The Canadian Securities Administrators (CSA) have issued updated guidance requiring listed companies to enhance their cybersecurity disclosures, citing identified weaknesses in current corporate practices.
The regulatory body, which coordinates provincial and territorial securities regulators, emphasized that firms must adopt more rigorous frameworks to address evolving digital threats, particularly those emerging from advanced artificial intelligence models.
The new directives come as the Canadian federal government moves to establish a centralized digital regulator with expanded powers to enforce online safety and privacy standards.
This broader legislative push aims to consolidate oversight of technology companies and address gaps in existing consumer protection laws.
The CSA’s updated guidance aligns with this national strategy, signaling a coordinated effort to strengthen the country’s digital infrastructure and corporate accountability.
For investors, the enhanced disclosure requirements mean greater transparency into how companies identify, assess, and mitigate cyber risks.