CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3550

As cited

Copy frozen at (site build).

regulatory

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada's Critical Cyber Systems Protection Act (Bill C-8) mandates that designated critical infrastructure operators report cyber incidents to authorities within 72 hours, with penalties up to 15 million Canadian dollars for non-compliance. The regulation applies to telecommunications, energy, transportation, and banking sectors and requires formalized cybersecurity programs and supply chain risk mitigation. The compressed reporting timeline creates operational challenges for organizations lacking unified visibility across converged IT and OT environments.

Why it matters: Critical infrastructure operators in Canada face legal and financial consequences if they cannot detect and report breaches within 72 hours; security teams need integrated IT/OT visibility and accelerated incident response capabilities to meet this deadline.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary