Security for Critical Infrastructure

Where physical security meets operational technology: Bill C-26 obligations, IEC 62443, network segmentation, and incident reporting for Canadian critical infrastructure.

Critical infrastructure operators in energy, telecom, transportation, water, and finance now carry cyber duties that reach the physical security stack. Cameras, door controllers, and intrusion panels used to sit in a corner of the facilities budget. Today they run on the same networks as the systems a regulator cares about, and that changes how integrators, consultants, and operators have to design and defend them.

What Bill C-26 changes

The Critical Cyber Systems Protection Act, better known as Bill C-26, sets cyber obligations for designated operators in federally regulated sectors. Designated operators must establish and maintain a cyber security program, manage supply chain and third-party risk, report cyber incidents to the Cyber Centre inside the mandated window, and follow cyber security directions when issued. Physical security systems that touch a critical cyber system fall inside that program, not outside it.

Where physical security meets OT

Access control, video, and life-safety devices increasingly live on operational technology networks alongside PLCs, SCADA, and building management systems. That means a compromised camera or badge reader is a route into the plant, not a nuisance. Practitioners should map every device to a network and an owner, and treat OT security as a first-class part of the security design rather than an afterthought bolted on at commissioning.

Segmentation and hardening

IEC 62443 gives you the model: zones and conduits, with defined security levels for each. Group devices by function and trust, then control the traffic between zones. Solid network security starts with segmentation, then adds device hardening, credential management, and a real patch process. Our guide to network cybersecurity hardening walks through the baseline, and NIST references help align controls with what auditors expect.

Video and access at scale

Connected cameras and access controllers are part of the critical cyber system, not an island. At scale, that means an inventory you trust, firmware you can update, and accounts you can revoke. Design video surveillance deployments with dedicated VLANs, disabled default credentials, and encrypted management traffic, so a single exposed recorder does not undo the rest of the program.

Incident reporting

When something goes wrong, the clock matters. Designated operators report cyber incidents to the Cyber Centre within the required timeframe, so your monitoring, logging, and escalation paths have to produce the facts fast. Build detection into the physical security estate, keep records that survive an investigation, and rehearse the reporting path before you need it.

References

  1. Critical Cyber Systems Protection Act overviewPublic Safety Canada · retrieved 2026-07-08
  2. ISA/IEC 62443 series of standardsInternational Society of Automation · retrieved 2026-07-08

Last updated 2026-07-08. Independent and editorial. Inclusion in the directory is merit-based and open to anyone.