NC-CIPSeR Archives - CIPSER /cipser/category/nc-cipser/ 杏吧原创 University Wed, 29 Jul 2026 17:03:04 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.4 Cybersecurity and Food-System Resilience in the Age of Artificial Intelligence /cipser/2026/agricultural-cybersecurity-food-system-resilience-ai/ Wed, 29 Jul 2026 15:20:07 +0000 /cipser/?p=2019 Canada鈥檚 farms and food systems should be treated as a critical-infrastructure cybersecurity priority. Those who feed the country should not be left to manage emerging digital risks alone.

The post Cybersecurity and Food-System Resilience in the Age of Artificial Intelligence appeared first on CIPSER.

]]>

Cybersecurity and Food-System Resilience in the Age of Artificial Intelligence

Published on July 29, 2026

Time to read: 3 minutes

Canadian grain fields and agricultural equipment are connected through a digital cybersecurity network.
Canada鈥檚 increasingly connected agricultural and food systems require a coordinated approach to cybersecurity and resilience.

By Mario Daigle & Dylan Odd

Canada鈥檚 farms and food systems should be treated as a critical-infrastructure cybersecurity priority. Those who feed the country should not be left to manage emerging digital risks alone.

Agriculture has digitized faster than its cybersecurity posture has matured. Farms and food-system operators increasingly depend on connected equipment, operational technology and remote-access services, which improve productivity but also create shared dependencies that amplify cyber disruption.

Artificial intelligence accelerates this threat by making incursions faster and less expensive to execute. Malicious actors can now identify exposed systems, test credentials, interpret technical documentation and adapt existing cyber tools at a pace not thought possible only a few years ago. It is a watershed moment. And it means smaller, geographically dispersed agricultural operations are economically viable targets for threat actors.

Canadian farmers need more information about this emerging risk, and so does the public. Disruptions to planting, harvesting, livestock care, food processing, storage, or transportation threaten Canada’s food infrastructure. In 2025, Canadian authorities reported an incident in which the temperature and humidity settings of an internet-accessible grain-drying silo were manipulated remotely, demonstrating how cyber incidents can have real-world consequences for food security.

Canada鈥檚 farmers are private operators, but collectively they perform a critical-infrastructure function. Most operators lack the internal resources to identify, assess and manage sophisticated cyber risks, particularly risks to digital service providers on which aspects of their operations depend.

Cybersecurity guidance for individual farms is helpful, but Canada needs a coordinated strategy tailored to the structure, operating realities, and shared dependencies of the agricultural sector.

The full article proposes four practical areas for federal action:

  • Establish a Centre of Excellence for Agricultural Cybersecurity.
  • Set cybersecurity expectations for agricultural technology vendors and service providers.
  • Map systemic digital dependencies across Canada鈥檚 food system.
  • Exercise how essential food-system functions will continue when digital systems fail.

Cybersecurity and food security are interwoven. Strengthening Canada鈥檚 agricultural cyber resilience will require federal leadership, bringing together governments, industry, researchers, technology providers, and, of course, Canadian farmers to ensure our food system is resilient, reliable, and secure.

Read the full 8-Page article: Cybersecurity and Food-System Resilience in the Age of Artificial Intelligence.

Image: AI-generated with ChatGPT by OpenAI for NC-CIPSeR, 2026.

The post Cybersecurity and Food-System Resilience in the Age of Artificial Intelligence appeared first on CIPSER.

]]>
NC-CIPSeR, 杏吧原创 University and 01 Quantum Launch Research Collaboration on AI Privacy and Data Security /cipser/2026/ai-privacy-data-security-research-collaboration/ Wed, 29 Jul 2026 13:53:28 +0000 /cipser/?p=2009 NC-CIPSeR and 杏吧原创 University are collaborating with 01 Quantum Inc. on a new research initiative to examine privacy and data-security vulnerabilities in modern artificial intelligence systems and evaluate technologies designed to mitigate them.

The post NC-CIPSeR, 杏吧原创 University and 01 Quantum Launch Research Collaboration on AI Privacy and Data Security appeared first on CIPSER.

]]>

NC-CIPSeR, 杏吧原创 University and 01 Quantum Launch Research Collaboration on AI Privacy and Data Security

Published on July 29, 2026

Time to read: 3 minutes

Representatives of NC-CIPSeR, 杏吧原创 University and 01 Quantum collaborating on AI privacy and cybersecurity research.
NC-CIPSeR and 杏吧原创 University are collaborating with 01 Quantum to study privacy and data-security risks in AI systems.

NC-CIPSeR and 杏吧原创 University are collaborating with 01 Quantum Inc. on a new research initiative to examine privacy and data-security vulnerabilities in modern artificial intelligence systems and evaluate technologies designed to mitigate them.

AI systems are increasingly being deployed across financial services, government operations, critical infrastructure and national-security environments. As multiple AI agents exchange and process information, sensitive data may be exposed in ways that organizations do not fully understand.

The project will simulate a realistic financial-institution environment in which multiple AI agents support activities such as fraud detection and customer-risk assessment. Researchers will stress-test the environment to identify potential vulnerabilities and quantify how sensitive information may be exposed.

A key area of study will be 鈥渕embership inference鈥- a method through which an outside party may statistically determine whether a particular record was included in an AI model鈥檚 training data. This type of exposure could present significant privacy and security concerns for financial institutions, governments, critical-infrastructure operators and defence organizations.

The first phase will measure data leakage within a standard, non-encrypted AI environment. A later phase will test an encryption-compatible model component and assess the ability of privacy-preserving technologies, including fully homomorphic encryption, to protect information while it is being processed.

鈥淭his project allows us to study real-world security and privacy challenges in technologies being deployed by critical infrastructure in Canada right now,鈥 said Adjunct Research Professor Perry Steckly, Principal Investigator at 杏吧原创 University (NPSIA) and Executive Director of NC-CIPSeR. 鈥淏y quantifying the vulnerabilities in modern AI models, we can help institutions understand the risks and evaluate technologies designed to mitigate them.鈥

The collaboration combines 杏吧原创 University鈥檚 research capabilities, NC-CIPSeR鈥檚 multidisciplinary work across critical infrastructure, emergency management, national security and defence, and 01 Quantum鈥檚 expertise in post-quantum cryptography and privacy-preserving technologies.

In addition to supporting independent research, the initiative will help validate the practical and commercial potential of encrypted AI technologies in realistic, security-sensitive environments.

This work contributes to a broader Canadian need to ensure that emerging AI technologies are secure, resilient and suitable for deployment in critical and sensitive systems.

Learn more: Read the full joint or explore NC-CIPSeR鈥檚 further work on AI, cybersecurity and critical-infrastructure resilience.

Image: AI-generated with ChatGPT by OpenAI for NC-CIPSeR, 2026.

The post NC-CIPSeR, 杏吧原创 University and 01 Quantum Launch Research Collaboration on AI Privacy and Data Security appeared first on CIPSER.

]]>
Our Teams in Action at Nuclear Defence Exercise in Chalk River /cipser/2026/nc-cipser-nuclear-defence-exercise-chalk-river/ Wed, 15 Jul 2026 13:22:35 +0000 /cipser/?p=1994 Several members of the NC-CIPSeR team recently had the opportunity to participate in the Nuclear Defence Exercise Series (NDX) at Canadian Nuclear Laboratories (CNL) in Chalk River.

The exercise brought together experts from government, industry, emergency management, and the nuclear sector to examine how Canada can better prepare for, respond to, and recover from complex threats affecting the nuclear sector and communities.

The post Our Teams in Action at Nuclear Defence Exercise in Chalk River appeared first on CIPSER.

]]>

Our Teams in Action at Nuclear Defence Exercise in Chalk River

Published on July 29, 2026

Time to read: 2 minutes

NC-CIPSeR Teams
Perry Steckly, Bettina Koschade, Tyson Macaulay, Matt Surch, Eric Griffin, Arnaud Lenglin, John Mania

Several members of the NC-CIPSeR team recently had the opportunity to participate in the Nuclear Defence Exercise Series (NDX) at Canadian Nuclear Laboratories (CNL) in Chalk River.

The exercise brought together experts from government, industry, academia, emergency management, and the nuclear sector to examine how Canada can better prepare for, respond to, and recover from complex threats affecting the nuclear sector and communities.

For our team, this was much more than a nuclear exercise. It was an opportunity to explore how the lessons, partnerships, and approaches developed within the nuclear sector can be adapted and applied across Canada’s broader critical infrastructure landscape. From coordinated decision-making and information sharing to resilience planning and cross-sector collaboration, the experience provided valuable insights that will help shape future NC-CIPSeR research, training, and collaborative projects.

As Canada continues to face increasingly complex and interconnected risks, learning from sectors that have long embraced rigorous safety, security, and resilience practices is essential.

A sincere thank you to Canadian Nuclear Laboratories (CNL) for their outstanding leadership, hospitality, and commitment to strengthening Canada’s resilience. We appreciate the opportunity to learn alongside such a diverse group of professionals and look forward to continuing these important conversations and partnerships.

If your organization has a role in protecting, operating, regulating, or supporting Canada’s critical infrastructure, the NDX Series is well worth your consideration. The challenges facing our nation increasingly span sectors, jurisdictions, and disciplines. Exercises like NDX provide an invaluable environment to strengthen partnerships, exchange knowledge, and build the collaborative capabilities that will be essential in responding to tomorrow’s complex threats. We highly recommend participating in future exercises.

The post Our Teams in Action at Nuclear Defence Exercise in Chalk River appeared first on CIPSER.

]]>
The FIFA World Cup and Canada鈥檚 Critical Infrastructure: Are Our Host Cities鈥 Energy and Water Utilities Secure? /cipser/2026/fifa-2026-critical-infrastructure-security/ Wed, 17 Jun 2026 22:59:36 +0000 /cipser/?p=1983 The threat environment with large sporting events: Large sporting events attract big crowds of fans and spectators, and they also attract the attention of malicious actors. With FIFA Cup 2026 just around the corner, securing our critical infrastructure (CI) in host cities against physical and cyber attacks is a top priority. In the last 10 […]

The post The FIFA World Cup and Canada鈥檚 Critical Infrastructure: Are Our Host Cities鈥 Energy and Water Utilities Secure? appeared first on CIPSER.

]]>

The FIFA World Cup and Canada鈥檚 Critical Infrastructure: Are Our Host Cities鈥 Energy and Water Utilities Secure?

Published on July 29, 2026

Time to read: 9 minutes

By Bettina Koschade and Shari St.John | Members of NC-CIPSeR Water Sector Task Force

The threat environment with large sporting events:

Large sporting events attract big crowds of fans and spectators, and they also attract the attention of malicious actors. With FIFA Cup 2026 just around the corner, securing our critical infrastructure (CI) in host cities against physical and cyber attacks is a top priority.

In the last 10 years, risks against CI during high-profile sporting events have undeniably increased, with water and power utilities targeted during recent Olympics and soccer tournaments. During the World Cup in Qatar in 2022 and the UEFA Euro Championships in 2024, several nations probed the CI of host cities, infiltrating operational control systems and mapping weak points for future exploitation.[i] At the Paris 2024 Olympic Games, security companies were hired to help monitor and manage physical and cyber threats targeting the water systems, roadways, housing facilities, and much more. Over the two-month period, they managed 485,000 threat alerts and 15 high priority cyber incidents.[ii] There is no doubt that the increase in threats and risks during high-profile events is real.

Threat actors are typically motivated by ideology, nationalism, financial incentives, or notoriety and reputation in criminal organizations.[iii]  These motivating factors make critical infrastructure, such as power and water utilities, high-value targets. Disrupting energy and water services can inspire public outcry and fear, while ransomware on critical utility network data can create large payouts for the perpetrator.

In normal operating environments, water and wastewater utilities across North America are already experiencing cyberattacks on their information technology (IT) and operational technology (OT) systems. Cyber alerts and advisories from federal organizations in Canada commonly identify vulnerabilities, attempted exploits, and successful hacks into our water and wastewater systems. During high-profile sporting events, and amidst current heightened geopolitical tensions around the globe, these attacks may become even more likely as increased attention is brought to host cities.[iv]

Threats against CI are not unique to specific parts of the globe; and the government of Canada has certainly recognized the increased risk to national security while hosting large-scale events.[v] In 2024, the Canadian Centre for Cybersecurity released a cyber threat bulletin highlighting risks associated with high-profile events, writing:

We assess that major international sporting events are compelling targets for a             variety of cyber threat activities, including cybercrime, hacktivism, state-sponsored                        cyber espionage, and state-sponsored disruptive or destructive cyber attacks.[vi]

The FIFA Cup 2026 is a particularly notable event, drawing massive crowds across three host countries: Canada, the United States of America (USA), and Mexico. Soccer is the most popular international sport and has historically been a common target for malicious actors.[vii] In the last 50 years, 45% of physical terrorist attacks targeting sporting events involved soccer venues.[viii] A big-name event like the World Cup offers state-sponsored and lone wolf actors alike a symbolic platform to make political statements by threat messaging, seeking media attention, and creating a sense of public insecurity and disruption.

The Canadian Centre for Cyber Security noted in 2024 that cyber-criminals are most likely to target large organizations during sporting events.[ix] The organizing bodies and high-profile athletes are encouraged to take extra precautions to prepare against known risks, and stadiums must implement effective security measures to protect spectators.[x] However, there are many more assets at risk during these games. Attacking a network of the host city鈥檚 interconnected critical infrastructure can create cascading effects that can disrupt not only the tournament itself,[xi] but the whole metropolitan area: from the transit system to the power grid to water and wastewater infrastructure. This puts the health and safety of all residents at risk.Host countries must be prepared to detect, respond, and recover from these physical and cyber acts.

This summer, in June and July, FIFA World Cup games are scheduled right in the centre of our biggest Canadian cities: Six games at the Toronto Stadium (BMO Field) located at the downtown waterfront of Lake Ontario and seven games at BC Place Vancouver, located in the core of the city.Even without intentional disruptions, the water and wastewater infrastructure of these host cities will be stressed by the temporary yet significant influx in population from visiting spectators. Many of the U.S. host cities already face water stress, and aging infrastructure is a common risk across all host cities.[xii] Water and wastewater utility operators in these host venues will be monitoring systems closely to keep operations running efficiently and to respond immediately to any issues.

Canada鈥檚 Water and Wastewater Infrastructure

Canada has recently recognized the need to deal with the vulnerabilities in our country鈥檚 water and wastewater infrastructure鈥攊t is a public safety issue. Water is a critical asset and therefore a high-value target to malicious actors, necessitating better protections and risk mitigation to reduce our growing exposure to attacks.[xiii] Water utilities extend far beyond the perimeter of the treatment plant; there are often thousands of kilometres of water main pipes,[xiv] along with pressure release valves, pump stations, and storage tanks scattered across a big city. Also scattered across various water and wastewater sites is operational technology (OT) which supports water and wastewater systems through remote monitoring, data logging, and operation of equipment. The Centre for Cyber Security has identified OT systems within water utilities as the primary target for actors seeking to disrupt water systems.[xv] With these known advisories, and water utilities already experiencing cyberattacks on a daily basis, increased cybersecurity on standard enterprise networks and OT networks is increasingly imperative to maintain safe and healthy drinking water for Canadians.[xvi]

However, most of our country鈥檚 water utilities were designed decades ago, without cyber-security in mind. The threat landscape has changed drastically over the years, especially with the rise of artificial intelligence (AI), which now rapidly and visibly exposes weaknesses in our essential services. A lack of vigilance and commitment of resources to better cyber protections will result in system security being outpaced by AI capabilities and exploits.

There is no question that the water industry will continue to increase its reliance on technology for service delivery, including automation and digitization. These are key solutions to meet the growing demand for water and wastewater treatment given population growth and more extreme weather events, and it even helps extend the life of our aging water infrastructure.[xvii] But it can also increase our vulnerability if security of the technology is not a priority.

ENHANCED SECURITY WITH A WHOLE-OF-SOCIETY APPROACH

Despite a real and complex threat environment, water and wastewater system security is still achievable through effective planning, implementation of risk mitigation measures, and continuous vigilance. For our immediate event-risk management, the security industry promotes an intelligence-led approach with real-time political monitoring, cyber-threat visibility, and infrastructure disruption awareness.[xviii] Physical security measures as simple as locking gates, building doors, and windows, and doing regular patrols of water and wastewater asset sites can be highly effective in deterring malicious actors. For an immediate improvement to cybersecurity, double-checking that your default passwords on IT and OT systems have been updated, and that remote access to critical equipment is restricted can be effective measures for limiting unauthorized access to networks. And for longer-term cybersecurity solutions which may require a greater commitment of time and resources, the government of Canada offers guidance based in industry best practices, such as the Cybersecurity Readiness Goals (CRGs)[xix] informed by The NIST Cybersecurity Framework 2.0.[xx]

Preliminary research on the security impact of large-scale sporting events on our CI highlights not only the vulnerabilities and threats against infrastructure during planned occasions, but also the potential mitigation approaches to protect our essential services year-round. However, it also uncovers the gap in research literature on the connection between large sporting events and the risk placed on the country鈥檚 critical infrastructure,[xxi] which is at best a burgeoning field of study. Lessons learned from the planning and discussions around water and wastewater systems supporting the FIFA Cup 2026 event may serve as a necessary launchpad for research into this critical area of study.

Indeed, a whole-of-society approach is what鈥檚 needed. By adopting a more community-centered security management approach to build resilience through awareness, preparedness, and mitigation we can create stronger links between citizens and the efforts and strategies of industry and government. During such a momentous event as the World Cup in Canada, there is an opportunity to benefit from the spirit of both the fans attending and the surrounding community.[xxii] As large-scale events continue to occur across our cities, identification of interdependencies between CI systems such as power, water, transportation, and more will become invaluable in risk mitigation planning to protect our infrastructure, our national security, and our people.

Endnotes


[i] Dave Rubenstein, host, The World Cup and Water鈥檚 Cyber-Preparedness Opportunity with 1898 & Co.鈥檚 Victor Atkins, episode 284, The Water Values Podcast, Bluefield Research, February 3, 2026, 50:38, https://www.bluefieldresearch.com/podcast/the-world-cup-and-waters-cyber-preparedness-opportunity-with-1898-co-s-victor-atkins/.

[ii] Nozomi Networks, 鈥淧rotecting the 2024 Paris Olympics Critical Infrastructure from Cyber Threats,鈥 2024, https://www.nozominetworks.com/case-studies/protecting-the-2024-paris-olympics-critical-infrastructure-from-cyber-threats.

[iii] Canada, The Cyber Threat to Canada鈥檚 Water Systems: Assessment and Mitigation (Canadian Centre for Cyber Security, 2025), https://www.cyber.gc.ca/en/guidance/cyber-threat-canadas-water-systems-assessment-mitigation; Ariel Stern and Yair Poleg, 鈥淐yber Security for Water Utilities,鈥 Water Canada, August 9, 2021, https://www.watercanada.net/cyber-security-for-water-utilities/.

[iv] Mike Lantz, 鈥淪ecurity Risks for the 2026 FIFA World Cup in North America,鈥 Paladin Security, March 19, 2026, https://paladinsecurity.com/security-prevention/2026-world-cup-security-risk-north-america/.

[v] Canada, Cyber Threat Bulletin:  Cyber Threats to Major International Sporting Events (Canadian Centre for Cyber Security, 2024), https://www.cyber.gc.ca/sites/default/files/cyber-threat-major-international-sporting-event-e_0.pdf; Lantz, 鈥淪ecurity Risks for the 2026 FIFA World Cup in North America.鈥

[vi] Ibid.

[vii] Grace R. Rahman et al., 鈥淭errorist Attacks against Sports Venues: Emerging Trends and Characteristics Spanning 50 Years,鈥 Prehospital and Disaster Medicine 38, no. 3 (2023): 366鈥70, https://doi.org/10.1017/S1049023X23000377.

[viii] Rahman et al., 鈥淭errorist Attacks against Sports Venues.鈥

[ix] Canada, Cyber Threat Bulletin:  Cyber Threats to Major International Sporting Events.

[x] Camille Singleton, 鈥淐ybersecurity at the World Cup: What You Should Know,鈥 IBM X-Force Threat Intelligence, June 6, 2018, https://www.ibm.com/think/x-force/cybersecurity-at-the-world-cup-what-you-should-know.

[xi] Lantz, 鈥淪ecurity Risks for the 2026 FIFA World Cup in North America.鈥

[xii] Rubenstein, The World Cup and Water鈥檚 Cyber-Preparedness Opportunity with 1898 & Co.鈥檚 Victor Atkins; Megan Bondar, 鈥淎re U.S. Water Systems Ready for World Cup 2026?,鈥 Bluefield Research, April 3, 2026, https://www.bluefieldresearch.com/are-u-s-water-systems-ready-for-world-cup-2026/.

[xiii] Canada, The Cyber Threat to Canada鈥檚 Water Systems.

[xiv] Ariel Stern and Yair Poleg, 鈥淐yber Security for Water Utilities,鈥 Water Canada, August 9, 2021, https://www.watercanada.net/cyber-security-for-water-utilities/.

[xv] Canada, The Cyber Threat to Canada鈥檚 Water Systems: Assessment and Mitigation (Canadian Centre for Cyber Security, 2025), https://www.cyber.gc.ca/en/guidance/cyber-threat-canadas-water-systems-assessment-mitigation.

[xvi] Stern and Poleg, 鈥淐yber Security for Water Utilities.鈥

[xvii] Stern and Poleg, 鈥淐yber Security for Water Utilities.鈥

[xviii] Mike Lantz, 鈥淪ecurity Risks for the 2026 FIFA World Cup in North America,鈥 Paladin Security, March 19, 2026, https://paladinsecurity.com/security-prevention/2026-world-cup-security-risk-north-america/.

[xix] Canada, Cyber Security Readiness Goals: Securing Our Most Critical Systems, Version 1.0 (Canadian Centre for Cyber Security, 2024), 24; Canada, Cyber Security Readiness Goals: Cross-Sector Toolkit, Version 1.0 (Canadian Centre for Cyber Security, 2024), 28, https://www.cyber.gc.ca/sites/default/files/cyber-readiness-goals-toolkit-e.pdf.

[xx] U.S. Department of Commerce, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (National Institute of Standards and Technology, 2024), NIST CSWP 29, https://doi.org/10.6028/NIST.CSWP.29.

[xxi] Stacey A. Hall, ed., Routledge Handbook of Sport Security, 1st ed. (Taylor & Francis Group, 2026), https://doi.org/10.4324/9781032641300.

[xxii] Brian E. Menaker et al., 鈥淩ethinking Sport Event Security: From Risk Management to a Community Driven Approach,鈥 Journal of Global Sport Management 9, no. 2 (2024): 346鈥68, https://doi.org/10.1080/24704067.2021.1929388.

The post The FIFA World Cup and Canada鈥檚 Critical Infrastructure: Are Our Host Cities鈥 Energy and Water Utilities Secure? appeared first on CIPSER.

]]>
The Accelerated Swivel Chair – Humans spinning in the AI loop /cipser/2026/the-accelerated-swivel-chair-humans-spinning-in-the-ai-loop/ Sun, 14 Jun 2026 15:28:17 +0000 /cipser/?p=1972 The Accelerated Swivel Chair – Humans spinning in the AI loop. For roughly six decades, across nearly every industry vertical, enterprise technology has attempted to eliminate swivel chair operations between disconnected systems. Same Chair, Different Decade Swivel chair operations occur when a human becomes the integration layer between disconnected systems. Humans manually move information, context […]

The post The Accelerated Swivel Chair – Humans spinning in the AI loop appeared first on CIPSER.

]]>

The Accelerated Swivel Chair – Humans spinning in the AI loop

Published on July 29, 2026

Time to read: 6 minutes

Daksha Bhasker | June 14, 2026

Evolution from swivel to chair to human in the loop.

The Accelerated Swivel Chair – Humans spinning in the AI loop.

For roughly six decades, across nearly every industry vertical, enterprise technology has attempted to eliminate swivel chair operations between disconnected systems.

Same Chair, Different Decade

Swivel chair operations occur when a human becomes the integration layer between disconnected systems. Humans manually move information, context and decisions between systems that cannot communicate directly. Information is received from one system, interpreted by a person, transformed mentally or manually, and then re-entered into another system or multiple systems. The human often performs semantic normalization, syntax customization, triage, prioritization, enrichment, classification, workflow routing while maintaining contextual continuity across multiple applications. This commonly means swiveling between terminals, physically switching between devices or applications, documents, spreadsheets, dashboards and software systems. More broadly, swivel chair operations describe any workflow where humans maintain coherence across fragmented software environments.

The human is an integral part of the workflow.

The Wobble in the Wheel

Weaknesses of swivel chair operations have been understood for decades. Human error is common in manual data transfers: transcription errors, forgetting context mid-pivot, misinterpreting values between different semantic models etc. When human operators, context switch between systems, semantics and workflows, the cognitive load increases and decision quality degrades. In addition, high-volume swivel chair work produces predictable error patterns. When human operators sustain fast operational load, they increasingly rely on heuristics, rather than analytical processing producing predictable misclassification and judgement failures.

 These are not usability problems. Nor are these problems fixed by training or process discipline. They are limitations inherent to systems where humans are integrated into system workflows.

We Thought We Fixed This

The industry spun up various solutions to eliminate the human mediated integration where possible. APIs, enterprise service buses, workflow orchestration platforms, event-driven architectures, robotic process automation and modern SaaS integration ecosystems all emerged from the same underlying objective: reduce latency, improve consistency, increase auditability and remove human bottlenecks from operational workflows. Swivel chair operations are inefficient, slow and structurally fragile.

The Loop Strikes Back

This is what makes the current AI landscape with Human-In-The-Loop (HITL) and Human-On-the-Loop (HOTL) particularly ironic. Modern AI systems, the most consequential technology revolution of our times, is increasingly putting humans back into workflows that the industry has spent decades trying to automate away. 

The term Human-In-The-Loop (HITL) emerged from control systems, aerospace, military systems, and simulation environments where human operators remained part of a feedback loop despite increasing automation. In AI, HITL is implemented to oversee AI outputs that could be probabilistic or potentially error prone. In HOTL, the system acts autonomously while the human supervises and can override AI output.

HITL/HOTL is commonly implemented in AI systems through several patterns. As a decision point, humans adjudicate high-risk actions, review low-confidence, ambiguous outputs, and provide override or kill-switch controls during anomalous behaviours or hallucinations. For exception management, anomalies, edge cases and threshold breaches are escalated for human triage. From an audit perspective, humans perform statistical sampling, spot-checking, compliance verification and drift monitoring to ensure ongoing oversight. Humans provide feedback into AI models, with human labelling, corrections and feedback loops used to retrain and recalibrate AI behaviour over time.

Most enterprise AI systems that claim to be 鈥渁utonomous鈥 still implement multiple layers of HITL or HOTL controls. This is especially true, in regulated, customer-facing, financial, safety-critical or reputationally sensitive environments. In many cases, it is simply the responsible business practice given the nature of AI systems that feature model hallucination and drift over time, besides anomalous behaviours. The result is that humans once again become the operational middleware layer between systems, decisions and workflows. Only now at machine speed and machine scale.

This matters because AI increases throughput without necessarily removing dependency on humans. Older swivel chair systems were limited by how fast people could process information manually. AI systems now generate thousands of recommendations, alerts, summaries and decisions per hour. If humans still need to supervise, validate or correct large portions of that output, then the underlying problem has not disappeared. The swivel chair has simply been accelerated with humans spinning faster than ever in the HITL/HOTL loops.

Keeping Humans in the Panic Loop

AI solutions are often justified based on speed, scale and complexity of tasks. HITL/HOTL reintroduces human error at precisely the moments of highest consequence in AI workflows, in the escalated, ambiguous, and high-risk decisions. To make matters worse, these aren鈥檛 routine tasks that swivel chair operations were typically deployed for in the past. The human in the AI workflow will be dealing with items that are time-pressured, cognitively demanding, poorly documented for the human reviewer (sometimes generated by AI black box), and outside the reviewers鈥 domain context.

HITL/HOTL does not mitigate AI error, hallucinations, AI inefficiencies or anomalies. It relocates them.As a result, it introduces its own compounding failure patterns. Figure-1 below illustrates how AI errors and human errors compound and circulate through the HITL/HOTL loop, with approved outputs feeding undetected errors back into AI systems.

Figure 1:Human-in-the-loop: Loop of Compounding Errors

AI amplifies automation bias where humans over-trust AI outputs, rubber stamping rather than genuinely reviewing all details. The HITL becomes a nominally placed human in the loop. There is context collapse where AI operates across thousands of data points, while the human reviewer only sees a summary or the condensed output. This lack of visibility and human limitation of processing vast swaths of data to validate the AI output makes verification structurally impossible, leading to errors in human decision. In addition, humans simply cannot actively supervise autonomous systems for extended periods without attention degrading. AI system designed to rely on 鈥渙ne fatigued human at 2am鈥 is neither reliable nor truly autonomous.

In fully automated systems, errors are systematic and traceable. When humans enter the loop at critical junctures, errors become unpredictable, hard to audit and carry the false legitimacy of human judgement. In addition to compounding errors, HITL/HOTL introduces degradation in AI workflows. Human latency replaces machine speed. Human bottlenecks replace volume handling. And human reviewers operating under time pressure with partial context add their own errors to AI systems, workflows and outputs.

The industry spent six decades engineering humans out of the integration workflows in systems. HITL/HOTL engineers humans back in by design, at machine speed and scale. The swivel chair has reincarnated as Human-in-the-Loop, spinning faster than ever in AI systems.

Escaping the AI Swivel Chair

HITL does not eliminate operational risk in AI. It redistributes and can compound it through human supervision, intervention and error. Human oversight also does not scale linearly with AI speed, scale or complexity. As organizations deploy increasingly 鈥渁utonomous鈥 AI systems, the real measure of autonomy will be the outcome of how dependent those systems remain on humans to operate safely and reliably. At the same time, it can be expected that new technologies and operating models will emerge to reduce the growing complexity and overhead introduced by HITL/HOTL AI workflows.

Author鈥檚 note: Opinions expressed in this post are the author鈥檚 and not necessarily those of her employer. Daksha is one of our Editors/Reviewers for the Pulse & Praxis Journal for Critical Infrastructure Protection, Security and Resilience.

Header Image and Figure 1 AI generated through various prompts provided by the author.

The post The Accelerated Swivel Chair – Humans spinning in the AI loop appeared first on CIPSER.

]]>
Small Modular Reactors to Power Northern Development Require New Approaches to Infrastructure Security /cipser/2025/small-modular-reactors-to-power-northern-development-require-new-approaches-to-infrastructure-security/ Tue, 02 Dec 2025 16:45:54 +0000 /cipser/?p=1836 IntroductionAcross the Canadian Arctic, energy is inseparable from survival. Electricity and heat in northern regions are not matters of convenience but conditions of life and death. Extreme cold, prolonged winter darkness, and geographic isolation demand reliable, predictable, and secure power systems. Yet today, most northern and Arctic communities and virtually all major industrial operations remain […]

The post Small Modular Reactors to Power Northern Development Require New Approaches to Infrastructure Security appeared first on CIPSER.

]]>

Small Modular Reactors to Power Northern Development Require New Approaches to Infrastructure Security

Published on July 29, 2026

Time to read: 8 minutes

Tyson Macaulay

Introduction
Across the Canadian Arctic, energy is inseparable from survival. Electricity and heat in northern regions are not matters of convenience but conditions of life and death. Extreme cold, prolonged winter darkness, and geographic isolation demand reliable, predictable, and secure power systems. Yet today, most northern and Arctic communities and virtually all major industrial operations remain dependent on diesel generation. This dependence comes at staggering operational, financial, environmental, and security costs.


As Canada looks to new technologies to reduce these burdens, small modular reactors (SMRs) have emerged as a promising complement or alternative to diesel-based microgrids. Their ability to deliver long-lived, emissions-free, high-capacity power makes them technologically suitable for mines, remote communities, and strategic sites. The 2018 Canadian Roadmap for Small Modular Reactors[1] formally recognized this potential, emphasizing the importance of 鈥渞emote deployment,鈥 鈥渟ecurity,鈥 and anchoring Canadian leadership in advanced manufacturing, cybersecurity, materials science, and remote operation.


However, replacing diesel with SMRs will not simply substitute one energy source for another. Rather, it will transform the underlying critical infrastructure interdependencies that northern operations depend upon. Diesel鈥檚 foremost dependency is transportation. SMRs, particularly when deployed in remote regions, shift that dependency toward telecommunications鈥攕pecifically, toward secure, resilient, and sovereign digital networks capable of enabling remote monitoring, diagnostics, control, and emergency response.

This shift presents a challenge Canada is not yet prepared for. Canada鈥檚 telecommunications systems already exhibit deep structural vulnerabilities.


Do we as Canadians have control over our own telecommunications CI?
Canadian critical infrastructures generally, not just the artic infrastructures, are heavily exposed to vulnerabilities associated with cross-border telecommunications flows and ownership. For instance, the largest business input to Canadian financial services is what Statistics Canada calls 鈥淐omputer and Design Services鈥濃攁n amalgam of cloud and software services; 50% of these services are imported, and 80% of those imports come from the United States.[2]听 At a higher level, 50% of Canadian-to-Canadian internet connection-paths leave Canada and then return in what is called a 鈥榖oomerang鈥 route, making them subject to interception or denial of service; another 50% of Internet Exchange Points (network junctions – IXPs) used by Canadians to reach each other are outside Canada, and therefore vulnerable to further at-will surveillance or disruption.[3] Finally, 100% of all CDNs used to scale and deliver critical services such as e-government, online banking, news, and media for Canadian consumers are under the control of foreign entities, and ultimately foreign governments[4].


Legislative threats from trading partners underscore this risk. The Cloud Act from 2018[5] gives the U.S. government authority to obtain digital data controlled by U.S.-based tech corporations, regardless of whether that data is in motion or stored, on servers at home or on foreign soil. In 2023, the European Council confirmed agreement with the European Parliament on new rules to improve cross-border access to 鈥渆-evidence鈥, giving European governments abilities akin to those granted by the U.S. Cloud Act[6]. As little as a year ago, the prospect of CI like datacentres, cloud-services, IXPs or CDNs being deliberately compromised or disabled sounded far-fetched to most Canadians. Recent history has shown that the previously unthinkable can no longer be dismissed.


These vulnerabilities have implications not only for privacy or financial transactions but increasingly for national security, particularly when critical systems such as SMRs become reliant on remote operation and real-time digital control flows.


To deploy SMRs safely and securely in northern Canada, telecommunications resiliency, security, and sovereignty must be elevated to foundational infrastructure requirements鈥攏ot afterthoughts.

The Cost and Fragility of Diesel Dependence
Diesel generation has long been the default solution in the Arctic because it is simple, familiar, and comparatively easy to deploy. Yet its limitations are well documented:
1. Diesel dominates Arctic imports.
In many northern regions, diesel fuel accounts for 18% to 32% of the total value of all imports. Every litre must be transported thousands of kilometres by truck, barge, or winter road[7].
2. Diesel supply chains are brittle.
Marine shipping windows are narrow, highly weather-dependent, and subject to unpredictable disruption. Winter roads are increasingly unstable due to climate change. The result is over-provisioning, stockpiling, and high distribution costs鈥攁ll of which strain community finances and industrial margins.
3. Diesel is prohibitively expensive.
A single large mine site can spend $10 million per year on diesel fuel alone, excluding generator maintenance, replacement capital, and environmental mitigation. Over a 40-year project life, the total cost of diesel-based power can exceed half a billion dollars for a single industrial site. [8]
4. Diesel has environmental and social impacts.
Beyond greenhouse gas emissions, diesel leaks and storage risks impose environmental burdens on fragile Arctic ecosystems and require costly remediation.


Together, these challenges create powerful incentives to transition toward alternative baseload power systems鈥攎otivating current interest in SMRs.

Why SMRs for the North?
SMRs offer several advantages uniquely suited to remote and Arctic deployment:
-Long refuelling intervals (5鈥20 years depending on design)
-High energy density relative to logistical footprint
-Continuous baseload output suitable for mines, communities, and defence installations
-Compatibility with district heating and industrial process needs
-Potential co-location with hydrogen production or mineral processing

The Canadian SMR Roadmap explicitly highlights remote and mining use cases, arguing that SMRs could enhance energy independence and reduce reliance on imported diesel.

However, these advantages come with structural requirements that differ markedly from diesel-based systems. SMRs, especially those deployed in remote locations, depend on specialized technical oversight, continuous environmental and performance monitoring, and rapid access to nuclear engineering expertise. These requirements cannot be met through on-site staffing alone in remote territories. Instead, modern SMR operating models rely on:
-Remote monitoring
-Remote diagnostics
-Remote operator-support

These features reduce the need for on-site nuclear specialists but dramatically increase the importance of telecommunications.

The New Dependency: Telecommunications Instead of Transportation
Where diesel depends on transportation infrastructure, SMRs depend on telecommunications infrastructure. The shift is not trivial: it alters security assumptions, supply-chain risks, regulatory needs, and emergency-response planning.
1. Resilience: More than a Single Satellite Link
Today, northern telecommunications overwhelmingly rely on a small number of satellite providers. While low-Earth orbit (LEO) constellations, such as Telesat Lightspeed[9], promise improved reliability, satellite systems remain vulnerable to:
-Jamming
-Space weather
-Orbital congestion
-Foreign manufacturer influence
-Ground station outages

For SMRs, redundancy must be engineered to the level used in aviation or defence:
-Two independent satellite providers at minimum
-Preferably triple-redundant architectures, including
-Satellite + terrestrial fibre + microwave, where feasible
-Independent routing paths
-Geopolitically diverse uplinks

Emerging fibre projects, including the Eastern Arctic Underwater Fibre Optic Network[10] and the Kivalliq Hydro-Fibre Link[11], offer important opportunities. The proposed Kivalliq link鈥攁 1,200-kilometre transmission鈥揻ibre corridor from Churchill, Manitoba to Nunavut鈥攚ould deliver both power and broadband capacity to Arviat, Whale Cove, Rankin Inlet, Chesterfield Inlet, and Baker Lake. Its value extends beyond community broadband; it could become critical enabling infrastructure for SMR deployments in Nunavut and surrounding regions[12].


2. Security: SMRs Require Quantum-Safe Remote Operations
If SMRs are to be monitored and controlled remotely, the cybersecurity posture of their communications networks becomes mission-critical.

The National Quantum Strategy (2022)[13] warns that quantum computing threatens widely used public-key cryptography. When these algorithms fail, attackers may:
-Masquerade as authorized operators
-Intercept confidential messages
-Inject or alter messages
-Jam or otherwise deny service

For SMRs, such risks cannot be tolerated. Communications systems must be:
-Encrypted end-to-end using quantum-safe or cryptographically agile algorithms
-Designed to fail safely on communication loss
-Audited under nuclear-grade cybersecurity standards (e.g., CSA N290.7:21[14])
-Verified through supply-chain security assessments, with restrictions on foreign-state influence

Satellite operators, equipment vendors, and network providers must demonstrate that their systems cannot be subject to manipulation by foreign intelligence or commercial interests.


3. Sovereignty: Control over the Infrastructure Underpinning Safety
Telecommunications sovereignty is not merely a commercial or privacy concern鈥攊t is a national-security imperative when critical systems rely on remote digital links.

As mentioned earlier:
-50% of Canada-to-Canada internet paths 鈥渂oomerang鈥 through the U.S. or Europe.
-50% of Canadian internet exchange points (IXPs) used for domestic routes are located outside Canada.
-100% of the content delivery networks (CDNs) used by Canadian governments, banks, and critical services are foreign-owned.
-U.S. and European providers are subject to the CLOUD Act or EU e-evidence laws, enabling lawful access to Canadian data.

For SMRs, such dependencies create unacceptable risk:
-Remote control links could be intercepted or manipulated outside Canadian jurisdiction.
-Data routing through foreign networks introduces exposure to foreign surveillance.
-Outages or traffic shaping by foreign providers could degrade operational integrity.
-Canada would lack effective recourse in the event of a geopolitical dispute.

In effect, SMRs cannot rely on telecommunications channels that Canada does not control. Sovereign operation requires:
-Canadian-owned satellite solutions, or
-Canadian-controlled terrestrial fibre, or
-At minimum, routing architectures that ensure Canadian-only pathways for operational data.

Telecommunications as the Zero-Order Requirement
A critical insight emerges from comparing SMR requirements with the realities of northern telecommunications:
Canada currently lacks the resilient, secure, and sovereign digital infrastructure needed to support remote nuclear power.

This is not a sequencing dilemma; it is a mathematical order-of-operations problem.

Telecommunications must come first. SMRs must come second.

Canada has historically underestimated the strategic role of telecommunications infrastructure in national security. Control over communications infrastructure was once considered a core instrument of wartime sovereignty; exemplified by the British cutting German telegraph cables in 1914 to shape geopolitical outcomes[15]. The modern equivalents are data centres, cloud services, satellite networks, IXPs, and CDNs, all of which Canada relies on but few of which Canada controls.

SMRs introduce a new category of infrastructure that depends on secure telecommunications, thereby increasing the importance of regaining sovereign control over digital networks.

Conclusion
SMRs offer transformative potential for northern development, mining, community energy independence, and national sovereignty. But their success hinges on an critical infrastructure foundation Canada has not yet built.
To realize the benefits of SMRs in the Arctic, Canada must first invest in:
1. Resilient telecommunications
-Multi-path, redundant satellite and terrestrial systems
-Infrastructure that is hardened against interference, weather, and foreign influence
2. Secure telecommunications
-End-to-end quantum-safe encryption
-Verified and trusted supply chains
3. Sovereign telecommunications
-Canadian-domiciled routing
-Canadian ownership or operational control of critical links
-Digital autonomy for remote industrial and nuclear operations

Without these capabilities, SMRs cannot be safely or securely deployed in northern Canada. The sequence is unambiguous: telecommunications first鈥攖hen SMRs.



[1] https://smrroadmap.ca/wp-content/uploads/2018/11/SMRroadmap_EN_nov6_Web-1.pdf
[2] https://www150.statcan.gc.ca/n1/en/catalogue/15-207-X
[3] https://pulse.internetsociety.org/en/ixp-tracker/country/CA/
[4] https://www.wmtips.com/technologies/cdn/country/ca/
[5]
[6] https://www.consilium.europa.eu/en/press/press-releases/2023/01/25/electronic-evidence-council-confirms-agreement-with-the-european-parliament-on-new-rules-to-improve-cross-border-access-to-e-evidence/
[7] Ibid. StatsCan
[8] /cipser/smrsecurityblog-2/is-going-nuclear-good-for-critical-resource-extraction/

[9] https://www.telesat.com/leo-satellites/
[10] https://krg.ca/en-CA/assets/Council/2024/May/EAUFON.pdf
[11] https://nukik.ca/khf/
[12] https://www.theglobeandmail.com/business/article-kivalliq-hydro-fibre-link-arctic-sovereignty-nunavut-major-projects/
[13] https://ised-isde.canada.ca/site/national-quantum-strategy/en/canadas-national-quantum-strategy
[14] https://www.csagroup.org/store/product/2428461/
[15] https://en.wikipedia.org/wiki/Zimmermann_telegram

The post Small Modular Reactors to Power Northern Development Require New Approaches to Infrastructure Security appeared first on CIPSER.

]]>
C-8鈥檚 Opportunity: Replace Chalk Lines with Metrics /cipser/2025/c-8s-opportunity-replace-chalk-lines-with-metrics/ Thu, 09 Oct 2025 20:19:30 +0000 /cipser/?p=1773 Tyson Macaulay, CISA, CEI LEL Deputy Director, National Centre for Critical Infrastructure Protection, Security and Resilience Up to the late 1500鈥檚 ships weren鈥檛 built to a plan. Craftsmen applied apocryphal guidelines and drew lines on the floor to eyeball dimensions. This approach had clear drawbacks for fleets of conquest or commerce: ships were harder to […]

The post C-8鈥檚 Opportunity: Replace Chalk Lines with Metrics appeared first on CIPSER.

]]>

C-8鈥檚 Opportunity: Replace Chalk Lines with Metrics

Published on July 29, 2026

Time to read: 6 minutes

Ship building in action
Image Created by Gamma 2025

Tyson Macaulay, CISA, CEI LEL

Deputy Director, National Centre for Critical Infrastructure Protection, Security and Resilience

Up to the late 1500鈥檚 ships weren鈥檛 built to a plan. Craftsmen applied apocryphal guidelines and drew lines on the floor to eyeball dimensions. This approach had clear drawbacks for fleets of conquest or commerce: ships were harder to reproduce, maintain, and supply; performance and stability varied widely; hidden structural weaknesses regularly slipped through construction; and standardized spares and repairs were impossible.

This made operational risk high. Starting in the 16th century, ship-building methods became standardized: mathematical hull geometry, and naval classifications emerged making safety, quality and resilience measurable and visible. Data from Lloyd鈥檚 insurance going back to the 1600鈥檚 show substantial reductions in losses to life and property as formal standards emerged.

In Canada today, critical infrastructure protection (CIP) still resembles that pre-plan era of shipbuilding: deciding what counts as 鈥渃ritical鈥 within the ten official sectors is more craft than science. The consequence is predictable: perceptions of risks vary widely, regulatory expectations are uneven, and national-level situational awareness is blurry when it most needs to be sharp. Jurisdictions are often left to their instincts, and CI owners/operators often apply very different methods; some rely on institutional memory and ad hoc thresholds. The result for public safety and national security is inconsistency: an asset type can be considered 鈥渃ritical鈥 but also invisible to interdependency analyses that should tie the whole system together.

The ten defined CI sectors in Canada are a useful policy scaffolding: Energy, Finance, Telecommunications, Food, Water, Health, Transportation, Manufacturing, Safety, and Government. But the practical determination of who is 鈥渋n鈥 or 鈥渙ut鈥 of each sector often looks like a shipwright鈥檚 chalk lines on the floor: mutable, subjective, and difficult to defend under stress. Some industries fall into grey zones; intuitively critical under some conditions but not all. That ambiguity bleeds into regulation, emergency planning and cross-border coordination, where counterpart definitions abroad can be both different and tighter. A taxonomy that cannot be applied consistently cannot be managed consistently.

The drawbacks of metaphorical chalk lines for CI sector definitions are not merely academic. Regulators need to know exactly whom they regulate and why. During a crisis, decision makers must justify the order in which lifeline resources like power, bandwidth, medicines, or fuel are triaged and restored. Ideally, they make decisions using criteria that will survive public scrutiny and after-action review. Similarly, post-incident reporting needs clean definitions to compare events across time and regions, to see whether regulations work and where dependencies may be changing. Without methodical definitions, we generate noise: incomparable risk registers, incompatible outage and recovery metrics, and assessments that cannot be pooled or trended.

A prime case in point is Bill C-8 鈥淎n Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts鈥 which establishes a cyber protection regime for federally regulated CI sectors, namely Telecommunications, Finance, Energy, and Transportation. The policy intent is sound: align oversight with systemic risk, sharpen reporting duties, and develop detailed regulatory guidance. But to be maximally effective, the instrument needs a crisp, modern, quantitative scoping logic. One that reflects how CI sectors are composed and how goods and services are delivered in 2025; considering layered platforms, cross-border supply-chains, and shared infrastructure that does not map neatly onto legacy sector definitions. If scope rests on dated or vague definitions, we will regulate the core while the systemic risk remains in the unseen edges.

Consider 鈥淭elecommunications,鈥 last operationally framed in the early 2000鈥檚 to include radio, television broadcasting, and print media in a time when carrier networks moved voice, video and data mostly separately versus everything based on Internet Protocols today. Two decades on, the sector has changed tremendously. Where do industries like data centres, cloud platforms, and AI clusters sit? Such questions become important when up to 50% of the cloud and software-as-a-service consumed by Canadian CI (Finance in particular) are imported and controlled by entities outside Canada. Figure 1 below visualizes how imports of 鈥淐omputer design and related services鈥 account for the largest single input into the Financial service industry in Ontario (Canada鈥檚 financial hub) 鈥 50% of these critical services are imports, delivered through cross-border trade dependencies.

Imports of BS5415
Imported Data

Figure 1: BS5415 – Computer Systems Design and service – Financial Industries in Ontario 2022

Another major consideration in the area of Telecommunications CI: there are no Canadian-owned Content Delivery Networks (CDN). Yet those CDNs underpin the service delivery of almost all e-government portals, online banking, and cultural (CBC, CTV) platforms. Over 65% of Canadians in 2024 relied on a mix of online streaming and legacy 鈥渓inear TV鈥, while another 20%+ of Canadian only streamed content via these CDNs. (Source: ThinkTV) If our CI definitions miss these realities, we create rules and regulations with diminished effectiveness.

Like modern ships, CI definitions must be grounded in reliable systems, not rules of thumb. With clear definitions, Canada can apply quantitative supply-chain metrics from Statistics Canada to identify which industries and regions are truly consequential under different impact scenarios. In parallel, we should explore additional indicators of CI interdependence for correlation with supply-chain metrics. For instance, the sensitivity of data flows, geographic proximity or distinctions between goods and services. With more than one indicator available, correlations (or lack of) will begin to expose the strengths and gaps in both definitions and measurement. Ultimately, these metrics turn intuition into evidence, making 鈥渃riticality鈥 a testable, reproducible property rather than a label assigned by tradition.

The same logic applies to risk assessment. Today, municipal and provincial emergency management offices expend heroic effort, but their outputs rarely interlock: differing templates, scales, hazard taxonomies, and consequence categories frustrate analysis across jurisdictions. A nationally standardized toolkit with common CI definitions, hazard libraries, and risk scales would let assessments be rolled up and aggregated. When every risk assessment and after-action report speaks the same language, trends emerge and controls can be prioritized by evidence, not anecdote. Standardization is not centralization; it is the grammar that allows a federation to reason collectively.

Call to action

First, treat Bill C-8 as a once-in-a-generation chance to replace chalk lines with mathematics. Use the legislative refresh to embrace a systematic, quantitative methodology for defining CI membership rooted in trusted measures like Statistics Canada鈥檚 econometrics. By this path, regulatory scope, security targets, and emergency management practices can all rest on the same defensible foundation. When the 鈥渨ho鈥 of CI definitions are founded on metrics and modeled consequences, stakeholders can regulate, plan and invest quickly and with confidence.

Second, work with Canadian standards bodies to publish a canon for risk assessment, definitions, data standards, scoring scales, dependency questions, and reporting templates. At that point, federally and provincially mandated assessments can be compiled, trended, and compared coast-to-coast-to-coast. This is how we turn thousands of local efforts into national intelligence: using interoperable methods, open guidance, and a commitment to measure what matters the same way everywhere. As in the evolution from chalked floor lines to naval architecture, the payoff is practical: fewer surprises, faster recovery, and a resilient, more prosperous Canada.

The post C-8鈥檚 Opportunity: Replace Chalk Lines with Metrics appeared first on CIPSER.

]]>
Leadership Announcement – Tyson Macaulay Deputy Director NC-CIPSeR /cipser/2025/1594/ Tue, 16 Sep 2025 12:51:53 +0000 /cipser/?p=1594 We are very pleased to announce that Tyson Macaulay has accepted an appointment of Deputy Director of the National Centre for Critical Infrastructure Protection, Security and Resilience (NC-CIPSeR). Tyson, a 杏吧原创 alumnus,听 brings decades of experience in cybersecurity, critical infrastructure interdependencies, standards development, and national resilience, and has been a trusted advisor to governments, industry, […]

The post Leadership Announcement – Tyson Macaulay Deputy Director NC-CIPSeR appeared first on CIPSER.

]]>

NC-CIPSeR Leadership Update

Published on July 29, 2026

Time to read: 2 minutes

Image of Tyson Macaulay

We are very pleased to announce that Tyson Macaulay has accepted an appointment of Deputy Director of the National Centre for Critical Infrastructure Protection, Security and Resilience (NC-CIPSeR).

Tyson, a 杏吧原创 alumnus,听 brings decades of experience in cybersecurity, critical infrastructure interdependencies, standards development, and national resilience, and has been a trusted advisor to governments, industry, and academia across Canada and internationally. His thought leadership and commitment to collaboration will be instrumental in advancing NC-CIPSeR鈥檚 mission: strengthening Canada鈥檚 critical infrastructure through research, innovation, collaboration and education.

In this role, Tyson will work closely with our Advisory Panel, support our strategic direction, lead key initiatives, and mentor the next generation of researchers and practitioners. We are fortunate to have his expertise and vision guiding NC-CIPSeR as we establish our Board of Directors and build out our certificate program, engage in meaningful projects with our partners and expand our work across the country.

Learn more about Tyson Macaulay

Please join us in welcoming Tyson to this important role!

The post Leadership Announcement – Tyson Macaulay Deputy Director NC-CIPSeR appeared first on CIPSER.

]]>
Critical Infrastructure Interdpendencies (CII) through Canada/US Financial Case Studies /cipser/2025/critical-infrastructure-interdpendencies-cii-through-canada-us-financial-case-studies/ Tue, 16 Sep 2025 11:50:41 +0000 /cipser/?p=1558 Exploring CII Through a Novel Taxonomy CIBC Presentation | September 2025 by Tyson Macaulay, CISA, P.Eng CIE LEL National Center for Critical Infrastructure Protection, Security and Resilience (NC-CIPSeR) tyson.macaulay@alumni.carleton.ca This session explores Critical Infrastructure Interdependency (CII) through real-world case studies from the U.S. and Canada with a focus on financial industries and cross-border interdependencies. Attendees will […]

The post Critical Infrastructure Interdpendencies (CII) through Canada/US Financial Case Studies appeared first on CIPSER.

]]>

Critical Infrastructure Interdependency (CII) through Canada & US financial case studies

Published on July 29, 2026

Time to read: 1 minutes

CI taxonomy chart linking goods and services to monopoly/market classes with likelihood-impact matrix.
Applying a Critical Infrastructure (CI) taxonomy to assess likelihood and impact across monopoly and market goods and services.

Exploring CII Through a Novel Taxonomy

CIBC Presentation | September 2025 by Tyson Macaulay, CISA, P.Eng CIE LEL

National Center for Critical Infrastructure Protection, Security and Resilience (NC-CIPSeR)

tyson.macaulay@alumni.carleton.ca

This session explores Critical Infrastructure Interdependency (CII) through real-world case studies from the U.S. and Canada with a focus on financial industries and cross-border interdependencies. Attendees will learn how cyber connectivity and economic indicators are correlated and can forecast cascading impacts across industries and CI sectors. The session highlights how to improve risk management and resilience planning, including an overview of a new risk assessment taxonomy and methodology for CII from 杏吧原创 University鈥檚 National Centre for Critical Infrastructure Protection, Security and Resilience

An icon of a saxophone

Critical Infrastructure Interdependency (CII) through Canada and US financial case studies – Macaulay

Access Tyson Macaulay’s Presentation for CIBC – September 2025.

Tyson Macaulay

The post Critical Infrastructure Interdpendencies (CII) through Canada/US Financial Case Studies appeared first on CIPSER.

]]>
Are We Ready? Rethinking Information Sharing for CI in Canada /cipser/2025/rethinking-information-sharing-for-ci-in-canada/ Wed, 02 Jul 2025 18:24:10 +0000 /cipser/?p=805 Are We Ready? Rethinking Information Sharing for CI in Canada Laura Rovina | July 2025 What is Critical Infrastructure Protection? Critical Infrastructure (CI) protection is integral to the safety and security of Canadian citizens. The interconnected and interdependent nature of CI sectors means that effective communication and collaborative efforts between infrastructure owners, operators, and government […]

The post Are We Ready? Rethinking Information Sharing for CI in Canada appeared first on CIPSER.

]]>

Are We Ready? Rethinking Information Sharing for CI in Canada

Published on July 29, 2026

Time to read: 4 minutes

image

Are We Ready? Rethinking Information Sharing for CI in Canada

Laura Rovina | July 2025

What is Critical Infrastructure Protection?

Critical Infrastructure (CI) protection is integral to the safety and security of Canadian citizens. The interconnected and interdependent nature of CI sectors means that effective communication and collaborative efforts between infrastructure owners, operators, and government agencies are paramount. This underscores the need for enhanced information sharing and coordination among these various stakeholders, specifically focusing on intelligence sharing capacities and their effectiveness in bolstering CI resilience. Amongst other reports, the Government of Canada’s Intelligence Priorities 2024 Report has highlighted the importance of intelligence, and strategic information sharing with government decision-makers, provincial and municipal authorities, business partners, and the public.[1]

Why is Information Sharing Crucial for Critical Infrastructure?

Critical infrastructure in Canada is managed through a shared responsibility between federal, provincial, and municipal governments, along with private-sector owners and operators. As the complexities surrounding CI evolve, the need for robust, intergovernmental, and cross-sector collaboration has become more pressing, with information sharing playing a key role in building resilience and ensuring effective responses to potential threats.[2]The process of sharing intelligence between different levels of government, CI sectors, and operators remains complex and fraught with challenges.

Challenges in Existing Information Sharing Models

Current communication methods for threat intelligence sharing in the private sector are often restrictive and reactive. For example, when alerts are issued, they are often directed at individual businesses and only occur after a threat has already materialized, reducing their usefulness in preventing attacks.  These alerts are not designed to support real-time threat response by the private sector. [3]

Inconsistencies exist amongst information sharing networks across all the CI sectors and within individual subsectors. There is a lack of concentration of responsibilities, information and authority across the sectors and different jurisdictions.[4] This fragmentation impedes the ability of stakeholders to respond effectively to threats in a timely and coordinated manner.

Is a Formalized Threat Intelligence Exchange A Part of the Solution?

The Business Continuity Council (BCC) has called on the Canadian government to establish a formalized threat intelligence exchange, similar to the U.S. Domestic Security Alliance Council (DSAC).[5] DSAC members benefit from direct engagement with senior leaders from the FBI and the Department of Homeland Security providing members with tailored threat intelligence, a space for exchanging best practices, and a platform to solve shared problems.[6] Could Canada benefit from a platform where both public and private sectors collaborate more effectively, enhancing overall CI protection and resilience?

Conclusion

As threats to critical infrastructure grow more sophisticated, it is essential for the Canadian government, alongside private-sector owners and operators, to adapt their information-sharing practices. The question remains: What is needed to enhance the effectiveness of information sharing in Canada鈥檚 CI sectors? Is the answer a unified platform, a shared network, or regional information hubs? Perhaps a combination of these approaches will provide the most effective solution. Regardless of the exact model, it is clear that enhanced information sharing is essential for the resilience of Canada鈥檚 critical infrastructure and the safety of its citizens.

[1] Privy Council. (2024). . Government of Canada.

[2] National Sector Forum -Action Plan for Critical Infrastructure 2021-2023.

[3] Hyder, G. (2025). Modernizing to Protect Canada from Economic Security Threats. Business Council of Canada.

[4] Public Safety Canada. (2022). .

[5]Bronskill, J. (2024). . Global News.听

[6] Domestic Security Alliance Council. (n.d.). Home. U.S. Department of Homeland Security. DSAC Facts Sheet. dsac-fact-sheet-111523.pdf

The Path Forward

Global instability doesn鈥檛 have to divide us鈥攊t can unite us around a common purpose. By safeguarding critical infrastructure, Canada can ensure its resilience, protect its economy, and demonstrate leadership on the world stage.  Leadership of Canada doesn鈥檛 have to come from the Prime Minister – it can start with every citizen, municipality and agency, taking ownership and being involved in helping to protect Canada.

This is not a time to rest. It鈥檚 a time to lead, innovate, and collaborate with agency. There are impressive examples where Canadians demonstrate brave leadership, along with dedicated, smart and strategic approaches – especially when the stakes are high.  Engagement that fuels unity will be the key moving forward. NC-CIPSeR is dynamic and forging ahead with our partners. We are moving strategically with purpose and agency.

Learn more about our efforts to protect Canada鈥檚 critical infrastructure and how you can get involved.

The post Are We Ready? Rethinking Information Sharing for CI in Canada appeared first on CIPSER.

]]>