individual attests to the answers OSC — advance notice of the 2026 Risk Assessment Questionnaire
Dealers also have a clock — three days from discovery CIRO Dealer Members only Report in three days; full investigation report in thirty
Binds Dealer Members. Firms registered only as advisers are not caught by this rule.
CIRO — amendments respecting mandatory reporting of cybersecurity incidents (archived; ciro.ca blocks automated retrieval)
Cyber insurance is not required of registrants Registered firms It is encouraged, not mandated — so say so CSA Staff Notice 33-322
You are expected to vet the firms you rely on Registered firms using third-party vendors or service providers A staff expectation, evidenced by what your peers already do
Survey of registrants, 2017 — sent to over 1,000 firms, 63% responded. Cited from the Saskatchewan FCAA copy because osc.ca blocks automated retrieval of the PDF.
CSA Staff Notice 33-321 — Cyber Security and Social Media
Report a breach that could seriously harm someone Every organisation subject to PIPEDA Knowingly failing to report is an offence under PIPEDA s.28 — a fine of up to $10,000 on summary conviction, or up to $100,000 as an indictable offence. The same section covers the record duty below. PIPEDA s.10.1(1) — report to Commissioner
Notify the people affected Every organisation subject to PIPEDA The duty is separate from reporting to the regulator, and it applies whether one person is affected or a thousand. Privacy Commissioner of Canada
Keep a record of EVERY breach for two years Every organisation subject to PIPEDA Most firms keep none. It applies whether or not anything was ever reportable, so a regulator’s request finds a gap that cannot be filled retroactively — and knowingly contravening it is the same s.28 offence. Breach of Security Safeguards Regulations, s. 6(1)
Make those records good enough to audit Every organisation subject to PIPEDA A record that does not show how you assessed the risk does not discharge the duty — the regulator has to be able to check your reasoning, not just see a log entry. Privacy Commissioner of Canada
Satisfy your insurer before you need to claim Any firm that wants cyber cover A condition you have not met is a claim your policy may refuse — an Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. Coalition Insurance Solutions Canada — cyber questionnaire
Answer your client’s regulator, not just your own Any firm holding a federally regulated client’s data A firm that cannot answer a third-party risk assessment is a firm its regulated clients now have to explain — which is a procurement problem long before it is a security problem. OSFI — Guideline B-10, Third-Party Risk Management (in force 1 May 2024)
QUESTION G10 – CYBERSECURITY… (A) Does your firm do any of the following? Check all that apply.

OSC 2026 Risk Assessment Questionnaire, general section

Most of these start running the moment you find out — which is the whole reason the date you notice matters as much as the breach itself. The rest are conditions you meet beforehand: what your insurer asks before it will quote you, and what your regulated clients are now required to verify about you.

We checked NI 31-103 and its companion policy and found no cyber obligation on advisers. The three-day rule is a Dealer Member rule. We say which is which because this is the one audience that knows precisely which category it holds.

Could you start the three-day clock on time?

No cost, no obligation — you keep the findings either way.

  1. Tell us your domain

    One short form. No access to your systems, no software to install.

  2. We look from the outside

    Passive, publicly observable checks only — the same view an attacker gets.

  3. You get one page

    Your top findings in plain English — one page, no meeting required.