Five places worth watching, and what a board should actually do with each. We have kept this deliberately short. A longer list would be easier to write and less useful to read.
Canadian Centre for Cyber Security
Alerts and advisories
The Government of Canada’s own warnings about vulnerabilities and campaigns affecting Canadian organisations. Numbered advisories, updated as things happen, with a web feed you can subscribe to.
Who should watch it: whoever is accountable for cyber, or the person who would have to answer if something on the list turned out to be running in your business.
The board question: do we know whether we run the affected product, and who decides on emergency patching?
Office of the Privacy Commissioner of Canada
Breach obligations and investigation findings
What PIPEDA actually requires when something goes wrong, and the OPC’s published findings from investigations. Worth reading before you need it, not after.
Who should watch it: whoever holds the privacy file, and anyone who would have to decide whether a breach is reportable.
The board question: do we keep a record of every breach, including the ones we judged harmless, and could we produce two years of it?
Commission d’accès à l’information du Québec
Law 25 decisions and guidance
Quebec’s regulator, and the one in Canada with real financial teeth: administrative penalties to C$10 million or 2% of worldwide turnover, penal fines to C$25 million or 4%. Much of the detailed guidance is in French.
Who should watch it: anyone holding the personal information of Quebec residents, wherever your office is.
The board question: have we established whether Law 25 reaches us at all, and written the answer down?
Office of the Superintendent of Financial Institutions
Guidelines B-10 and B-13
B-13 on technology and cyber risk management has applied to federally regulated financial institutions since 1 January 2024. B-10 on third-party risk has applied since 1 May 2024.
Who should watch it: federally regulated institutions, and anyone who sells to one, because these obligations get passed down the supply chain in contracts.
The board question: if our client is regulated, are we the third party they now have to assess?
Open Office of the Superintendent of Financial Institutions →
CISA
Known Exploited Vulnerabilities catalogue
American, and the one international source we think earns its place. It lists vulnerabilities confirmed as being exploited in real attacks, which is a far shorter and more useful list than everything that has merely been disclosed.
Who should watch it: whoever prioritises patching, or whoever is being asked why something was not patched.
The board question: are we prioritising by what is actually being exploited, or by whatever the scanner shouted loudest about?
The part that matters
Watching is not the same as deciding
Every organisation we assess already has access to all of this. Almost none of them can show what they did about any of it. The advisory gets read, or it does not, and either way nothing is written down.
The gap is never the information. It is that nobody owns the question of what to do with it, on what timescale, at the expense of what else. That is a governance problem, and it is the one we work on.
Links open on the publishers’ own sites. We do not mirror or summarise them, and we have no affiliation with any of these bodies.
Turn watching into evidence
If you want to know whether your organisation could show what it did about any of the above, the ten-question self-check takes five minutes and asks for no email address.