Services Standards Process Weekly Review Contact
Weekly Review

Governance & Compliance Review

Developments in technology governance, cybersecurity standards, and regulatory compliance.

Week of July 20 to 26, 2026
This is an archived edition. View the latest review →
Lead Story
CyberSecure Canada & Cyber Threats
CybersecurityVulnerability

CISA Adds Two Actively Exploited Vulnerabilities to Its Catalog as the July SharePoint Exploitation Wave Continues

On July 22, the United States Cybersecurity and Infrastructure Security Agency added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation: CVE 2026 50522, a deserialization of untrusted data flaw in Microsoft SharePoint, and CVE 2026 16232, an improper authentication flaw in Check Point SmartConsole. The SharePoint entry extends a difficult month for on premises collaboration estates that began with Microsoft's record July 14 Patch Tuesday and continued with Canadian Centre for Cyber Security alert AL26 017, issued July 15, covering CVE 2026 56164, CVE 2026 55040, and CVE 2026 58644.

The Check Point entry is a reminder that management tooling deserves the same urgency as the servers it administers. SmartConsole is the administration client for Check Point security gateways, so a compromised console can translate directly into control of the perimeter it manages. Both flaws now carry mandated remediation deadlines for United States federal civilian agencies, and both belong at the top of Canadian patch queues for the same reason.

  • CVE 2026 50522, SharePoint deserialization of untrusted data, and CVE 2026 16232, Check Point SmartConsole improper authentication, were added to the KEV catalog July 22
  • Both additions are based on evidence of active exploitation in the wild
  • CCCS alert AL26 017, issued July 15, remains the standing Canadian guidance for the July SharePoint vulnerabilities
  • Exploitation of administration tooling can yield control of the security infrastructure it manages

Implications

Confirm this week that internet facing SharePoint estates are fully updated to July patch levels and that machine keys have been rotated wherever compromise is suspected, then verify Check Point SmartConsole versions against the vendor fix. Treat KEV catalog inclusion and CCCS alerts, not vendor severity labels, as the trigger for emergency change handling under ISO/IEC 27001:2022 A.8.8 management of technical vulnerabilities and A.8.32 change management. Management consoles should be reachable only from segregated administrative networks per A.8.22 segregation of networks and A.8.2 privileged access rights, with monitoring per A.8.16 to detect authentication anomalies.

Source: CISA
CybersecurityCritical Infrastructure

US Agencies Expand Their Warning on Iran Affiliated Attacks Against Industrial Control Systems to Cover More Manufacturers

United States federal agencies, including CISA, the National Security Agency, and the Treasury, published a July 22 revision of their April advisory on attacks against internet facing operational technology by actors affiliated with the Iranian regime. The original advisory focused on programmable logic controllers from Rockwell Automation and Allen Bradley; the revision expands the scope to observed targeting of Schneider Electric and Siemens equipment, with other manufacturers possibly affected. Reported incidents include malicious project file interactions and manipulation of data on human machine interface and SCADA displays, with targeted organizations suffering operational disruption and financial loss.

The same vendor equipment runs across Canadian utilities, manufacturing, and building systems, and the Canadian Centre for Cyber Security routinely mirrors partner advisories on operational technology exposure. Attribution is complicated by the regime's use of criminal and proxy groups as cover, but the defensive guidance does not depend on attribution: internet exposed controllers are being found and manipulated, whoever is behind the traffic.

  • The July 22 revision expands April guidance on Iran affiliated targeting of internet facing operational technology
  • Scope now includes Schneider Electric and Siemens equipment alongside Rockwell Automation and Allen Bradley controllers
  • Observed activity includes malicious project file interactions and manipulation of HMI and SCADA displays
  • Targeted organizations have suffered operational disruption and financial loss

Implications

Operators should inventory every controller, HMI, and engineering workstation reachable from the internet this week and remove direct exposure, placing required remote access behind authenticated VPN with multi factor authentication. Change default credentials, and segment OT from IT networks using the zone and conduit model of ISA/IEC 62443. Map supporting controls to ISO/IEC 27001:2022 A.8.20 networks security, A.8.22 segregation of networks, A.8.9 configuration management, and A.5.7 threat intelligence, and subscribe engineering teams, not only security teams, to CCCS and CISA advisory feeds so control system changes reach the people who can act on them.

Source: The Record by Recorded Future
CanadaCybersecurity

Canada Presses the United States for Joint Action Against Industrial Scale Cyber Scam Operations as 2025 Fraud Losses Pass C$704 Million

Foreign Minister Anita Anand, speaking July 22 on the sidelines of the Association of Southeast Asian Nations meeting in Manila, said Canada is pressing the United States for deeper collaboration to dismantle industrial scale cyber crime operations, and that she raised the issue directly with US Secretary of State Marco Rubio. Canadians lost more than C$704 million to fraud in 2025, and the operations behind much of that loss run as organized enterprises out of Southeast Asia. The same day, United States prosecutors filed civil forfeiture complaints seeking more than US$25 million in cryptocurrency traced to fraud networks, including scams that targeted Canadians.

The diplomatic push signals that scam infrastructure is being treated as a national security and foreign policy problem, not only a consumer protection issue. For organizations, the practical exposure is business email compromise, payment diversion, and employee targeted investment and impersonation scams, which reach staff through the same industrialized channels.

  • Canada raised joint action on cyber scam operations directly with the US Secretary of State on July 22
  • Canadians lost more than C$704 million to fraud in 2025
  • US prosecutors moved the same day to forfeit more than US$25 million in cryptocurrency tied to fraud networks targeting North Americans
  • Scam operations are increasingly treated as organized, industrial scale enterprises rather than isolated incidents

Implications

Treat fraud as a controls problem, not only an awareness topic. Enforce out of band verification for any change to payment instructions or supplier banking details, and test staff against current scam patterns rather than generic phishing templates. Map the program to ISO/IEC 27001:2022 A.6.3 information security awareness, education and training, A.5.7 threat intelligence, and A.5.19 information security in supplier relationships, and ensure incidents are reported to the Canadian Anti Fraud Centre so losses feed the enforcement picture governments are now acting on. Boards should ask for fraud loss and near miss metrics alongside security metrics.

Source: Bloomberg
AI Governance & Regulation
AICanadaRegulation

Ottawa Opens a Public Consultation on AI Transparency, Signalling the Next Regulatory Layer After the National AI Strategy

On July 23, the Minister of Artificial Intelligence and Digital Innovation, Evan Solomon, launched a public consultation on how to strengthen transparency for AI systems and AI generated outputs. Running to September 23, the consultation seeks views on how Canadians and businesses can know when they are interacting with an AI system, assess the origin of online content, and make informed decisions about adopting AI technologies. Responses can be submitted through an anonymous survey or by email. The consultation is the first substantive regulatory follow through since the AI for All national strategy launched June 4, which committed to protecting Canadians as one of its six pillars while leaving regulatory specifics open.

Transparency is the most likely first target for binding obligations because it is measurable: labelling AI interactions, disclosing AI generated content, and evidencing content provenance are requirements a regulator can verify. Jurisdictions including the European Union have already moved this direction, and Canadian obligations that align with international practice would let organizations reuse the same compliance work across markets.

  • The consultation runs July 23 to September 23, 2026, via anonymous survey or email submission
  • Focus areas include disclosure of AI interactions, provenance of AI generated content, and informed adoption decisions
  • It is the first substantive regulatory step since the AI for All strategy launched June 4
  • Feedback will inform next steps on safe, responsible and reliable AI in Canada

Implications

Organizations deploying AI in customer facing channels should respond to the consultation, and should not wait for the outcome to act. Inventory every point where an AI system interacts with customers or generates published content, and decide now how each would be labelled if disclosure became mandatory. An AI management system aligned to ISO/IEC 42001:2023 already requires transparency and communication measures, so organizations building toward it will hold the documentation a future obligation would demand. Map records and accountability to ISO/IEC 27001:2022 A.5.31 legal, statutory, regulatory and contractual requirements, and diarize September 23 as the close of the comment window.

Source: Government of Canada
Frameworks & Standards
NISTCybersecurity

NIST Opens Public Comment on Overhauled Storage Infrastructure Security Guidelines as Backup Integrity Becomes the Ransomware Battleground

On July 22, the United States National Institute of Standards and Technology released the initial public draft of Special Publication 800 209 Revision 1, Security Guidelines for Storage Infrastructure, with comments open through September 8, 2026. The revision updates the 2020 original for the shift to software defined storage across cloud, virtualized, and network attached environments, and organizes its guidance into seven control families covering areas including encryption, access control, authentication, configuration management, and audit accountability. The draft gives particular attention to platform compromise of underlying storage infrastructure and to threats against data resilience and backup protection.

Storage is where ransomware campaigns are won or lost: attackers now routinely target backup platforms and storage administration consoles before detonating encryption, precisely because recoverability determines whether a victim pays. Dedicated storage security guidance gives infrastructure teams a checklist that generic control frameworks do not reach.

  • SP 800 209 Revision 1 initial public draft released July 22; comments close September 8, 2026
  • Guidance is reorganized into seven control families for modern software defined storage
  • Coverage spans cloud, virtualized, and network attached storage architectures
  • The draft emphasizes threats to data resilience, backup protection, and storage platform integrity

Implications

Infrastructure and security teams should assess their storage estate against the draft now and submit comments where guidance conflicts with operational reality. Priorities: isolate and harden backup infrastructure so a domain compromise cannot reach it, require multi factor authentication on storage administration consoles, and verify that at least one backup copy is immutable or offline. Map the work to ISO/IEC 27001:2022 A.8.13 information backup, A.8.24 use of cryptography, A.8.9 configuration management, and A.5.29 information security during disruption, and test restoration, not only backup completion, on a defined schedule.

Source: NIST
Previous Reviews

Get the Weekly Briefing

Governance, compliance, and cybersecurity developments delivered to your inbox every Monday. No noise, just what matters.