Cyber Risks in Canada

The Impact of Bill C-26 on Financial Institutions and Other Federally Regulated Critical Infrastructure in Canada

November 22, 2023 4:00pm

Richard Larose
Senior Technical Advisor, Critical Cyber Systems Protection Act
Canadian Centre for Cyber Security

Kelly-Anne Gibson
Director, Cyber Protection Policy Division
Public Safety Canada

This panel will discuss Bill C-26, a significant piece of legislation that will require designated critical cyber systems’ operators to establish a cyber security program to protect their critical cyber systems. The Bill mandates that each designated critical cyber system operator will need to take reasonable steps to identify and manage cyber security risks and immediately report any cybersecurity incidents above a certain threshold to the Communications Security Establishment (CSE) and notify their regulator. We will explore:

  • The new obligations to financial institutions introduced by the Bill C-26 and compliance requirements
  • How breaches are to be reported and the required timeline for reporting and notifying
  • Keeping records of how you are implementing your cybersecurity program
  • Mitigations of supply-chain and third-party risks