Global fintech and funding innovation ecosystem

Global Governance Insights on Emerging Risks

Bleu Azur Consulting | June 17, 2018

A HEIGHTENED FOCUS ON RESPONSE AND RECOVERY

Over a third of directors of US public companies now discuss cybersecurity at every board meeting. Cyber risks are being driven onto the agenda by

  • high-profile data breaches,
  • distributed denial of services (DDoS) attacks,
  • and rising ransomware and cyber extortion attacks.

The concern about cyber risks is justified. The annual economic cost of cyber-crime is estimated at US$1.5 trillion and only about 15% of that loss is currently covered by insurance.

MMC Global Risk Center conducted research and interviews with directors from WCD to understand the scope and depth of cyber risk management discussions in the boardroom. The risk of cyberattack is a constantly evolving threat and the interviews highlighted the rising focus on resilience and recovery in boardroom cyber discussions. Approaches to cyber risks are maturing as organizations recognize them as an enterprise business risk, not just an information technology (IT) problem.

However, board focus varies significantly across industries, geographies, organization size and regulatory context. For example, business executives ranked cyberattacks among the top five risks of doing business in the Asia Pacific region but Asian organizations take 1.7 times longer than the global median to discover a breach and spend on average 47% less on information security than North American firms.

REGULATION ON THE RISE

Tightening regulatory requirements for cybersecurity and breach notification across the globe such as

  • the EU GDPR,
  • China’s new Cyber Security Law,
  • and Australia’s Privacy Amendment,

are also propelling cyber onto the board agenda. Most recently, in February 2018, the USA’s Securities and Exchange Commission (SEC) provided interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents.

Regulations relating to transparency and notifications around cyber breaches drive greater discussion and awareness of cyber risks. Industries such as

  • financial services,
  • telecommunications
  • and utilities,

are subject to a large number of cyberattacks on a daily basis and have stringent regulatory requirements for cybersecurity.

See:  Bithumb $31 Million Crypto Exchange Hack: What We Know (And Don’t)

Kris Manos, Director, KeyCorp, Columbia Forest Products, and Dexter Apache Holdings, observed, “The manufacturing sector is less advanced in addressing cyber threats; the NotPetya and WannaCry attacks flagged that sector’s vulnerability and has led to a greater focus in the boardroom.” For example, the virus forced a transportation company to shut down all of its communications with customers and also within the company. It took several weeks before business was back to normal, and the loss of business was estimated to have been as high as US$300 million. Overall, it is estimated that as a result of supply chain disruptions, consumer goods manufacturers, transport and logistics companies, pharmaceutical firms and utilities reportedly suffered, in aggregate, over US$1 billion in economic losses from the NotPetya attacks. Also, as Cristina Finocchi Mahne, Director, Inwit, Italiaonline, Banco Desio, Natuzzi and Trevi Group, noted, “The focus on cyber can vary across industries depending also on their perception of their own clients’ concerns regarding privacy and data breaches.”

LESSONS LEARNED: UPDATE RESPONSE PLANS AND EVALUATE THIRD-PARTY RISK

The high-profile cyberattacks in 2017, along with new and evolving ransomware onslaughts, were learning events for many organizations. Lessons included the need to establish relationships with organizations that can assist in the event of a cyberattack, such as l

  • aw enforcement,
  • regulatory agencies and recovery service providers
  • including forensic accountants and crisis management firms.

Many boards need to increase their focus on their organization’s cyber incident response plans. A recent global survey found that only 30% of companies have a cyber response plan and a survey by the National Association of Corporate Directors (NACD) suggests that only 60% of boards have reviewed their breach response plan over the past 12 months. Kris Manos noted, “[If an attack occurs,] it’s important to be able to quickly access a response plan. This also helps demonstrate that the organization was prepared to respond effectively.”

Experienced directors emphasized the need for effective response plans alongside robust cyber risk mitigation programs to ensure resilience, as well as operational and reputation recovery. As Jan Babiak, Director, Walgreens Boots Alliance, Euromoney Institutional Investor, and Bank of Montreal, stressed, “The importance of the ’respond and recover’ phase cannot be overstated, and this focus needs to rapidly improve.”

Directors need to review how the organization will communicate and report breaches. Response plans should include preliminary drafts of communications to all stakeholders including customers, suppliers, regulators, employees, the board, shareholders, and even the general public. The plan should also consider legal requirements around timelines to report breaches so the organization is not hit with financial penalties that can add to an already expensive and reputationally damaging situation. Finally, the response plan also needs to consider that normal methods of communication (websites, email, etc.) may be casualties of the breach. A cyber response plan housed only on the corporate network may be of little use in a ransomware attack.

Other lessons included the need to focus on cyber risks posed by third-party suppliers, vendors and other impacts throughout the supply chain. Shirley Daniel, Director, American Savings Bank, and Pacific Asian Management Institute, noted, “Such events highlight vulnerability beyond your organization’s control and are raising the focus on IT security throughout the supply chain.” Survey data suggests that about a third of organizations do not assess the cyber risk of vendors and suppliers. This is a critical area of focus as third-party service providers (e.g., software providers, cloud services providers, etc.) are increasingly embedded in value chains.

More:  The growing cost of cybersecurity

FRUSTRATIONS WITH OVERSIGHT

Most directors expressed frustrations and challenges with cyber risk oversight even though the topic is frequently on meeting agendas. Part of the challenge is that director-level cyber experts are thin on the ground; most boards have only one individual serving as the “tech” or “cyber” person. A Spencer Stuart survey found that 41% of respondents said their board had at least one director with cyber expertise, with an additional 7% who are in the process of recruiting one. Boards would benefit from the addition of experienced individuals who can identify the connections between cybersecurity and overall company strategy.

A crucial additional challenge is obtaining clarity on the organization’s overall cyber risk management framework. (See Exhibit 1: Boards Need More Information on Cyber Investments.) Olga Botero, Director, Evertec, Inc., and Founding Partner, C&S Customers and Strategy, observed, “There are still many questions unanswered for boards, including:

  • How good is our security program?
  • How do we compare to peers?

There is a big lack of benchmarking on practices.” Anastassia Lauterbach, Director, Dun & Bradstreet, and member of Evolution Partners Advisory Board, summarized it well, “Boards need a set of KPIs for cybersecurity highlighting their company’s

  • unique business model,
  • legacy IT,
  • supplier and partner relationships,
  • and geographical scope.”

Nearly a quarter of boards are dissatisfied with the quality of management-provided information related to cybersecurity because of insufficient transparency, inability to benchmark and difficulty of interpretation.

EFFECTIVE OVERSIGHT IS BUILT ON A COMPREHENSIVE CYBER RISK MANAGEMENT FRAMEWORK

Organizations are maturing from a “harden the shell” approach to a protocol based on understanding and protecting core assets and optimizing resources. This includes the application of risk disciplines to assess and manage risk, including quantification and analytics. (See Exhibit 2: Focus Areas of a Comprehensive Cyber Risk Management Framework.) Quantification shifts the conversation from a technical discussion about threat vectors and system vulnerabilities to one focused on maximizing the return on an organization’s cyber spending and lowering its total cost of risk.

See:  FSB warns of third-party FinTech risk

Directors also emphasized the need to embed the process in an overall cyber risk management framework and culture. “The culture must emphasize openness and learning from mistakes. Culture and cyber risk oversight go hand in hand,” said Anastassia Lauterbach. Employees should be encouraged to flag and highlight potential cyber incidents, such as phishing attacks, as every employee plays a vital role in cyber risk management. Jan Babiak noted, “If every person in the organization doesn’t view themselves as a human firewall, you have a soft underbelly.” Mary Beth Vitale, Director, GEHA and CoBiz Financial, Inc., also noted, “Much of cyber risk mitigation is related to good housekeeping such as timely patching of servers and ongoing employee training and alertness.”

Boards also need to be alert. “Our board undertakes the same cybersecurity training as employees,” noted Wendy Webb, Director, ABM Industries. Other boards are putting cyber updates and visits to security centers on board “offsite” agendas.

Continue to the full article --> here

 

Click for News:

 

September 15, 2026 | NCFA Market Activity | Lending Consumer Credit And BNPL, Embedded Finance, Artificial Intelligence And Data Zown Connects Rent Rewards, AI Search and Home Finance On September 15, 2026, Toronto-based Canadian proptech Zown updated its homebuying app with Rent Rewards alongside AI property search, affordability estimates, mortgage pre-approval and transaction services. Zown advertises up to 8% back on rent, giving it a reason to start working with consumers years before many will be ready to buy a home. The 8% combines two potential rewards. Zown Money says Zown currently provides up to 4% cashback directly on rent, while an eligible credit card can add up to another 4% depending on the card's terms. At C$2,500 in monthly rent, Zown's 4% portion would equal C$100 a month or C$1,200 a year. If a renter also earned the full additional 4% through their card, the total could reach C$200 a month or C$2,400 a year before any card or payment-related costs. The Canadian iPhone app, developed by Zown Realty Inc., also lets users upload a lease and proof of rent, search properties through an AI assistant called Zoro, view estimated affordability, request showings with licensed agents, seek mortgage pre-approval, ...
AI Image – Man outside a rental home using a rent rewards app to save toward homeownership
September 15, 2026 | NCFA Market Activity | Digital Banking And BaaS, Cross Border Payments And FX, Competition And Market Structure Wise Adds Everyday Canadian Payments Without Becoming a Bank On September 14, 2026, UK-based global payments company Wise launched a Chequing Account in Canada with no monthly fee, Interac e-Transfer support, Canadian account details, pre-authorized debits, debit-card access and multi-currency features. The launch takes Wise further into everyday Canadian financial activity while keeping the cross-border tools that built its original customer base. The account is available to personal and business customers in Canada. Customers can hold more than 40 currencies, receive money using account details available across 22 currencies and send money to more than 70 countries. Wise converts currencies at the mid-market rate and charges a separate conversion fee that currently starts from 0.19%, depending on the currency and transaction. Interac Makes Wise More Useful Day to Day Canadian customers can send up to C$25,000 to a supported Interac email address and receive up to C$25,000 per day through Interac Autodeposit. Wise doesn't charge its own fee to receive Autodeposit payments, and the September launch removed the Wise fee for sending CAD to an Interac alias and adding ...
AI Image – Illustration of a Canadian consumer using a multi-currency fintech chequing account on a smartphone for everyday banking and Interac payments
September 15, 2026 | NCFA Insight | Capital Markets And Market Infrastructure, Competition And Market Structure, Public Sector Policy And Industrial Strategy Nearly $500B In Commitments And A Proposed 6.4% Investment Tax Rate Today, on September 15, 2026, Canada's first Canada Investment Summit 2026 commitments reached nearly $500 billion across Canadian pension funds, insurers, banks, investment funds and a major AI infrastructure project. The September 14–15 summit in Toronto also brought together investors from nearly 30 countries managing more than $100 trillion in assets. The $500 billion isn't one pool of foreign equity. It combines institutional investment, bank financing and capital mobilization, investment funds and corporate infrastructure spending. A large share comes from Canadian institutions putting more capital to work at home while Ottawa tries to attract additional global investment. Canadian Institutions Supply Much Of The Capital Canadian pension funds, insurers and other institutional investors committed nearly $100 billion CPP Investments and Brookfield Asset Management launched the $50 billion Maple Fund for Canadian critical infrastructure and strategic industries PSP Investments plans another $25 billion of Canadian investment Ontario Teachers' Pension Plan committed an additional $10 billion by the end of 2027 Sun Life Financial committed $5 billion over five years ...
AI Image – Illustration of Canadian business investment, infrastructure and capital growth
Sep 15, 2026 Market volatility remains a persistent factor in wealth management, driving investors to seek strategies that balance capital stability with strategic diversification. While physical property has traditionally served as a tangible asset class, direct ownership often carries operational friction and localized concentration risk. Real estate funds present a structured alternative, pooling capital to access larger-scale assets under professional administration. However, evaluating these vehicles requires a realistic understanding of their risk profiles, liquidity terms, fee structures, and underlying statutory frameworks. Structural Trade-offs: Scale, Risk, and Liquidity Managed real estate portfolios offer distinct operational benefits while introducing clear structural constraints: Institutional Execution: Funds leverage pooled capital to negotiate institutional pricing, access commercial or multi-unit residential developments, and spread risk across multiple properties within the fund's mandate. Inflation Pass-Through and Fee Drag: Real estate often mitigates inflation through index-linked commercial leases or periodic residential rent adjustments. However, net investor returns are directly impacted by fund fee structures—typically including a 1–2% annual management fee and potential performance hurdles—which must be weighed against the ongoing maintenance and transaction costs of direct ownership. Operational Relief: Professional managers oversee tenant administration, maintenance, and legal compliance, removing the daily burdens associated with direct landlord responsibilities. Realistic ...
Image credit – Pexels, investment
September 14, 2026 | NCFA Insight | Cross Border Payments And FX, Payments Infrastructure And Money Movement, Digital Assets Blockchain And Tokenization, Competition And Market Structure New Delhi Declaration Advances Payment Interoperability On September 12, 2026, BRICS leaders met in New Delhi for the 18th BRICS Summit and backed further work connecting national payment and financial messaging systems. The New Delhi Declaration confirms that the BRICS Payment Task Force has been studying cross border interoperability and the use of local currencies for trade settlement and investment. BRICS hasn't yet created a common payment network or digital currency. However, payment interoperability has moved into an official technical workstream rather than remaining a series of proposals from individual members. The progression has been fairly quick. India proposed stronger payment and central bank digital currency connectivity in January. In August, Reserve Bank of India Governor Sanjay Malhotra confirmed that members were discussing links between fast payment systems and central bank digital currencies. The September declaration gives the Payment Task Force a formal basis to continue that work across the bloc. The commercial backdrop has also changed significantly since we last covered the 2023 BRICS summit. The group has expanded, supply chains have been ...
AI Image – 2026 BRICS Summit Advances Cross Border Payment Links
September 14, 2026 | NCFA Insight | Competition And Market Structure, Regulation And Policy, Capital Markets Infrastructure And Funding Routledge Speech Puts Growth and Competition Higher on OSFI Agenda On September 11, 2026, Superintendent Peter Routledge delivered a speech at the Economic Club of Canada, explaining how the Office of the Superintendent of Financial Institutions (OSFI) is refining its risk appetite. Financial resilience remains central, but OSFI is giving more weight to economic growth and competition when it decides whether a regulatory requirement is proportionate to the risk. For financial technology firms, smaller banks, federal credit unions and prospective entrants, the commercial question is whether those decisions make Canada's regulated financial market easier to enter and compete in. Some fintechs may eventually seek a federal bank, trust or loan company structure. Others need regulated partners that can support new lending, payments or financial products without the economics forcing every partnership toward Canada's largest institutions. OSFI is already changing parts of that equation. New entrants have a more structured approval process, selected capital requirements are being recalibrated and unnecessary supervisory material is being removed. The value to the market will depend on what happens to entry costs, operating economics and the ...
AI Image – Canadian regulatory gateway for fintech growth and competition
September 14, 2026 | NCFA Market Activity | Capital Markets Infrastructure And Funding, Digital Assets Blockchain And Tokenization, Artificial Intelligence And Data Institutional Investors Back Tokenized Market Data On September 14, 2026, Paris-baesed digital asset firm Kaiko raised US$110 million in a Series B extension led by S&P Global. RBC joined BNP Paribas, Nasdaq Ventures, Bpifrance, Broadridge, Coinbase Ventures, DRW Venture Capital, Canton Foundation, Stellar and Susquehanna Private Equity Investments. Existing shareholders Anthemis, Point Nine and Revaia also participated. Kaiko plans to invest the capital in its market data business and services for onchain capital markets. Its coverage spans more than 150 exchanges and protocols, with data used for pricing, trading, valuation, risk, surveillance and benchmarks. S&P Global, RBC, Nasdaq, BNP Paribas and Broadridge bring something beyond capital. They operate businesses that depend on reliable prices, benchmarks, market data and institutional distribution. Their investment gives Kaiko deeper relationships with firms that could also become customers, partners or distribution channels as tokenized securities and digital assets enter more institutional products. S&P Backs Kaiko After Launching 4,000+ Indices S&P Global was already working with Kaiko before leading the round. On September 1, S&P Dow Jones Indices and Kaiko launched the S&P Kaiko ...
AI Image – Digital asset market data dashboard for tokenized capital markets
Sep 14, 2026 Industrial machinery is essential in the manufacturing, construction, processing, agriculture, energy production, and other industries. Unexpected machine failures can have more than repair costs. Production can be halted, deadlines can be missed, workers can face safety hazards, and businesses can suffer financial losses. By knowing the common causes of machinery failure, operators and maintenance staff can identify problems early and take preventive action. Industrial machinery failure can have many causes. Why Industrial Machinery Fails By determining the root cause, businesses can avoid the same issue, minimize downtime, and extend the useful life of valuable industrial equipment. Here are 10 of the most common reasons for industrial machinery failure. Poor maintenance One of the biggest causes of equipment failure is poor maintenance. A machine has many moving parts and interdependent components that must be inspected, cleaned, adjusted, and serviced regularly. Small issues can turn into big ones if they aren't addressed during routine maintenance. A preventive maintenance schedule can help to detect worn components and other issues before they lead to unexpected failures. Inadequate lubrication Moving parts need proper lubrication to minimize friction and heat. Insufficient lubrication, improper lubricants, or not lubricating parts as recommended can cause faster ...
AI Image – Industrial maintenance technician inspecting heavy factory machinery to identify common causes of industrial machinery failure and prevent equipment downtime
Sep 5, 2026 | Last Updated Sep 14, 2026 | NCFA Fintech Whisperer | Payments Infrastructure And Money Movement, Digital Assets Blockchain And Tokenization, Digital Identity And Trust, Cybersecurity Fraud And Financial Crime, Digital Banking And BaaS, Capital Markets Infrastructure And Funding, Artificial Intelligence And Data, Cross Border Payments And FX, Wealthtech Investing And Trading, Embedded Finance, Insurance And Insurtech, Lending Consumer Credit And BNPL, Open Banking Open Finance And Data Sharing, Risk Compliance And Regtech, Treasury Liquidity And Cash Management, Regulation And Policy, Data Privacy And Governance This live weekly NCFA intelligence page tracks financial technology developments that significantly affect how fintechs build, sell, raise capital, and operate under scrutiny. Coverage prioritizes Canada and includes global events that directly influence competitive conditions, market access, and execution realities across fintech sectors.  This page will be updated throughout the week with market movers in a live format and then each week we'll close the prior week's contents in prep for the upcoming week, and continue on a rolling basis.  (Missed prior week's Fintech Whisperer?  (December 6-12, 2025, December 13-19, 2025, January 1-9, 2026, January 10-16, 2026, January 17-23, 2026, January 24-30, 2026, January 31-February 6, 2026, February 7-13, 2026, February 14-20, 2026, ...
Image Freepik, Data visualization signals
September 11, 2026 | NCFA Regulatory Insight | Artificial Intelligence And Data, Regulation And Policy, Risk Compliance And Regtech AI Literacy, Transparency and Agent Governance On September 9, 2026, the Government of Canada launched a National AI Literacy Initiative with the Alberta Machine Intelligence Institute. The $13 million partnership is expected to reach up to 1 million post secondary students and more than 50,000 K to 12 educators, alongside free learning for workers and other Canadians. The program sits under Canada's AI for All strategy and focuses on helping people understand AI, use it responsibly and recognize risks such as bias, misinformation and privacy loss. Ottawa is working on the governance side at the same time. Its AI transparency consultation remains open until September 23 and asks whether Canada needs stronger ways to identify AI generated content, tell people when they are interacting with AI, explain system capabilities, track serious incidents and record what AI agents actually do. The consultation paper says 19.2% of Canadian companies used AI to produce goods or deliver services in the second quarter of 2026, up from 12.2% a year earlier and three times the 2024 level. The federal government has already been working through ...
AI Image – Canada AI transparency, literacy and agent governance

 


The National Crowdfunding & Fintech Association of Canada (NCFA Canada) is a cross-Canada non-profit actively engaged with cryptocurrency, blockchain, crowdfunding, alternative finance, fintech, P2P, ICO, STO, and online investing stakeholders globally. NCFA Canada provides education, research, industry stewardship, services, and networking opportunities to thousands of members and subscribers and works closely with industry, government, academia, community and eco-system partners and affiliates to create a strong and vibrant crowdfunding and fintech industry. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: ncfacanada.org

Leave a Reply

Your email address will not be published. Required fields are marked *