Identity Is the New Perimeter: Locking Down Access in the Cloud Era
June 10, 2025Scattered Spider and the Help Desk: When Social Engineering Beats Your Firewall
July 15, 2025In June 2025, the federal government introduced Bill C-8, An Act respecting cyber security, reviving the cyber-security framework that had been developing in the previous Parliament. For organizations in and around Canada’s designated critical infrastructure, it signals a shift from voluntary good practice toward legislated expectations.
What the bill sets out to do
At a high level, the legislation would establish a framework to protect critical cyber systems in federally regulated sectors such as finance, telecommunications, energy, and transportation. It contemplates obligations to establish cyber-security programs, to manage risks including those from the supply chain, to report cyber incidents to the Cyber Centre, and to comply with directions from government.
Why it matters beyond the named sectors
- Supply-chain reach. Regulated operators will push requirements down to their vendors and partners.
- Mandatory incident reporting. A formal duty to report incidents to the Cyber Centre changes how carefully organizations must handle events.
- Direction of travel. Even if your organization is not covered, the bill signals the standard of care the market will expect.
Preparing without waiting
Establish a documented cyber-security program with clear ownership. Understand and manage your supply-chain risk. Ensure you can detect, assess, and report incidents on a defined timeline. None of this is wasted effort if the details change; it is simply good security expressed as governance.
Takeaway
Bill C-8 moves Canadian cyber security toward legislated baselines and mandatory incident reporting, and its effects will reach far beyond the named sectors through supply-chain requirements. Build a documented program, manage vendor risk, and get your incident detection and reporting in order now.
