Canadian investment dealers
CIRO Cybersecurity Program Dealer Members
CIRO, the Canadian Investment Regulatory Organization, sets the cybersecurity obligations for its Dealer Members. Some of it is a binding rule you can be sanctioned for breaking; the rest is guidance CIRO expects you to follow and will ask about.
CIRO was formed on 1 January 2023 when IIROC and the MFDA amalgamated, so a lot of older material still says "IIROC." The obligations below are the current CIRO set, and they replace the retired IIROC framework.
Who this applies to
- Investment dealers registered with CIRO.
- Mutual fund dealers now regulated under CIRO after the MFDA amalgamation.
- Portfolio managers and advisors operating inside a Dealer Member.
If you are a registered firm that is not a CIRO Dealer Member, the rules that apply to you are the CSA's, in Staff Notice 33-322. See CSA 33-322.
The binding layer: the IDPC Rules
These are the Investment Dealer and Partially Consolidated (IDPC) Rules. They are enforceable, and one of them makes not reporting an offence on its own.
- Rule 3703 — incident reporting. Report a cybersecurity incident to CIRO with an initial report within 3 calendar days of discovery, and a follow-up report within 30 calendar days.
- Rule 3704 — failure to report. Failing to report under 3703 is itself a breach, separate from the incident. The clock is the thing regulators look at first.
- Rules 4710–4714 — business continuity. Maintain a business continuity plan, and review and test it every year.
The reporting clock in one line
Discovery → initial report to CIRO within 3 calendar days → follow-up within 30. Miss it and Rule 3704 is a second problem on top of the incident.
The guidance layer: what CIRO publishes
Three documents carry CIRO's expectations. They are not rules in the 3703 sense, but an examiner will expect to see you working from them.
- Cybersecurity Best Practices Guide. The main one, organized on the functions of the NIST Cybersecurity Framework, covering governance, risk management, personnel and insider threat, physical security, awareness and training, threat and vulnerability assessment, network security, account and access control, asset management, incident response, information sharing, cyber insurance, and vendor risk.
- Cyber Incident Management Planning Guide. Five phases: plan and prepare, detect and report, assess and decide, respond, and post-incident activity.
- Cybersecurity Self-Assessment Tool. The baseline questionnaire. CIRO does not publish it for download; a Dealer Member requests a copy through the guides and resources page.
- Incident Reporting Summary. CIRO's summary of what and how members have reported, useful for calibrating your own reporting.
Three levels we scope it at
The tiers stack, so the top level includes everything below it. Pick the one that matches how far along your program is.
| Level | What it covers |
|---|---|
| Baseline — Self-Assessment | The CIRO Self-Assessment Tool: roughly 40 questions on whether the basics exist at all — a written policy, an owner, an asset list, backups, MFA, training, and an incident plan. The right starting point for a small dealer. |
| Best Practices Guide | The full Best Practices Guide, sections 3.1 through 3.15. Includes the Baseline. |
| Incident Management | Adds the Cyber Incident Management Planning Guide in full and the Rule 3703 reporting clock. Choose this if you are building or testing incident response, or CIRO has asked about your readiness. Includes both levels below it. |
How Lavawall® maps CIRO
Most of the Best Practices Guide is technical controls you have to run and prove. Lavawall runs those and keeps the evidence current, so a CIRO review is a report you export, not a scramble.
- Controls, mapped. MFA, patching, access review, backups, network monitoring, and vendor risk map straight onto the Best Practices Guide sections.
- Evidence, continuous. Timestamped records of the technical controls, ready for an examiner or an insurer.
- The 3703 clock, supported. Breach detection surfaces the incident early, which is the only way the 3-day report is comfortable rather than frantic.
- Business continuity, tracked. Evidence that the plan under 4710–4714 was reviewed and tested this year.
CIRO and NIST CSF overlap on purpose.
Because the Best Practices Guide is built on the NIST CSF functions, the work you do for one carries most of the way to the other. If you already run NIST CSF, you are most of the way to CIRO.
Frequently asked questions
An initial report within 3 calendar days of discovery, and a follow-up within 30, under IDPC Rule 3703. Not reporting is a separate breach under Rule 3704.
No. CIRO does not publish it for download. A Dealer Member requests a copy from CIRO through the guides and resources page.
IIROC amalgamated with the MFDA on 1 January 2023 to form CIRO. The CIRO program replaces it, and existing assessments against the old IIROC framework remain readable.
ThreeShield's CISSP- and CISA-certified team can scope CIRO with you and run the assessment. Rule and guidance references are summarized for planning; confirm the current CIRO text before certifying.