Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
The Mortgage Broker Regulators’ Council of Canada published four Principles for Cybersecurity Preparedness, and FSRA adopted them for Ontario brokerages effective August 18, 2022. Four. Not nine.
I keep correcting that number because this post is where the confusion starts. The nine in the title is my control count, the working decomposition I use to turn four outcome-based principles into things a 12-agent brokerage can actually switch on. Four principles, nine controls, one framework.
The principles are deliberately outcome-based so a small brokerage can size its own implementation. The unanswered question for a broker-of-record is what they look like as configuration on a Microsoft 365 Business Premium tenant on a Tuesday afternoon. That is what follows. It is a companion to our FSRA-aligned cybersecurity playbook for Ontario financial brokerages.
Across our managed endpoint base of Ontario brokerages I find the same four blind spots when examiners arrive: shared MFA-exempt admin accounts, deal-submission portals without conditional access, borrower SIN emailed to closing services, and incident playbooks nobody has ever rehearsed.
Key Takeaways
- MBRCC published four principles, not nine. FSRA adopted them via guidance MB0048INF effective August 18, 2022. The nine controls in this post are my decomposition, not the regulator’s.
- The four are responsibility and resourcing, identification and prevention of risks, incident monitoring and detection and response, and third-party management.
- FSRA’s IT Risk Management Guidance (GR0016INT, effective April 1, 2024) sits on top. Practice 7 asks for notification as soon as is reasonable, normally within 72 hours or sooner, after the entity determines an incident is material.
- The MBRCC document carries a 22-question self-assessment checklist, and MBRCC says examiners may use it during routine brokerage monitoring. Most brokerages have never opened it.
- A 12-agent brokerage covers roughly 80% of the principle-mapped evidence on Microsoft 365 Business Premium alone, using bundled MFA, conditional access, Defender for Business and Intune.
The four MBRCC principles explained: what each one requires, and where the checklist sits
The document is five pages. Four numbered principles, a self-assessment checklist, and a standards list naming ISO/IEC 27001, the NIST Cybersecurity Framework and OSFI. It also anchors itself to Principle 8 of the MBRCC Code of Conduct, on security and confidentiality.
Principle 1: responsibility and resourcing. Name who owns cybersecurity risk, keep that person’s skills current through ongoing education, raise staff awareness, and consider cyber-liability insurance. In a 12-agent shop the named owner is the broker-of-record.
Principle 2: identification and prevention of risks. Identify risks across staff access, third-party providers and safeguards, keep endpoint protection current, run a cyber business-impact assessment, fold cyber into continuity planning, and state a risk tolerance.
Principle 3: incident monitoring, detection and response. Hold a documented protocol covering suspension of business processes, information-sharing with clients and mortgage lenders and regulators, return-to-normal criteria, and restoration of lost or corrupted data.
Principle 4: third-party management. Take reasonable steps to confirm external providers hold preparedness practices across the whole application-to-closing chain. MBRCC is explicit that a larger provider network raises the risk.
Principle 1, Annotated: Responsibility and Resourcing for a 12-Agent Brokerage
Principle 1 reads simply: name an owner, allocate resources, write the policy, train the people, consider insurance. For a 12-agent shop I decompose it into two controls, and both are documentary rather than technical.
Control 1.1: named accountable owner plus a documented governance cadence. The broker-of-record is the named owner. The cadence is a quarterly 60-minute review where the owner signs off on the last backup test, the Intune patch-compliance report, the Microsoft Entra user-access list, and third-party attestation status. Minutes land in a SharePoint library behind conditional access.
Control 1.2: written cybersecurity policy plus an annual continuing-education tie-in. The policy runs 4 to 6 pages and is signed at onboarding and annually. It covers acceptable use, MFA enforcement, lender-portal credential handling, incident reporting, and offboarding. The annual signature rides alongside the continuing-education renewal agents already know under the Mortgage Brokerages, Lenders and Administrators Act, 2006.
According to the Canadian Centre for Cyber Security (2020), Baseline control 6.1 expects awareness training covering password practice, email threat identification, approved software, internet safety and social media. Pairing that scope with the existing renewal cycle is the cleanest way to land Principle 1 in a small brokerage.
Need the 4-page policy drafted? Book a review with Mike Pearlstein, CISSP →
Principle 2, Annotated: Identification and Prevention of Risks
Principle 2 is where a brokerage builds its preventive surface. On Microsoft 365 Business Premium plus a handful of lender-portal logins, I decompose it into three controls.
Control 2.1: asset and data inventory mapped to lender-portal touchpoints. List every device touching borrower data, every cloud service holding it, and every lender-portal credential granting access. A two-tab spreadsheet kept current at the quarterly governance review is enough for 12 agents.
Control 2.2: MFA on every lender portal plus conditional access on Microsoft 365. This is the single most consequential control in the framework. Enforce MFA on Filogix, Velocity, Finmo, BluMortgage and Newton, then add a conditional access policy blocking legacy authentication across the Microsoft 365 tenant. Add passkeys wherever the portal supports them.
Control 2.3: patching cadence and vulnerability management on every endpoint. Baseline control 2.1 recommends automatic patching for small organizations. Here that means Intune pushing Windows Update for Business with a 7-day quality-update deferral, third-party app patching through Intune, and a monthly vulnerability report reviewed at governance.
For the per-portal enrolment flow, see the Filogix and Velocity account-hardening guide.
Principle 3, Annotated: Incident Monitoring, Detection, and Response
Principle 3 is where FSRA layers on top of the MBRCC baseline. The two work together. MBRCC asks you to hold a protocol, and FSRA attaches a notification window to it that starts at the materiality determination rather than at detection.
Control 3.1: endpoint detection and response on every device. Microsoft Defender for Business, bundled in Business Premium, covers detection, automated investigation and remediation for a brokerage this size. Evidence is the device-inventory report plus one sample alert with a documented response.
Control 3.2: written incident-response plan with the notification path baked in. One page. Who declares, who contains, who notifies. The decision tree defines what counts as material: borrower SIN exposed, a lender-portal credential compromised, ransomware on any device holding deal files.
The contact list carries the after-hours number, the FSRA IT risk inbox at [email protected], the Privacy Commissioner breach line, and the cyber-insurance hotline. Rehearse it once a year in a 60-minute tabletop. Our FSRA IT Risk Incident Notification 15-minute SOP is the runbook for the form itself.
Control 3.3: backup and recovery sized for broker-of-record liability. A 12-agent brokerage needs immutable third-party backup of Exchange, SharePoint, OneDrive and Teams data. Microsoft retention is not a backup. Target a 24-hour recovery point and an 8-business-hour recovery time, with weekly restore tests logged.
Principle 4, Annotated: Third-Party Risk for a Lender-Portal-Centric Brokerage
Principle 4 surfaces the largest evidence gap in a 12-agent brokerage, and the reason is structural. Borrower SIN, T4 income documents, deal-submission data and executed applications all flow through third parties: Filogix, Velocity, Finmo, BluMortgage, Newton, and the e-signing service. The brokerage stays liable for the posture of every one of them.
Control 4.1: written third-party cybersecurity attestation per vendor. For each lender portal and IT vendor, keep on file either a current SOC 2 Type II report, a current ISO 27001 certificate, or a vendor questionnaire the brokerage has reviewed and approved. Refresh annually at the governance review.
In our Ontario engagements this is the gap I find most often. The contracts exist, the portals themselves are well controlled, and the SOC 2 reports are never requested. Conditional access on those integrations also drifts inside 90 days of a staff change, which is why the re-attestation cycle is quarterly rather than annual.
FIELD NOTE FROM MIKE.
A 12-agent Mississauga brokerage I worked with in Q1 2026 had a clean Microsoft 365 tenant, MFA on every lender portal, and Defender for Business on every laptop. The principal walked into his self-assessment sure he was 90% of the way there.
What he did not have was one page attesting to the posture of any of his five lender portals or his signing vendor. He had assumed the portals came with that handled. We closed it by requesting SOC 2 reports from three, completing questionnaires for the other two, and filing the set behind conditional access. That folder was the most consequential output of the engagement.
The 9-control decision matrix: how to choose controls versus buying more tools
The spine is nine controls mapped to the four principles, each with the evidence an examiner would expect and the Microsoft 365 Business Premium feature that produces it. Read it as a buying decision. Eight of the nine are already paid for.
| Control | MBRCC principle | Evidence expected | M365 Business Premium feature |
|---|---|---|---|
| 1.1 Named owner and governance cadence | P1 | Quarterly minutes approved by the broker-of-record. | SharePoint library behind conditional access. |
| 1.2 Written policy and annual sign-off | P1 | Policy document plus dated agent signatures. | E-signature envelope per agent, filed annually. |
| 2.1 Asset and data inventory | P2 | Current device and portal-credential inventory. | Intune inventory plus a portal list in SharePoint. |
| 2.2 MFA on every portal and conditional access | P2 | Policy report plus per-portal MFA confirmation. | Microsoft Entra conditional access. |
| 2.3 Patching and vulnerability management | P2 | Monthly patch-compliance report. | Intune Windows Update for Business. |
| 3.1 Endpoint detection on every device | P3 | Device inventory plus a sample alert response. | Microsoft Defender for Business. |
| 3.2 IR plan with the notification path | P3 | One-page plan plus annual tabletop minutes. | Plan in SharePoint, Teams channel for comms. |
| 3.3 Backup and recovery | P3 | Weekly restore-test logs. | Third-party immutable backup platform. |
| 4.1 Third-party attestation per vendor | P4 | SOC 2, ISO 27001 or completed questionnaire. | SharePoint vendor-attestation library. |
Read the matrix honestly. Eight of the nine controls live inside Microsoft 365 Business Premium at no extra licence cost. The ninth, immutable backup, runs CA$4 to CA$7 per user per month. For 12 agents that is roughly CA$50 to CA$100 a month in tooling, plus the retainer that runs the cadence.
Want this matrix turned into a 12-week plan? Talk to Mike Pearlstein, CISSP →
Want your vendor-attestation library built? Book a session with Mike Pearlstein, CISSP →
The four most common evidence gaps
ORIGINAL DATA, FUSION COMPUTING BENCHMARK.
Across our 2025 and 2026 Ontario mortgage-brokerage reviews we measured four documentary gaps recurring in roughly 7 of every 10 engagements. The pattern is consistent. Technical controls are usually adequate. The evidence trail, meaning the policy text, the attestation log, the tabletop minutes and the vendor SOC 2, is what is missing when an examiner asks.
- Do not skip the third-party attestation file. Filogix, Velocity, Finmo, BluMortgage and Newton all publish or share security documentation. A brokerage with nothing on file fails Principle 4 even when every portal is well controlled.
- Do not confuse Microsoft 365 retention with backup. Retention does not survive an attacker holding admin credentials. Budget the third-party target at kickoff, rather than after a restore test fails.
- Do not leave the notification path untested. The 72-hour window starts the moment your brokerage determines the incident is material. A broker-of-record who has never opened the form spends the first hour finding it.
- Do not treat the policy as a one-time deliverable. MBRCC expects it re-signed annually and updated when something material changes. A 2022 policy nobody has reviewed since is its own finding.
“We had MFA on every lender portal and a backup we tested every week. What we did not have was a signed page saying so. The MBRCC framework cared about the page.”
How FSRA’s 2025-26 enforcement context raises the stakes
Worth being precise here, because the number gets stretched. That CA$875,000 is one fiscal year, not a multi-year run, and none of the published matters is a cyber matter. What changed is the standing obligation. GR0016INT took effect April 1, 2024, and it applies whether or not a supervision plan names IT risk as a theme.
In fact the 2025-26 Mortgage Brokering Supervision Plan does not name IT risk and does not mention MBRCC at all. I flag that because brokerages sometimes wait for a plan to name a topic before treating it as live. The guidance is the obligation.
For what an enforcement-grade finding actually contains, see the FSRA mortgage brokerage penalty teardown.
How much reasonable cybersecurity costs a 12-agent brokerage in 2026
The honest answer for a 12-agent Ontario brokerage on Microsoft 365 Business Premium: roughly CA$50 to CA$100 a month in incremental tooling, mostly the backup add-on, plus CA$3,500 to CA$5,500 one-time for the 12-week implementation, plus a managed-services retainer that varies with scope.
MBRCC does not require a brokerage to spend more than that. It expects deliberate choices, written down. Most 12-agent brokerages I meet overspend on tools and underspend on the document trail. Reverse the ratio and the examination gets easier.
Further reading and primary sources
- MBRCC Principles for Cybersecurity Preparedness (PDF).
- FSRA IT Risk Management Guidance (GR0016INT).
- CCCS Baseline Cyber Security Controls.
- OSFI Technology and Cyber Risk Management guideline.
- PIPEDA, Justice Canada consolidation.
HOW THIS GUIDANCE WAS ASSEMBLED.
This draws on anonymized client data from Fusion Computing’s 2025 and 2026 Ontario mortgage brokerage engagements, an FC internal benchmark of MBRCC readiness reviews, and first-person field observation from my own practice since 2012.
Frequently asked questions
How many cybersecurity principles did the MBRCC actually publish?
Four: responsibility and resourcing, identification and prevention of risks, incident monitoring and detection and response, and third-party management. FSRA adopted them via guidance MB0048INF effective August 18, 2022. The nine in this post’s title is my count of implementation controls decomposed from those four principles, and that decomposition is where the widely repeated nine-principle claim comes from.
What is the FSRA incident notification window for mortgage brokerages?
Practice 7 of GR0016INT asks a regulated entity to notify as soon as is reasonable, normally within 72 hours or sooner, after determining that an IT risk incident is material. Guidance MB0048INF names the channel: the IT risk inbox at [email protected] and the Incident Notification Portal. The clock starts at the materiality determination, not at the incident.
What makes an incident material?
FSRA publishes no numeric threshold, so an Ontario brokerage sets and documents its own. The 4 triggers I use are borrower SIN or T4 income data exposed, a lender-portal credential confirmed compromised, ransomware on any device holding deal files, or a disruption that stops the brokerage meeting client commitments. Writing the test into the IR plan removes the judgment delay during a live incident.
Can a 12-agent brokerage meet Principle 4 without a governance platform?
Yes. At this size the Principle 4 evidence is a SharePoint folder of vendor attestations, meaning SOC 2 reports, ISO 27001 certificates or completed questionnaires, refreshed annually at the quarterly governance review. A governance platform is operational sugar. What the framework asks is that the brokerage reviewed each vendor, documented the review, and can produce it.
Does Microsoft 365 Business Premium meet the technical baseline on its own?
Roughly 80% of it. Business Premium bundles MFA enforcement, conditional access, Microsoft Entra ID P1, Intune for device management and patching, and Defender for Business for endpoint detection. The two gaps are immutable third-party backup and the documentary evidence trail. Adding backup and running the quarterly cadence covers the remaining 20%.
Where does borrower SIN data live, and which principle covers it?
Usually in three places: the deal-submission platform such as Filogix Expert or Velocity, the document-signing service, and any agent-side spreadsheet or PDF in Microsoft 365. Principle 2 requires the brokerage to know which systems hold it, and Principle 4 covers the posture of those third parties. Note that FINTRAC record-keeping rules impose a separate 5-year retention duty on the same files.
Is cyber liability insurance required under Principle 1?
The principle asks a brokerage to consider it, not to carry it. In practice, for 12 agents handling borrower SIN and T4 income data, a CA$1 to CA$2 million policy covering recovery, notification, ransom and regulatory action runs roughly CA$2,500 to CA$5,000 a year. Insurers ask for evidence of MFA, endpoint detection, backup and a written IR plan before quoting.
Do these principles apply outside Ontario?
Yes. MBRCC is a pan-Canadian framework adopted by multiple provincial regulators, including FSRA in Ontario and the Financial and Consumer Services Commission in New Brunswick. A brokerage operating in several jurisdictions implements one control set and maps it to each adopter. The GR0016INT notification window is Ontario-specific, and other provinces set their own thresholds.
FINANCIAL-SERVICES BROKERAGE DEEP DIVES (2026 CLUSTER)
Bottom line
MBRCC is four principles, outcome-based, sized to fit a 12-agent brokerage on Microsoft 365 Business Premium. My decomposition turns them into nine controls, a 12-week deployment, roughly CA$50 to CA$100 a month in incremental tooling, and a folder of nine documents as the evidence package.
Reviewed by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited.

