Cyber security for credit unions and insurers in Canada

Canadian credit unions and insurers are expected to run cyber security as a governed risk owned by the board and executives. Federally regulated institutions work to OSFI Guideline B-13 on technology and cyber risk and Guideline B-10 on third-party risk. Provincially regulated credit unions and insurers answer to their provincial regulator, which in British Columbia is the BC Financial Services Authority (BCFSA), with its own Information Security and Outsourcing Guidelines.

The detail differs by regulator. The direction does not: a named owner for cyber risk, controls you can show working, vendors you actually oversee, and a board that sees the picture regularly.

Which regulator covers your institution

Start here, because it decides which guidance an examiner will hold you to. OSFI supervises federally regulated financial institutions. An insurer incorporated federally answers to OSFI for prudential matters; one incorporated in BC answers to BCFSA. An insurer incorporated elsewhere that writes business in BC is also authorized by BCFSA and carries BCFSA obligations, including incident reporting, alongside those of its home regulator. Most credit unions are provincially regulated, and in BC that is also BCFSA.

For a BC credit union or a BC-incorporated insurer, the documents an examiner works from are BCFSA’s own: the Information Security Guideline and the Outsourcing Guideline, published on its credit union and insurance guideline pages. Read those first. OSFI’s B-13 and B-10, below, are their federal counterparts and cover the same ground in more detail. If you are unsure which applies, ask your regulator or your counsel. We are not lawyers; we work alongside your counsel.

What OSFI Guideline B-13 expects

Guideline B-13 sets OSFI’s expectations for technology and cyber risk management. It is organized in three domains: governance and risk management, technology operations and resilience, and cyber security.

In practice that means a technology and cyber risk framework with clear accountability, an accurate inventory of assets, change and patch management that works, tested recovery, and the ability to detect and respond to attacks. None of it is exotic. The hard part is evidence that it runs every month, not just in the week before a review.

Third-party risk under Guideline B-10

A credit union rarely runs its own core banking platform. An insurer usually relies on outside claims, policy and cloud systems. Guideline B-10 sets OSFI’s expectations for managing those arrangements across their whole life: due diligence before signing, contract terms, ongoing monitoring and a workable exit.

A core banking provider with access to member records is a good test case. If you cannot say who reviews its security reports and how often, that is the gap. We set up this work as a vendor risk management programme.

What examiners look for

Examiners tend to test whether the framework on paper matches what happens. Common questions:

  • Who owns cyber risk, and does the board receive regular reporting?
  • Is there a current risk assessment that drives the security plan?
  • Have incident response and recovery been exercised, with lessons recorded?
  • Are critical vendors identified, assessed and monitored?
  • Does the internal audit function or a second line review the controls?

A tabletop exercise with the executive team is one of the most direct ways to produce evidence on the third point.

What boards look for

Boards read trends and exceptions, not tool output. Cyber KRIs the board will read gives examples.

The governance structure behind that reporting is covered on cyber risk and governance. Member and policyholder data usually lives in a handful of core databases, and a database security review is a practical way to check who can reach it.

Questions we are asked

Who regulates cyber security for a credit union or insurer in Canada?

It depends on how the institution is incorporated. Banks, federally incorporated insurers and federal credit unions are supervised by OSFI for prudential matters. Most credit unions, and insurers incorporated in a province, answer to the provincial regulator, which in BC is BCFSA. An insurer incorporated federally or in another province that does business in BC is also authorized by BCFSA, which has its own expectations of it, including incident reporting.

Does OSFI B-13 apply to a provincial credit union?

Not directly. B-13 is written for federally regulated financial institutions. A BC credit union works to BCFSA’s own Information Security Guideline and Outsourcing Guideline. B-13 is the federal counterpart: public and detailed, and a useful second reference once your own regulator’s guideline is covered.

What does a board want to see on cyber risk?

Boards want to know whether cyber risk sits within appetite, which risks do not, and what is being done about them. A short set of indicators with trends and named owners answers that better than a technical dashboard.

Are we responsible for our vendors’ security?

Yes. Outsourcing a service does not outsource the accountability for it. The institution still has to know what each critical vendor does, how it is monitored, and what happens if the vendor fails or is breached.

Preparing for your next examination

Tell us who regulates you and what the last examination or board review raised. For contract-driven frameworks such as PCI DSS, see regulated sector readiness. More pieces are listed on writing.

Discuss a scope