Independent cyber and AI governance for Canadian boards and owners

Assessments, AI deployment reviews and vendor due diligence — for boards that must show they looked, and for owners who have nobody to ask. We never sell the fix, which is what makes the findings hold up.


help@cyber-safe.ca
Where do you stand?
What we do
What bad looks like
Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

For Canadian boards, owners and executives

The questions arrive long before the incident does

A customer sends a security questionnaire. An insurer asks what has changed since last renewal. A director wants to know whether anybody checked the AI tool before it was switched on. None of these are technical questions. All of them need an answer somebody outside your business will believe.

Your customers

Will not sign until the questionnaire comes back clean.

Your insurer

Prices the renewal on what you can show, not what you say.

Your board

Carries the duty, and is the last to find out.

Two Canadian laws most businesses have not read

You are already required to do more than you think

PIPEDA and Quebec Law 25, Canadian privacy and data protection
PIPEDA

The federal privacy law

It governs personal information handled in the course of commercial activity across most of Canada.

What it actually asks of you: keep a record of every privacy breach, including the ones you decided were harmless, for two years, and produce them for the Privacy Commissioner on request. Where a breach creates a real risk of significant harm, report it and tell the people affected as soon as feasible.

Most Canadian businesses keep no such record at all.

Quebec Law 25

The one that already covers AI

Canada has no AI Act. Quebec did not wait for one.

What it actually asks of you: since September 2023, if a decision about a person is made exclusively by automated processing, you must tell them. On request you must say what personal information you used and the reasons and main factors behind it, and let them put their case to a human who is in a position to change the answer.

That describes a great deal of what companies are currently calling AI.

Neither of these needs a new law to reach you. They are in force today.

27 August 2026

The window they are describing is a governance window

116 companies and organisations, among them OpenAI, Anthropic, Google, Microsoft, Amazon and Oracle, signed a joint letter warning that AI-enabled attacks will become far more widespread and sophisticated within months. Their instruction to every other organisation was short: fix your vulnerabilities, modernise the systems you have been putting off, and put AI to work on defence.

It is good advice, and most Canadian mid-market businesses cannot act on it. Not for want of tools, but because nobody owns the question of which vulnerabilities, ranked how, signed off by whom, at the expense of what else. A risk measured in months does not wait for an organisation that needs three months to decide who decides.

Before you talk to anyone

Where do you stand?

Ten questions about whether you could show it, not whether you feel secure. Five minutes, no email required, and nothing you answer leaves your browser. You get the gaps back in the order we would fix them.

No mystery scoring

The control set, published in full

Thirty-six governance controls, what evidence satisfies each one, and what it maps to in Canadian law. We publish it so you can see what is being asked of you before you engage us, or work through it yourself if you would rather not.

Free, and nothing to sign up for

Where to watch

The five sources worth following if you are accountable for this in a Canadian organisation, and the board question that goes with each. Canadian regulators first, one international source, no newsletter.

Recognise any of these

What bad looks like

The seven failures we keep finding in Canadian organisations — the supplier nobody assessed, the account with no second factor, the backup nobody restored. Written as patterns rather than named companies, with the question a board should ask about each one.

Why anyone believes our answer

We either help you fix it, or we assess you. Never both.

An assessment is only worth something if the person doing it has no stake in the result. If we have designed your controls or written your policies, we will not then turn round, assess you and tell the world you passed.

It costs us work. We think that is the point.

Latest blog news

Keep up to date with the latest news and Views from Canada Cyber-Safe Team

116 companies called for a defensive surge. Who in your business would answer?
|
More than a hundred technology companies warned this week that…
Why MFA on Corporate Email Is the Best Security Money Your Business Never Spent
|
MFA blocks over 99% of account-compromise attacks, and corporate email…
Your AI assistant will not break your file permissions. That is the problem.
|
Microsoft says Copilot only reaches content a user is already…

Start with a conversation

Tell us what has been asked of you and who is asking. We will tell you what we think it needs, and whether that is us. The first conversation is free and there is no obligation at the end of it.

Tell us about your organisation+1 647 361 2215

Canada Cyber-Safe is based in Toronto. We work with Canadian organisations only.

French Version »