Skip to main content

Where to watch

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

Six places worth watching, and what a board should actually do with each. We have kept this deliberately short. A longer list would be easier to write and less useful to read.

Canada · federal

Canadian Centre for Cyber Security

Alerts and advisories

The Government of Canada’s own warnings about vulnerabilities and campaigns affecting Canadian organisations. Numbered advisories, updated as things happen, with a web feed you can subscribe to.

Who should watch it: whoever is accountable for cyber, or the person who would have to answer if something on the list turned out to be running in your business.

The board question: do we know whether we run the affected product, and who decides on emergency patching?

Open Canadian Centre for Cyber Security →

Canada · federal

Office of the Privacy Commissioner of Canada

Breach obligations and investigation findings

What PIPEDA actually requires when something goes wrong, and the OPC’s published findings from investigations. Worth reading before you need it, not after.

Who should watch it: whoever holds the privacy file, and anyone who would have to decide whether a breach is reportable.

The board question: do we keep a record of every breach, including the ones we judged harmless, and could we produce two years of it?

Open Office of the Privacy Commissioner of Canada →

Quebec

Commission d’accès à l’information du Québec

Law 25 decisions and guidance

Quebec’s regulator, and the one in Canada with real financial teeth: administrative penalties to C$10 million or 2% of worldwide turnover, penal fines to C$25 million or 4%. Much of the detailed guidance is in French.

Who should watch it: anyone holding the personal information of Quebec residents, wherever your office is.

The board question: have we established whether Law 25 reaches us at all, and written the answer down?

Open Commission d’accès à l’information du Québec →

Canada · federal

Office of the Superintendent of Financial Institutions

Guidelines B-10 and B-13

B-13 on technology and cyber risk management has applied to federally regulated financial institutions since 1 January 2024. B-10 on third-party risk has applied since 1 May 2024.

Who should watch it: federally regulated institutions, and anyone who sells to one, because these obligations get passed down the supply chain in contracts.

The board question: if our client is regulated, are we the third party they now have to assess?

Open Office of the Superintendent of Financial Institutions →

International

CISA

Known Exploited Vulnerabilities catalogue

American, and the one international source we think earns its place. It lists vulnerabilities confirmed as being exploited in real attacks, which is a far shorter and more useful list than everything that has merely been disclosed.

Who should watch it: whoever prioritises patching, or whoever is being asked why something was not patched.

The board question: are we prioritising by what is actually being exploited, or by whatever the scanner shouted loudest about?

Open CISA →

Canada · federal

Canada Gazette, Part II

Where a law that has already passed actually starts

Royal Assent is not a start date. Regulations and orders in council are published here, and they are what turn a passed Act into a duty you can put a date against. The live example is the Critical Cyber Systems Protection Act, which came in as Part 2 of Bill C-8 and received Royal Assent on 16 June 2026. Its substantive obligations are not in force. They begin on a day to be fixed by the Governor in Council; the incident reporting window is to be set by regulation at no more than 72 hours; the penalties, up to $15 million for an organisation, are statutory ceilings still to be fixed; and both schedules — including the one naming which classes of operator are actually covered — are blank.

Who should watch it: whoever would have to build the reporting process, and whoever signs the customer contracts that will inherit it. If you supply telecommunications, energy, finance or transport, these duties will reach you by contract long before they reach you by law.

The board question: if the schedule naming covered operators were published tomorrow, would we be on it — or selling to somebody who is? And is anyone currently selling us readiness for a schedule nobody has written?

Open the Canada Gazette →

The part that matters

Watching is not the same as deciding

Every organisation we assess already has access to all of this. Almost none of them can show what they did about any of it. The advisory gets read, or it does not, and either way nothing is written down.

The gap is never the information. It is that nobody owns the question of what to do with it, on what timescale, at the expense of what else. That is a governance problem, and it is the one we work on.

Links open on the publishers’ own sites. We do not mirror or summarise them, and we have no affiliation with any of these bodies.

Turn watching into evidence

If you want to know whether your organisation could show what it did about any of the above, the ten-question self-check takes five minutes and asks for no email address.

Take the self-checkSee the control set

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.