Governance, risk & compliance
CIRO Cybersecurity Program - Dealer Members 2026
RegionalCanada
The cybersecurity obligations and expectations CIRO (the Canadian Investment Regulatory Organization) places on its Dealer Members.
Two layers. The binding layer is the Investment Dealer and Partially Consolidated Rules: section 3703 requires an initial cybersecurity incident report to CIRO within 3 calendar days of discovery and a follow-up within 30 calendar days, section 3704 makes failure to report an offence in itself, and sections 4710 to 4714 require a business continuity plan that is reviewed and tested annually.
The guidance layer is the three documents CIRO publishes - the Cybersecurity Self-Assessment Tool, the Cybersecurity Best Practices Guide, and the Cyber Incident Management Planning Guide. The Best Practices Guide is organized on the NIST Cybersecurity Framework functions, so the domains here follow the guide's own section numbering.
Pick the tier that matches how far along your program is - the tiers stack, so the top tier includes everything below it. This framework replaces the retired IIROC framework; IIROC amalgamated with the MFDA on 1 January 2023 to form CIRO.
Official reference: https://www.ciro.ca/office-investor/guides-and-resources
Assessment tiers & levels Lavawall supports
Lavawall assesses CIRO Cybersecurity Program - Dealer Members at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Baseline - Self-Assessment | The starting point, modelled on the CIRO Cybersecurity Self-Assessment Tool for Dealer Members. Roughly 40 questions covering whether the basics exist at all: a written policy, an owner, an asset list, backups, multi-factor authentication, training, and a plan for when something goes wrong. Right-sized for a small dealer doing this for the first time. Note that CIRO does not publish the Self-Assessment Tool as a download - a Dealer Member requests a copy from CIRO through the form on the guides and resources page. | Yes |
| Best Practices Guide | The full Cybersecurity Best Practices Guide for Dealer Members, section 3.1 through 3.15: governance and risk management, personnel screening and insider threat, physical security, awareness and training, threat and vulnerability assessment, network security, information system protection, account management and access control, asset management, incident response, information sharing and breach reporting, cyber insurance, vendor risk management, and cyber policy. Includes everything in the Baseline tier. | Yes |
| Incident Management | Adds the Cyber Incident Management Planning Guide in full - the five phases (plan and prepare, detect and report, assess and decide, respond, post-incident activity), the incident response team, the incident checklists, and the IDPC Rule 3703 reporting clock. Choose this tier if you are building or testing an incident response capability, or if CIRO has asked about your incident readiness. Includes both tiers below it. | Yes |
How Lavawall® helps you get to CIRO Cybersecurity Program - Dealer Members compliance
Most of CIRO Cybersecurity Program - Dealer Members comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CIRO Cybersecurity Program - Dealer Members, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against CIRO Cybersecurity Program - Dealer Members in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Ready to tackle CIRO Cybersecurity Program - Dealer Members?
Assess, remediate, and stay audit-ready for CIRO Cybersecurity Program - Dealer Members — and every other framework you carry — from one Lavawall® console.
Lavawall® supports CIRO Cybersecurity Program - Dealer Members as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.