Critical Infrastructure · Canada

Canada’s Critical Infrastructure Security Playbook Is Changing in 2026

Canada is tightening its approach to protecting essential systems as cyber threats, operational technology risks and physical security increasingly converge. For security leaders in energy, transportation, telecommunications, water and other critical sectors, the challenge is no longer simply preventing intrusion—it is maintaining essential operations when multiple layers of protection fail at once.

By Security News Staff ·

Security operations centre monitoring Canadian critical infrastructure, including energy, communications and industrial systems.

Canada’s critical-infrastructure security environment entered a new phase in 2026.

Energy systems, telecommunications networks, transportation infrastructure, financial systems and other essential services have always required protection. What has changed is the degree to which their physical facilities, operational technology, corporate networks, contractors and remote systems now depend on one another.

A cyber incident can create a physical consequence.

A physical intrusion can provide access to a digital system.

A compromised contractor account can affect equipment hundreds of kilometres away.

And a prolonged outage in one sector can create consequences across several others.

Canada’s federal government is responding to that convergence with new legislation, new resilience initiatives and greater collaboration with infrastructure operators.

For security leaders, the important question is no longer simply:

How do we stop an intrusion?

It is increasingly:

How do we keep the essential service operating if the intrusion succeeds?

That distinction could define the next generation of critical-infrastructure security in Canada.

Canada Has Ten Critical-Infrastructure Sectors

Public Safety Canada recognizes ten critical-infrastructure sectors:

  • energy and utilities;
  • finance;
  • food;
  • government;
  • health;
  • information and communication technology;
  • manufacturing;
  • safety;
  • transportation; and
  • water.

These sectors are different operationally, but they increasingly share the same security problem: dependence on interconnected digital and physical systems.

A water utility may depend on remote industrial controls.

A transit operator depends on telecommunications, electrical power, digital dispatch and physical facilities.

A hospital depends on networks, utilities, suppliers, access control and medical systems.

An industrial site may depend on remote operators, vendors and third-party technology.

A disruption rarely remains contained within one security discipline.

That is why critical infrastructure security in Canada is increasingly becoming a cyber-physical resilience problem.

Two infrastructure workers reviewing operations at a Canadian water treatment facility with surveillance equipment overlooking the site.
Protecting Canada’s Water InfrastructureView full-size image

Bill C-8 Changes the Canadian Cybersecurity Landscape

One of the most important developments came on June 16, 2026, when Bill C-8, the Act Respecting Cyber Security, received Royal Assent.

The legislation strengthens federal cybersecurity authorities and introduces the Critical Cyber Systems Protection Act, creating a regulatory framework for designated operators in federally regulated sectors including finance, telecommunications, energy and transportation.

According to Public Safety Canada, designated operators will be required to protect critical cyber systems and report significant cybersecurity incidents as the framework is implemented.

The legislation is being introduced in phases, so individual operators will need to determine which requirements apply to their organizations and when.

But security leaders should pay attention to the direction of travel.

Cybersecurity is moving further away from being treated solely as an internal IT function.

For organizations responsible for essential services, cyber resilience is increasingly becoming part of operational risk and regulatory accountability.

That has implications well beyond the cybersecurity department.

The Security Perimeter Is No Longer Just a Fence

Critical infrastructure traditionally has some of the most recognizable physical-security environments in Canada:

substations, generating stations, pipelines, ports, rail facilities, telecommunications sites, water plants, control centres and industrial installations.

Most have well-established physical controls.

Fencing.

Cameras.

Controlled gates.

Badging.

Security patrols.

Restricted areas.

Alarm monitoring.

But the operational perimeter now extends well beyond the property line.

A technician connecting remotely may have access to equipment inside a protected facility without ever entering the gate.

A communications cabinet kilometres away may support a much larger operational network.

A contractor laptop can become an indirect route into sensitive systems.

A cloud service can affect operations inside infrastructure that is physically secured to a very high standard.

The physical perimeter therefore remains important—but it is no longer sufficient.

Telecommunications technician servicing rooftop communications equipment overlooking Toronto at sunset.
Securing Canada’s Telecommunications InfrastructureView full-size image

This same issue is emerging in resource operations. SecurityNews.ca recently examined how distributed wells, pipelines and processing infrastructure are changing the traditional perimeter model in Alberta lithium mining security.

[INTERNAL LINK → [Alberta’s Lithium Projects Are Redrawing the Mining Security Perimeter](https://securitynews.ca/articles/alberta-lithium-mining-security)

The principle carries directly into critical infrastructure:

Protect the system, not merely the property boundary.

Operational Technology Has Changed the Consequences of a Cyber Incident

Operational technology, or OT, controls physical processes.

Depending on the sector, OT environments can include:

  • programmable logic controllers;
  • remote terminal units;
  • industrial control systems;
  • SCADA systems;
  • building management systems;
  • pumps;
  • valves;
  • sensors;
  • industrial communications;
  • process-control equipment; and
  • safety systems.

That makes OT security fundamentally different from ordinary office cybersecurity.

If an employee loses access to email, productivity suffers.

If an industrial control system is manipulated, physical processes may change.

The Canadian Centre for Cyber Security warns that internet-accessible industrial systems can be targeted by attackers exploiting weaknesses such as insecure remote access or default credentials.

Its current National Cyber Threat Assessment identifies ransomware as the leading cybercrime threat facing Canadian critical infrastructure and warns that state-sponsored actors are also targeting infrastructure networks.

For security operations, this creates an important shift.

A suspicious digital event may be a safety event.

And a physical-security event may be the beginning of a cyber incident.

Physical Security and Cybersecurity Need the Same Incident Picture

Consider a hypothetical critical-infrastructure facility.

At 2:07 a.m., a credential opens a restricted equipment room.

At 2:12 a.m., an unusual remote connection reaches an operational system.

At 2:16 a.m., a camera records a vehicle leaving a secondary access point.

At 2:18 a.m., operators receive an equipment alarm.

If four systems generate four separate incident tickets, the organization may initially see four unrelated abnormalities.

An integrated security operation sees a timeline.

That means critical-infrastructure operators should increasingly correlate:

access control

  • video surveillance
  • cybersecurity alerts
  • OT events
  • contractor records
  • guard observations
  • vehicle activity

The objective is not necessarily to combine every platform into one enormous piece of software.

It is to make sure the people responsible for responding can determine whether separate signals are related.

That becomes especially important when incidents cross organizational boundaries.

Drone Detection Is Becoming Part of the Perimeter Conversation

Critical infrastructure also has a third dimension to protect.

Facilities traditionally design perimeter security around movement across the ground.

But inexpensive unmanned aircraft can approach a facility without crossing the fence or passing through a controlled entrance.

SecurityNews.ca has previously examined how port-security buyers are beginning to connect aerial intrusion reporting with access control, patrol verification and incident command.

\[INTERNAL LINK → “Port Operators Add Drone Detection Clauses To Critical Site Contracts”]

The operational question is bigger than whether an organization owns a drone detector.

Operators need to decide:

  • what constitutes suspicious aerial activity;
  • who receives an alert;
  • how an observation is verified;
  • whether video surveillance can track the aircraft;
  • how evidence is preserved;
  • when police or other authorities are contacted; and
  • whether the event changes the physical-security posture of the facility.

Technology without a response procedure simply creates another alarm.

Canada Is Starting to Plan for Severe Cyber Disruption

One particularly significant development came in April 2026.

The Canadian Centre for Cyber Security launched the Critical Infrastructure Resilience and Escalated Threat Navigation initiative, known as CIREN.

Its focus goes beyond preventing attacks.

CIREN asks critical-infrastructure organizations to prepare for severe disruption and maintain essential services during worst-case scenarios.

Among its central recommendations are preparing to:

isolate critical systems for up to three months;

operate independently during severe incidents; and

rebuild systems following major compromise.

Those recommendations deserve attention from physical-security leaders as well as cybersecurity teams.

Imagine operating a critical facility while:

  • normal corporate systems are unavailable;
  • remote access is disabled;
  • some communications channels cannot be trusted;
  • third-party support is limited;
  • electronic credential management is degraded; or
  • digital incident-management platforms are offline.

Security procedures that function perfectly during normal operations may fail under those conditions.

Resilience planning therefore needs offline alternatives.

How are contractors validated?

How are guards briefed?

How are visitors documented?

How are incident reports recorded?

How are emergency credentials issued?

How does a control room verify instructions received over an alternate communication method?

The answers need to exist before the primary systems fail.

Critical Infrastructure Should Be Able to Operate in a Degraded State

Security planning often assumes technology is available.

Cameras are online.

Access control is functioning.

Networks are connected.

Phones work.

Cloud systems are reachable.

Databases are accessible.

But resilient critical infrastructure needs another operating mode:

degraded operations.

That means defining what happens when important systems become unreliable.

An organization may determine that:

  • guards switch to manual access logs;
  • certain entrances close completely;
  • contractor access is temporarily suspended;
  • physical patrol frequency increases;
  • local video storage becomes more important;
  • critical equipment requires two-person verification;
  • supervisors receive alternative communication devices; and
  • predefined offline contact lists are activated.

These procedures should not be invented during the incident.

They should be documented and exercised.

Security Exercises Need Physical Consequences

Public Safety Canada has already tested this concept.

Its cyber-physical exercise initiative brought together approximately 150 public- and private-sector organizations and more than 650 participants to practise responses to cyber incidents that produced physical consequences.

The exercise was specifically designed around the reality that critical infrastructure crosses both cyber and physical domains.

That approach should be replicated internally.

A tabletop exercise should not simply ask:

What happens if ransomware encrypts the corporate network?

It should ask:

What happens if ransomware affects operational visibility, contractors cannot authenticate normally, communications are degraded and an unrelated physical intrusion occurs at the same time?

That is a much harder exercise.

It is also much closer to the type of uncertainty real security teams may face.

Transportation Shows Why Security Events Need to Be Shared

Transportation infrastructure illustrates another challenge: incidents can occur across numerous geographically separated locations.

A transit system may include stations, depots, maintenance facilities, parking areas, control centres, vehicles and communications infrastructure.

One vandalism incident may look insignificant.

A pattern across several locations is different.

SecurityNews.ca has previously examined how transportation operators are moving toward shared incident intelligence when vandalism appears across multiple facilities.

\[INTERNAL LINK → “Transit Agencies Tighten Night Patrol Coverage After Coordinated Vandalism Run”]

That principle applies across critical infrastructure.

An attempted cabinet intrusion at one location may appear minor.

The same behaviour at four infrastructure sites within a week may indicate reconnaissance or coordinated criminal activity.

Security teams therefore need the ability to compare incidents across locations rather than treating each facility as an information silo.

Security professional overlooking a Canadian hydroelectric dam, electrical infrastructure and water-control systems at dusk.
Hydroelectric Critical Infrastructure SecurityView full-size image

Contractor Access Is a Critical-Infrastructure Vulnerability

Modern infrastructure depends heavily on third parties.

Maintenance companies.

Software vendors.

Engineering firms.

Equipment manufacturers.

Telecommunications providers.

Security contractors.

Temporary workers.

Specialist technicians.

Some require physical access.

Some require digital access.

Others require both.

That creates one of the most complicated identity-management problems in critical infrastructure.

A vendor may legitimately require remote access during commissioning but not six months later.

A technician may need access to one equipment room but not an entire facility.

A subcontractor may change employers while an old credential remains active.

Security programs should therefore apply the principle of least privilege to physical access as well as digital systems.

Credentials should reflect:

identity

location

job function

time

specific operational need

Temporary access should expire automatically wherever practical.

And when a vendor relationship ends, organizations should be able to remove both physical and digital access through coordinated offboarding.

Remote Access Deserves Special Attention

Remote access provides enormous operational value.

It can also bypass many layers of physical protection.

A vendor connecting from another province does not encounter the gate guard.

They do not pass the turnstile.

Nobody visually verifies their identity.

The security system therefore needs an equivalent digital gate.

The Cyber Centre recommends reducing unnecessary internet exposure of OT systems and protecting required remote connections with measures such as controlled network access, authentication and segmentation.

From an operational perspective, organizations should also know:

  • who approved the remote session;
  • which individual actually connected;
  • what equipment they accessed;
  • how long the session lasted;
  • whether activity was recorded;
  • and whether access automatically terminated afterward.

Remote access should be treated as an entry point into a protected facility—even when nobody physically enters it.

Canada Is Also Expanding Public-Private Cyber Collaboration

On September 29, 2026, Public Safety Canada and the Communications Security Establishment held the first in-person meeting of the Canadian Cyber Defence Collective Strategic Forum Advisory Council.

The initiative brings public- and private-sector organizations together to strengthen Canada's defence against cyber threats.

That matters because most Canadian critical infrastructure is not protected by government alone.

Infrastructure ownership, operation, technology and supply chains span governments, utilities and private companies.

Threat information therefore has to move between organizations faster than many traditional reporting structures allow.

Security leaders should understand what information their organization can share, with whom, and under what circumstances before a crisis occurs.

An incident affecting one operator may provide warning to another.

Security professional overlooking a Canadian hydroelectric dam, electrical infrastructure and water-control systems at dusk.
Hydroelectric Critical Infrastructure SecurityView full-size image

The Most Important Assets May Not Be the Most Expensive Assets

Security risk assessments sometimes prioritize assets primarily by replacement cost.

Critical infrastructure requires another measure:

operational consequence.

A modest communications cabinet may cost far less than a large transformer.

But if losing that cabinet removes visibility across multiple remote assets, its operational importance may be much greater than its price.

Operators should therefore map assets according to questions such as:

  • What happens if this asset becomes unavailable?
  • What other systems depend on it?
  • How quickly can it be replaced?
  • Is there an alternative?
  • Can the organization operate manually?
  • How many customers or operations would be affected?
  • Could the failure create a safety consequence?

This dependency mapping should influence physical-security investment.

The most expensive building on the site is not automatically the most important security target.

A Six-Layer Model for Critical-Infrastructure Security

Canadian operators can use a simple six-layer framework when reviewing their security programs.

1. Asset and Dependency Mapping

Identify critical physical assets, OT systems, communications systems, vendors and operational dependencies.

2. Identity and Access

Control employees, contractors, vendors, vehicles and remote users according to operational need.

3. Detection and Verification

Use surveillance, intrusion detection, cyber monitoring and operational alarms to identify credible abnormal activity.

4. Cyber-Physical Correlation

Give responders the ability to determine whether physical, cyber and operational events are related.

5. Response

Define who verifies an event, who makes decisions, when external responders are contacted and how evidence is protected.

6. Resilience and Recovery

Prepare to operate essential services when normal systems and communications are unavailable.

The sixth layer is increasingly important.

The strongest security program is not necessarily the one that prevents every incident.

No organization can guarantee that.

The stronger program is often the one that prevents what it can, detects what gets through and continues operating when something goes wrong.

What Security Providers Should Take From This

Canada's evolving approach to critical-infrastructure protection creates opportunities for security integrators, consultants, guarding companies and technology providers.

But selling individual products will become less persuasive.

A critical-infrastructure operator may not simply want:

more cameras.

It may want cameras that integrate with access control and incident response.

It may not simply want:

more guards.

It may want mobile response tied to verified alarms across dispersed assets.

It may not simply want:

cybersecurity monitoring.

It may want a security operation capable of understanding when a digital event affects a physical process.

The commercial opportunity therefore increasingly belongs to providers that understand the whole operating environment.

Physical security.

OT.

Cybersecurity.

Remote operations.

Contractors.

Resilience.

Incident command.

Canada’s Critical-Infrastructure Security Model Is Becoming About Resilience

The major Canadian developments of 2026 point in the same direction.

Bill C-8 creates a stronger cybersecurity framework for designated critical systems.

The Cyber Centre's CIREN initiative asks infrastructure organizations to prepare for severe and prolonged disruption.

Canada's national cyber-threat assessment warns that critical infrastructure remains attractive to both criminal and state-sponsored actors.

And public-private collaboration is expanding as infrastructure operators confront threats that cross sector and organizational boundaries.

For security leaders, that means prevention alone is no longer enough.

The next generation of Canadian critical-infrastructure security will be measured by whether an organization can:

identify unusual activity;

understand whether physical and digital events are connected;

contain the incident;

maintain essential operations;

and recover without losing control of the environment.

Critical infrastructure has always been about protecting assets.

In 2026, the larger mission is becoming clearer:

protect the service those assets exist to provide.

Frequently Asked Questions

What is considered critical infrastructure in Canada?

Canada recognizes ten critical-infrastructure sectors: energy and utilities, finance, food, government, health, information and communication technology, manufacturing, safety, transportation and water.

What is critical-infrastructure security?

Critical-infrastructure security covers the protection and resilience of the systems, facilities, technologies, networks and services necessary for essential societal and economic functions. It can include physical security, cybersecurity, operational technology, personnel security, emergency management and business continuity.

What is OT security?

Operational technology security protects the hardware and software used to control physical industrial processes. Examples include industrial control systems, SCADA environments, programmable controllers, sensors, pumps and other operational equipment.

Why should physical security and cybersecurity teams work together?

Modern infrastructure connects physical facilities with digital systems. Unauthorized physical access can create cyber risk, while cyber compromise can create physical or operational consequences. Sharing information allows security teams to determine whether apparently separate events are part of a single incident.

What did Bill C-8 change for Canadian critical infrastructure?

Bill C-8 received Royal Assent in June 2026. Among other changes, it introduced the Critical Cyber Systems Protection Act, which establishes a cybersecurity framework for designated operators in federally regulated sectors including telecommunications, finance, energy and transportation. Implementation is being phased, so organizations should confirm their specific obligations.

What is CIREN?

CIREN stands for Critical Infrastructure Resilience and Escalated Threat Navigation. The Canadian Centre for Cyber Security launched the initiative in April 2026 to help critical-infrastructure organizations prepare for severe cyber incidents and maintain essential services during prolonged disruption.

What should critical-infrastructure operators prioritize?

A strong baseline includes identifying critical assets and dependencies, tightening physical and digital access, securing remote access, monitoring OT systems, connecting cyber and physical incident information, exercising severe-disruption scenarios and preparing procedures for degraded operations.