The Canadian Centre for Cyber Security publishes a National Cyber Threat Assessment every two years, and it is one of the more useful documents produced by the federal government, partly because it is written in plain language and partly because it is willing to name states. The picture it describes is consistent across editions and worth restating, because the organisations most exposed are frequently the ones least equipped to read threat assessments.

Ransomware remains the most disruptive form of cybercrime facing Canadian organisations, and critical infrastructure is a preferred target for a straightforward reason: operators of essential services cannot tolerate downtime, which makes them more likely to pay. This is not a technically sophisticated observation and it does not need to be. The economics of the crime select for victims who are under pressure to restore service quickly.

The assessment is also explicit that state-sponsored programs, and it names the People's Republic of China, Russia, Iran and North Korea, conduct activity against Canadian targets ranging from espionage to pre-positioning on critical networks. Pre-positioning is the item that deserves more attention than it gets. It describes an intrusion whose purpose is not to steal anything now but to establish and maintain access that could be used to disrupt operations later, during a crisis. It is intentionally quiet, it can persist for years, and it does not announce itself the way ransomware does.

Canada's specific exposure has a shape determined by what the country actually operates. The electricity system, oil and gas production and transmission, pipelines, rail, ports, water treatment and health care are all essential, all increasingly instrumented, and all reliant on operational technology that was designed for reliability and long service life rather than for security. A control system commissioned in the 1990s was built on the assumption that physical access was the security boundary. Connecting it to a corporate network, which is what remote monitoring and modern analytics require, dissolves that assumption without changing the equipment.

That convergence of information technology and operational technology is the structural problem underneath most critical infrastructure security work. Enterprise systems can be patched on a monthly cycle and rebooted at night. A turbine controller, a pipeline SCADA system or a water treatment programmable logic controller often cannot be taken offline without an outage, may run software the vendor no longer supports, and may not survive a patch at all. Security teams in these environments spend their time on segmentation, monitoring and compensating controls precisely because the direct fix is unavailable.

Alberta sits at the centre of the Canadian version of this problem, because the province operates a disproportionate share of the country's energy infrastructure. Production facilities, gas plants, pipeline networks, the transmission grid and increasingly large data centre loads are all here, and they are all more instrumented than they were a decade ago. Remote operations centres, condition-based maintenance and grid analytics deliver real efficiency, and every one of them creates a network path into a physical process. The efficiency case is strong enough that the connections will keep being made, which makes the security question one of how rather than whether.

The organisations in the most difficult position are not the large ones. A major pipeline operator or a bank has a security team, a budget and a board that asks about it. The exposure is concentrated in municipalities, school boards, hospitals, health authorities and small utilities, which run genuinely critical services on constrained public budgets with security staffing that is frequently a fraction of a single position. Canadian municipalities and health organisations have been hit repeatedly and disruptively, and the reason is not negligence. It is that a mid-sized city is expected to defend against the same adversaries as a bank, on a fraction of a percent of the resources.

The supply chain dimension makes the resourcing problem worse rather than better. Smaller operators rely heavily on vendors and managed service providers, which is the correct decision when internal capacity does not exist. It also means a compromise of one provider can reach many clients simultaneously, and the client has limited ability to audit the provider's security. Consolidating on a competent vendor is genuinely the right answer for a small utility, and it concentrates risk at the same time. Both things are true and neither cancels the other.

Canada's regulatory framework for this has developed unevenly across sectors. Financial institutions and telecommunications carriers operate under established regulatory expectations. Federally regulated energy infrastructure has requirements attached. Municipal water systems and regional health authorities largely do not, and legislative efforts to build a general critical cyber systems framework have moved slowly through successive parliaments. The result is that the sectors with the most resources also have the most obligations, and the sectors with the fewest resources have the fewest.

For Canadian security companies this is a market with an unusual property: the demand is real and urgent, and a large part of it sits with buyers who cannot pay very much. That shapes what gets built. Products priced for enterprise security operations centres do not fit a municipality with one part-time analyst, and the useful products for that buyer are managed services, sensible defaults and tooling that assumes no dedicated staff. It is a less glamorous market than enterprise security and it is where the national exposure actually is.

The measures that matter for an operator are well established and mostly unexciting: know what is connected, segment operational technology from corporate networks, control and monitor remote access, maintain offline backups that have been tested by restoring from them, and have an incident plan that has been rehearsed. None of it is novel and all of it is documented in the Cyber Centre's own guidance. The gap between organisations that do these things and organisations that intend to is where most Canadian incidents happen.

The reason to treat the assessment as more than a formality is the pre-positioning finding. Ransomware is loud, damaging and recoverable. An adversary quietly holding access to a grid control network or a pipeline system is preparing for a scenario in which disruption is the objective and the timing is theirs. Detecting that requires monitoring an organisation only builds when it accepts that being a target is the normal condition rather than an exceptional one, and for Canadian critical infrastructure the assessment is fairly clear that it is.

Sources

  1. Canadian Centre for Cyber Security: National Cyber Threat Assessment
  2. Cyber Centre: Ransomware playbook (ITSM.00.099)
  3. Public Safety Canada: critical infrastructure
  4. Canadian Centre for Cyber Security

Figures in this article are drawn from the sources above. Spotted an error? Tell us and we will correct it.