
Regulated organizations are rarely asked whether they are secure. They are asked to evidence it, with records, on a deadline, in a format somebody else specifies.
This page sets out what Ontario organizations are commonly asked to produce and the part an IT provider plays in producing it. It describes obligations generally and is not legal advice: what applies to you depends on your sector, your registrations and your contracts.
Frameworks, questionnaires and audit requests differ in wording and converge on the same four demands. No product satisfies them on its own, which is why the work lands on IT.
Something is configured that addresses the risk: access is restricted, data is encrypted, the account requires a second factor. This is the part vendors sell, and it is the smallest part of the exercise.
The control covers everyone and everything in scope, not head office and not most laptops. An undocumented exception reads far worse than a documented one with a reason and a date attached.
A screenshot proves a Tuesday. Evidence means logs, reports and records covering months, which requires the logging to have been switched on and retained long before anybody asked to see it.
A named owner, a review cadence, and a record of what was reviewed and when. Outsourcing the work never outsources the responsibility, which is why supplier agreements now get read closely.
Ontario's Personal Health Information Protection Act places responsibility on the health information custodian for safeguarding personal health information and for being able to say who has accessed it. That responsibility sits with the practice rather than with its suppliers; an IT provider acts as an agent on the custodian's instructions. What it looks like in daily practice is consistent, and so are the gaps.
Custodians routinely ask suppliers to sign an agreement covering how information is handled and what happens on termination. That is a reasonable thing to ask of any provider, including us.
Firms in investment, lending, brokerage and insurance answer to sector regulators and, increasingly, to their own carriers. What applies depends on the registrations a firm holds, so treat the list below as the common core rather than a complete set.
Cyber and business-interruption insurance has become the other de facto regulator. Application and renewal forms now ask directly about multi-factor authentication, endpoint detection, backup immutability, privileged access management and end-of-life operating systems. Those answers are warranties rather than aspirations, which makes accuracy more valuable than optimism: a control claimed but not in place is exactly what surfaces during a claim.
Duties of confidentiality and safekeeping extend to the electronic file, and firms now face a second layer imposed by clients themselves. Outside counsel guidelines commonly specify encryption, access control, notification timelines and a right to audit, and they carry commercial consequences rather than professional ones.
The same shape applies to accountants, engineering practices and consultancies working under a client security schedule. Where the requirement comes from a client rather than a regulator, the deadline is usually shorter.
For a growing number of Ontario businesses the toughest reviewer is not a regulator. It is an enterprise customer's procurement team, a prime contractor's prequalification, or a public-sector vendor assessment. The questionnaire arrives with a deadline and a contract waiting behind it. These are answerable, but rarely in a week, because most of what they ask about has to have been true for months.
Where the questions are aimed at your provider rather than at you, an independent attestation shortens the exercise. Our controls are examined under a SOC 2 Type 2 attestation, which assesses how they operated across a period rather than on one convenient day. That is our attestation, covering our environment and processes. It does not certify our clients, and no provider's attestation substitutes for the controls inside your own business.
Beneath the sector rules sits a general federal baseline. PIPEDA governs how organizations handle personal information in the course of commercial activity, and its breach provisions carry a detail that catches people out: organizations must keep records of breaches of security safeguards, and that record-keeping is not confined to the ones meeting the reporting threshold. The requirement presumes a log exists before anything goes wrong.
Businesses taking card payments carry PCI DSS obligations through their payment brands and acquirers. Scope and assessment route depend on how cards are processed and how many transactions are involved, so the starting point is your acquirer rather than a generic checklist. The recurring themes are separation of the payment environment from staff and guest networks, current patching, restricted administrative access, and logging that can be produced on request. Multi-site operators carry the obligation at every location, which makes consistency the difficulty.
Public-sector contracts add their own security schedules. The practical consequence is identical wherever the requirement originates: controls have to be configured, maintained and evidenced continuously, and that is largely an IT function.
Read that division of labour as the useful part rather than the disclaimer. Reviews are rarely failed because a product was missing; they fail because nobody was clear about who produced which piece of evidence. The questions worth putting to any provider, including us, are in our guide to choosing an IT provider.
No, and it is worth being blunt about that. A provider implements and maintains technical controls and produces evidence that they operated. Whether an organization meets its obligations is determined by its regulator, its auditor or its customer, and the responsibility stays with the organization.
The paperwork is; the underlying position may not be. Questions about patching cadence, monitoring coverage and recovery testing ask about a period rather than a day. If the controls have been running, answering is a collation exercise. If not, answer accurately and state what is being remediated and by when. Reviewers accept a credible plan far more often than an overstated answer.
It is an independent examination of how a service organization's controls operated across a period rather than at a single point. Ours covers our own environment and processes, which is what your auditor asks about when they look at the supplier holding administrative access to your systems. It does not extend to your systems or make your organization compliant.
Under PIPEDA, organizations must keep records of breaches of security safeguards, and that obligation is not limited to breaches meeting the reporting threshold. The practical implication is that logging and an incident record have to exist in advance, because neither can be reconstructed afterwards. Confirm the specifics with your privacy advisor.
The mechanics are the same and the deadline is usually tighter. Contractual security schedules specify controls precisely and grant a right to audit, so evidence has to be producible on request. Read the schedule before signing rather than at renewal.
If you have a deadline and questions you cannot yet answer, we will work through them with you and be straightforward about what is in place and what is not. Our head office is at 141 Main Street N, Markham ON L3P 1Y2, and the number is 647-476-5259.