National

Hackers are coming for Canada – are we ready?

Support TNI Subscribe

Last month, hackers linked to a pro-Russian group posted a video showing them adjusting chlorine dosage settings at a drinking water plant in Saint-Noël, Quebec, a municipality of fewer than 400 residents. The plant switched into safe mode before the tampering reached the water supply. 

It was not Quebec’s first such incident. The Communications Security Establishment (CSE) reported a separate breach at another Quebec water treatment plant last October, claimed by another hacker group.  During this attack, hackers were able to control pumps, chlorine dosing, pressure settings, and the alarms designed to flag that kind of interference. In the United States, federal investigators are examining a wave of suspected Iran-linked attacks on water utilities in at least a dozen states. More than 100 municipalities have reported hacking attempts since the start of the month. 

Earlier this year, Canada’s first comprehensive federal cybersecurity law was passed into law by Parliament. It brings Canada’s approach closer to that of our allies. The new legislation requires operators of “critical cyber systems” to run mandatory security programs, report incidents to the CSE within 72 hours, and face administrative penalties of up to $15 million per violation.

The law applies to only six sectors: telecommunications, interprovincial pipelines and power lines, nuclear energy, federally regulated transportation, banking, and clearing and settlement systems. Water is not among them, and it is unlikely to be added. Water utilities in Canada are built, owned, and operated by municipalities and provinces, a jurisdiction Ottawa does not control. The systems currently being targeted sit entirely outside the law Parliament just passed.

That is not simply a drafting oversight. It reflects a structural feature of Canadian water infrastructure that the Canadian Centre for Cyber Security has documented directly: many systems are run out of single municipal offices with limited budgets, aging equipment, and little dedicated cybersecurity staff. A 2023 survey of water-related devices in the United States and the United Kingdom found nearly half could be accessed without any login credentials at all.

The federal government’s response so far has relied on cooperation rather than legal compulsion. The Cyber Centre’s Provincial-Territorial Sensor Expansion Strategy now extends to several provinces and all three territories, accounting for roughly five percent of its sensor fleet. Last fall, federal, provincial, and territorial governments signed the Canadian Cybersecurity Collaboration Agreement to improve intelligence sharing. Both initiatives are voluntary. A province can exit an information-sharing agreement in a way it cannot exit a federal statute.

The gap is opening at a moment when Ottawa is redefining what counts as defence spending. The Canadian Armed Forces established a dedicated Cyber Command in 2024, a joint capability with the CSE responsible for both defensive and offensive cyber operations. Canada announced in March that it had reached NATO’s target of spending two per cent of GDP on defence in the 2025-26 fiscal year, five years ahead of schedule. Budget 2025 added $72.8 billion in new defence spending over five years, bringing the total to $81.8 billion, described by officials as the largest year-over-year increase to Canada’s defence budget in generations.

NATO’s own definition of that spending leaves room for exactly this kind of gap to close. At last year’s summit in The Hague, alliance members agreed to raise total defence and security spending to five per cent of GDP by 2035, split between 3.5 per cent on core military requirements and 1.5 per cent on what NATO calls security and infrastructure resilience, spending explicitly intended to protect critical infrastructure, defend networks, and strengthen civil preparedness. That category was built for a case like Saint-Noël. Little of Canada’s new defence spending has been directed toward it so far.

The distinction is not academic. U.S. officials believe Iran-linked hackers have already disabled the alarms meant to flag contamination risks at some targeted water systems, meaning an operator’s monitoring screen can indicate normal operations even when something has gone wrong. Whether the intent behind the recent attacks is disruption or intimidation, the systems under threat are run by the level of government with the fewest resources to defend them.

Bill C-8 closes a real gap for the sectors it covers, and the new Cyber Command gives Canada capabilities it lacked five years ago. Whether either translates into protection for the water systems now being probed by foreign hackers depends on decisions that have not yet been made: whether provinces write their own version of C-8 for the municipalities they oversee, and whether any share of Canada’s expanding defence budget is redirected toward paying for it.

Your donations help us continue to deliver the news and commentary you want to read. Please consider donating today.

Support TNI
Copy link
Powered by Social Snap