For Canadian financial institutions, public sector and enterprises

Bilingual Security Awareness Training for Canadian Organizations

OSFI Guideline B-13 expects training and awareness as part of managing cyber risk. Quebec's Law 25 means a meaningful share of your workforce needs it in French. A-SAT delivers both with adaptive phishing, smishing, deepfake and voice-clone simulation, and evidence your regulator will accept.

85%
Avg. reduction in security incidents
92%
Training completion rate
300+
Organizations served
EN/FR
Bilingual delivery
Book your 30-minute demo
A live walkthrough against your own environment — available within 24 hours, in English or French.
Reply within 24 hours
No commitment

By submitting, you agree to receive communications from Aspire Tech. You can unsubscribe at any time.

For Canadian teams who have to evidence it, in both official languages

SOC 2 Type IIEnglish and French deliveryPIPEDA aligned99.9% uptime SLA300+ organizations

Change behaviour with realistic, personalized simulations

Four channels, two languages, one adaptive platform. Every simulation is role-based, escalates with each user risk score, and teaches at the exact moment a mistake is made.

Canadian context, both languages

Tested on messages your staff would actually open

CRA notices, e-transfer confirmations, supplier payment changes and payroll updates — delivered in the language each employee works in, not translated from a US template after the fact.

  • AI-generated email and SMS in English and French
  • Language assigned per user within a single campaign
  • Mobile-optimized landing pages staff actually meet
See it in a demo
Messages · ARC / CRA

ARC : un remboursement de 312,45 $ vous attend. Confirmez vos renseignements avant expiration :

arc-remboursement-depot.info

Simulated smishing · FR

Bien vu. Same simulation, delivered in each employee's working language — and the micro-lesson lands in that language too.

Point-of-click training

Catch the click at the exact moment it happens

When someone clicks, taps or complies, micro-training fires immediately — in their language, while the lesson lands. A module assigned three weeks later connects to nothing.

  • Instant micro-lesson tied to what was missed
  • Live risk score per user drives difficulty
  • High-risk staff get more; low-risk staff are left alone
See it in a demo
Inbox
now

Supplier payment details updated — action before 4:00 PM ET

from: finance@aspire-tss-payables.co

Please use the revised banking information for today's transfer…

This was a simulated phish

3 clues you can spot next time:

  • Look-alike domain
  • Same-day deadline
  • Banking details changed by email

Beyond email

Meet a deepfake before a criminal introduces you to one

A cloned voice needs about thirty seconds of audio; a deepfake video needs a short clip. Around two-thirds of employees cannot reliably spot AI-generated video — a controlled test is a better place to learn that than a payment request.

  • Photorealistic deepfake video from a short clip
  • Live conversational AI voice-clone calls
  • Dark web credential exposure fed into risk profiles
See it in a demo

Chief Financial Officer

Incoming call · +1…

Warning: this voice may be AI-cloned. Verify the request on a second, known channel before you act.
Deepfake video and voice-clone scenarios, in English and French.

The evidence file

Evidence proportionate to your risk profile

OSFI B-13 is principles-based, so you have to justify the programme you chose. Reporting is automated and mapped to PIPEDA, ISO/IEC 27001:2022 and PCI DSS v4.0 — with completion split by language group for Law 25 coverage.

  • Per-user completion by department, site, role and language
  • Click rate, report rate and repeat-offender tracking
  • Proof that board and senior management were trained too
See it in a demo

Human risk dashboard

OSFI B-13 · PIPEDA · Law 25 · ISO 27001

Export evidence

Phishing click rate — trending down

Q1
Q2
Q3
Q4

85%

fewer security incidents

92%

training completion

Completion by language, site and role — one click to CSV.

Four channels, two official languages

Most platforms simulate one thing: English email. Attacks on Canadian organizations arrive by SMS, by phone and increasingly by video — and in whichever language the target actually works in.

SMS smishing

AI-generated SMS in English and French, modelled on the messages your staff actually receive — CRA notices, delivery alerts, e-transfer confirmations, payroll changes.

Deepfake video

Upload a short clip; the platform generates a photorealistic avatar for a simulated executive-impersonation attack.

Voice cloning (vishing)

A cloned voice from around 30 seconds of audio; an AI agent calls staff and holds a live conversation, responding in real time.

Dark web monitoring

Continuous scanning of breach data for compromised staff credentials — included from the entry tier, not sold separately.

Canadian compliance

The Canadian regulatory picture just changed

Bill C-8 received Royal Assent on 15 June 2026, after passing the House on 26 March and the Senate on 4 June. The Critical Cyber Systems Protection Act will phase in through regulation — which means designated operators have a preparation window, not an emergency. Building a measurable programme takes longer than the notice period you are likely to get.

OSFI B-13 is principles-based. That is not a lighter obligation — it means you have to justify the programme you chose, with evidence.

OSFI Guideline B-13

In effect 1 January 2024

Sets OSFI expectations for technology and cyber risk management at federally regulated financial institutions, across governance and risk management, technology operations and resilience, and cyber security. Training and awareness is named among the organisational measures expected. It is explicitly not one-size-fits-all — your programme must be proportionate to your risk profile, and you have to be able to show why.

Bill C-8 / CCSPA

Royal Assent 15 June 2026

Canada’s cyber security legislation is now law — S.C. 2026, c.9. The Telecommunications Act amendments took effect on Royal Assent; the Critical Cyber Systems Protection Act is being implemented in phases, and as of late July 2026 no implementation date had been announced. It creates a regulatory framework for designated operators in finance, telecommunications, energy and transportation.

PIPEDA

Safeguards principle

Requires safeguards appropriate to the sensitivity of the personal information held. The Office of the Privacy Commissioner has consistently treated staff awareness as part of an adequate safeguard regime, and it is routinely examined after a breach.

Quebec Law 25

Privacy and language

Substantially raised privacy obligations for organisations operating in Quebec, including governance, breach reporting and accountability. Combined with Quebec’s French-language requirements, training delivered only in English is a practical compliance gap — not just an HR preference.

Confirm the current implementation status of the Critical Cyber Systems Protection Act before relying on it in a procurement conversation — the phased regulations are still being made.

Why bilingual matters more than vendors admit

Most global platforms offer French — usually European French, machine-translated, with scenarios set somewhere nobody recognises. A Quebec employee reading a phishing simulation in Parisian French about a company that does not exist learns to spot the training, not the attack.

Typical global platform
A-SAT in Canada
European French, machine-translated
French-Canadian, written for Canadian workplaces
Scenarios set in an office nobody recognises
CRA notices, e-transfer fraud, supplier invoice redirection
One language per tenant
Language assigned per user, in the same campaign
English-only reporting
Completion and risk reporting split by language group

Simulations and micro-training are assigned by each user language preference — so one campaign covers a Montreal branch and a Toronto head office without running two programmes.

What Canadian organizations see

85%

average reduction in security incidents

92%

training completion rate

300+

organizations served

Measured across Aspire Tech client deployments. Methodology and measurement period available on request.

How A-SAT compares

Canada has strong domestic incumbents with years of local presence — we say so. The rows that decide it are deepfake, vishing, dark web and adaptive difficulty.

CapabilityA-SATCanadian incumbentsGlobal platforms
Email phishing simulationYes, AI-generated, continuously refreshedYesYes, large template library
French-Canadian contentYes, written for Canadian workplacesYesOften European French, translated
SMS smishing simulationYes, EN and FRLimitedLimited
Deepfake video simulationYes, self-service avatar creationNot availableNot available
Voice-clone (vishing) simulationYes, live conversational AI agentNot availableNot available
Dark web credential monitoringIncluded from entry tierVariesSeparate product
Point-of-click micro-trainingImmediate, at moment of failureVariesBatch assignment
Adaptive per-user difficultyYes, driven by live risk scorePartialPartial
Canadian market presenceNew entrantEstablished, Canadian-ownedGlobal incumbent

Full feature-by-feature comparison on our KnowBe4 alternative page.

How deployment works

  1. 1

    Discovery call, 30 minutes

    We map your workforce, language split and current programme against what OSFI, PIPEDA or Law 25 expects. Available within 24 hours, in English or French.

  2. 2

    Pilot

    A defined group with a baseline simulation, so you see the real click rate — by language group — before anything changes.

  3. 3

    Directory integration

    Active Directory, Okta, SAML or HR system sync, including language preference mapping.

  4. 4

    Rollout

    Role-based paths assigned in each user language, adaptive simulation schedule begins — in days, not quarters.

  5. 5

    First evidence file

    Baseline versus current, structured for OSFI-style evidence and split by language for Law 25 coverage.

A 30-day free trial is available, or start with a scoped pilot.

Pricing

Plans start from $1.17 per user per month, billed annually. Every plan includes phishing simulation, adaptive training, risk profiling and dark web exposure monitoring — in English and French. Higher tiers add 24/7 support, automated compliance reporting, real-time attack simulation and SOC integration. 30-day free trial.

CAD pricing and applicable taxes confirmed on your quotation.

See it against your own environment

Thirty minutes, a live walkthrough, and a straight answer on what it takes to evidence a training programme proportionate to your risk profile — in both official languages.

Demo available within 24 hours, EN or FR
SOC 2 Type II · No commitment
Evidence mapped to OSFI B-13, PIPEDA and ISO 27001
Book your 30-minute demo
A live walkthrough against your own environment — available within 24 hours, in English or French.
Reply within 24 hours
No commitment

By submitting, you agree to receive communications from Aspire Tech. You can unsubscribe at any time.

Frequently asked questions

Does OSFI B-13 require security awareness training?

Guideline B-13, in effect since 1 January 2024, sets OSFI expectations for managing technology and cyber risk at federally regulated financial institutions and names training and awareness among the organisational measures expected. It is principles-based, so the programme must be proportionate to the institution risk profile — and defensible on that basis.

What is Bill C-8 and does it apply to us?

Bill C-8 received Royal Assent on 15 June 2026 as S.C. 2026, c.9, after passing the House of Commons on 26 March 2026 and the Senate on 4 June 2026. The Telecommunications Act amendments took effect immediately; the Critical Cyber Systems Protection Act is being implemented in phases and, as of late July 2026, no implementation date had been announced. It creates a regulatory framework for designated operators in the finance, telecommunications, energy and transportation sectors.

Is training available in French?

Yes. A-SAT delivers courses, phishing simulations and micro-training in French as well as English, with Canadian scenarios rather than translated European content. Language is assigned per user, so one campaign can cover a Montreal branch and a Toronto head office at the same time.

Does PIPEDA require employee security training?

PIPEDA requires safeguards appropriate to the sensitivity of the personal information held. Employee awareness training is a widely accepted component of an adequate safeguard regime and is routinely examined by the Office of the Privacy Commissioner after a breach.

How does Quebec Law 25 affect our training programme?

Law 25 substantially raised privacy obligations for organisations operating in Quebec, including governance, breach reporting and accountability. Combined with Quebec French-language requirements, delivering training only in English leaves a practical gap for the part of your workforce that works in French.

Can A-SAT simulate deepfake and voice-phishing attacks?

Yes. Administrators can generate a photorealistic avatar from a short video clip for deepfake simulations, and the platform AI agent can call staff using a cloned voice and hold a live conversation, tracking who complied, who questioned and who reported.

How does A-SAT compare with Canadian incumbents?

Canada has established domestic vendors with years of local presence. The A-SAT differences are simulation coverage beyond email — SMS, deepfake video and voice cloning — dark web credential monitoring included from the entry tier, adaptive per-user difficulty driven by a live risk score, and micro-training that fires at the moment of failure, in the user language.

What does A-SAT cost?

Plans start from $1.17 per user per month, billed annually, including phishing simulation, adaptive training, risk profiling and dark web exposure monitoring in both languages. Higher tiers add 24/7 support, automated compliance reporting, real-time attack simulation and SOC integration. A 30-day free trial is available.