CSA Cybersecurity Review Finds Gaps at 73 Registered Firms — New Guidance for Wealth Managers
The Canadian Securities Administrators reviewed cybersecurity practices at 73 registered firms and found real gaps in written policies, staff training, risk assessments, vendor oversight, and incident response. Here's what CSA Staff Notice 33-322 means for registrants.

The Canadian Securities Administrators published CSA Staff Notice 33-322 on July 15, 2026, closing out a year-long compliance sweep of cybersecurity practices at 73 registered firms — investment fund managers, portfolio managers, restricted portfolio managers, and exempt market dealers. The review measured firms against section 11.1 of Regulation 31-103, which requires registrants to manage business risks, including cyber threats, through adequate controls. The headline: many larger firms already had strong programs, but the notice catalogues five specific areas where others fell short — with real numbers attached to each one.
If your firm is a registrant under NI 31-103, or you advise clients who are, this is worth reading closely. It isn't just guidance — it's a benchmark regulators have now published, and one your next compliance examination will likely be measured against.
Five weak spots, five sets of numbers
1. Written policies
Eight percent of firms examined had no written cybersecurity policy at all. Of the firms that did have one, 55 percent had policies staff identified as needing improvement. Put differently: a majority of firms with a policy on paper still had gaps worth flagging.
What this looks like in practice: a "cybersecurity policy" that's really a single paragraph inside a five-year-old employee handbook — no mention of multi-factor authentication, no guidance on cloud storage or personal devices, no named owner, and no review date. If nobody at your firm could tell an examiner when the policy was last updated or who's responsible for it, that's the 55 percent gap the notice is describing.
2. Employee training
Twenty-one percent of firms provided no cybersecurity training to employees whatsoever. Among firms that did train staff, another 21 percent could have made that training more comprehensive, and 16 percent kept little or no record that training had actually happened — a distinction that matters as much for a compliance examination as for actual security.
What this looks like in practice: an annual, click-through training module bundled in with AML compliance, using the same slide deck three years running, with no phishing simulation and no way to confirm anyone actually retained the material — just a completion checkbox in an LMS. Training that can't produce a record of who took it, when, and what it covered doesn't hold up well under examination.
3. Risk assessments
Forty-five percent of firms ran risk assessments staff considered could have been more rigorous, and 12 percent had no documentation of an assessment during the review period at all.
What this looks like in practice: a generic vendor checklist filled out once at onboarding and never revisited — even after the firm migrated client data to a new cloud-based CRM or added a new remote-access tool. A risk assessment with no likelihood/impact scoring, no senior compliance sign-off, and no update trigger tied to actual changes in your technology stack is the kind the CSA is describing as "could be more rigorous."
4. Third-party oversight
This was the gap that touched every single firm reviewed: all 73 used third-party service providers with access to their systems or data. Forty-one percent could tighten their oversight of those vendors, and 62 percent kept little or no documentation of the oversight they did perform. If your firm outsources IT, custody, fund administration, or any system with client data to a vendor, this is the section of the notice to read twice.
What this looks like in practice: a firm running its portfolio management software, IT managed services, and CRM all through outside vendors — with no signed security questionnaire on file for any of them, no SOC 2 or equivalent report ever requested, and no contractual right to audit. Every one of the 73 firms reviewed used third-party providers; the notice's 62 percent "little or no documentation" finding suggests most of them couldn't produce a paper trail proving they'd ever asked the hard questions.
5. Incident response planning
Fifteen percent of firms had no written incident response plan at all. Among firms that had one, 53 percent could have made it stronger, and 63 percent should have been testing it more regularly. Having a plan sitting in a drawer, untested since the day it was written, appears to be nearly as common as not having one.
What this looks like in practice: a one-page incident response plan that says, in effect, "call IT" — with no named roles for who talks to affected clients, who notifies the regulator, who preserves evidence, and no tabletop exercise ever run against it. A plan nobody has tested is a plan you're finding out doesn't work for the first time during an actual breach.
Separately, staff noted that 62 percent of firms carry cybersecurity insurance — described as helpful, though not a regulatory requirement, and not a substitute for the controls above.
What the CSA actually expects
Staff Notice 33-322 updates guidance the CSA first issued in 2017 and leans explicitly on scalability: smaller firms aren't expected to replicate the frameworks of large institutions, but they are expected to address their real risks with controls appropriate to their size and operations. That's a meaningful distinction for small and mid-sized registrants who might otherwise read a notice like this and assume it only applies to firms with dedicated security teams. It doesn't. It applies to every registrant, and the scaling is in how you address the gaps, not whether you're expected to close them.
CSA Chair Stan Magidson, who also chairs the Alberta Securities Commission, put it plainly: strong cybersecurity practices "are not optional in today's threat environment." Staff have already delivered compliance feedback directly to the firms examined in this sweep — but every registrant, examined or not, is expected to use this notice to check its own practices against these five areas.
What we recommend
- If you don't have a written cybersecurity policy, that's the first gap to close — it's the most basic finding in the notice and the easiest one for an examiner to flag immediately.
- Audit your employee training program specifically for documentation. A training program that isn't recorded is, from a compliance standpoint, close to no training program at all.
- Revisit your last risk assessment. If it predates this notice, or wasn't documented in writing, treat that as unfinished business rather than a completed task.
- Inventory every third-party vendor with access to your systems or client data, and confirm you have current, documented oversight of each one — this gap affected 100% of firms reviewed, not a subset.
- Pull out your incident response plan and actually test it. If you don't have one, building even a modest, documented plan puts you ahead of 15% of your peers immediately.
Griffin IT Group works with registered firms across Niagara and the GTA on exactly these five areas — policy documentation, staff training with proper records, risk assessments, vendor oversight, and incident response planning and testing. If you want a straightforward gap check against CSA Staff Notice 33-322 before your next compliance examination, reach out and we'll walk through it with you.