SECURITY RESOURCE CENTER

Cybersecurity frameworks, threat intelligence, and training resources

A curated reference for businesses navigating compliance requirements across Canada, the United States, and internationally. Updated regularly with the latest framework versions, threat landscape data, and training resources.

Last updated: July 2026

CURRENT THREAT LANDSCAPE

What businesses are facing right now

Compiled from published threat reports by CrowdStrike, Mandiant, CISA, the Canadian Centre for Cyber Security, and Verizon DBIR. This summary reflects the most significant trends affecting North American businesses.

CRITICAL

Ransomware & Multi-Front Extortion

Still the most financially damaging threat to mid-market businesses. The RaaS model keeps the barrier to entry low, and encryption-plus-data-leak extortion is standard. 2025 added a harder lesson: operational shutdown is often the real cost — major retailers and manufacturers lost weeks of operations to intrusions that started with a single phone call to a help desk. Recovery costs for mid-market businesses routinely run into seven figures (Sophos State of Ransomware).

Healthcare Manufacturing Retail Professional Services Education
CRITICAL

AI-Enabled Social Engineering & Agentic Attacks

Generative AI has made phishing nearly indistinguishable from legitimate communication, and voice cloning made the phone a primary attack vector (vishing grew 442% through 2024, per CrowdStrike). Reported cyber-crime losses hit a record $16.6B in 2024, with business email compromise accounting for $2.77B (FBI IC3). The newest development: attackers using AI agents to automate reconnaissance, intrusion, and extortion end-to-end, documented in incident disclosures by AI vendors through 2025.

All Industries Finance Executive Teams
HIGH

Identity Attacks & Help-Desk Social Engineering

79% of initial-access detections are now malware-free (CrowdStrike 2025): stolen credentials, session hijacking, and MFA fatigue instead of malicious attachments. Average eCrime breakout time is down to 48 minutes; the fastest observed was under a minute. The signature technique of 2025 was simply calling the IT help desk and talking a human into a password or MFA reset. Phishing-resistant MFA (FIDO2/passkeys) and hardened reset procedures are the current bar.

Cloud-First Orgs Remote Workforces SaaS-Heavy
HIGH

Supply Chain & Third-Party Attacks

Third-party involvement in breaches doubled year-over-year (Verizon DBIR 2025). Recent campaigns hit the connective tissue: stolen OAuth tokens for SaaS integrations turned single vendor compromises into hundreds of downstream data thefts, and self-propagating malware reached the open-source package ecosystem. If a vendor holds your data, or a token that can reach it, their security posture is part of your attack surface.

SaaS Users MSP Clients Enterprise
ELEVATED

Cloud & SaaS Exposure

New cloud intrusions rose 26% year-over-year (CrowdStrike 2025). Misconfigurations, overly permissive IAM policies, and exposed storage remain the entry points, and large-scale data-theft campaigns against SaaS platforms showed that one weak integration or one admin account without MFA is enough. Most breaches aren't sophisticated: they exploit basics that were never locked down.

Cloud-Native Multi-Cloud Startups
ELEVATED

Edge Device & Vulnerability Exploitation

Vulnerability exploitation as an initial access vector grew 34%, with VPNs and edge appliances now the leading targets (Verizon DBIR 2025). Over 40,000 CVEs are published annually, and time from disclosure to active exploitation is measured in days, sometimes hours. If it faces the internet and patches slowly, it is being scanned right now. CISA's Known Exploited Vulnerabilities catalog is the practical patch-priority list.

Legacy Systems On-Prem Infrastructure VPN & Firewall Users
ELEVATED

Nation-State Pre-Positioning

State-sponsored groups spent 2024-2025 quietly embedding in telecommunications and critical infrastructure across North America, holding access rather than using it. Joint advisories from CISA, the FBI, and the Canadian Centre for Cyber Security detail living-off-the-land techniques that evade signature-based detection. This matters beyond critical infrastructure: these campaigns frequently route through the unpatched routers and edge gear of ordinary businesses.

Telecom Critical Infrastructure Government Suppliers
COMPLIANCE FRAMEWORKS

Framework directory by region

Direct links to the latest versions of major cybersecurity and privacy frameworks. Whether you need to comply with Canadian privacy law, US federal standards, or international requirements, start here.

Canada

PIPEDA

Current, under review

Personal Information Protection and Electronic Documents Act. Federal private-sector privacy law governing how businesses collect, use, and disclose personal information.

Applies to: All private-sector organizations operating across provincial borders

Bill C-27 (CPPA / AIDA)

Stalled — died on the Order Paper, Jan 2025

Digital Charter Implementation Act. Would have replaced PIPEDA with the Consumer Privacy Protection Act (CPPA) and introduced the AI and Data Act (AIDA). Died when Parliament was prorogued in January 2025; successor privacy legislation is expected but has not been re-tabled. PIPEDA remains in force.

Watch for: replacement privacy and AI legislation in the current Parliament

Quebec Law 25

Fully in force, final phase Sept 2024

Quebec's modernized private-sector privacy law, phased in from 2022 through 2024 and now fully in force, including data portability. Requires a designated privacy officer, breach reporting, privacy impact assessments, and carries significant administrative penalties.

Applies to: Any business handling Quebec residents' personal information

PHIPA (Ontario)

Current

Personal Health Information Protection Act. Ontario's health-sector privacy law governing custodians of personal health information.

Applies to: Healthcare providers, hospitals, pharmacies in Ontario

CCCS Guidance

Ongoing

Canadian Centre for Cyber Security publishes baseline security controls, advisory alerts, and sector-specific guidance for Canadian organizations.

Applies to: All Canadian organizations (recommended)

OPC Privacy Toolkit

Current

Office of the Privacy Commissioner compliance and training tools. Practical guidance for PIPEDA compliance including self-assessment tools.

Applies to: Businesses seeking PIPEDA compliance guidance

Bill C-8 (CCSPA)

In Parliament — reintroduced June 2025

Critical Cyber Systems Protection Act, reintroduced as Bill C-8 after its predecessor (Bill C-26) died at prorogation. Establishes cybersecurity programs, incident reporting, and compliance obligations for operators of critical systems in telecom, finance, energy, and transportation.

Applies to: Critical infrastructure operators in federally regulated sectors

United States

NIST CSF 2.0

Version 2.0, February 2024

NIST Cybersecurity Framework. The gold standard voluntary framework organized around six functions: Govern, Identify, Protect, Detect, Respond, Recover. Version 2.0 added the Govern function and expanded supply chain guidance.

Applies to: All organizations (voluntary, widely adopted)

SOC 2 Type II

Current, AICPA

Service Organization Control reports evaluating controls relevant to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover a sustained period of operation.

Applies to: SaaS companies, service providers, any org handling client data

PCI DSS 4.0.1

v4.0.1 — fully mandatory since March 2025

Payment Card Industry Data Security Standard for organizations that store, process, or transmit cardholder data. The transition is complete: all future-dated v4 requirements became mandatory on March 31, 2025. Key changes: customized approach, enhanced authentication, and targeted risk analysis.

Applies to: Any organization processing card payments

HIPAA

Current — Security Rule overhaul proposed Jan 2025

Health Insurance Portability and Accountability Act. Mandatory security and privacy protections for protected health information (PHI). HHS published a proposed Security Rule overhaul in January 2025 (mandatory encryption, MFA, asset inventories); the final rule is still pending.

Applies to: Healthcare providers, insurers, business associates

CMMC 2.0

v2.0 — phased enforcement began Nov 2025

Cybersecurity Maturity Model Certification. Required for Department of Defense contractors. Three levels: Foundational, Advanced, Expert. The program rule was finalized in December 2024 and the acquisition rule took effect in November 2025, putting CMMC requirements into new DoD contracts under a phased rollout.

Applies to: DoD contractors and subcontractors

CISA CPGs

Version 1.0.1, March 2023

Cross-Sector Cybersecurity Performance Goals. Voluntary, prioritized security practices for critical infrastructure. Designed as a quick-start guide for organizations that need to know "where to begin."

Applies to: Critical infrastructure (voluntary, recommended baseline)

FTC Act (Section 5)

Current, active enforcement

The FTC uses its authority over "unfair or deceptive practices" to enforce data security. No specific cybersecurity law, but the FTC has taken action against hundreds of companies for inadequate security practices.

Applies to: All US businesses (de facto enforcement)

NIST Privacy Framework 1.0

Version 1.0, January 2020

Voluntary framework for managing privacy risk. Designed to complement the Cybersecurity Framework. Organized around Identify, Govern, Control, Communicate, Protect.

Applies to: All organizations (voluntary)

International & EU

GDPR

Current, May 2018

General Data Protection Regulation. The EU's comprehensive data protection law with extraterritorial reach. Applies to any organization processing data of EU residents, regardless of where the organization is located.

Applies to: Any org processing EU resident data

NIS2 Directive

In force — member-state transposition ongoing

Network and Information Security Directive 2. Expanded scope covering essential and important entities across 18 sectors. Mandatory incident reporting within 24 hours, supply chain security, and management accountability with personal liability for executives.

Applies to: Essential & important entities operating in the EU

DORA

In force since January 2025

Digital Operational Resilience Act. EU regulation for financial sector ICT risk management. Covers ICT risk frameworks, incident management, digital operational resilience testing, third-party risk, and information sharing.

Applies to: EU financial entities and their ICT service providers

ISO/IEC 27001:2022

2022 edition — transition complete Oct 2025

International standard for information security management systems (ISMS). Certifiable framework covering 93 controls across organizational, people, physical, and technological domains. The transition window has closed: certificates against the 2013 edition expired October 31, 2025.

Applies to: Any organization seeking certification (global recognition)

EU Cyber Resilience Act

In force — reporting duties from Sept 2026

Mandatory cybersecurity requirements for products with digital elements sold in the EU. Manufacturers must ensure security throughout the product lifecycle, report actively exploited vulnerabilities (obligation begins September 2026), and provide security updates. Full application December 2027.

Applies to: Manufacturers and distributors of digital products in the EU

EU AI Act

In force — phasing through 2027

World's first comprehensive AI regulation, applying by risk tier. Now applying: prohibited practices and AI literacy duties (since Feb 2025) and general-purpose AI obligations (since Aug 2025). High-risk system requirements phase in through 2026-2027.

Applies to: Any org deploying or developing AI systems used in the EU

Not sure which frameworks apply to your business?

30 min free assessment
SOC 2 certified partners
24 hr response time