Icon chevron up
Here's a dismissible notice for cookies notices etc.
Dismiss
Server racks in a data centre

IT Compliance Support in Ontario

Regulated organizations are rarely asked whether they are secure. They are asked to evidence it, with records, on a deadline, in a format somebody else specifies.

This page sets out what Ontario organizations are commonly asked to produce and the part an IT provider plays in producing it. It describes obligations generally and is not legal advice: what applies to you depends on your sector, your registrations and your contracts.

What a reviewer is actually asking for

Frameworks, questionnaires and audit requests differ in wording and converge on the same four demands. No product satisfies them on its own, which is why the work lands on IT.

1
The control exists

Something is configured that addresses the risk: access is restricted, data is encrypted, the account requires a second factor. This is the part vendors sell, and it is the smallest part of the exercise.

2
It is applied consistently

The control covers everyone and everything in scope, not head office and not most laptops. An undocumented exception reads far worse than a documented one with a reason and a date attached.

3
It can be demonstrated over a period

A screenshot proves a Tuesday. Evidence means logs, reports and records covering months, which requires the logging to have been switched on and retained long before anybody asked to see it.

4
Somebody is accountable for it

A named owner, a review cadence, and a record of what was reviewed and when. Outsourcing the work never outsources the responsibility, which is why supplier agreements now get read closely.

Healthcare, dental and PHIPA

Ontario's Personal Health Information Protection Act places responsibility on the health information custodian for safeguarding personal health information and for being able to say who has accessed it. That responsibility sits with the practice rather than with its suppliers; an IT provider acts as an agent on the custodian's instructions. What it looks like in daily practice is consistent, and so are the gaps.

Custodians routinely ask suppliers to sign an agreement covering how information is handled and what happens on termination. That is a reasonable thing to ask of any provider, including us.

Financial services and insurance

Firms in investment, lending, brokerage and insurance answer to sector regulators and, increasingly, to their own carriers. What applies depends on the registrations a firm holds, so treat the list below as the common core rather than a complete set.

Cyber and business-interruption insurance has become the other de facto regulator. Application and renewal forms now ask directly about multi-factor authentication, endpoint detection, backup immutability, privileged access management and end-of-life operating systems. Those answers are warranties rather than aspirations, which makes accuracy more valuable than optimism: a control claimed but not in place is exactly what surfaces during a claim.

Legal and professional services

Duties of confidentiality and safekeeping extend to the electronic file, and firms now face a second layer imposed by clients themselves. Outside counsel guidelines commonly specify encryption, access control, notification timelines and a right to audit, and they carry commercial consequences rather than professional ones.

The same shape applies to accountants, engineering practices and consultancies working under a client security schedule. Where the requirement comes from a client rather than a regulator, the deadline is usually shorter.

Security questionnaires and customer-run reviews

For a growing number of Ontario businesses the toughest reviewer is not a regulator. It is an enterprise customer's procurement team, a prime contractor's prequalification, or a public-sector vendor assessment. The questionnaire arrives with a deadline and a contract waiting behind it. These are answerable, but rarely in a week, because most of what they ask about has to have been true for months.

“Describe your network segmentation.”
→ A current diagram with the boundaries named
“What is your patching cadence?”
→ A policy, plus a report showing it happening
“How is administrative access controlled?”
→ An inventory and a dated review record
“Who responds to an alert overnight?”
→ Named coverage hours and an escalation path
“What is your recovery time objective?”
→ A figure you have tested, not one you hope for
“Is your own supply chain assessed?”
→ Including the IT provider, in writing

Where the questions are aimed at your provider rather than at you, an independent attestation shortens the exercise. Our controls are examined under a SOC 2 Type 2 attestation, which assesses how they operated across a period rather than on one convenient day. That is our attestation, covering our environment and processes. It does not certify our clients, and no provider's attestation substitutes for the controls inside your own business.

The baseline underneath all of it

Beneath the sector rules sits a general federal baseline. PIPEDA governs how organizations handle personal information in the course of commercial activity, and its breach provisions carry a detail that catches people out: organizations must keep records of breaches of security safeguards, and that record-keeping is not confined to the ones meeting the reporting threshold. The requirement presumes a log exists before anything goes wrong.

Businesses taking card payments carry PCI DSS obligations through their payment brands and acquirers. Scope and assessment route depend on how cards are processed and how many transactions are involved, so the starting point is your acquirer rather than a generic checklist. The recurring themes are separation of the payment environment from staff and guest networks, current patching, restricted administrative access, and logging that can be produced on request. Multi-site operators carry the obligation at every location, which makes consistency the difficulty.

Public-sector contracts add their own security schedules. The practical consequence is identical wherever the requirement originates: controls have to be configured, maintained and evidenced continuously, and that is largely an IT function.

What an IT provider does, and what it cannot do

What the provider does
  • Implements and maintains the technical controls: identity, access, encryption, patching, monitoring, backup and recovery.
  • Produces the evidence: reports, logs, inventories, review records and diagrams, in a form a reviewer will accept.
  • Answers the technical sections of questionnaires and audit requests, and says plainly where an answer would be inaccurate.
  • Raises gaps before an auditor does, with the risk and the cost of closing them stated.
What the provider cannot do
  • Certify your organization. Compliance is assessed by regulators, auditors and customers, never by a supplier.
  • Guarantee an outcome. No provider can promise a review will be passed, and one that does is promising something outside its control.
  • Own the obligation, which stays with the custodian, the registrant or the contracting party.
  • Replace legal or compliance advice on what applies to you, which is a question for counsel or a compliance advisor.

Read that division of labour as the useful part rather than the disclaimer. Reviews are rarely failed because a product was missing; they fail because nobody was clear about who produced which piece of evidence. The questions worth putting to any provider, including us, are in our guide to choosing an IT provider.

Frequently asked questions

Can an IT provider make us compliant?

No, and it is worth being blunt about that. A provider implements and maintains technical controls and produces evidence that they operated. Whether an organization meets its obligations is determined by its regulator, its auditor or its customer, and the responsibility stays with the organization.

A customer has sent a security questionnaire with a two-week deadline. Is that realistic?

The paperwork is; the underlying position may not be. Questions about patching cadence, monitoring coverage and recovery testing ask about a period rather than a day. If the controls have been running, answering is a collation exercise. If not, answer accurately and state what is being remediated and by when. Reviewers accept a credible plan far more often than an overstated answer.

What does SOC 2 Type 2 mean, and does it cover us?

It is an independent examination of how a service organization's controls operated across a period rather than at a single point. Ours covers our own environment and processes, which is what your auditor asks about when they look at the supplier holding administrative access to your systems. It does not extend to your systems or make your organization compliant.

Do we have to keep records of breaches that were not reportable?

Under PIPEDA, organizations must keep records of breaches of security safeguards, and that obligation is not limited to breaches meeting the reporting threshold. The practical implication is that logging and an incident record have to exist in advance, because neither can be reconstructed afterwards. Confirm the specifics with your privacy advisor.

Our requirement comes from a contract rather than a regulator. Is that different?

The mechanics are the same and the deadline is usually tighter. Contractual security schedules specify controls precisely and grant a right to audit, so evidence has to be producible on request. Read the schedule before signing rather than at renewal.

Facing an audit, a questionnaire or a renewal?

If you have a deadline and questions you cannot yet answer, we will work through them with you and be straightforward about what is in place and what is not. Our head office is at 141 Main Street N, Markham ON L3P 1Y2, and the number is 647-476-5259.

Close search

Search