Don’t do SECURITY. Do business SECURELY.

OSFI’s Guideline B-13 on technology and cyber risk takes effect

Canada’s federally regulated financial institutions must now meet OSFI’s expectations for technology and cyber risk management.

OSFI Guideline B-13 Technology and Cyber Risk Management takes effect today for Canada’s federally regulated financial institutions.

Key points

  • Governance and a technology and cyber risk management framework.
  • Technology operations and resilience, including change management and disaster recovery.
  • Cyber security controls, including threat assessment, secure configuration and incident response.
  • Third-party technology providers are expected to meet equivalent standards.

UK technology suppliers to Canadian banks and insurers should expect B-13 requirements to flow into contracts and due diligence. The guideline aligns with the operational resilience approach seen in the UK and the EU’s DORA.

Source: Guideline B-13 Technology and Cyber Risk Management (OSFI)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights