CSA Provides Guidance on Disclosure of Cyber Security Risks
On January 19, 2017, the Canadian Securities Administrators (CSA) published Multilateral Staff Notice 51-347 Disclosure of cyber security risk and incidents (the “Staff Notice”) reporting on the CSA’s review of cyber security-related disclosure. The notice is part of a series of initiatives being undertaken by Canadian securities regulators to assist market participants in understanding, mitigating and providing effective disclosure of potential cyber security risks.
CSA Staff Review of Cyber Security Disclosure
Cyber security was identified as a priority area by the CSA in their 2016-2019 Business Plan. In September 2016, the CSA published Staff Notice 11-332 Cyber Security, which noted that cyber attacks have become more frequent, complex and costly for organizations. In that context, the CSA announced that it would undertake a review of cyber security-related disclosure by larger Canadian issuers. The CSA’s review focused on whether and how issuers had disclosed (1) potential impacts of cyber attacks on their businesses, (2) the kind of material information that could be exposed as a result of attacks, and (3) governance and cyber security risk mitigation initiatives, including who is responsible for the issuer’s cyber security strategy. The review also searched for disclosure of previous cyber security incidents.
The CSA noted that 61% of the issuers reviewed addressed cyber security in their risk factor disclosure and that issuers in a wide variety of industries acknowledged cyber security as a material risk to their business. Issuers recognized a range of potential impacts from cyber security incidents, including:
- access to, and/or comprising of, proprietary or sensitive information, including confidential customer or employee information;
- loss of revenues due to disruption of business activities;
- litigation and regulatory costs;
- reputational harm affecting customer and investor confidence; and
- devaluation of intellectual property.
The CSA also noted that while a few issuers disclosed that they had been subject to cyber attacks in the past, no issuers had disclosed specific incidents as being material.
CSA Staff Guidance for Issuers
Not surprisingly, the CSA Staff expects issuers to be thoughtful about the cyber security risks they are subject to, to avoid boilerplate language and to provide disclosure that focuses on material information that is specific to the issuer. CSA members expected that to the extent issuers have determined that cyber security risk is a material risk, they will provide risk disclosure that is as detailed and “entity specific” as possible. There is an express expectation that specific risks will be disclosed, rather than generic risks applicable to all issuers, and that disclosure will be tailored to the specific circumstances of the issuer.
In preparing risk factor disclosure regarding cyber security matters, the CSA expects that issuers will consider (among other things):
- the reasons they may be exposed to a potential breach;
- the source and nature of the breaches;
- the potential consequences of the breach;
- insurance coverage in case of the breach;
- identifying the group or individuals responsible for the issuer’s cyber security; and
- where required, apply disclosure controls and procedures under National Instrument 52-109 Certification of Disclosure in Issuers’ Annual and Interim Filings to detected cyber security incidents.
At the same time, the CSA does not expect issuers to disclose sensitive information that could compromise their cyber security risk mitigation strategies.
The CSA also reminds issuers to consider whether a specific security incident might be a material change that requires immediate disclosure or a material fact that requires disclosure as part of issuers’ ongoing reporting obligations. Materiality in this context depends on the circumstances of the security breach. For example, an isolated minor breach may not be material but a series of minor breaches may become material in light of the level of disruption caused. The determination of whether an incident is material is a dynamic process through the detection, assessment and remediation process of a cyber security incident and depending on the circumstances, disclosure could be required before that process is complete.
In light of the CSA’s stated focus on cyber security, the general recognition by all market participants that most entities are subject to some degree of material cyber security risk, and the potential for liability if material cyber security risks are not appropriately disclosed, issuers and their boards of directors would be well advised to formalize their framework for assessing the particular cyber security risks and evaluating and implementing appropriate risk mitigation strategies. This will not only assist issuers in providing timely and effective disclosure, but in developing and implementing effective strategies for mitigating cyber security risk and monitoring possible cyber security breaches.
Expertise
Authors
Insights
-
Capital Markets
SCC Affirms Broad and Contextual Interpretation of “Material Change”
The Supreme Court of Canada (SCC) has provided further guidance on what may constitute a “material change” under Ontario securities law and the leave test for bringing a claim for failure to make… -
Capital Markets
CSA Proposes Amendments to Align Non-GAAP Financial Measures Disclosure Framework with IFRS 18
On November 13, 2025, the Canadian Securities Administrators (CSA) published a notice and request for comment regarding proposed amendments to National Instrument 52-112 – Non-GAAP and Other Financial… -
Capital Markets
Canadian Securities Administrators Propose Semi-Annual Reporting Pilot Project
On October 23, 2025, the Canadian Securities Administrators (CSA) announced a pilot project to allow certain venture issuers to voluntarily adopt semi-annual financial reporting (the “SAR Pilot”). The… -
Capital Markets
Pre-Budget Consultations by The Coalition to Support Investment in Canada
On August 27, 2025, The Coalition to Support Investment in Canada made written submissions in response to the Canadian government’s 2025 pre-budget consultations. The submissions seek to foster… -
Capital Markets
The Going Public Alternative
Since 2023, publicly listed Canadian senior living companies1 have generated strong returns for investors and have been some of the best performing issuers in Canada’s public real estate sector. With… -
Capital Markets
Successful Exercise of Dissent Rights Reaffirms Importance of Transaction Price
In a rare example of a successful exercise of statutory dissent rights, a group of shareholders dissenting from a court-approved merger recently obtained a fair value determination five times above…
Featured Work
-
Banking and Financial Services
Doman Building Materials Group completes reopening of C$170 million senior notes
Goodmans LLP advised Doman Building Materials Group Ltd. in connection with the closing of its offering of an additional C$170 million aggregate principal amount of its 7.50% Senior Unsecured Notes… -
Capital Markets
Brookfield Corporation completes C$250 million preferred share offering
Goodmans LLP acted as counsel for the underwriters in connection with the offering by Brookfield Corporation (“Brookfield”) of 10,000,000 Class A Preference Shares, Series 54 (“Preferred Shares… -
Banking and Financial Services
Algoma Steel secures C$500 million in government financing facilities
Goodmans LLP acted for Algoma Steel Group Inc. in connection with its C$500 million financing transaction with the Governments of Canada and Ontario… -
Capital Markets
Brookfield Infrastructure Corporation announces at-the-market equity issuance program
Goodmans LLP acted as Canadian counsel for the agents in connection with the “at-the-market” equity issuance program (the “ATM Program”) of Brookfield Infrastructure Corporation (the “BIPC… -
Capital Markets
CIBC Capital Markets leads C$700 million Oxford Properties Group Trust debt offering
Goodmans LLP acted for CIBC Capital Markets and the agents in connection with their role as Joint Bookrunner for a C$700 million senior unsecured notes offering for Oxford Properties Group Trust… -
Capital Markets
Brookfield Asset Management Ltd. announces aggregate US$1 billion cross-border senior notes offering
Goodmans LLP is acting as Canadian counsel for the underwriters in connection with a public offering by Brookfield Asset Management Ltd. (“BAM”) of (i) US$600 million principal amount of senior notes…
News & Events
-
Banking and Financial Services
Goodmans Receives Top-Tier Recognition from The Legal 500 Canada 2026
We are pleased to announce Goodmans has once again received top-tier recognition from The Legal 500 Canada in their 2026 Guide.Recognition from The Legal 500 is based on independent research and… -
Banking and Financial Services
IFLR1000 2025 Recognizes Goodmans Lawyers and Practices
We are proud to announce Goodmans is once again recognized by IFLR1000 in its annual guide.Recognition in IFLR1000 is based on a combination of in-depth qualitative research and direct client… -
Banking and Financial Services
Goodmans Recognized in the Best Law Firms - Canada 2026
Goodmans is pleased to share we are once again featured in the Best Law Firms - Canada 2026, recognizing us as one of Canada’s most exceptional law firms across 42 industries and practices.We are also…