IIROC Adopts Rules Regarding Mandatory Reporting Of Cybersecurity Incidents

SE
Stikeman Elliott LLP
Contributor
Stikeman Elliott LLP logo
Stikeman Elliott is a global leader in Canadian business law and the first call for businesses working in and with Canada. We provide clients with the highest quality counsel, strategic advice, and creative solutions. Stikeman Elliott consistently ranks as a top law firm in our primary practice areas. www.stikeman.com
In November 2019, the Investment Industry Regulatory Organization of Canada (IIROC) announced amendments to its Dealer Member Rules and IIROC Dealer Member Plain Language Rule Book.
Canada Technology
To print this article, all you need is to be registered or login on Mondaq.com.

In November 2019, the Investment Industry Regulatory Organization of Canada (IIROC) announced amendments to its Dealer Member Rules and IIROC Dealer Member Plain Language Rule Book to require that dealers report any cybersecurity incidents to IIROC within three days of discovery.

Under the amendments, a "cybersecurity incident" is defined to include "any act to gain unauthorized access to, disrupt or misuse a Dealer Member's information system, or information stored on such information system, that has resulted in, or has a reasonable likelihood of resulting in:

  1. substantial harm to any person,
  2. a material impact on any part of the normal operations of the Dealer Member,
  3. invoking the Dealer Member's business continuity plan or disaster recovery plan, or
  4. the Dealer Member being required under any applicable laws to provide notice to any government body, securities regulatory authority or other self-regulatory organization.

The amendments require that the report to IIROC include such information as the date and description of the cybersecurity incident, as well as a preliminary assessment of the risk of harm. Further, within 30 days of the incident, dealers must provide IIROC with a follow-up report that includes information such as an assessment of the scope of the incident, details of the steps taken to remediate any harm, and actions planned to improve cybersecurity preparedness.

The amendments went into effect on November 14, 2019. For more information, see IIROC Notice 19-0194.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

IIROC Adopts Rules Regarding Mandatory Reporting Of Cybersecurity Incidents

Canada Technology
Contributor
Stikeman Elliott LLP logo
Stikeman Elliott is a global leader in Canadian business law and the first call for businesses working in and with Canada. We provide clients with the highest quality counsel, strategic advice, and creative solutions. Stikeman Elliott consistently ranks as a top law firm in our primary practice areas. www.stikeman.com
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More