For Canadian boards, owners and executives
The questions arrive long before the incident does
A customer sends a security questionnaire. An insurer asks what has changed since last renewal. A director wants to know whether anybody checked the AI tool before it was switched on. None of these are technical questions. All of them need an answer somebody outside your business will believe.
Will not sign until the questionnaire comes back clean.
Prices the renewal on what you can show, not what you say.
Carries the duty, and is the last to find out.
Two Canadian laws most businesses have not read
You are already required to do more than you think
The federal privacy law
It governs personal information handled in the course of commercial activity across most of Canada.
What it actually asks of you: keep a record of every privacy breach, including the ones you decided were harmless, for two years, and produce them for the Privacy Commissioner on request. Where a breach creates a real risk of significant harm, report it and tell the people affected as soon as feasible.
Most Canadian businesses keep no such record at all.
The one that already covers AI
Canada has no AI Act. Quebec did not wait for one.
What it actually asks of you: since September 2023, if a decision about a person is made exclusively by automated processing, you must tell them. On request you must say what personal information you used and the reasons and main factors behind it, and let them put their case to a human who is in a position to change the answer.
That describes a great deal of what companies are currently calling AI.
Neither of these needs a new law to reach you. They are in force today.
27 August 2026
The window they are describing is a governance window
116 companies and organisations, among them OpenAI, Anthropic, Google, Microsoft, Amazon and Oracle, signed a joint letter warning that AI-enabled attacks will become far more widespread and sophisticated within months. Their instruction to every other organisation was short: fix your vulnerabilities, modernise the systems you have been putting off, and put AI to work on defence.
It is good advice, and most Canadian mid-market businesses cannot act on it. Not for want of tools, but because nobody owns the question of which vulnerabilities, ranked how, signed off by whom, at the expense of what else. A risk measured in months does not wait for an organisation that needs three months to decide who decides.
What we do
Five ways in. Every one ends with something your board can act on.
AI Deployment Review
Before you switch it on: what the deployment would actually expose, the oversight you need around it, and whether Quebec's Law 25 automated decision rules reach you.
From $6,000Board & executive session
A facilitated half-day, and the evidence pack that proves it happened.
From $4,500Cyber simulation
Find out what your people do before it matters. Nothing goes near live systems.
From $5,000Virtual CISO
Senior security judgement without the hire, and someone accountable for it.
From $3,500 / monthIndependent assessment
A dated report against a defined control set that you can hand to a customer or an insurer.
Typically $6,000–$9,000Before you talk to anyone
Where do you stand?
Ten questions about whether you could show it, not whether you feel secure. Five minutes, no email required, and nothing you answer leaves your browser. You get the gaps back in the order we would fix them.
No mystery scoring
The control set, published in full
Thirty-six governance controls, what evidence satisfies each one, and what it maps to in Canadian law. We publish it so you can see what is being asked of you before you engage us, or work through it yourself if you would rather not.
Free, and nothing to sign up for
Where to watch
The five sources worth following if you are accountable for this in a Canadian organisation, and the board question that goes with each. Canadian regulators first, one international source, no newsletter.
Recognise any of these
What bad looks like
The seven failures we keep finding in Canadian organisations — the supplier nobody assessed, the account with no second factor, the backup nobody restored. Written as patterns rather than named companies, with the question a board should ask about each one.
Why anyone believes our answer
We either help you fix it, or we assess you. Never both.
An assessment is only worth something if the person doing it has no stake in the result. If we have designed your controls or written your policies, we will not then turn round, assess you and tell the world you passed.
It costs us work. We think that is the point.
Latest blog news
Keep up to date with the latest news and Views from Canada Cyber-Safe Team
Start with a conversation
Tell us what has been asked of you and who is asking. We will tell you what we think it needs, and whether that is us. The first conversation is free and there is no obligation at the end of it.
Tell us about your organisation+1 647 361 2215
Canada Cyber-Safe is based in Toronto. We work with Canadian organisations only.