A managed security provider for Canada and the US should do three things a single-country provider may not: monitor and respond around the clock across Pacific to Eastern time, tell you exactly where your data and security logs are stored, and help you meet breach rules in both countries. That means PIPEDA in Canada and, in the US, the breach notification laws that the National Conference of State Legislatures says exist in all 50 states.

This guide is for owners and operations leaders of small and mid-sized businesses with staff, customers or offices on both sides of the border. It lists what to check before you sign, using guidance from the Canadian Centre for Cyber Security (CCCS), the US Cybersecurity and Infrastructure Security Agency (CISA), the Office of the Privacy Commissioner of Canada (OPC) and the US Federal Trade Commission (FTC).

What does a managed security provider for Canada and the US actually do?

A managed security provider watches your systems for attacks and responds when it finds one. That is different from routine IT support. As our guide to MSP vs MSSP explains, a managed service provider keeps computers, networks and cloud systems running, while a managed security service provider is built to detect and respond to attacks against them. For a cross-border business, the same service also has to fit two legal systems.

Most providers deliver this through endpoint software plus a team of analysts. The software is the tool and the analysts are the service, which is the distinction covered in EDR vs MDR. When you compare providers, ask which part you are buying.

Who is responsible if a provider misses an attack?

You are. The CCCS guide ITSM.50.030 says the customer "is the data owner and is legally responsible for data security," and that your organization "remains accountable for incident response" even when a provider carries out part of it. Outsourcing moves the work, not the accountability.

That is why the contract matters more than the brochure. ITSM.50.030 recommends that the service level agreement specify expected turnaround times, communication methods, escalation processes, performance metrics and penalties for missed turnaround times. CISA's Risk Considerations for Managed Service Provider Customers makes similar points from the US side, including detailed incident management responsibilities and direct customer access to security logging data.

Where will your data and security logs be stored?

Ask for the country, not just the cloud brand. ITSM.50.030 notes that data stored outside Canada "is subject to different privacy, security, and data ownership laws and regulations." Security tools collect a lot of data (device activity, email metadata, sign-in records), so the question covers logs and backups as well as your files.

Storing data in the US is not automatically a problem for a Canadian business. The OPC's guidelines for processing personal data across borders say PIPEDA does not prohibit transfers to an organization in another jurisdiction for processing. The Canadian organization stays accountable and must use contractual or other means to provide a comparable level of protection. In practice, you need to know the location so you can describe it honestly to customers and cover it in the contract.

Which breach notification rules apply on each side of the border?

Often several at once. In Canada, the OPC's breach guidance says businesses must report breaches that pose a real risk of significant harm and keep records of all breaches. In the US, NCSL reports that all 50 states, plus the District of Columbia, Guam, Puerto Rico and the Virgin Islands, require businesses to notify people of breaches.

Some US businesses have an extra federal duty. Since May 13, 2024, the FTC's Safeguards Rule notification requirement has required covered non-bank financial institutions to notify the FTC no later than 30 days after discovering a breach involving at least 500 consumers. Our guide to data breach notification laws covers the deadlines in more detail. A cross-border provider should be able to produce the facts each of these regimes asks for, quickly.

What should you ask before you sign?

Ask questions that force specific, written answers. These seven come straight from the CCCS and CISA guidance above:

  1. Who watches alerts at 2 a.m. Pacific and 2 a.m. Eastern? Ask whether it is a staffed security operations centre and what happens after an alert fires.
  2. What are the response times in the contract? Look for turnaround times, escalation steps and what happens when the provider misses them.
  3. Where are our data, logs and backups stored? Get the country for each.
  4. Can we see our own security logs? CISA lists direct access to logging and intrusion detection data as a contract consideration.
  5. Who else touches our systems? CISA recommends notification of subcontractors and documented vetting of the provider's staff, including subcontractors.
  6. What is your role during a breach? Ask how the provider helps you decide whether PIPEDA, a US state law or the FTC rule applies, and how fast it can supply the facts.
  7. What framework do you measure us against? For Canadian operations, the CCCS Baseline Cyber Security Controls are written for organizations with fewer than 500 employees.

Our broader checklist on how to choose a managed IT and cybersecurity provider covers references, pricing structure and red flags.

Is one provider for both countries better than two?

Usually, for a small or mid-sized business. Two providers means two contracts, two sets of logs and two incident playbooks, and during an incident each may point to the other's scope. One provider that covers both countries gives you a single accountable party and one view of your environment. The trade-off is that you depend on one firm, so the contract checks above matter even more.

Cyber Unit is based in Vancouver and serves businesses in Canada and the US with 24/7 monitoring by its security operations centre. Whoever you choose, ask your current provider this question first: if something goes wrong on a Saturday night, who is watching, how fast do they respond, and where is that written down? To see where your own controls stand before that conversation, take the free cybersecurity assessment.


This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Descriptions of PIPEDA, US state breach laws and the FTC Safeguards Rule are based on guidance from the Office of the Privacy Commissioner of Canada, the National Conference of State Legislatures and the Federal Trade Commission as of the date of publication. Organizations should consult qualified legal and cybersecurity professionals about their specific obligations.