Bilingual Security Awareness Training for Canadian Organizations
OSFI Guideline B-13 expects training and awareness as part of managing cyber risk. Quebec's Law 25 means a meaningful share of your workforce needs it in French. A-SAT delivers both with adaptive phishing, smishing, deepfake and voice-clone simulation, and evidence your regulator will accept.
By submitting, you agree to receive communications from Aspire Tech. You can unsubscribe at any time.
For Canadian teams who have to evidence it, in both official languages
Change behaviour with realistic, personalized simulations
Four channels, two languages, one adaptive platform. Every simulation is role-based, escalates with each user risk score, and teaches at the exact moment a mistake is made.
Canadian context, both languages
Tested on messages your staff would actually open
CRA notices, e-transfer confirmations, supplier payment changes and payroll updates — delivered in the language each employee works in, not translated from a US template after the fact.
- AI-generated email and SMS in English and French
- Language assigned per user within a single campaign
- Mobile-optimized landing pages staff actually meet
ARC : un remboursement de 312,45 $ vous attend. Confirmez vos renseignements avant expiration :
arc-remboursement-depot.info
Bien vu. Same simulation, delivered in each employee's working language — and the micro-lesson lands in that language too.
Point-of-click training
Catch the click at the exact moment it happens
When someone clicks, taps or complies, micro-training fires immediately — in their language, while the lesson lands. A module assigned three weeks later connects to nothing.
- Instant micro-lesson tied to what was missed
- Live risk score per user drives difficulty
- High-risk staff get more; low-risk staff are left alone
Supplier payment details updated — action before 4:00 PM ET
from: finance@aspire-tss-payables.co
Please use the revised banking information for today's transfer…
3 clues you can spot next time:
- Look-alike domain
- Same-day deadline
- Banking details changed by email
Beyond email
Meet a deepfake before a criminal introduces you to one
A cloned voice needs about thirty seconds of audio; a deepfake video needs a short clip. Around two-thirds of employees cannot reliably spot AI-generated video — a controlled test is a better place to learn that than a payment request.
- Photorealistic deepfake video from a short clip
- Live conversational AI voice-clone calls
- Dark web credential exposure fed into risk profiles
Chief Financial Officer
Incoming call · +1…
The evidence file
Evidence proportionate to your risk profile
OSFI B-13 is principles-based, so you have to justify the programme you chose. Reporting is automated and mapped to PIPEDA, ISO/IEC 27001:2022 and PCI DSS v4.0 — with completion split by language group for Law 25 coverage.
- Per-user completion by department, site, role and language
- Click rate, report rate and repeat-offender tracking
- Proof that board and senior management were trained too
Human risk dashboard
OSFI B-13 · PIPEDA · Law 25 · ISO 27001
Phishing click rate — trending down
85%
fewer security incidents
92%
training completion
Four channels, two official languages
Most platforms simulate one thing: English email. Attacks on Canadian organizations arrive by SMS, by phone and increasingly by video — and in whichever language the target actually works in.
SMS smishing
AI-generated SMS in English and French, modelled on the messages your staff actually receive — CRA notices, delivery alerts, e-transfer confirmations, payroll changes.
Deepfake video
Upload a short clip; the platform generates a photorealistic avatar for a simulated executive-impersonation attack.
Voice cloning (vishing)
A cloned voice from around 30 seconds of audio; an AI agent calls staff and holds a live conversation, responding in real time.
Dark web monitoring
Continuous scanning of breach data for compromised staff credentials — included from the entry tier, not sold separately.
Canadian compliance
The Canadian regulatory picture just changed
Bill C-8 received Royal Assent on 15 June 2026, after passing the House on 26 March and the Senate on 4 June. The Critical Cyber Systems Protection Act will phase in through regulation — which means designated operators have a preparation window, not an emergency. Building a measurable programme takes longer than the notice period you are likely to get.
OSFI B-13 is principles-based. That is not a lighter obligation — it means you have to justify the programme you chose, with evidence.
OSFI Guideline B-13
In effect 1 January 2024Sets OSFI expectations for technology and cyber risk management at federally regulated financial institutions, across governance and risk management, technology operations and resilience, and cyber security. Training and awareness is named among the organisational measures expected. It is explicitly not one-size-fits-all — your programme must be proportionate to your risk profile, and you have to be able to show why.
Bill C-8 / CCSPA
Royal Assent 15 June 2026Canada’s cyber security legislation is now law — S.C. 2026, c.9. The Telecommunications Act amendments took effect on Royal Assent; the Critical Cyber Systems Protection Act is being implemented in phases, and as of late July 2026 no implementation date had been announced. It creates a regulatory framework for designated operators in finance, telecommunications, energy and transportation.
PIPEDA
Safeguards principleRequires safeguards appropriate to the sensitivity of the personal information held. The Office of the Privacy Commissioner has consistently treated staff awareness as part of an adequate safeguard regime, and it is routinely examined after a breach.
Quebec Law 25
Privacy and languageSubstantially raised privacy obligations for organisations operating in Quebec, including governance, breach reporting and accountability. Combined with Quebec’s French-language requirements, training delivered only in English is a practical compliance gap — not just an HR preference.
Confirm the current implementation status of the Critical Cyber Systems Protection Act before relying on it in a procurement conversation — the phased regulations are still being made.
Why bilingual matters more than vendors admit
Most global platforms offer French — usually European French, machine-translated, with scenarios set somewhere nobody recognises. A Quebec employee reading a phishing simulation in Parisian French about a company that does not exist learns to spot the training, not the attack.
Simulations and micro-training are assigned by each user language preference — so one campaign covers a Montreal branch and a Toronto head office without running two programmes.
What Canadian organizations see
average reduction in security incidents
training completion rate
organizations served
Measured across Aspire Tech client deployments. Methodology and measurement period available on request.
How A-SAT compares
Canada has strong domestic incumbents with years of local presence — we say so. The rows that decide it are deepfake, vishing, dark web and adaptive difficulty.
| Capability | A-SAT | Canadian incumbents | Global platforms |
|---|---|---|---|
| Email phishing simulation | Yes, AI-generated, continuously refreshed | Yes | Yes, large template library |
| French-Canadian content | Yes, written for Canadian workplaces | Yes | Often European French, translated |
| SMS smishing simulation | Yes, EN and FR | Limited | Limited |
| Deepfake video simulation | Yes, self-service avatar creation | Not available | Not available |
| Voice-clone (vishing) simulation | Yes, live conversational AI agent | Not available | Not available |
| Dark web credential monitoring | Included from entry tier | Varies | Separate product |
| Point-of-click micro-training | Immediate, at moment of failure | Varies | Batch assignment |
| Adaptive per-user difficulty | Yes, driven by live risk score | Partial | Partial |
| Canadian market presence | New entrant | Established, Canadian-owned | Global incumbent |
Full feature-by-feature comparison on our KnowBe4 alternative page.
Built for your regulator
Federally regulated financial institutions
OSFI B-13 training and awareness evidence, proportionate to your risk profile and defensible on that basis.
Critical infrastructure operators
Finance, telecommunications, energy and transportation — the sectors named under the Critical Cyber Systems Protection Act.
Public sector and Crown corporations
Bilingual delivery and reporting, with evidence formatted for internal audit.
Healthcare and life sciences
Sensitive personal information under PIPEDA and provincial health privacy legislation.
Quebec enterprises
Law 25 obligations with training and reporting delivered in French for the workforce that needs it.
How deployment works
- 1
Discovery call, 30 minutes
We map your workforce, language split and current programme against what OSFI, PIPEDA or Law 25 expects. Available within 24 hours, in English or French.
- 2
Pilot
A defined group with a baseline simulation, so you see the real click rate — by language group — before anything changes.
- 3
Directory integration
Active Directory, Okta, SAML or HR system sync, including language preference mapping.
- 4
Rollout
Role-based paths assigned in each user language, adaptive simulation schedule begins — in days, not quarters.
- 5
First evidence file
Baseline versus current, structured for OSFI-style evidence and split by language for Law 25 coverage.
A 30-day free trial is available, or start with a scoped pilot.
Pricing
Plans start from $1.17 per user per month, billed annually. Every plan includes phishing simulation, adaptive training, risk profiling and dark web exposure monitoring — in English and French. Higher tiers add 24/7 support, automated compliance reporting, real-time attack simulation and SOC integration. 30-day free trial.
CAD pricing and applicable taxes confirmed on your quotation.
See it against your own environment
Thirty minutes, a live walkthrough, and a straight answer on what it takes to evidence a training programme proportionate to your risk profile — in both official languages.
By submitting, you agree to receive communications from Aspire Tech. You can unsubscribe at any time.
Frequently asked questions
Does OSFI B-13 require security awareness training?
Guideline B-13, in effect since 1 January 2024, sets OSFI expectations for managing technology and cyber risk at federally regulated financial institutions and names training and awareness among the organisational measures expected. It is principles-based, so the programme must be proportionate to the institution risk profile — and defensible on that basis.
What is Bill C-8 and does it apply to us?
Bill C-8 received Royal Assent on 15 June 2026 as S.C. 2026, c.9, after passing the House of Commons on 26 March 2026 and the Senate on 4 June 2026. The Telecommunications Act amendments took effect immediately; the Critical Cyber Systems Protection Act is being implemented in phases and, as of late July 2026, no implementation date had been announced. It creates a regulatory framework for designated operators in the finance, telecommunications, energy and transportation sectors.
Is training available in French?
Yes. A-SAT delivers courses, phishing simulations and micro-training in French as well as English, with Canadian scenarios rather than translated European content. Language is assigned per user, so one campaign can cover a Montreal branch and a Toronto head office at the same time.
Does PIPEDA require employee security training?
PIPEDA requires safeguards appropriate to the sensitivity of the personal information held. Employee awareness training is a widely accepted component of an adequate safeguard regime and is routinely examined by the Office of the Privacy Commissioner after a breach.
How does Quebec Law 25 affect our training programme?
Law 25 substantially raised privacy obligations for organisations operating in Quebec, including governance, breach reporting and accountability. Combined with Quebec French-language requirements, delivering training only in English leaves a practical gap for the part of your workforce that works in French.
Can A-SAT simulate deepfake and voice-phishing attacks?
Yes. Administrators can generate a photorealistic avatar from a short video clip for deepfake simulations, and the platform AI agent can call staff using a cloned voice and hold a live conversation, tracking who complied, who questioned and who reported.
How does A-SAT compare with Canadian incumbents?
Canada has established domestic vendors with years of local presence. The A-SAT differences are simulation coverage beyond email — SMS, deepfake video and voice cloning — dark web credential monitoring included from the entry tier, adaptive per-user difficulty driven by a live risk score, and micro-training that fires at the moment of failure, in the user language.
What does A-SAT cost?
Plans start from $1.17 per user per month, billed annually, including phishing simulation, adaptive training, risk profiling and dark web exposure monitoring in both languages. Higher tiers add 24/7 support, automated compliance reporting, real-time attack simulation and SOC integration. A 30-day free trial is available.
