Home › Industries › Wealth Management
CIRO Cybersecurity for Canadian Wealth-Management Firms: A 2026 Compliance Guide
Last updated: August 2026 · Reviewed by Mike Pearlstein, CISSP.
Canadian wealth-management firms hold detailed client financial data and move money on instructions. CIRO published its Compliance Report for 2026 on February 17, and cybersecurity opens section 1. This guide sets out what a registered dealer should have in place, and what an examiner asks to see.
- CIRO’s Compliance Report for 2026, bulletin 26-0034, opens with cybersecurity.
- IDPC Rule 3703 makes incident reporting mandatory, and a second clock runs to the federal privacy regulator.
- Third-party incidents are rising, so vendor due diligence is examined evidence now.
- CIRO ran this sector’s largest recent breach itself: roughly 750,000 investors, confirmed January 14, 2026.
What CIRO expects on cybersecurity
According to the CIRO Compliance Report for 2026 (2026), cybersecurity “continues to be a key business risk for all dealers, regardless of size and complexity”. That is bulletin 26-0034, published February 17, 2026, and it puts cybersecurity first in section 1.
CIRO oversees investment dealers and mutual fund dealers across Canada. A registered firm must protect client information, manage operational and third-party risk, and keep records. Cybersecurity sits inside sound business conduct, so a control gap reads as a conduct issue.
In practice CIRO looks for 3 things. Who can reach client data, and when that list was last reviewed. How an incident is detected, contained and reported. How the vendors touching client systems are supervised.
Want this reviewed against your firm’s current setup?
What is CIRO, and which firms must comply?
According to CIRO (2026), it is the pan-Canadian self-regulatory organization overseeing all investment dealers, mutual fund dealers, and trading on Canada’s debt and equity marketplaces. If your firm holds a dealer registration, CIRO rules bind it. A portfolio manager registered only provincially does not.
That distinction changes what you buy. A CIRO dealer carries incident-reporting duties under IDPC Rule 3703 that a provincially registered portfolio manager does not. Both still answer to federal privacy law.
CIRO’s Montreal office has overseen Quebec-headquartered mutual fund dealers since January 1, 2025, under powers delegated by the Autorite des marches financiers. Those dealers prepare for CIRO and Quebec privacy law together.
The threats that actually hit advisory firms
According to the Competition Bureau (2026), Canadians lost over CA$704 million to fraud in 2025, and only 5% to 10% of frauds are reported at all. Investment fraud ranked first among the fraud types with the highest financial impact. Advisory firms sit inside that number.
The dramatic breach is the rare one. A typical incident is quiet: an attacker spoofs a mailbox, reads a transfer thread for 2 weeks, then sends revised banking details at the right moment.
The defence is process before technology. Call the client back on a number your file already holds, never the one in the email. Pair that callback rule with multi-factor authentication enforced across Microsoft 365.
Our breakdown of cyber attacks on wealth management firms walks the Client-Money Attack Surface end to end.
Third-party and vendor risk
According to the CIRO Compliance Report for 2026 (2026), incidents involving third-party service providers affecting dealers have increased. CIRO asks firms to assess risk “at all stages: before, during, and after the engagement”, and points to Guidance Note GN-2300-21-003 on outsourcing arrangements.
Choosing that outsourced provider is its own decision. Our buyer comparison of IT providers for Canadian financial-services firms scores 5 provider types against the CCCS ITSM.50.030 due-diligence areas and lists the evidence to ask each one for.
Wealth firms depend on custodians, portfolio platforms and outsourced IT. CIRO wants to see where client data physically sits, which side owns each control, and what happens on a vendor’s worst day.
Keep 3 artifacts an examiner can read: a dated due-diligence file per vendor, a written data-residency answer, and an access register. Our guide to third-party and vendor risk for wealth firms sets out the questions, and we can build the file with you.
How to report an incident: what IDPC Rule 3703 requires
According to CIRO (2026), “IDPC Rule 3703 requires the mandatory reporting of cybersecurity incidents by Dealers to CIRO”. Guidance Note GN-3700-22-0001, issued in February 2022, covers compliance with that duty, and CIRO reports a yearly decline in findings against it.
Two clocks start together. CIRO wants a report from the dealer. Federal privacy law wants a report to the Office of the Privacy Commissioner of Canada where a breach of security safeguards creates a real risk of significant harm.
One incident log serving both CIRO and the privacy regulator is easier to defend than two. Record the detection time, the systems touched, the client data in scope, and who made the notification call.
“The CIRO examiner asked for our incident-response runbook, our access-review evidence, and our Croesus integration controls. Fusion built all three, signed off on the runbook with their name on it, and walked our CCO through every artifact. The first examination cycle since they came on board closed clean.”
Chief Compliance Officer, 22-advisor Ontario investment dealer, Toronto. Published on our wealth-management practice page and shared with permission.
CIRO vs OSFI vs PIPEDA: which rules apply to your firm
According to OSFI (2022), Guideline B-13 Technology and Cyber Risk Management took effect on July 31, 2022 and binds federally regulated financial institutions. A CIRO dealer is not automatically one of those, so B-13 usually reaches it through a bank or insurer relationship.
| Rule. | Who it binds. | What it asks for. |
|---|---|---|
| IDPC Rule 3703, CIRO. | CIRO investment dealers. | Mandatory reporting of qualifying cybersecurity incidents. |
| GN-2300-21-003, CIRO. | Dealers using outsourced services. | Risk assessment before, during and after an engagement. |
| Guideline B-13, OSFI. | Federally regulated financial institutions. | Technology and cyber risk management, in force July 31, 2022. |
| Breach reporting, PIPEDA. | Most private-sector organizations in Canada. | Report and record breaches posing real risk of significant harm. |
A single control set satisfies all 4 rows. What gets skipped is the evidence layer: dating the access review, writing the callback rule down, and keeping the vendor file where someone other than the IT provider can find it.
Building a defensible program
According to the Center for Internet Security, CIS Controls v8.1 gives a prioritized starting set a small firm can finish. For a wealth firm the high-value items are enforced multi-factor authentication, tested restores, least-privilege access to client records, and mail-impersonation defence.
CIRO makes the same point about people. The 2026 report says inadequate training can make staff “the weakest link in cybersecurity defense”, and recommends continuous training with multi-factor authentication as a second layer of protection.
If the AI question is what brought you here, our companion guide on Claude Cowork for wealth management firms works through plan tier, folder scoping, and the audit-trail gap under CIRO bulletin 26-0034.
None of this needs an internal security team. It needs an owner who can produce evidence when a CIRO examiner, an institutional partner or the federal privacy regulator asks for it.
CIRO cybersecurity requirements: the evidence checklist for a 2026 examination
According to the CIRO Compliance Report for 2026 (2026), examiners review 3 things. How a dealer demonstrates compliance with the cybersecurity incident reporting requirements. How cybersecurity risk is managed day to day. How that assessment then feeds the dealer’s own risk score.
That last clause is the one principals miss. A weak cyber file does not stay in the cyber file. It moves the firm’s CIRO risk score, and that score sets examination frequency.
Six artifacts answer most of what gets asked:
- An access register for client data, dated within 12 months.
- A written callback rule for banking and transfer changes.
- Evidence of a real restore test, with date and scope.
- A dated due-diligence file for each vendor touching client data.
- A runbook naming who reports to CIRO and to the privacy regulator.
- Training records covering all staff, not only advisors.
Missing 2 or 3 of those is normal at a first assessment. Ask us for the gap list before an examiner writes it for you.
Frequently asked questions
Twelve questions we field most often from dealer principals and chief compliance officers, answered against the published CIRO Compliance Report for 2026 and the rules it cites. Where CIRO sets an outcome rather than a checklist, the answer says so.
Does CIRO require wealth-management firms to have specific cybersecurity controls?
What does IDPC Rule 3703 require a dealer to report?
What is the most common cyber incident at advisory firms?
How many investors were affected by CIRO’s own cyber incident?
Does CIPF cover losses from a cyber incident?
How should a wealth firm handle vendor and third-party risk?
Will CIRO ask about our use of AI in 2026?
Does OSFI Guideline B-13 apply to a CIRO-registered dealer?
Do small wealth firms need an internal security team?
What core controls should every wealth firm have?
What should we bring to a CIRO cybersecurity examination?
Is Fusion Computing the same as Fusion Cyber Group?
Written by Mike Pearlstein, CISSP, founder of Fusion Computing, a Canadian managed IT and cybersecurity provider serving regulated SMBs since 2012.
Talk to Fusion about your firm’s security
Fusion Computing supports CIRO-registered dealers in Toronto and across Ontario that want the evidence layer built once and then kept current. We review your posture against the 2026 CIRO report, and leave you with the dated artifacts an examiner will accept.

