OSFI Guideline B-13 Technology and Cyber Risk Management takes effect today for Canada’s federally regulated financial institutions.
Key points
- Governance and a technology and cyber risk management framework.
- Technology operations and resilience, including change management and disaster recovery.
- Cyber security controls, including threat assessment, secure configuration and incident response.
- Third-party technology providers are expected to meet equivalent standards.
UK technology suppliers to Canadian banks and insurers should expect B-13 requirements to flow into contracts and due diligence. The guideline aligns with the operational resilience approach seen in the UK and the EU’s DORA.
Source: Guideline B-13 Technology and Cyber Risk Management (OSFI)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.