How Group 4 Networks and SecureAware align with Canadian telecom, anti-spam, and privacy regulations for ethical SMS and voice phishing simulation testing.
Last updated: February 2026
SecureAware is an enterprise security awareness and phishing simulation platform operated by Group 4 Networks. This document outlines our commitment to regulatory compliance under Canadian law — specifically the Canadian Radio-television and Telecommunications Commission (CRTC) regulations, Canada's Anti-Spam Legislation (CASL), and the Personal Information Protection and Electronic Documents Act (PIPEDA). Our platform conducts authorized, ethical SMS phishing (smishing) and voice phishing (vishing) simulations to help organizations measure and reduce human security risk.
How SecureAware aligns with CASL requirements for commercial electronic messages and phishing simulation.
CASL Penalties
Violations of CASL can result in administrative monetary penalties of up to $1 million for individuals and $10 million for businesses per violation. Group 4 Networks takes these obligations seriously and maintains rigorous compliance controls across all SecureAware operations.
How SecureAware aligns with CRTC telecom regulations for SMS and voice-based testing.
How SecureAware protects personal information and respects employee privacy rights.
Group 4 Networks' commitment to safe, responsible, and ethical security testing.
Every simulation campaign requires documented, signed authorization from the client organization before any testing begins.
Simulations are designed to measure awareness — not to cause harm, collect real credentials, or disrupt business operations.
Every simulation ends with an educational reveal that explains what happened, why it matters, and how to recognize real attacks.
Results are used for training and organizational risk assessment. We recommend clients use results for education, not disciplinary action.
We collect only what's necessary for testing. No actual credentials, financial information, or sensitive personal data is captured.
Rate limiting, opt-out mechanisms, kill switches, and campaign frequency controls ensure responsible operation at all times.
SecureAware is designed to support organizations in meeting requirements across industry-recognized security frameworks.
Supports Control 14 (Security Awareness and Skills Training) by providing measurable phishing simulation campaigns and human risk scoring.
Aligns with the Protect function (PR.AT - Awareness and Training) through regular security awareness testing and risk measurement.
Supports Annex A controls for information security awareness, education, and training (A.6.3) with documented evidence and metrics.
Addresses AT-2 (Literacy Training and Awareness) and AT-3 (Role-Based Training) through targeted, role-stratified phishing simulations.
Official Canadian regulatory documents and resources that inform our compliance framework.
Canada's Anti-Spam Legislation (CASL) — Full Text
Justice Laws Website
CRTC — Frequently Asked Questions about CASL
CRTC
CRTC Bulletin 2018-415 — Guidelines on Section 9 Liability
CRTC
CRTC — Implied Consent Guidance
CRTC
PIPEDA — Full Text
Justice Laws Website
Innovation, Science and Economic Development Canada — CASL Overview
ISED Canada
CRTC Decision 2025-343 — STIR/SHAKEN Reporting Requirements
CRTC
This document is provided for informational purposes only and does not constitute legal advice. Group 4 Networks and SecureAware make reasonable efforts to align our platform and operations with applicable Canadian regulations including CASL, CRTC telecom regulations, and PIPEDA. However, client organizations retain full responsibility for ensuring their use of SecureAware complies with all applicable laws, including obtaining appropriate employee consent, maintaining required documentation, and adhering to their own regulatory obligations. Telecommunications compliance (including STIR/SHAKEN) is managed by our infrastructure provider (Twilio) as a licensed telecom service provider. We recommend consulting with qualified Canadian legal counsel specializing in CASL, privacy, and telecom law before launching phishing simulation programs. Regulatory requirements may change; this document reflects our understanding as of the date indicated above.
Group 4 Networks is committed to operating SecureAware in full alignment with Canadian regulatory requirements. Contact our team to discuss compliance, request documentation, or schedule a regulatory review session.