Download PDF (764 KB)
PDF version, ready to print or share with your team.
Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
In August 2025, the regulator that polices cybersecurity at Canadian investment dealers disclosed its own breach. A phishing attack against CIRO reached data tied to roughly 750,000 Canadian investors, and CIRO needed until January 2026 to confirm the full extent. If the body that writes the exam can be phished, the 12-person portfolio manager down the street should assume it’s a target too.
Fusion Computing secures Canadian wealth management firms and CIRO dealer members, and we sell no platforms or custody systems ourselves. I wrote this guide around the threats that actually cost firms client money, and around the control program a compliance examination expects to find. In our practice the exam is the floor, not the target, and my aim here is to show you which controls actually stop a loss.
Short answer: Cybersecurity for wealth management firms in Canada means defending 3 surfaces where client money actually leaves: the wire and transfer approval chain; client account access; and the third-party vendors connected to your book.
In practice that means MFA on every system, a written wire callback rule, vendor risk reviews, managed endpoint detection, tested backups, plus the personnel training CIRO’s own compliance report singles out.
KEY TAKEAWAYS
- Even the regulator got phished. CIRO confirmed in January 2026 that a phishing attack first disclosed in August 2025 reached roughly 750,000 Canadian investors, after more than 9,000 hours of examination.
- Finance is Canada’s costliest breach sector. IBM puts the average Canadian financial-sector breach at CA$9.97 million against a CA$6.98 million national average.
- Client money leaves through 3 doors. Wire fraud, account takeover and vendor compromise account for the losses that matter, and all 3 are controllable.
- Ransomware still pays the attacker. CIRA found 24% of Canadian organizations hit inside 12 months, and 74% of those victims paid the demand.
- Third-party risk is the theme CIRO named. Its Annual Compliance Report warns of rising incident reports involving third-party service providers that impacted dealer clients.
- Size is no defence. CIRO calls cybersecurity a key business risk irrespective of dealer size and complexity, and 43% of Canadian organizations were targeted in the last 12 months.
Why are wealth management firms prime cyber targets in Canada?
According to IBM Canada (2025), the average Canadian data breach costs CA$6.98 million, and the financial sector carries the highest bill of any industry at CA$9.97 million. Wealth firms concentrate the 2 things attackers monetize fastest: authority over client money movements, and deep personal information on high-net-worth households.
The economics work against small firms in a specific way. A 15-person portfolio manager runs the same custody connections, wire workflows and client PII as a bank branch, with a fraction of the security staffing. Attackers price that gap. The CIRA Cybersecurity Survey (2025), which polled 500 Canadian security decision-makers, found 43% of organizations targeted inside 12 months.
The fraud market adds a second pull. Canadians reported losing over CA$704 million to fraud in 2025, and the Competition Bureau (2026) names investment fraud first among the categories with the highest financial impact. Only 5% to 10% of frauds get reported at all. Wealth firms sit where that money moves, which makes their mailboxes and client portals premium targets.
What did the 2025 CIRO breach teach every Canadian dealer?
According to CIRO (2026), a sophisticated phishing attack first disclosed in August 2025 impacted approximately 750,000 Canadian investors, confirmed after more than 9,000 hours of examination. The exposed fields included dates of birth, social insurance numbers, government-issued ID numbers and investment account statements. Phishing remains the entry; people remain the surface.
Three takeaways translate directly to a dealer’s program. Phishing defence and MFA are the controls that fail first under a targeted campaign, so treating them as done is the mistake. Verizon’s Data Breach Investigations Report (2025) put the human element in 60% of breaches, with credential abuse the single most common entry vector at 22%.
Want your wire process tested against a spoofed instruction? Talk to us. →
Incident response is measured in hours of review, not days. More than 9,000 hours is a number a 20-person firm cannot absorb without a plan and a partner. Disclosure duties follow you as well: clients, the Office of the Privacy Commissioner (2018) under PIPEDA, and CIRO itself all expect timely notification. Our CIRO guide for wealth management firms covers the regulatory side.
The Client-Money Attack Surface: 3 doors client funds walk out of
The Client-Money Attack Surface is the 3-door model I use with wealth firms, built from a decade of incident patterns. Door 1 is wire and transfer fraud through a compromised or spoofed mailbox. Door 2 is client account takeover through stolen portal credentials. Door 3 is vendor compromise riding a trusted third-party connection into your book.
| Door | How client money leaves | The control that closes it |
|---|---|---|
| 1. Wire and transfer fraud | Altered instructions from a compromised or spoofed mailbox. | Callback to a known client number plus dual approval. |
| 2. Client account takeover | Replayed credentials trigger a fraudulent redemption. | Portal MFA, login anomaly alerts and redemption verification. |
| 3. Vendor compromise | A trusted third-party connection carries the attacker in. | Vendor inventory, due diligence and breach-notification clauses. |
Door 1 is the most direct. An attacker phishes an advisor or operations mailbox, watches transfer cadence for weeks, then injects altered instructions timed to a real client request. The defence is the same one that stops payment fraud everywhere: MFA, mailbox-rule monitoring and a callback to a known client number for any disbursement or banking change. Our wire fraud and BEC guide walks the full anatomy.
Door 2 is client-side. Stolen credentials from unrelated breaches get replayed against your client portal, and a takeover becomes a fraudulent redemption request. Door 3 is the one CIRO keeps flagging, and it gets its own treatment below.
Ransomware and data extortion, explained for a 20-person dealer
According to the CIRA Cybersecurity Survey (2025), 24% of Canadian organizations were hit by ransomware inside 12 months, and 74% of those victims paid the demand. That payment rate is the number I would put in front of a dealer board, because it tells you the attacker’s business case is working.
Ransomware lands on a dealer differently than on a retailer. Your books and records are a regulatory obligation, so an encrypted portfolio system becomes a compliance event before it is an IT event. The same survey found 42% of organizations restored systems inside a week. The firms that recover fastest tested a restore before they needed one.
We tested the restore path at every wealth firm we onboarded in the past year. Our engineers found the same pattern: the backup nobody had exercised was the one holding the portfolio database. Immutable copies plus a quarterly test restore is the whole answer here. It is cheap and it is boring, and it decides whether a bad Tuesday becomes a bad quarter.
“I got the call no business owner wants. Our systems were locked and there was a ransom demand on every screen. Fusion had someone working on it within the hour, and by Monday we were operating normally again with no ransom paid.”
Client CEO, industrial supply company, Ontario. A Fusion Computing ransomware recovery client.
What controls does a CIRO-ready cybersecurity program need?
According to CIRO (2025), cybersecurity remains a key business risk irrespective of the size and complexity of the dealer member. Dealers must report incidents that meet certain criteria and implement the controls that protect clients and client assets. Our 7-control program maps that expectation onto the workflows where a dealer actually moves money.
| Control | Dealer workflow it protects | Minimum standard |
|---|---|---|
| 1. Multi-factor authentication | Email, portfolio system, custodian portals, client portal. | MFA on every account; legacy sign-in blocked. |
| 2. Email and phishing defence | Advisor and operations mailboxes, client instructions. | Advanced filtering, external banners, mailbox-rule alerts. |
| 3. Wire and disbursement verification | Transfers, redemptions, banking changes. | Callback to a known client number plus dual approval, no exceptions. |
| 4. Vendor risk management | Back office, portfolio systems, fintech integrations. | Inventory, due-diligence reviews, contractual breach notification. |
| 5. Endpoint detection (EDR) | Advisor laptops, office workstations, remote devices. | Managed EDR with 24/7 response, not just antivirus. |
| 6. Tested, immutable backups | Books and records, client files, CRM. | Immutable copies with a restore tested at least quarterly. |
| 7. Training and tabletops | Everyone who touches client instructions. | Quarterly phishing simulations plus an annual tabletop exercise. |
The 7 are sequenced by where money actually leaves. Identity and email first, the wire callback rule the same week, and the rest inside 90 days. For a 10 to 200 person firm this is a right-sized stack run by our managed IT services team, not an enterprise program scaled down.
How do third-party and AI risks change the program in 2026?
According to CIRO (2025), incident reports involving third-party service providers that impacted dealer clients are rising. The same report presses dealers to review whether they hold the controls needed to protect clients and client assets, and to train personnel to fortify their cybersecurity. Vendor risk is the theme CIRO named. Tabletops and documented AI rules are what I add on top of it.
The practical response to the vendor warning is unglamorous. Build an inventory of every vendor touching client data, keep a due-diligence file per vendor, and put breach-notification language in the contract. Wealth Professional (2025) summarized the same warning for dealers. Our vendor and third-party risk guide turns it into a worksheet.
The AI question is newer. CIRO has not issued a dealer AI rule, but its Compliance Report for 2026 says FinOps examiners will be enquiring about the use of AI in dealers’ operations and reviewing the controls around it. The absence of a rule is not the absence of a question.
Advisors are already pasting client information into consumer AI tools, and in our practice that is the fastest-growing exposure at firms under 50 seats. A written AI-use policy, an approved-tool list and tenant-level controls close it. Our AI governance guide for wealth firms covers the rollout.
Book a 20-minute call before your next compliance examination cycle. →
Why Canadian firms bring this work to Fusion Computing.
CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing IT for Canadian SMBs across Toronto, Hamilton and Metro Vancouver since 2012.
What mistakes do we see in the field at wealth firms?
The spending instinct usually runs backwards at firms under 50 seats. They ask about network upgrades while the real exposure is an operations inbox that can move client money without a callback. Identity, email and the disbursement process protect more dollars per budget dollar than any appliance, because that is the chain attackers actually use.
The other recurring miss is treating compliance as the ceiling. The 2025 breach proved a compliant-looking program still fails against targeted phishing, so the examination checklist is the floor. Build for the attack and the examination takes care of itself. A 20-person firm running MFA, callbacks, managed detection and quarterly simulations is harder to rob than firms 10 times its size.
What does a 90-day path to CIRO-exam-ready look like?
90 days covers the distance for most firms, based on the rollout Fusion Computing runs with dealers. Days 1 to 30 cover MFA everywhere, legacy sign-in blocked and the wire callback rule written and signed. Days 31 to 60 cover managed detection, the vendor inventory and a personal-device policy. Days 61 to 90 cover a tested restore, a documented incident plan and the first tabletop.
| Phase | What gets done |
|---|---|
| Days 1-30 | MFA on every system, legacy sign-in blocked, wire callback rule signed by operations. |
| Days 31-60 | Managed EDR live, vendor inventory and due-diligence files, device policy enforced. |
| Days 61-90 | Backup restore tested, documented incident plan, first tabletop exercise completed. |
The sequence mirrors the Client-Money Attack Surface. The controls that stop wire fraud land first, the vendor and device work lands second, and the resilience layer lands third. I have watched firms try all three at once and finish none of them before examination season.
The exam evidence checklist a dealer should keep on file
A CIRO compliance examination does not ask whether you feel secure. It asks for evidence, and the evidence is boring: the MFA enforcement report, the signed callback procedure, the vendor due-diligence files, the dated restore test log, and the tabletop attendance sheet. I keep that list on one page for every dealer we onboard.
- MFA enforcement report from the tenant, showing coverage and any exclusions.
- Signed callback procedure for disbursements and banking changes, dated and owned by operations.
- Vendor due-diligence file per provider touching client data, with the breach-notification clause.
- Restore test log with the date, the system restored and who verified it.
- Tabletop and training records, including phishing simulation results by quarter.
Firms that keep the evidence current spend an afternoon on an examination instead of the 2 weeks I have watched other firms burn reconstructing it. That gap is the single biggest time cost I see at CIRO dealer members, and it has nothing to do with how good the underlying security is.
Get the 7 controls mapped against your firm’s current setup. →
Free download
The Wealth-Management Cybersecurity Controls Checklist (2026)
The control program above, laid out as 42 yes/no items across money movement, access, vendor risk, AI use, client data and detection. It includes the wire callback rule, the vendor evidence file and the tested restore, each phrased as the evidence a 2026 compliance examination asks to see.
Reviewed by Mike Pearlstein, CISSP. No sales call required. Want your own firm scored against the 7 controls first? Book a consultation.
Budget: what the 7 controls cost, versus one diverted wire
Right-sized managed cybersecurity for a Canadian wealth firm runs CA$180 to CA$250+ per user per month, on top of managed IT. At 20 seats that is roughly CA$31,000 to CA$43,000 a year. One diverted redemption at a firm that size clears the whole program budget, and IBM (2025) prices the average Canadian financial-sector breach at CA$9.97 million.
The number that matters is not the monthly fee. It is which controls the fee buys first, and my first question is whether the wire callback rule is signed before anything gets installed. In our practice a firm that sequences correctly is materially safer at day 30 than a firm that bought more tooling and sequenced badly.
Fusion Computing helps Canadian businesses across Toronto and the GTA, Hamilton and Metro Vancouver with managed IT, cybersecurity and Microsoft 365.
Your first two moves, starting Monday
Start with the 2 controls that protect client money this week. Put MFA on every account that can touch a transfer, then write the callback rule for disbursements and banking changes and have operations sign it. Book the tabletop before examination season. Our wealth management IT services page shows the stack behind the program I have described here.
If choosing the partner comes before choosing the control, compare IT providers for wealth-management firms against the 4 selection criteria and the evidence each type should hand you.
Frequently Asked Questions
What does CIRO require for cybersecurity at wealth management firms?
CIRO calls cybersecurity a key business risk irrespective of dealer size and complexity. Dealers must report incidents that meet certain criteria and implement controls that protect clients, client information and assets. The Annual Compliance Report also warns of rising incident reports involving third-party service providers and presses firms to train personnel. A written, evidenced program is the practical bar.
Why are wealth management firms targeted by cyber attacks?
They combine authority over client money movements with deep personal information on high-net-worth households, and most run thin security staffing. IBM puts the average Canadian financial-sector breach at CA$9.97 million, the costliest of any sector. The Competition Bureau reports Canadians lost over CA$704 million to fraud in 2025, with investment fraud first among the categories by financial impact.
What happened in the 2025 CIRO cybersecurity breach?
A sophisticated phishing attack against CIRO, first disclosed in August 2025, impacted roughly 750,000 Canadian investors. CIRO confirmed the full extent in January 2026 after more than 9,000 hours of examination. Exposed fields included dates of birth, social insurance numbers and investment account statements. The dealer lesson is that phishing defence and MFA fail first under targeted campaigns.
What is wire transfer fraud in wealth management?
An attacker compromises or spoofs a mailbox in the instruction chain, watches transfer cadence for 4 to 8 weeks, then injects altered banking details timed to a real client request. The reliable defence is procedural: a callback to a known client phone number plus dual approval on every disbursement or banking change, with zero exceptions for urgency.
How much should a wealth management firm spend on cybersecurity?
Right-sized managed cybersecurity runs CA$180 to CA$250+ per user per month for a 10 to 200 person Canadian firm, on top of managed IT. At 20 seats that is roughly CA$31,000 to CA$43,000 a year. Sequence matters more than size: identity and MFA first, then the wire callback rule, then detection, vendor reviews and training inside 90 days.
Are third-party vendors really a cyber risk for dealers?
Yes. CIRO’s Annual Compliance Report warns of an increase in incident reports involving third-party service providers that impacted dealer clients. A compromised back-office system, portfolio platform or marketing tool carries trusted access into your book. The program answer is an inventory of every vendor touching client data, a due-diligence file per vendor, and breach notification written into the contract.
Do small advisory firms need tabletop exercises?
CIRO does not mandate that each dealer run its own tabletop. It does run one for the industry: its Compliance Report for 2026 states that in 2026 CIRO will conduct another cybersecurity table-top exercise, aimed particularly at small and mid-sized dealers.
Running your own is our recommendation on top of that. A 2-hour tabletop is the cheapest way to find out who calls the custodian, who notifies clients and who talks to the Privacy Commissioner. Finding that out during a real incident at 2 a.m. costs a great deal more than an afternoon.
Can advisors use AI tools like ChatGPT with client information?
Only under controls, and the controls are yours to write because CIRO has not issued a dealer AI rule.
Its Compliance Report for 2026 does say FinOps examiners will enquire about AI use and review the controls around it, so expect the question at examination. The workable setup is a written AI-use policy, an approved-tool list and tenant-level data controls, plus training that names the failure mode. That failure mode is pasting client PII into consumer tools that retain it.
How fast can a wealth firm become CIRO-exam-ready on cybersecurity?
Most firms cover the distance in 90 days. MFA everywhere and a signed wire callback rule land in the first 30 days. Endpoint detection and the vendor inventory land by day 60. A tested backup restore, a written incident plan and the first tabletop land by day 90. The controls that protect client money come first by design.
Does PIPEDA apply on top of CIRO requirements?
Yes. Client personal information sits under PIPEDA regardless of CIRO membership. Breaches posing a real risk of significant harm must be reported to the Privacy Commissioner and affected clients notified, and breach records must be kept at least 24 months. A dealer incident usually triggers both tracks at once, which is why the written incident plan names both.

