What you actually receive
Most cyber reporting arrives as forty pages a board cannot act on. Ours arrives as one page a board can. This is a complete example — not an extract — so you can judge the format before you buy anything.
This is an illustrative example. Northbridge Logistics is a fictional company and every finding below is invented to demonstrate the format. It is not a real client, redacted or otherwise — we do not publish client work. The structure, the control references and the regulatory framing are exactly what we use.
Prepared for the Board — Northbridge Logistics Inc.
Cyber and AI governance: position at 31 July 2026
The one thing to take away
Northbridge can evidence 24 of 36 controls. The gap that matters is not technical: no one is formally accountable for personal information, which is a requirement of PIPEDA and the reason three of the other gaps have stayed open for two quarters.
Position against the control set
| Domain | Evidenced | Status | Movement since Q1 |
|---|---|---|---|
| A — Accountability | 1 of 4 | Action required | No change |
| B — What matters to us | 3 of 4 | Watch | +1 |
| C — Privacy obligations | 3 of 5 | Watch | +1 |
| D — Technical baseline | 7 of 8 | Holding | +2 |
| E — Third parties | 2 of 5 | Action required | No change |
| F — AI deployment | 1 of 4 | Action required | New domain |
| G — Incident readiness | 4 of 4 | Holding | +1 |
| H — People | 2 of 3 | Holding | No change |
| I — Evidence | 1 of 3 | Watch | +1 |
Three things for the board to decide
| Decision | Why it sits with the board | If deferred |
|---|---|---|
| Name an accountable person for personal information (control A1) | PIPEDA requires an identified individual. It is an appointment, not a project, and only the board can make it. | Every privacy gap stays unowned. In an incident, the first hours go on deciding who decides. |
| Approve the AI tool list, or accept its absence (F1) | Staff are already using AI tools. The board is choosing between a short approved list and an unmanaged one. | Client information continues to leave the business through tools nobody has assessed. |
| Fund vendor reviews for the four critical suppliers (E1) | These four hold customer personal information. Accountability for it remains with Northbridge whatever the contract says. | A supplier breach becomes Northbridge’s regulator report, on Northbridge’s clock. |
What improved this quarter
- Multi-factor authentication now covers all staff accounts and, since June, all service accounts (D3).
- A backup restore was tested end to end on 12 June; recovery took 6 hours against a 4-hour target, and the gap is being addressed (G2).
- The breach register now exists and holds four entries, including two incidents judged not reportable — which is the point of keeping it (C4, I2).
What we would tell an insurer or a customer today
Northbridge could demonstrate a defensible technical baseline and a tested incident response. It could not currently demonstrate who is accountable for personal information, nor that its critical suppliers have been assessed. Both are commonly asked, and both are answerable within a quarter.
Canada Cyber-Safe assessed Northbridge Logistics and did not remediate any of the findings above. We do not sell the tools or services that would close them. Full control-by-control detail and the evidence reviewed are in the accompanying assessment record.
One page, because that is what gets read
The detail exists — every finding traces to a control in our published control set and to the evidence we were shown. What goes to the board is this. If you want to see where you would land, the ten-question self-check takes about four minutes.