{"id":132699,"date":"2023-09-08T09:08:35","date_gmt":"2023-09-08T13:08:35","guid":{"rendered":"https:\/\/stg.cira.ca\/?post_type=cira_news&#038;p=132699"},"modified":"2023-09-08T10:11:25","modified_gmt":"2023-09-08T14:11:25","slug":"recent-cyber-attacks-show-that-we-need-to-get-on-with-bill-c-26","status":"publish","type":"cira_news","link":"https:\/\/stg.cira.ca\/en\/resources\/news\/state-of-internet\/recent-cyber-attacks-show-that-we-need-to-get-on-with-bill-c-26\/","title":{"rendered":"Recent cyber attacks show that we need to get on with Bill C-26"},"content":{"rendered":"<p>This April, against a backdrop of Canadian and Ukrainian flags, Prime Minister Justin Trudeau stood on stage at Toronto&#8217;s Royal York hotel alongside Ukrainian Prime Minister Denys Shmyhal. Mr. Trudeau reiterated Canada\u2019s support for Ukraine and told reporters about a new military aid package designed to help Kyiv fend off Russia&#8217;s illegal invasion.<\/p>\n<p>In the weeks that followed, pro-Russian hackers retaliated the way they <a href=\"https:\/\/www.cbc.ca\/news\/politics\/cse-cyber-attack-ukranian-visit-1.6806709\">often do<\/a> against governments that support Ukraine, with a <a href=\"https:\/\/nationalpost.com\/news\/canada\/russian-cyber-attacks-canada\">rash<\/a> of distributed denial of service attacks that aim to overwhelm high-profile websites and knock them offline.<\/p>\n<p>Pro-Russian groups went on to claim responsibility for a string of incidents affecting major targets including <a href=\"https:\/\/www.theglobeandmail.com\/canada\/article-russia-hacking-canada-gas-pipeline\/\">a natural gas pipeline<\/a>, the <a href=\"https:\/\/www.theglobeandmail.com\/politics\/article-pro-russian-cyberattacks-strike-at-pmo-senate-websites\/\">Prime Minister\u2019s Office<\/a> and <a href=\"https:\/\/montreal.ctvnews.ca\/cyber-attack-at-hydro-quebec-pro-russia-hackers-claim-responsibility-1.6353627\">Hydro-Quebec.<\/a> Their message? They have the power to disrupt Canada\u2019s networks and they\u2019re not afraid to use it.<\/p>\n<p>In August, the Canadian Centre for Cyber Security and RCMP issued a <a href=\"https:\/\/www.canada.ca\/en\/communications-security\/news\/2023\/08\/cyber-centre-releases-baseline-cyber-threat-assessment-on-cybercrime-with-support-from-rcmp.html\">report<\/a> warning that cyber criminals operating from \u201ccybercrime safe havens\u201d like Russia will \u201calmost certainly\u201d continue to target critical infrastructure in Canada.<\/p>\n<p>With geopolitical tensions and cybercrime on the rise, these attacks underscore the need for Canada\u2019s cyber defences to step up in the face of a constantly evolving threat landscape.<\/p>\n<p>Bill C-26, the federal government\u2019s draft legislation to improve cybersecurity across federally-regulated cyber systems critical to Canadian society \u2013 the ones that support the energy, finance, telecommunications, and transportation sectors \u2013 is our next best chance to have a national conversation about what\u2019s needed to create strong, coordinated cyber defences.<\/p>\n<p>The good news is that, so far, these acts have failed to significantly disrupt the lives of Canadians. But, more serious and debilitating cyber attacks are a matter of when \u2500 not if.<\/p>\n<p>Tomorrow, pro-Russian groups or other adversaries could show their true powers and shut down the operations of a power company, a water supplier, a large hospital. Such attacks, if successful, could <a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/security-considerations-critical-infrastructure-itsap10100\">harm or even threaten<\/a> the lives of Canadians.<\/p>\n<p>Despite our best efforts, Canada is stuck in a game of whack-a-mole. We\u2019ve got the tools, but we need the coordination. Cybersecurity is a team sport, not solely the responsibility of any single stakeholder\u2014government, the private sector, technical operators, civil society and Canadian citizens\u2014but of all of them.<\/p>\n<p>That\u2019s why we need to get on with <a href=\"https:\/\/www.parl.ca\/DocumentViewer\/en\/44-1\/bill\/C-26\/first-reading\">Bill C-26<\/a>, which would raise the baseline level of cybersecurity across the federally-regulated cyber systems Canadians rely on most.<\/p>\n<p>Among other requirements, the bill would have designated operators in the energy, finance, telecommunications, and transportation sectors create cybersecurity programs and report incidents. These measures are vital to keep pace with the changing threat environment and innovation in technology and will enhance Canada\u2019s national security and public safety.<\/p>\n<p>Ensuring that these operators secure their networks is of utmost importance. A forthcoming survey commissioned by CIRA suggests that only 44 per cent of surveyed organizations that experience a cyber incident report it to customers whose data are compromised\u2014despite an existing <a href=\"https:\/\/www.priv.gc.ca\/en\/privacy-topics\/business-privacy\/safeguards-and-breaches\/privacy-breaches\/respond-to-a-privacy-breach-at-your-business\/gd_pb_201810\/\">requirement<\/a> to do so. That so few organizations report on cyber incidents demonstrates that we, as a country, need to do better.<\/p>\n<p>Bill C-26 has <a href=\"https:\/\/www.parl.ca\/legisinfo\/en\/bill\/44-1\/c-26\">been referred<\/a> to the House of Commons Standing Committee for Public Safety and National Security for study, but it likely won\u2019t be reviewed by the committee until later this fall. The slew of recent cyber attacks against Canadian critical infrastructure operators make it clear that we need to move quickly.<\/p>\n<p>The committee phase of the legislative process is a key opportunity for rigorous study and public debate to strengthen the bill. This process can bring the cybersecurity community together with critical infrastructure operators and parliamentarians to ensure that C-26 is the most effective legislation it can be.<\/p>\n<p>The string of recent cyber attacks attributed to pro-Russian organizations should serve as Canada\u2019s warning. Bill C-26 is our opportunity to heed the call and work together to protect Canadians. Let\u2019s get on with it, before we find ourselves making legislation in the middle of a national cybersecurity crisis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This piece originally appeared in The Hill Times on September 7, 2023. <\/p>\n","protected":false},"featured_media":132834,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Recent cyber attacks show that we need to get on with Bill C-26 - CIRA","description":"This piece originally appeared in The Hill Times on September 7, 2023."},"footnotes":""},"topic":[1028],"class_list":["post-132699","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blog","cira_topic-cira-topic-state-of-internet","cira_author-byron-holland"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/cira\/v1\/news\/132699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/cira\/v1\/news\/132699\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/media\/132834"}],"wp:attachment":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/media?parent=132699"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/cira\/v1\/topic?post=132699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}