Board advisory · Ontario, Canada · Practising since 2003
Governance that holds when everything else moves.
Dr. Orlando Olumide Odejide advises Canadian boards and executive leadership on governance, risk, compliance and cyber resilience — translating Ontario Regulation 51/26, federal cyber law, OSFI expectations and privacy obligations into capability your organization can evidence.
Dr. Orlando Olumide Odejide — Governance · Risk · Compliance · Cyber Resilience
- ISO 37000Governance
- ISO 31000Risk
- ISO 37301Compliance
- NIST CSF 2.0Cyber
- ISO 27001Security
- ISO 42001AI
The premise
Organizations rarely fail for want of a policy. They fail because nobody could say who decided, on what basis, and who would answer for it.
Governance is an operating system, not a binder. The work is to make authority, evidence and accountability visible enough that sound decisions become the default — and then to prove it to a regulator, an auditor, an insurer or a board. In Canada that proof is now being asked for on a clock: maturity assessments, incident reports within 72 hours, resilience testing against fixed dates.
Frameworks that live in documents
A policy set nobody uses, written for an audit that has already passed. Nothing changes at the point where decisions are actually made.
Risk registers nobody reads
Risk recorded but never priced into strategy, capital or delivery. The register is complete and the exposure is unmanaged.
Assurance that arrives too late
Findings raised after the loss, the breach or the disclosure. Assurance becomes reporting rather than protection.
The Canadian horizon
What Canadian boards are now asked to prove.
Cyber, privacy, resilience and sustainability obligations have moved from guidance to duty — each with an owner, an assessment and a reporting deadline attached. The work is to answer them as one governance system rather than four separate projects.
Ontario Regulation 51/26 meets NIST Cybersecurity Framework 2.0
Regulation 51/26 under the Enhancing Digital Security and Trust Act, 2024 has been in force since 1 July 2026. Prescribed public-sector entities — colleges and universities, specified public hospitals, school boards and children’s aid societies — must run a cybersecurity program, designate senior cybersecurity contacts, carry out recurring maturity assessments, report results and improvement opportunities, and report a confirmed critical incident within 72 hours.
The executive question is no longer whether the technology is adequate. It is whether cybersecurity can be shown to be governed, assessed, managed, monitored and continuously improved. NIST CSF 2.0 gives that answer an architecture.
Cybersecurity programs, maturity assessments and 72-hour incident reporting for prescribed Ontario entities.
Federal cyber law received Royal Assent in June 2026, with CCSPA obligations for designated operators phasing in by order in council.
Critical operations mapped, impact tolerances set, third-party and technology risk governed, scenario testing evidenced.
Federal, Quebec, health and public-sector privacy duties handled as one accountability framework rather than four.
Canadian Sustainability Disclosure Standards governed with the controls and evidence that assurance will eventually require.
AI systems classified, assessed and governed across the lifecycle, ahead of the Canadian rules now taking shape.
Anti-bribery, whistleblowing and fraud governed as one system, aligned to Canadian conduct and supply-chain expectations.
The governing spine: decision rights, enterprise risk and compliance obligations owned, controlled and auditable.
Regulatory positions change. This page states a management interpretation, not legal advice; organizations should confirm applicable requirements and current Ministry, OSFI and regulator guidance before acting.
Where the work sits
Six domains, governed as one system.
Each domain is anchored to a recognized standard, so the work is portable, auditable and defensible in front of a regulator, an auditor, an insurer or a board.
Governance
Decision rights, board effectiveness and accountability designed into how the organization actually runs.
ISO 37000Risk
Enterprise risk that informs capital, strategy and delivery rather than sitting in a spreadsheet.
ISO 31000Compliance
Obligations mapped, owned and controlled, with evidence a Canadian regulator would accept without argument.
ISO 37301 · ISO 19011Integrity
Bribery, whistleblowing and fraud governed as one system rather than three disconnected policies.
ISO 37001 · 37002 · 37003Sustainability
ESG governed as business risk and long-term value, aligned to the SDGs and Canadian disclosure standards.
SDGs · ISO 53001 · CSDSTechnology & AI
Technology risk governed as business risk — from service management and cyber resilience through to responsible AI.
ISO 27001 · 22301 · 42001Board readiness diagnostic
Six questions. An honest read on where you stand.
Answer as your board would answer, not as the policy says. The result names your maturity band and the three practices that would move it fastest.
If a critical cyber incident were confirmed this morning, could you report it to the regulator within 72 hours with evidence?
Can your board name the person accountable for cybersecurity, and the date of the last maturity assessment?
Are your regulatory obligations mapped to named owners and working controls?
Does enterprise risk change what gets funded, or is it reported after the decision?
Have you identified your critical operations and set tolerances for how long they can be disrupted?
Do you know where AI is already in use across the organization, and who signed off on it?
The register
Eighteen practices. One standards-led method.
Filter by service line or search by standard. Open any practice for its full scope, deliverables and business case.
No practice matches that search. Try a standard number, or reset the filters.
How engagements run
Five phases. Capability stays behind.
The same sequence whether the subject is a board charter, a Regulation 51/26 readiness review, an ISMS or an AI management system. It ends when your people can run it without us.
Assess
Regulatory readiness review and a current-state assessment against the applicable standard.
Gap analysis
Governance, people, process, technology, reporting and resilience gaps named and sized.
Roadmap
Target profile, priorities, owners, investment, milestones and performance indicators.
Implement
Controls, policies, structures and skills built where decisions are actually made.
Assure & improve
Evidence maintained, maturity measured, readiness tested and capabilities reassessed.
The record
Two decades, measured.
Advisory, assurance and capacity building for Canadian and international organizations — from board charters to certification audits, built on more than twenty years of practice across Africa, Europe and North America.
Independent advisory across governance, risk, compliance and sustainability.
Professional credentials across governance, IT, assurance and security.
Lead Implementer, Lead Auditor and management-system specializations.
Standards-anchored disciplines across two service lines.
Where it applies
Sectors where the stakes are governance.
The standard is constant. The regulator, the risk appetite and the failure mode are not.
Colleges & universities
Regulation 51/26 cybersecurity programs, maturity assessments, incident reporting and research-data governance.
Hospitals & health
PHIPA obligations, clinical system continuity, third-party risk and privacy accountability.
School boards & CAS
Prescribed-entity cyber duties, student data protection and board-level oversight that survives turnover.
Financial services
OSFI E-21, B-13 and B-10 expectations, conduct risk, operational resilience and third-party oversight.
Government & municipalities
FIPPA and MFIPPA accountability, procurement integrity and institutional capacity across political cycles.
Energy & utilities
Critical cyber systems, ESG disclosure and operational risk across long, regulated supply chains.
Telecoms & technology
Federal cyber obligations, service continuity, cloud governance and responsible AI deployment.
Not-for-profit & development
Funder accountability, fraud control, whistleblowing systems and SDG alignment.
In their words
What people say.
Clients, colleagues and the professionals trained across two decades of practice.
Insights
Writing from the practice.
On cyber resilience, wicked problems and the discipline of governing well.
Ontario Regulation 51/26 and NIST CSF 2.0: from regulatory compliance to cyber resilience
Request the briefing Article · SDGsWicked problem solving applied to the Sustainable Development Goals
Read the article Article · CapabilityProblem solving is a life skill. Wicked problem solving is a national capability.
Read the articleStart the conversation
A first conversation costs an hour.
Bring the obligation you are least able to evidence today. We will name where the gap actually sits, what closing it involves, and whether it is work you need help with at all.