Skip to main content

Resources

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

Free, and nothing to sign up for

Everything we give away

No email gate, no newsletter, no form in the way. If you can use any of this without ever speaking to us, that is a good outcome and we would rather you had it.

Start here

Where do you stand?

Ten questions about whether you could show it, not whether you feel secure. Five minutes. Nothing you answer leaves your browser. You get the gaps back in the order we would fix them.

Take the self-check →
New

What actually governs AI in Canada

There is no Canadian AI Act — AIDA died with Bill C-27, and a great deal of published guidance still pretends otherwise. What actually binds you, what does not, and the two bills tabled in June 2026 that almost nobody has caught up with. Every claim linked to its primary source.

Read it →
Closes 23 September

What Canada is asking about AI transparency

Five things the federal government is consulting on — labelling AI-generated content, telling people when they are dealing with a machine, reporting AI incidents, and logging what AI agents actually do. None of it is law yet, and we say so plainly. What each would mean in practice, and the two things worth doing before it closes.

Read it →
New

The documents a buyer asks for before they will sign

Supplier code of conduct, forced labour statement, anti-bribery, harassment, health and safety, accessibility — the twenty documents a Canadian SME is asked for in supplier onboarding, with every legal threshold checked against the statute rather than a summary of it.

See the pack →
New

Before you switch on Copilot

Copilot does not break your permissions — it respects them perfectly, and that is the problem. Twelve questions on whether the permissions, labelling and retention groundwork is done. Five minutes, nothing leaves your browser, and you get the gaps back in the order we would fix them.

Take the readiness check →
Runbook

The first hour

What to do in the sixty minutes after you realise something has gone wrong, and the notification decision tree for both Canadian regimes. Complete, free, and in English and French.

Read the runbook →
Paid · from CAD $165

The three runbook modules

If the free one above is useful, these are the rest: eighteen procedures across incident response, everyday operations and AI oversight. English and French Canadian, PDF and Word. Buying one does not stop us assessing you — buying a documentation pack does.

See what is in them →
Crosswalk

SOC 2 mapped to ISO 27001

Your American customer wants a SOC 2 and you have ISO 27001. All thirty-eight criteria mapped, with what carries over, what does not, and the one genuine gap. Free, complete, no email address.

Read the crosswalk →
Posters

Staff awareness posters

Free printable one-page posters on AI-powered scams, PIPEDA, Quebec Law 25 and passwords — in English and in French. Five points each, written for the people who never read the policy. No sign-up and no email address required.

Download the posters →
AI-powered scams posterPIPEDA posterQuebec Law 25 posterStrong passwords poster

Worth reading

The one security change worth making this quarter

If you could do exactly one thing, multi-factor authentication on corporate email would almost certainly be it. Why, in plain terms, and what it actually stops.

Read it

Your AI assistant will not break your file permissions

It will faithfully surface everything your permissions already allow — which is a different problem, and a larger one. What Microsoft’s own documentation says, and what it means for your file shares.

Read it

How exposed is a Canadian small business, really?

The honest answer is further than most owners believe, and the gap between belief and evidence is where the risk lives. What the numbers show.

Read it

A hundred companies warned about AI attacks. Who would answer?

The useful question is not whether they are right. It is who in your business would pick up the phone, and whether they would know what to do next.

Read it

Everything we have written is in the briefings, oldest to newest. There is not much of it, and we would rather publish four things worth reading than forty that are not.

Why we give it away

A method you cannot inspect is not a method

Plenty of firms will score your organisation against a standard they will not show you, and hand you a number you cannot check. We think that is the wrong way round. If our control set is any good it survives being read by the people we assess.

The awareness posters and the three Canadian policy templates are already here, listed above. Nothing on this page is a preview, an extract or a teaser — if it is listed, it is complete and you can take it today.

Everything here is free and licensed to one organisation. Why we publish it · what a paid engagement adds.

When you want a second pair of eyes

Everything above is yours whether or not you ever contact us. If you want someone independent to work through it with you, the first conversation costs nothing and carries no obligation.

Tell us about your organisationSee what we do

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.