Requirements of the CCSPA
The CCSPA would require designated operators to design and implement the following controls:
A cybersecurity program must be established within 90 days of being classified as a designated operator.
A well-defined cybersecurity program accounts for organizations'; business objectives, risk profile, regulatory and compliance requirements, and external threat landscape. It should also have active participation from the executive board, senior management, employees, contractors, and third-party vendors.
The program must meet the following criteria:
- Identify cybersecurity risks within the organization, including supply chain threats and the use of third-party products and services.
- Implement technologies to proactively detect and protect CCS from being compromised.
- Devise mitigation plans to align risks with corresponding risk appetite levels and minimize the impact of a cyber incident on CCS.
- Track the regulatory requirements and ensure compliance.
The program must be reviewed within 60 days after each year of establishment. Any changes made or set to be made from the review must be notified to the regulator within 30 days of the review.
Designated operators will be required to immediately notify regulators in the event of any significant change in ownership/control, use of third-party services, or any clauses prescribed in the regulation.
A cybersecurity incident is defined by Bill C-26 as an act, omission, or circumstance that interferes or may interfere with the continuity or security of the vital service or system, or the confidentiality, integrity, and availability of the critical cyber system.
Designated operators must report cybersecurity incidents impacting their critical cyber systems'; operations to both:
- The appropriate regulator associated with their critical infrastructure sector.
- The Communication Security Establishment's (CSE's) Canadian Centre for Cyber Security.
The Cyber Centre will investigate the incident and provide mitigation advice. Designated operators must follow the Cyber Centre's recommendations to reduce risk and protect their critical systems.
Regulators may have varying requirements for what constitutes a timely duration of reporting a cyber incident, so please review your reporting obligations with the relevant regulator.
Designated operators will be required to keep records of the following:
- Any steps taken to implement designated operators'; cybersecurity program that spans across people, process, and technology controls. This includes all steps implemented across five cyber domains – identify, protect, detect, respond, and recover.
- Every cybersecurity incident that the designated operator reported.
- Any steps taken by the designated operator to mitigate any supply-chain or third-party risks.
- Any measures taken by the designated operator to implement a cybersecurity direction.
- Any other matter prescribed by the regulations.
Designated operators will be required to keep records in Canada at a place prescribed by regulation or, if no place is prescribed, at their place of business. They will also be required to keep records in the manner and for the period determined by the appropriate regulator unless another manner or period is prescribed by regulation.
Overall implications and governmental powers
The bill allows the federal government to share technical or confidential information, as necessary, to protect vital infrastructure. Specifically, the Cyber Centre would be able to:
- Share its findings with designated operators belonging to the same sector.
- Inform regulators of a designated operator's failure to implement a cybersecurity program.
If regulators request advice, guidance, or services from CSE, the regulator may provide to CSE any information, including confidential information, about the designated operator's cybersecurity program and mitigation of risk from the supply chain, or use of third-party products and services.
The bill allows the federal government to issue cybersecurity directions to designated operators to protect a critical cyber system as they see fit, mandating compliance and maintaining records of compliance.
These directives are set out as follows:
- Identify the designated operators.
- Specify the required cybersecurity actions to be employed.
- Outline an implementation period.
Upon failure to comply, the bill allows each regulator to issue monetary penalties, with maximum penalties to be established by regulation at amounts of up to $1 million in the case of an individual, and up to $15 million in any other case.
Administrative monetary penalties may be issued for any violation of the CCSPA, including failing to report a cybersecurity incident and failing to comply with a cybersecurity directive.
Regulators will also have the authority to initiate regulatory proceedings leading to fines and possible imprisonment for non-compliance with the provisions of the CCSPA.
Security safeguards are meant to protect an organization's information assets from unauthorized disclosure, disruption, access, use, or modification. BDO recommends having the following key safeguards in place to ensure confidentiality, integrity, and availability of your organization's information assets:
- Risk management programs – Build awareness of organizational risk by conducting assessments of your controls and processes, establishing risk registers, assigning roles and responsibilities to manage risk accountably, and developing operating standards that meet compliance requirements. Being risk aware is the first step on the road to cybersecurity maturity.
- Secure platforms and architectures – Utilize secure cloud platforms with built-in security features that accelerate organizations' journey to security.
- Continuous monitoring, detection, and response capability – Maximize your threat response capabilities and threat awareness by leveraging tools that provide detection capability with actionable alerting.
- Offensive security – While having procedures and policies in place is important, testing organizational controls by running a simulated test is equally important. Controlled testing that employs a threat actor's tactics can help identify and remediate any weaknesses in your people, process, and technology controls.
- Asset and vulnerability management – Build your IT asset inventory list and leverage tools to identify the vulnerabilities within your network. Removing vulnerabilities in priority assets reduces risk.
- Incident response (IR) and data recovery (DR) procedures – It is not a matter of if one gets breached, but when. Having appropriate IR and DR plans with actionable steps, roles and responsibilities, and offline contact information helps speed your organization's containment and recovery times.
- Threat awareness – Leverage cyber threat intelligence to protect your organization against common threats and threat actors who plan to attack or exploit your organization on the dark web.
How can BDO Digital help?
BDO Digital offers a comprehensive approach to cyber management to help you rise to the challenge of today's cyber landscape.
Our team of experts can help you develop the tools and technologies you need to safeguard your critical assets, allowing you to focus on what's most important: growing your core business.
Our approach
We believe that your business objectives and IT strategy work together to create an effective security strategy that can be leveraged now and for future planning.
Therefore, our team can help you understand your current cybersecurity status, envision future needs, and implement a plan to achieve an optimal cybersecurity maturity level by taking a risk management and a business-forward approach to support your security enhancements.
Our services
The cybersecurity team covers every angle of today's business needs with a comprehensive suite of solutions. Our cybersecurity capabilities include:
- Application Security
- Cloud Security
- Cyber Risk Management & Transformation
- Managed Detection & Response
- Offensive Security
- Threat Hunting
- Threat Intelligence
- Vulnerability Management
For more information, contact
Get the latest cybersecurity news
No business can afford to be uninformed or unprepared for digital threats. Get the latest cybersecurity news, insights, and best practices delivered straight to your inbox.
1. https://cyber.gc.ca/en/guidance/cyber-threat-bulletin-ransomware-threat-2021
2. https://www.cisa.gov/uscert/ncas/alerts/aa22-110a
3. https://www.parl.ca/DocumentViewer/en/44-1/bill/C-26/first-reading