Specialism
Obligation
Activity
Themes
Functions
Keywords

canadian securities administrators, CSA, CSA staff notice 33-322, registered firms’ cybersecurity practices, cybersecurity

2026-07-15 18:21:30 · ataylor@vixio.com
Meta Id
3327967
Content ID
3336449
GUID
71bfd535f7e98d6a85a2517b13fa5028

Pipeline Progress

🔄 Pipeline Journey

⏱ 34s total
Queued 18:20:56
+16s
Metadata 18:21:12
+0s
S3 Content 18:21:12
+0s
Extracted 18:21:12
+4s
LLM Gen 18:21:16
+14s
Stored 18:21:30
TITLE: Canadian Securities Administrators Publishes Updated Cybersecurity Guidance for Registered Firms BODY: On July 15, 2026, the Canadian Securities Administrators (CSA) published CSA Staff Notice 33-322 Review of Registered Firms' Cybersecurity Practices and Additional Guidance. The notice follows a focused compliance examination sweep of 73 registered firms' cybersecurity practices and sets out observed practices, identified gaps, and updated guidance to support firms in strengthening their cybersecurity frameworks. The CSA examined a range of areas, including cybersecurity policies and procedures, employee training, risk assessments and controls, oversight of third-party service providers, and incident response planning. The examination found that larger firms generally maintained robust cybersecurity policies and procedures; however, the CSA identified gaps where firms could strengthen their cybersecurity practices. The notice aims to provide practical, scalable guidance to firms of all sizes—including small and medium-sized firms—recognizing that cybersecurity risks and resources vary across registrants. Stan Magidson, CSA Chair and Chair and Chief Executive of the Alberta Securities Commission, said: "Strong cybersecurity practices are not optional in today's threat environment. Our guidance is intended to help firms establish and maintain cybersecurity practices that are appropriate to their size and operations, and are responsive to an evolving threat landscape." The CSA expects registered firms to review the notice and assess whether their cybersecurity practices can be strengthened, considering their current operations and identifying any gaps. Compliance feedback has been provided to relevant firms to address the findings. The notice builds on CSA Staff Notice 33-321 Cyber Security and Social Media, published in 2017. Registered firms' cybersecurity practices are assessed by CSA staff as part of compliance examinations conducted under section 11.1 of National Instrument 31-103 Registration Requirements, Exemptions and Ongoing Registrant Obligations. REFERENCES: Canadian Securities Administrators. CSA Staff Notice 33-322 Review of Registered Firms' Cybersecurity Practices and Additional Guidance. July 15, 2026. Available at: https://www.securities-administrators.ca/
  • Scraped:2026-07-15 18:21:30
  • Created:2026-07-15 18:21:30
  • By:ataylor@vixio.com (61)