Canada · independent · cited
Canadian cybersecurity, explained plainly.
Guides to the frameworks, privacy duties, and sector rules that Canadian organizations deal with, written from the official sources, and a clear path for when something goes wrong.
// 01 start here
Three places most people start
Baseline cyber security controls for small and medium organizations
A practical starting list of controls written for organizations under 500 employees.
Read the guide →PIPEDA breach reporting
Private-sector organizations must report certain breaches, notify people, and keep a record of every breach.
Read the guide →Ransomware prevention and recovery
The Cyber Centre publishes a prevention guide and a response playbook for ransomware.
Read the guide →// 02 the guides
Guides by topic
Each guide says who it applies to, what matters, what to do next, and links to the primary source.
Frameworks and controls
The control sets and risk frameworks Canadian organizations build programs on.
Baseline cyber security controls for small and medium organizations
A practical starting list of controls written for organizations under 500 employees.
NIST Cybersecurity Framework 2.0
A widely used outcome-based framework for organizing a security program and explaining it to executives.
CIS Critical Security Controls
A prioritized set of 18 controls, with implementation groups that scale to organization size.
ISO/IEC 27001 information security management
The international standard for running an information security management system, with third-party certification.
ITSG-33 IT security risk management
The Government of Canada lifecycle approach to managing IT security risk, widely referenced in public sector work.
Privacy and breach duties
What the law expects when personal information is lost or exposed.
Sector and contracting
Rules and assurance schemes that come with a regulator, a contract, or a customer.
OSFI Guideline B-13 technology and cyber risk
Expectations for how federally regulated financial institutions govern and manage technology and cyber risk.
CPCSC for defence suppliers
The Canadian Program for Cyber Security Certification sets cyber requirements for suppliers on defence contracts.
SOC 2 reports
An independent auditor report on a service organization’s controls, often requested by customers.
PCI DSS for card payments
The industry security standard for any organization that stores, processes, or transmits payment card data.
Incident response
What to do before and after something goes wrong.
// 03 the directory
Find a Canadian cybersecurity firm
43 firms across 6 provinces, mapped by the services they offer and the frameworks they name. Sorted alphabetically, with no paid placement.
// 04 resource hubs
Step-by-step, with the sources
Windows hardening
An ordered path to harden Windows clients and servers, with the official baselines and documentation to build from.
CPCSC: Canadian Program for Cyber Security Certification
What the program is, how its three levels work, the 13 Level 1 controls, and how to prepare, drawn from the official government pages.
Small business security baseline
A 90-day plan built on the Canadian Centre for Cyber Security baseline controls for small and medium organizations.
Privacy breach response in Canada
A practical sequence for handling a breach involving personal information, covering PIPEDA and Quebec Law 25 duties.
ISO/IEC 27001 certification
The path from scoping to certification audit for an information security management system, with practical notes.
// 05 if you have been hit
The first hour matters
Most of the damage in an incident comes from the first decisions. These steps hold for most situations.
- Contain itIsolate affected devices from the network. Do not wipe them yet.
- Preserve evidenceKeep logs, emails, ransom notes, and screenshots. Note times.
- Call for helpReach your response provider, insurer, and legal counsel.
- Report itTell the Cyber Centre, and the privacy regulator if personal information is involved.
// 06 how we work
Editorial standards
No pay for placement
Nobody can buy a mention, a ranking, or a better description. If we ever carry sponsored material, it will be labelled and kept apart.
Primary sources
Every guide links to the regulator, standards body, or government page it is based on. We read them, and we say when a source is a summary.
No standard text
Paid standards are copyrighted. We explain what they do and point you to the owner, and we do not reproduce them.
Corrections welcome
Rules change. If a guide is out of date, tell us through the contact form and we will check and fix it.