Where to watch

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

Five places worth watching, and what a board should actually do with each. We have kept this deliberately short. A longer list would be easier to write and less useful to read.

Canada · federal

Canadian Centre for Cyber Security

Alerts and advisories

The Government of Canada’s own warnings about vulnerabilities and campaigns affecting Canadian organisations. Numbered advisories, updated as things happen, with a web feed you can subscribe to.

Who should watch it: whoever is accountable for cyber, or the person who would have to answer if something on the list turned out to be running in your business.

The board question: do we know whether we run the affected product, and who decides on emergency patching?

Open Canadian Centre for Cyber Security →

Canada · federal

Office of the Privacy Commissioner of Canada

Breach obligations and investigation findings

What PIPEDA actually requires when something goes wrong, and the OPC’s published findings from investigations. Worth reading before you need it, not after.

Who should watch it: whoever holds the privacy file, and anyone who would have to decide whether a breach is reportable.

The board question: do we keep a record of every breach, including the ones we judged harmless, and could we produce two years of it?

Open Office of the Privacy Commissioner of Canada →

Quebec

Commission d’accès à l’information du Québec

Law 25 decisions and guidance

Quebec’s regulator, and the one in Canada with real financial teeth: administrative penalties to C$10 million or 2% of worldwide turnover, penal fines to C$25 million or 4%. Much of the detailed guidance is in French.

Who should watch it: anyone holding the personal information of Quebec residents, wherever your office is.

The board question: have we established whether Law 25 reaches us at all, and written the answer down?

Open Commission d’accès à l’information du Québec →

Canada · federal

Office of the Superintendent of Financial Institutions

Guidelines B-10 and B-13

B-13 on technology and cyber risk management has applied to federally regulated financial institutions since 1 January 2024. B-10 on third-party risk has applied since 1 May 2024.

Who should watch it: federally regulated institutions, and anyone who sells to one, because these obligations get passed down the supply chain in contracts.

The board question: if our client is regulated, are we the third party they now have to assess?

Open Office of the Superintendent of Financial Institutions →

International

CISA

Known Exploited Vulnerabilities catalogue

American, and the one international source we think earns its place. It lists vulnerabilities confirmed as being exploited in real attacks, which is a far shorter and more useful list than everything that has merely been disclosed.

Who should watch it: whoever prioritises patching, or whoever is being asked why something was not patched.

The board question: are we prioritising by what is actually being exploited, or by whatever the scanner shouted loudest about?

Open CISA →

The part that matters

Watching is not the same as deciding

Every organisation we assess already has access to all of this. Almost none of them can show what they did about any of it. The advisory gets read, or it does not, and either way nothing is written down.

The gap is never the information. It is that nobody owns the question of what to do with it, on what timescale, at the expense of what else. That is a governance problem, and it is the one we work on.

Links open on the publishers’ own sites. We do not mirror or summarise them, and we have no affiliation with any of these bodies.

Turn watching into evidence

If you want to know whether your organisation could show what it did about any of the above, the ten-question self-check takes five minutes and asks for no email address.

Take the self-checkSee the control set

French Version »