Guideline 2022
OSFI Guideline B-13 — Technology and Cyber Risk Management
Issued by Office of the Superintendent of Financial Institutions
Effective: 1 Jan 2024
Plain-English summary
Guideline B-13 of OSFI is an all-encompassing regulatory framework published by Canada's Office of the Superintendent of Financial Institutions (OSFI) requiring federally regulated financial institutions (FRFIs) to develop effective operational strategies to protect themselves from the rising threat of technology and cybersecurity risks. Divided into three key pillars – Governance and Risk Management, Technology Operations and Resilience, and Cyber Security – the guideline takes the regulatory perspective from being based on technical checkmarks and makes it an outcomes-based approach to risk management. The guideline places full responsibility on the shoulders of senior management and boards to establish risk appetites for cyber threats, safeguard digital assets, ensure data confidentiality, and enforce identity management. Moreover, by integrating itself with the third-party requirements in Guideline B-10, it ensures that the threat management, incident response, and disaster recovery testing by an institution extends beyond its vendor and cloud ecosystem.
Who it applies to
Banking · Insurance
Topics
Cybersecurity & IT Risk
Latest news
No related news yet. We publish updates as regulators act.