Following a compliance sweep that found an array of gaps with investment firms’ cybersecurity preparations, the Canadian Securities Administrators (CSA) is calling on the industry to beef up its defences.
In a staff notice issued Wednesday, the CSA detailed the findings of a review that examined cybersecurity practices at 73 firms including fund managers, portfolio managers and exempt-market dealers. It found that the industry’s large firms generally had robust defences, but also uncovered a number of weaknesses, including deficiencies in firms’ cybersecurity risk assessments, their policies and procedures, staff training, and incident response plans.
Among other things, the review found that 8% of firms had no cybersecurity policies at all, and the CSA identified weaknesses in 55% of those that did. It also found that 45% of firms need more comprehensive cybersecurity risk assessments.
Additionally, the review found that 41% of firms need to strengthen their oversight of third-party providers; 21% don’t do any cybersecurity training, and another 21% that do provide training need to enhance that training. Additionally, 15% of firms didn’t have any written incident response plan and 53% needed stronger plans, the CSA said.
These deficiencies come at a time when the importance of cybersecurity has ramped up alongside the industry’s growing reliance on technology, and amid trends such as the rise of remote working, which have expanded vulnerabilities through the increased use of mobile devices, cloud-based applications and electronic client communications.
“With these technological advances and a greater online presence also comes an increased risk of a firm being affected by cybersecurity threats, which are becoming increasingly prevalent and sophisticated,” the report said.
In response, the CSA set out additional guidance in the notice, which aims to alert firms to the fundamental risk of cyberattacks and the threat to client data.
“Staff expect firms to have robust cybersecurity practices relevant to the firm’s business,” the notice said, adding that firms need to stay on top of evolving threats, their shifting cybersecurity needs and their responsibility to meet their legal and regulatory obligations in this area.
“The CSA wants to be clear with registrants that strong cybersecurity practices are not optional in today’s threat environment. Our guidance is intended to help firms establish and maintain cybersecurity practices that are appropriate to their size and operations, and are responsive to an evolving threat landscape,” said Stan Magidson, chair of the CSA and chair and CEO of the Alberta Securities Commission (ASC), in a release.
“Cybersecurity risks continue to grow on many fronts, particularly as firms rely more heavily on digital tools, hybrid work arrangements and online platforms to serve clients. We expect firms to review this guidance, assess their own cybersecurity practices, identify any gaps, and take proactive steps to address them,” he added.