CyberSecure Canada certification for Ontario CFDCs Recorded March 6, 2024. Historical webinar transcript. Obvious transcription errors in Complade and CFDC names corrected. Spoken wording retained; other transcription errors may remain. For current guidance and corrections: https://www.complade.com/webinars/cybersecure-canada-ontario-cfdcs-2024#current-guidance 0:00 see the title d uh title of the session is demystifying 0:04 the cybersecurity canada certification and 0:07 we've been working with Complade on um helping the southern CFDCs get through 0:13 those final stages of the certification and they have some valuable 0:17 uh information and resources that they'd like to talk to you about so i'll let 0:21 them take over the meeting and 0:24 i know that i have to leave a little bit early so i won't be here at the end but 0:27 denise will be here and keeping an eye on the chat and after any comments or 0:31 questions so uh doing the presentation today will be bronwyn from Complade 0:36 and take it away 0:39 thanks anna and hello everybody uh welcome to our 0:44 webinar um we had another webinar in november 0:48 i'm not sure if anyone was present for that but um 0:52 previously we talked about um sort of the financial risks of cyber security 0:57 and the implications of that and sort of what you can do and what kind of costs 1:02 they'd be running you on average and sort of setting up the situation to deal 1:06 with now i understand we're at a stage 1:10 where we now need to do that and deal with it and sort of we've 1:14 taken in the costs and you know certain uh groups have received funding and um 1:19 sort of it's it's it's a great time and an opportunity to 1:22 move forward with that but it can be a little bit daunting um it can look like 1:28 a long process a lot of things to sort of muddle through a lot of technical 1:32 language so today our objective is really to 1:37 strip away some of that technical jargon and just let you know 1:41 what you're looking at what the process will be like 1:44 and break down the concepts a little bit so that you can hopefully have a greater 1:48 understanding and not have to rely so heavily on people totally outside of 1:53 your sphere and what you do on the daily basis 1:57 so just to begin 2:00 this is me um bronwyn i am the analyst for Complade and i'm usually giving 2:05 these presentations and i am sort of the go-between 2:10 client relations whatever i wear i wear many hats but if at any point you want 2:15 to reach out to me for any questions or to 2:17 get in contact with anybody from our company 2:20 um or you need help um directing where to go 2:24 you can always email me my contact information will be at the end 2:27 so let's get started just to let you know about Complade we are a cyber 2:32 security standards conformity auditor uh we deliver an informed sense of 2:37 assurance that your risks and controls are in balance and so we partner with 2:41 boards of directors and senior management teams to solve cyber security 2:44 assurance and governance challenges we provide impartial audits tailored to 2:48 your organizational objectives based on de jour standards that's just our 2:54 little disclaimer at the beginning and here's our certificate um showing we 3:00 are an accredited management system certification body 3:04 that means we can give you the certification and complete your audits 3:07 given to us by the standards council of canada who's the one who decides um 3:12 basically who does and does get these things if you're qualified we bought the 3:16 qualification from them and there's our certificate 3:19 um and just to let you know as another disclaimer we are one of four groups in 3:23 canada who offer this um what they call certification bodies 3:27 those have been accredited by standards council of canada or scc 3:31 um we offer you 3:34 the ability to connect with any of these i understand bulletproof for example has 3:39 a long-standing relationship with CFDCs do the tech part uh we're just kind of 3:43 coming into the game here to offer um educational services and let you know 3:48 what's up so that hopefully you can learn from us 3:52 the agenda today we will just talk a little bit about 3:56 what all of this means from financial audits and something you might 4:01 be a little more familiar with to a cyber security audit which likely you 4:04 are not unless you have done most of the process or better yet completed it 4:08 um to understand the cybersecure canada ecosystem 4:12 um all the parts of the hole that make up the standard that it is now 4:17 the pasta certification what you actually need to do to achieve the 4:20 certificate and the next steps that you should take 4:23 um after today hopefully starting this afternoon and then we'll open up at the 4:27 end to a q a so from financial audits to a cyber 4:32 security audit we will start with something that i hope 4:36 everyone here is very familiar with the gap principles in accounting 4:42 um basically 4:45 if um what we think is a great way to understand a new concept is to take old 4:51 concepts and apply the parallels there you know this is a new system that 4:56 everyone in the world is getting used to cyber security is obviously relatively 5:00 new reflective of technology and all the advancements over the last 5:04 you know couple decades and especially five years or so 5:08 whereas accounting and financial audits are all very familiar to us because 5:12 they have been the standard for a long time and for most of our working lives 5:16 and something that we just know that we have to do we have to do taxes every 5:20 year we have to do our business audits we have to keep our books we've all 5:23 worked with cpas we've all worked with bookkeepers 5:26 um you know it's just something that we're used to and something that we 5:29 don't say like okay like should we get this done it just it just is 5:33 and we we sort of hope that as we coast along with this industry that cyber 5:38 security audits will be something that just are as well uh they're incredibly 5:43 crucial and it's not yet clear to a lot of people 5:46 why they're as crucial as your financial audits but um 5:50 they follow sort of a similar framework so we will get into that 5:55 so this is a graph that i think everyone will recognize as well 5:59 just to um give some background that um basically for the past 25 years the 6:06 annual financial audit has served as a pivotal framework for corporate 6:11 integrity and transparency driven by historical necessities and much much 6:16 precedent such as this the enron scandal and the resulting sarbanes-oxley act the 6:21 sox act um basically 6:24 uh this shows a progression from a financial chaos to a structured 6:29 accountability where here you see stock prices fell so drastically in the year 6:34 2000 that basically 6:38 there had to be a scramble to come up with a standard to level it 6:42 and bring it to a place where everyone was 6:46 you know annually updating their information to make sure that it didn't 6:50 go all over the place you don't lose track of it because obviously then we 6:53 headed further towards a financial recession and i can only imagine that if 6:56 in 2008 if these standards weren't in place 7:00 how unaccountable businesses would have been 7:04 um how much people would have how much more we imagine people would have lost 7:07 how much more chaos it would have been and you know the thing to take away here 7:12 is that there is always going to be chaos so 7:15 the better controls we have in balance to mitigate those risks and the 7:21 resulting chaos hopefully not too much is to have a system 7:25 and like i said we have a new system here 7:29 cybersecure canada is just an example of it it's the one that you will all get 7:33 but there are versions of cybersecure canada all over the world for all 7:37 different kinds of businesses suiting all different kinds of needs and 7:40 they all adhere to these similar principles and structure as something 7:44 like gap that we use in accounting um 7:48 basically um you know it was and it was an optional 7:53 thing and like i said we'd like it to move a little bit 7:56 further from the trajectory of an optional precaution to a critical and 8:01 more standardized necessity um so that it mirrors the financial systems and 8:06 because just as financial standards like gaap have been instrumental in restoring 8:10 trust and stability in financial reporting 8:13 as is the principle of a standard itself cyber security standards such as iso 8:19 27001 you may have heard um very similar to cyber circuit canada 8:23 which we now have they have been developed to safeguard digital assets 8:26 and data just like financial ones safeguard your money 8:33 and how do we implement this accounting system in an organization 8:36 it's in four simple steps first of all you have a cpa who implements the 8:40 accounting system for your business then the cpa will recommend an 8:46 accounting tool such as quickbooks sage tools that again you will be familiar 8:51 with and that everybody uses this just shows how 8:55 these things can be complicated but once you use them you look at it as just 8:59 commonplace and yeah we we do that every day and you know a student can be 9:03 trained to do it fresh out of undergrad and 9:06 someone who's been in their career 35 years can probably learn how to do it 9:09 they're adoptable and that is great um 9:14 the next step crucially on that is that you 9:17 get everyone trained in it so the cpa will then branch out to train assistance 9:21 on bookkeeping and then eventually reach others in the organization 9:26 lastly another cpa a different impartial auditor outside of 9:31 this structure will audit the books and deliver your annual audit report 9:36 so how does this work for cybersecure canada 9:39 well there is a standard that we follow um 9:44 some of you may have seen it we are more than happy to send it out or 9:48 to go through it with you at a later date 9:51 um this is the standard that lets you know we'll take a quick look at the 9:55 index here exactly what your organization needs to do to meet the 9:59 requirements to get that certificate um i think there are 18 different 10:04 controls and points that you need to meet um we won't go through it too 10:08 detailed but basically there are the organizational controls so that's the 10:12 main points within your organization your actual employees in your office 10:15 which is the leadership the accountability cyber security 10:19 training and cyber security risk assessment which looks at your exact 10:22 organization who's working there what do you need to do 10:26 who's in charge who's going to be accountable for getting all of this done 10:30 then the actual nitty-gritty which is the baseline 10:33 controls you need to create an incident response plan 10:36 patch your operating system make sure your software is up to 10:40 date make sure you have a system for your devices whether you bring your own 10:43 phones whether the phones need to have work done whether the 10:48 company issues phones etc etc um these are all the little things that you will 10:52 encounter on your way that you need to keep track of and 10:55 um there's quite a lot but it does all fit on this one page so it is definitely 10:59 manageable um 11:02 to understand that you need to understand the ecosystem of a cyber 11:06 security um organize a certification basically 11:10 what are the parts to this hole that we're talking about 11:14 so achieving the cybersecure canada certification does require a structured 11:19 ecosystem quite similar to that of the financial auditing as we said 11:23 and it's comprised of several parts one implementers that's just like your cpa 11:28 they are certified professionals such as cyber security lead implementers trained 11:33 in setting up cyber security environments following iso 27003 and 11:38 other relevant guidelines like this one then you have your grc tools grc stands 11:43 for the cyber security governance risk management and compliance 11:47 they range from spreadsheets um you know using excel basically logging things 11:53 writing them down keeping lists to more specialized software like vanta drata 11:58 and maple grc these are tools that the implementers use 12:02 which support the implementation and ongoing activities of your cyber 12:06 security management finally you have your independent 12:09 auditors just like that second cpa who comes in there is an auditor who has to 12:13 who hasn't been a part of your process initially 12:16 um and they haven't looked at anything until you are prepared to do your audit 12:20 they are accredited certification bodies by the standard council of canada like 12:24 us so just to map out what they look like 12:28 the implementer starts out just like the cpa 12:32 implementing your system then they recommend a tool to use just 12:36 like your quickbooks or sage which um is you know used by a specialist and then 12:42 given to everyone else so that people can train and learn it as a commonplace 12:46 tool just as we use excel the implementer will then train 12:50 assistants and further the rest of the company and hopefully it spreads and the 12:54 cybersecurity auditor finally audits your cyber security and delivers your 12:58 annual audit report very similar system following different 13:02 standards and dealing with slightly different information 13:05 but basically an audit is an audit we have all done them and they can be 13:11 time consuming and taxing but um once you understand the system and you 13:16 have professionals in place to help you it can be 13:19 quite painless and not take too long so the path to certification uh what 13:25 does it look like basically you take that initial 13:29 implementation phase and ideally you arrive at a place where you are just 13:33 maintaining and all the work is done and after your initial audit is done we hope 13:38 that you're in a place where again you know what to do you're familiar with the 13:41 system you have people in place to deal with everything and you just maintain 13:45 you just tweak little things you know if you hire 13:48 someone new you let them know if you totally change 13:52 your software and your systems you adjust that to show that that's what 13:55 you're going to be using in three main parts we begin with the 13:59 initial implementation establishing the security framework 14:04 within the organization guided by the standards and facilitated by certain 14:08 implementers step one the initial implementation looks a 14:12 little bit like this this is basically what do you do when you begin the 14:17 process how do we actually do the audit how does 14:20 it work we start with a security manual that is your policy 14:25 and the document that you are going to generate that says 14:29 we are going to adhere to cybersecure canada because we are going to do this 14:34 this and this now that's all well and good to have a 14:38 claim a policy that says you're going to do something but you know who's going to 14:42 implement that who's going to check up on it what's in it where do you begin 14:46 how do you organize that how do you structure it the next step is the 14:50 standard and guideline procedures describes who what when and where so 14:53 that's who's in charge who's doing it who's being trained on this 14:59 you know who works here who uses what computer etc 15:02 then you have your working checklists forms and controls that describes how 15:07 the specific tasks and activities are done so we take an example of we were 15:12 just talking about a restaurant when you have your your health checkups when the 15:16 health inspector comes and they have to make sure 15:18 you know okay you say that this is a a clean and sanitary 15:22 restaurant but who is in charge of that that takes number one is your claim your 15:27 policy number two is the management and the employees who uh implement this and 15:32 enforce this number three your working checklist forms controls that's your 15:36 chart on the bathroom for daily cleaning that's who signed off on who mopped in 15:40 the kitchen just a 15:43 list that keeps everybody accountable and organized of what exactly needs to 15:46 be done and how that will work and then finally number four that is your 15:50 material evidence your records what is going into everything so when 15:56 someone says okay yes we made a form 16:00 but also here's the inventory for the cleaning products that we bought and 16:04 this is where they're kept and here's the book of all the previous logs from 16:07 the past six weeks of all the cleanings and basically everything that you 16:11 collect and use is evidence so that when the auditor comes and says okay 16:15 well i see that you have a form in place to show that you're doing this but where 16:19 is the evidence to show that you've been doing this for the last 11 months since 16:23 i've been here because one day of cleaning is obviously not sufficient to 16:27 prove that you adhered to their to your policy so that's your bulk of records 16:31 and that's the paperwork that you can have a little help with collecting 16:34 because it can be pretty overwhelming i would say that of all the parts 16:38 looking at all of your stuff and thinking what do we do with all of this 16:41 is probably the most daunting so um 16:45 that's why the system is here to just begin at step one and break it down 16:48 piece by piece then the certification process itself 16:53 undergoing a rigorous audit by an independent certified auditor to verify 16:58 adherence to cybersecure canada standards culminating in the issuance of 17:01 the certification much like your annual financial report that is a certificate 17:06 that you will get from cybersecure canada 17:08 um it looks a little bit okay next step so basically we look at 17:16 our process like i laid it out number one that you have to do in this process 17:20 is submit your documents that's after you've done everything 17:24 from the initial implementation here once you've looked at your steps when 17:28 you've got gathered everything once you've worked with an implementer to 17:31 figure out you know how are we going to organize this and then how are we going 17:34 to make it into basically a package of 17:37 documents that we give in to the auditor that is the first thing that you do once 17:42 you are ready to give it into the auditor once you have done your 17:44 implementation once once you have slogged through all of your work all of 17:48 your documents made sure that everything is checked off in the cyber secure 17:52 canada standards list you've reached all 18 17:54 points you've generated a policy that says you are going to reach all 18 17:58 points then you take all of that and you give it to your auditor 18:02 what they will do is begin stage one which is once they have access to your 18:06 documents they will um look it over 18:10 um make sure that there's nothing missing um you know get you to a place 18:16 where you and they will collectively decide that you're ready for stage two 18:19 where then you sit together with the auditor online in person whatever works 18:23 for you you basically have one day set aside 18:26 to be with your auditor where they look at your documents and they say okay we 18:30 took a look you prepared we let you know what we you needed to fix let's make 18:35 sure and the auditor will ask you questions like 18:37 okay have all your employees done the training for 18:41 uh let's say phishing one that we all know 18:44 does everybody know how to recognize you know scam links and emails okay yes they 18:48 do right well then who are your employees 18:51 let's see that all the employees have taken the training you will need some 18:54 evidence of that you know screenshots people giving 18:58 certificates from completing trainings online whatever you have collected to 19:02 show that your employees have indeed completed the trainings and can 19:06 demonstrate knowledge that they gain from it 19:08 once that is finished the auditor will um take a look at everything they will 19:14 let you know absolutely if um i'll just go next to let you know here 19:19 they will go across all the requirements one by one and they will see policy 19:23 procedure and proof of it happening like i said evidence or a screenshot 19:27 important to note they will share with you what is missing so it's not like an 19:30 exam at school where if you're missing something you don't pass and then you 19:34 begin all over again the point of sitting all day with the auditor is 19:38 because rather than them taking a couple hours to independently review your 19:41 information they want to share with you what you can do and give you the 19:45 opportunity to fix it you will have then six months to fix what is missing and 19:50 share that with them if there are major things missing like nobody completed 19:55 training highly highly unlikely and no implementer would recommend you go into 19:59 your audit without that but for example if there's something missing they will 20:02 let you know and it will be you know pretty obvious and they'll say look you 20:06 need to complete this and this is what you need to do and here's who you can 20:09 work with and whatever and there are always opportunities to fix things 20:14 once you're on the system basically you are set up to succeed it is not set up 20:18 to make you fail and once it's fixed you will get 20:22 certified um after let's go back to our process 20:27 here uh just to 20:30 sort of summarize the last two points here the annual surveillance and the 20:33 re-certification the important thing to know is that it is an ongoing process 20:38 they're sort of once you get your certificate it does certify you for two 20:41 years but it's a little confusing because your 20:44 policy will say you know we declare that we are going to 20:48 do this this and this within the next year and they need to check up on you at 20:51 the end of that year to make sure that you did in fact do everything that you 20:54 claimed you were going to do in your audit there's sort of a surveillance 20:57 audit just to make sure that everything is going well and 21:00 um get you that certificate you know 21:03 lasting your second year at the end of that second year you will then need to 21:06 recertify because several things in an organization can change in a year just 21:11 like we do our taxes every year just like we do any audits they're cyclical 21:15 and they have to reflect the evolving rotating nature of not only 21:20 cyber security threats the new things that can come up new things that you may 21:23 have to train employees on but your organization what turnover you may have 21:27 what new revenue you may take in what new 21:30 organizational systems you might implement 21:32 so basically um it's pretty manageable like i said 21:36 once you have done the whole bulk of the thing all subsequent ones are just 21:41 an issue of maintenance and you just need to like update it as it goes along 21:45 it will get easier and easier once an organization we hope in the future has 21:49 done 40 50 of these it will just be a quick thing that you need to set aside a 21:53 little time to do every year so 22:00 this is basically just an example of the audit report um 22:04 it will let you know you know 22:07 you can you can take a look at what the auditor is going to do 22:11 sort of the limitations um the classification of what means a major 22:17 non-conformity what is a minor non-conformity like what's a big thing 22:20 that you're missing and what's not a big deal 22:23 what is absolutely necessary to have in there what needs to be fixed sooner 22:26 rather than later what it will look like 22:29 um you will know basically for all steps in this process exactly what it will 22:33 look like beforehand and you will be i hope 100 prepared 22:38 and this is the certificate you'll get this is what it will look like you can 22:42 display the seal here it will be personalized to your organization you 22:46 can display it on your website it's really great for 22:49 clients and all your future stakeholders board 22:52 members just to let them know that it's something that you put time into 22:58 and that you care about safeguarding their data their financial information 23:02 it's a great sense of assurance and not only does it establish trust with your 23:06 clients but your boards the people that are giving you money the people that you 23:09 work with it's a whole system and we talked about the concept of an ecosystem 23:13 it's really important to maintain trust accountability transparency make sure 23:18 that everything is above board and that's basically why we have standards 23:21 and um this is just sort of a fun thing that you get you can print it out frame 23:26 it just like any other certificate um 23:31 and this is the seal that cybersecure canada will give you 23:34 and then this is a custom seal that we will give you 23:39 so the ongoing maintenance what do you do once you get your certification 23:43 and basically how does that work it's the continuous monitoring 23:49 um of um 23:54 an updating of your cybersecurity practices to ensure your compliance with 23:58 like i said the evolving landscape of cyber threats and standards but also of 24:02 your organization what does that require quarterly 24:05 training you know updating on new things you need to train employees on or new 24:09 employees that need to be trained from the get 24:12 monthly checking access to your systems for example prior employees that don't 24:16 have access making sure that someone has left the company that they don't still 24:20 have access their passwords are changed they're removed from the system the due 24:23 diligence is done appointing updating your software when you get those little 24:27 reminders that say you know please update your computer tonight whatever 24:31 just try to click yes and all that kind of thing once you go into this process 24:35 it will be very clear with you what is worth it to maintain and what you need 24:39 to be doing on a regular basis so 24:43 let's take a little breather here because this was a lot of information 24:47 it's sort of you know it's all well and good to say 24:51 okay this is how the certification works but you may not be at that stage you may 24:54 have no idea what iso is or what security logs are or patches or 25:00 softwares or all this kind of thing so the question is what do you do now 25:04 regardless of what stage you're at whether you are just beginning 25:08 whether you are looking down the barrel at the day that you have to get this 25:11 done or you are one step away and you're ready to do your audit next week if 25:15 that's the case call us but basically we need to let you know 25:19 what are the next steps regardless of what stage you're at 25:22 so you find an implementer first of all to help you out that can help you 25:26 hugely to muddle through the system and implement the cybersecure canada 25:30 standard it's not something that you individually as an organization every 25:34 single member needs to intricately understand the standard 25:37 but you do have to have an idea of the gist of it and an implementor is a 25:41 professional who works with something like this 25:44 to help you there to help you understand it 25:46 next once you've done your implementation once you've worked 25:50 through and reached met all the requirements of the standard 25:53 you will reach out to a certification body to get certified 25:57 then all you have to do like i said is maintain your system 26:01 and of course every year you will renew it you will complete the yearly audits 26:05 that will be a breeze as long as you're maintaining 26:09 so where to find an implementer you want to make sure that your implementer has 26:14 iso lead implementer certification that's the classification that says that 26:19 they can take you 26:21 from your information that you have now and get it to the standard of cyber 26:25 secure canada or whatever standard you're meeting whatever certification it 26:28 is you want to achieve um many implementers work with 26:32 many different kinds of certification they're all kind of similar when it 26:35 comes down to it it's just the nitty-gritty of what certification 26:38 you're trying to achieve here we're trying to do cybersecure canada so we 26:42 are more than prepared because um everybody is working towards the same 26:46 goal which is great and your implementer will certainly 26:51 uh be able to get you there they will have the ability to lead you there here 26:54 are examples of some implementers you can use 26:57 drada maple six clicks they're all over the place if you sort of muddle through 27:02 and um you wanna use somebody who like we 27:06 said has that lead implementer certification um basically who is able 27:11 to work with you um help you use this tool the grc tools um like using 27:17 quickbooks and help your organization get on board with that and get all your 27:21 information built into a software that hopefully is you know highly specialized 27:25 and um can take what you have and sort of 27:28 organize it automatically and make it not look like a huge bulk of documents 27:32 but rather a well-oiled machine with easy to read charts that kind of thing 27:37 so once you are implemented once all of that is done you need to reach out to a 27:41 cybersecure canada accredited certification body 27:44 now here again are some examples here are the four that can issue you the 27:48 cybersecure canada certification um 27:52 if you look online at different certification bodies they do 27:56 offer you know iso and the various other 27:59 certifications you may seek to achieve after cyber secure canada but we will 28:03 start here and so here is your scope then basically all you need to do is 28:09 keep running your security management system to keep a sense of assurance of 28:13 course that your cyber risks and controls are in balance now that is a 28:17 statement that basically encapsulates what it is we are doing here we just 28:21 want to create a sense of assurance we want to 28:24 make everybody feel okay about their systems we want to make it so that 28:28 people aren't hearing news articles about hacks that are happening every day 28:33 and thinking that we are plummeting towards the equivalent of a financial 28:36 crisis in the cyber security world and say well we're going to get ahead of 28:41 this and do what needs to be done give 28:44 yourself a sense of assurance instead of seeing the news articles and saying oh 28:47 my god like do i need to change my password what do i do to prevent us 28:51 being hacked and all of our client data being leaked well this is exactly what 28:54 you need to do just gives you peace of mind assurance 28:58 is just you thinking okay i've done what needs to be done i've done 29:02 cybersecure canada as a standard for a reason they tell you what they think 29:06 needs to be done in your organization to get you to a point where all of those 29:10 risks are in balance and you know exactly how to mitigate them if and when 29:13 the time comes so for the CFDCs here we have 29:19 um for our audit should you work with us and should you be at a stage where 29:24 you're ready to do audit you're completed your implementation the stage 29:28 one and stage two so the part where the auditor actually works with you with 29:31 your data takes your documents and then reviews it 29:35 together with you is 29:38 just over a thousand here we have a little bit of a 29:41 discount for the CFDCs um because we've been working with you guys for a little 29:45 while and because you're a collective 29:48 organization with whom we like to build trust and that sense of 29:51 assurance as well um we 29:56 basically uh can't because we are auditors we have 30:00 to remain impartial we can't offer you that implementation 30:03 but when you are ready we will be here when you're at the stage where hopefully 30:08 all of that hard work is done and you're ready to just give over your documents 30:11 to us get that audit and get that beautiful certificate we will be here 30:15 when you need and so in conclusion here we'll just 30:20 sort of give a statement of um 30:24 what it is we need to remember about the audits here and 30:28 especially cater to businesses like the cfdc small financial services 30:32 organizations we know that navigating the complexities of the cybersecurity 30:37 world and all of this language and this whole process can be very daunting 30:42 however by understanding i hope the parallel between financial audits and 30:47 cyber security certification we hope that leaders board members 30:52 executive directors everybody involved in your organization can eventually get 30:56 on board and understand this language by appreciating the importance of 31:00 cybersecure canada and a certification like this in establishing a robust cyber 31:06 security posture the certification not only enhances an 31:09 organization's security measures but also reinforces its credibility and 31:13 trustworthiness in the eyes of stakeholders 31:16 as digital threats continue to evolve embracing standards such as a 31:20 cybersecure canada will be pivotal in safeguarding the future of financial 31:24 services organizations and all of the sensitive data that you manage 31:30 so we will open it up now to a quick q a if anybody has questions um 31:35 we have a couple of us here from uh Complade 31:39 um if you have questions about anything in 31:42 the presentation if you have questions about what should you do next and 31:47 particular to your organization anything that you like we are here to answer so i 31:51 will open up the floor to start um also yeah yeah just posted in the 32:01 chat here if anybody needs full details for the certification process 32:06 um you can go to our website we'll have that displayed here and i will 32:11 show it helpful here at the end if you need to ask specific questions you need 32:16 a little more time of it you can email me you can set up a meeting give us a 32:19 call come by your office whatever you like um 32:22 yes hand raised and