20+ Canadian resources

Canadian cybersecurity resources.

The authoritative Canadian sources for threat intel, breach reporting, training, certification, and funding. No sponsored content.

Provincial

Provincial privacy & insurance regulators

If you operate in a province with its own private-sector privacy law (Quebec, Alberta, BC, Ontario), your regulator is here.

ProvinceRegulator(s)Scope
OntarioIPC / FSRAPrivacy: Information and Privacy Commissioner of Ontario. Insurance: FSRA.
QuebecCAI / AMFPrivacy: Commission d acces a l information (Law 25). Insurance: AMF.
British ColumbiaOIPC / BCFSAPrivacy: Office of the Information and Privacy Commissioner. Insurance: BCFSA.
AlbertaOIPCOffice of the Information and Privacy Commissioner of Alberta. PIPA enforcement.
ManitobaOMICOmbudsman Manitoba. FIPPA enforcement.
SaskatchewanIPC / IBCInformation and Privacy Commissioner. Insurance: IBC referral.
New BrunswickOIPCOffice of the Information and Privacy Commissioner. Right to Information and Privacy Act.
Nova ScotiaOIPCOffice of the Information and Privacy Commissioner for Nova Scotia.
PEIFOIPPOPFreedom of Information and Protection of Privacy Office of PEI.
Newfoundland & LabradorOIPCOffice of the Information and Privacy Commissioner. ATIPPA enforcement.
Free tools

Start here if you have $0

No budget? These free resources get you 80% of the way to a defensible cybersecurity posture.

CyberSecure Canada Certification

Free federal certification program. Self-assess against 13 baseline controls, get certified, display the badge. Recognized by carriers and procurement teams.

Get certified ↗

Get Cyber Safe Guides

Free, plain-language guides for Canadian SMBs. Topics: phishing, ransomware, passwords, remote work, incident response planning.

Browse guides ↗

Cyber Centre - Baseline Cyber Security Controls for SMBs

The Canadian government's official baseline. ITSAP.10.002. Print it. Tape it to the wall. Use it as your security checklist.

Read the baseline ↗

OPC PIPEDA Breach Reporting

Free breach reporting portal. The 72-hour clock starts when you determine RROSH, not when the breach happened.

Report a breach ↗

Want us to implement these for you?

We are the team that turns these free resources into a managed, monitored, documented cybersecurity program. Free 30-minute assessment.

Book a free assessment