Board advisory · Ontario, Canada · Practising since 2003

Governance that holds when everything else moves.

Dr. Orlando Olumide Odejide advises Canadian boards and executive leadership on governance, risk, compliance and cyber resilience — translating Ontario Regulation 51/26, federal cyber law, OSFI expectations and privacy obligations into capability your organization can evidence.

Dr. Orlando Olumide Odejide, governance, risk and compliance advisor, Ontario, Canada

Dr. Orlando Olumide Odejide — Governance · Risk · Compliance · Cyber Resilience

  • ISO 37000Governance
  • ISO 31000Risk
  • ISO 37301Compliance
  • NIST CSF 2.0Cyber
  • ISO 27001Security
  • ISO 42001AI

The premise

Organizations rarely fail for want of a policy. They fail because nobody could say who decided, on what basis, and who would answer for it.

Governance is an operating system, not a binder. The work is to make authority, evidence and accountability visible enough that sound decisions become the default — and then to prove it to a regulator, an auditor, an insurer or a board. In Canada that proof is now being asked for on a clock: maturity assessments, incident reports within 72 hours, resilience testing against fixed dates.

Failure mode 01

Frameworks that live in documents

A policy set nobody uses, written for an audit that has already passed. Nothing changes at the point where decisions are actually made.

Failure mode 02

Risk registers nobody reads

Risk recorded but never priced into strategy, capital or delivery. The register is complete and the exposure is unmanaged.

Failure mode 03

Assurance that arrives too late

Findings raised after the loss, the breach or the disclosure. Assurance becomes reporting rather than protection.

The Canadian horizon

What Canadian boards are now asked to prove.

Cyber, privacy, resilience and sustainability obligations have moved from guidance to duty — each with an owner, an assessment and a reporting deadline attached. The work is to answer them as one governance system rather than four separate projects.

Ontario Regulation 51/26 meets NIST Cybersecurity Framework 2.0

Regulation 51/26 under the Enhancing Digital Security and Trust Act, 2024 has been in force since 1 July 2026. Prescribed public-sector entities — colleges and universities, specified public hospitals, school boards and children’s aid societies — must run a cybersecurity program, designate senior cybersecurity contacts, carry out recurring maturity assessments, report results and improvement opportunities, and report a confirmed critical incident within 72 hours.

The executive question is no longer whether the technology is adequate. It is whether cybersecurity can be shown to be governed, assessed, managed, monitored and continuously improved. NIST CSF 2.0 gives that answer an architecture.

GOVERNAccountability, policy, risk appetite, oversight
IDENTIFYAssets, suppliers, threats, current-state profile
PROTECTAccess, data, training, platform safeguards
DETECTMonitoring, analysis, escalation
RESPONDIncident management and 72-hour reporting
RECOVERRestoration, lessons, strengthened resilience
Public-sector cybersecurity O. Reg. 51/26 · NIST CSF 2.0

Cybersecurity programs, maturity assessments and 72-hour incident reporting for prescribed Ontario entities.

Critical cyber systems Bill C-8 (ARCS) · CCSPA

Federal cyber law received Royal Assent in June 2026, with CCSPA obligations for designated operators phasing in by order in council.

Operational resilience OSFI E-21 · B-13 · B-10

Critical operations mapped, impact tolerances set, third-party and technology risk governed, scenario testing evidenced.

Privacy and personal data PIPEDA · Law 25 · PHIPA · FIPPA

Federal, Quebec, health and public-sector privacy duties handled as one accountability framework rather than four.

Sustainability disclosure CSDS 1 & 2 · OSFI B-15 · ISO 53001

Canadian Sustainability Disclosure Standards governed with the controls and evidence that assurance will eventually require.

Artificial intelligence ISO 42001 · NIST AI RMF

AI systems classified, assessed and governed across the lifecycle, ahead of the Canadian rules now taking shape.

Integrity and conduct ISO 37001 · 37002 · 37003

Anti-bribery, whistleblowing and fraud governed as one system, aligned to Canadian conduct and supply-chain expectations.

Board and management systems ISO 37000 · 31000 · 37301

The governing spine: decision rights, enterprise risk and compliance obligations owned, controlled and auditable.

Regulatory positions change. This page states a management interpretation, not legal advice; organizations should confirm applicable requirements and current Ministry, OSFI and regulator guidance before acting.

Where the work sits

Six domains, governed as one system.

Each domain is anchored to a recognized standard, so the work is portable, auditable and defensible in front of a regulator, an auditor, an insurer or a board.

Domain 01

Governance

Decision rights, board effectiveness and accountability designed into how the organization actually runs.

ISO 37000
Domain 02

Risk

Enterprise risk that informs capital, strategy and delivery rather than sitting in a spreadsheet.

ISO 31000
Domain 03

Compliance

Obligations mapped, owned and controlled, with evidence a Canadian regulator would accept without argument.

ISO 37301 · ISO 19011
Domain 04

Integrity

Bribery, whistleblowing and fraud governed as one system rather than three disconnected policies.

ISO 37001 · 37002 · 37003
Domain 05

Sustainability

ESG governed as business risk and long-term value, aligned to the SDGs and Canadian disclosure standards.

SDGs · ISO 53001 · CSDS
Domain 06

Technology & AI

Technology risk governed as business risk — from service management and cyber resilience through to responsible AI.

ISO 27001 · 22301 · 42001

Board readiness diagnostic

Six questions. An honest read on where you stand.

Answer as your board would answer, not as the policy says. The result names your maturity band and the three practices that would move it fastest.

If a critical cyber incident were confirmed this morning, could you report it to the regulator within 72 hours with evidence?

Can your board name the person accountable for cybersecurity, and the date of the last maturity assessment?

Are your regulatory obligations mapped to named owners and working controls?

Does enterprise risk change what gets funded, or is it reported after the decision?

Have you identified your critical operations and set tolerances for how long they can be disrupted?

Do you know where AI is already in use across the organization, and who signed off on it?

The register

Eighteen practices. One standards-led method.

Filter by service line or search by standard. Open any practice for its full scope, deliverables and business case.

No practice matches that search. Try a standard number, or reset the filters.

How engagements run

Five phases. Capability stays behind.

The same sequence whether the subject is a board charter, a Regulation 51/26 readiness review, an ISMS or an AI management system. It ends when your people can run it without us.

01

Assess

Regulatory readiness review and a current-state assessment against the applicable standard.

02

Gap analysis

Governance, people, process, technology, reporting and resilience gaps named and sized.

03

Roadmap

Target profile, priorities, owners, investment, milestones and performance indicators.

04

Implement

Controls, policies, structures and skills built where decisions are actually made.

05

Assure & improve

Evidence maintained, maturity measured, readiness tested and capabilities reassessed.

The record

Two decades, measured.

Advisory, assurance and capacity building for Canadian and international organizations — from board charters to certification audits, built on more than twenty years of practice across Africa, Europe and North America.

Practising since2003

Independent advisory across governance, risk, compliance and sustainability.

Certifications0

Professional credentials across governance, IT, assurance and security.

ISO standards0

Lead Implementer, Lead Auditor and management-system specializations.

Practices0

Standards-anchored disciplines across two service lines.

Where it applies

Sectors where the stakes are governance.

The standard is constant. The regulator, the risk appetite and the failure mode are not.

Colleges & universities

Regulation 51/26 cybersecurity programs, maturity assessments, incident reporting and research-data governance.

Hospitals & health

PHIPA obligations, clinical system continuity, third-party risk and privacy accountability.

School boards & CAS

Prescribed-entity cyber duties, student data protection and board-level oversight that survives turnover.

Financial services

OSFI E-21, B-13 and B-10 expectations, conduct risk, operational resilience and third-party oversight.

Government & municipalities

FIPPA and MFIPPA accountability, procurement integrity and institutional capacity across political cycles.

Energy & utilities

Critical cyber systems, ESG disclosure and operational risk across long, regulated supply chains.

Telecoms & technology

Federal cyber obligations, service continuity, cloud governance and responsible AI deployment.

Not-for-profit & development

Funder accountability, fraud control, whistleblowing systems and SDG alignment.

In their words

What people say.

Clients, colleagues and the professionals trained across two decades of practice.

Start the conversation

A first conversation costs an hour.

Bring the obligation you are least able to evidence today. We will name where the gap actually sits, what closing it involves, and whether it is work you need help with at all.

Based inOntario, Canada
ServingCanada & internationally

We provide expert guidance and personalized strategies to help you achieve financial growth.

Elgin St. Celina, Delaware 299
Call Us: (603) 555-0123
Mon - Sat: 8.00am - 18.00pm