This is a single speech (committee meeting) resource from the openparliament.ca API. If you’re new here, you might want to look at the documentation. If API and JSON are gibberish to you, you’re better off at our main site.

Content

Get this resource as raw JSON.

See the corresponding webpage.

{
    "time": "2024-02-08 08:25:00",
    "attribution": {
        "en": "Mr. Francis Bradley (President and Chief Executive Officer, Electricity Canada)",
        "fr": "M. Francis Bradley (pr\u00e9sident-directeur g\u00e9n\u00e9ral, \u00c9lectricit\u00e9 Canada)"
    },
    "content": {
        "en": "<p data-HoCid=\"8213750\" data-originallang=\"fr\"> Thank you, Mr. Chair.</p>\n<p data-HoCid=\"8213751\" data-originallang=\"fr\">I'm CEO of Electricity Canada, formerly known as the Canadian Electricity Association. Our members are companies that generate, transmit and distribute electricity in every province and territory in Canada.</p>\n<p data-HoCid=\"8213752\" data-originallang=\"fr\">My comments today will focus on part 2 of Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a>, which enacts the Critical Cyber Systems Protection Act.</p>\n<p data-HoCid=\"8213753\" data-originallang=\"en\"> Before I proceed, I want to acknowledge the efforts of federal departments in drafting Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C-26</a> and the time spent engaging stakeholders over the past two years. The problems that the bill is trying to solve are hard ones, with lots of moving pieces and far-reaching implications against the backdrop of a constantly evolving threat landscape.</p>\n<p data-HoCid=\"8213754\" data-originallang=\"en\">While I commend the efforts, I must add my voice to the witnesses you've already heard from who emphasized the importance of getting this legislation right. While we acknowledge the urgency to pass this type of legislation, it is crucial to carefully consider amendments and resist the pressure to rush through the review the bill.</p>\n<p data-HoCid=\"8213755\" data-originallang=\"en\">Mandatory security requirements can help strengthen our overall security posture, but the approach taken by Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C-26</a> risks having the opposite effect, adding very little security to our sector and redundantly adding additional layers of regulatory requirements. Today, I will highlight three areas where the legislation falls short and requires improvement.</p>\n<p data-HoCid=\"8213756\" data-originallang=\"en\">First, the bill must align with existing regulatory frameworks. The electricity sector is unique in that the assets targeted by Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C-26</a> are already regulated by the North American Electric Reliability Corporation, or NERC. This poses a risk of regulatory conflicts, increases the burden on operators and introduces compliance confusion and ambiguity, ultimately impeding the goal of Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C-26</a> to enhance the safety of our critical system.</p>\n<p data-HoCid=\"8213757\" data-originallang=\"en\">A witness last week recommended that the bill should take a risk-based approach and impose fewer requirements on those with already strong cybersecurity programs. Under this approach, mature organizations could spend more resources on incident prevention instead of compliance activities, and regulators could better focus their time on high-risk operators. Given our sector's strong security posture and the existing NERC standards, we feel that a risk-based approach to Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C-26</a> would be a step in the right direction.</p>\n<p data-HoCid=\"8213758\" data-originallang=\"en\">Another area needing improvement in the bill is its reporting requirements. The reference to the immediate reporting of cyber-incidents should be revised. Reporting obligations should not divert critical infrastructure operators from their response and recovery efforts during and post incident. Reporting requirements should be well defined and consistent and have a reporting timeline that is flexible enough to allow the effective use of limited resources during incident response and recovery.</p>\n<p data-HoCid=\"8213759\" data-originallang=\"en\">Still on the topic of reporting requirements, the goals of the legislation would be better served if it included legal protection for operators. Safe harbour provisions are an important part of promoting information sharing between industry and government, ensuring the successful implementation of the new reporting requirements and promoting voluntary information sharing.</p>\n<p data-HoCid=\"8213760\" data-originallang=\"en\">The final aspect I wish to address is the unintended impact of the bill on the existing industry-government collaboration. Imposing mandatory requirements may create a chilling effect on the industry's relationship with government departments and agencies. Without appropriate safeguards, operators would likely receive legal advice to share just enough information to comply with the act and nothing more. </p>\n<p data-HoCid=\"8213761\" data-originallang=\"en\">This is counterproductive to the goals of the legislation, but there are a couple of things you could do to mitigate those risks. First, put clear limits on how the government can use the information collected by way of this act. Several provisions in the bill would allow for information sharing among a range of persons and entities, and it does not explicitly limit how recipients use the collected information.</p>\n<p data-HoCid=\"8213762\" data-originallang=\"en\">Second, the cyber centre should be carved out from the legislation and exempt from obligations to report information obtained by way of the act to other entities. Critical infrastructure operators currently enjoy a positive and collaborative relationship with the cyber centre. This is grounded in the confidence that the cyber centre does not disclose operators' information to regulators, enforcement agencies or other departments. Protecting the cyber centre from information-sharing obligations is crucial to maintaining this collaborative relationship.</p>\n<p data-HoCid=\"8213763\" data-originallang=\"fr\">Many other aspects of Bill <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> also deserve our attention, but my time's up for this morning.</p>\n<p data-HoCid=\"8213764\" data-originallang=\"fr\"> However, I encourage you to take a look at our brief, which contains 14 recommendations on how to improve Bill C\u201126.</p>\n<p data-HoCid=\"8213765\" data-originallang=\"fr\">Thank you.</p>",
        "fr": "<p data-HoCid=\"8213750\" data-originallang=\"fr\"> Merci beaucoup, monsieur le pr\u00e9sident.</p>\n<p data-HoCid=\"8213751\" data-originallang=\"fr\">Je suis le PDG d'\u00c9lectricit\u00e9 Canada, qui \u00e9tait connu sous le nom de l'Association canadienne de l'\u00e9lectricit\u00e9. Nos membres sont des compagnies qui produisent, transportent et distribuent l'\u00e9lectricit\u00e9 dans toutes les provinces et tous les territoires du Canada.</p>\n<p data-HoCid=\"8213752\" data-originallang=\"fr\">Mes commentaires aujourd'hui se concentreront sur la partie 2 du projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a>, qui \u00e9dicte la Loi sur la protection des cybersyst\u00e8mes essentiels.</p>\n<p data-HoCid=\"8213753\" data-originallang=\"en\"> Avant d'aller plus loin, je tiens \u00e0 souligner les efforts d\u00e9ploy\u00e9s par les minist\u00e8res f\u00e9d\u00e9raux pour r\u00e9diger le projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> et le temps qu'ils ont consacr\u00e9 \u00e0 mobiliser les intervenants au cours des deux derni\u00e8res ann\u00e9es. Les probl\u00e8mes que le projet de loi tente de r\u00e9gler sont difficiles \u00e0 r\u00e9soudre, avec beaucoup d'\u00e9l\u00e9ments changeants et de vastes r\u00e9percussions dans un contexte de menaces en constante \u00e9volution.</p>\n<p data-HoCid=\"8213754\" data-originallang=\"en\">Bien que je salue les efforts d\u00e9ploy\u00e9s, je dois ajouter ma voix \u00e0 celles des t\u00e9moins que vous avez d\u00e9j\u00e0 entendus et qui ont insist\u00e9 sur l'importance de bien faire les choses. M\u00eame si nous reconnaissons l'urgence d'adopter ce genre de mesure l\u00e9gislative, il est essentiel d'envisager attentivement des amendements et de r\u00e9sister \u00e0 la pression de pr\u00e9cipiter l'examen du projet de loi.</p>\n<p data-HoCid=\"8213755\" data-originallang=\"en\">Les exigences de s\u00e9curit\u00e9 obligatoires peuvent contribuer \u00e0 renforcer notre posture globale au chapitre de la s\u00e9curit\u00e9, mais l'approche adopt\u00e9e par le projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> risque d'avoir l'effet contraire, en augmentant tr\u00e8s peu la s\u00e9curit\u00e9 pour notre secteur et en ajoutant de fa\u00e7on redondante des couches suppl\u00e9mentaires d'exigences r\u00e9glementaires. J'aimerais souligner aujourd'hui trois domaines o\u00f9 le projet de loi laisse \u00e0 d\u00e9sirer et o\u00f9 des am\u00e9liorations s'imposent.</p>\n<p data-HoCid=\"8213756\" data-originallang=\"en\">Premi\u00e8rement, le projet de loi doit s'harmoniser avec les cadres r\u00e9glementaires existants. Le secteur de l'\u00e9lectricit\u00e9 est unique en ce sens que les actifs vis\u00e9s par le projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> sont d\u00e9j\u00e0 r\u00e9glement\u00e9s par la North American Electric Reliability Corporation, ou NERC. Cela pose un risque de conflits au chapitre de la r\u00e9glementation, alourdit le fardeau des exploitants et introduit de la confusion et de l'ambigu\u00eft\u00e9 en mati\u00e8re de conformit\u00e9, ce qui, au bout du compte, nuit \u00e0 l'objectif du projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> d'am\u00e9liorer la s\u00e9curit\u00e9 de nos syst\u00e8mes essentiels.</p>\n<p data-HoCid=\"8213757\" data-originallang=\"en\">La semaine derni\u00e8re, un t\u00e9moin a recommand\u00e9 que, dans le cadre du projet de loi, on adopte une approche fond\u00e9e sur le risque et on impose moins d'exigences \u00e0 ceux qui ont d\u00e9j\u00e0 de solides programmes de cybers\u00e9curit\u00e9. Selon cette approche, les organisations bien \u00e9tablies pourraient consacrer plus de ressources \u00e0 la pr\u00e9vention des incidents plut\u00f4t qu'aux activit\u00e9s li\u00e9es \u00e0 la conformit\u00e9, et les organismes de r\u00e9glementation pourraient mieux concentrer leur temps sur les exploitants pr\u00e9sentant un risque \u00e9lev\u00e9. Compte tenu de la solide posture de notre secteur au chapitre de la s\u00e9curit\u00e9 et des normes actuelles de la NERC, nous croyons qu'une approche fond\u00e9e sur le risque dans le cadre du projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> serait un pas dans la bonne direction.</p>\n<p data-HoCid=\"8213758\" data-originallang=\"en\">Le projet de loi doit aussi am\u00e9liorer les exigences en mati\u00e8re de rapports. La r\u00e9f\u00e9rence au signalement imm\u00e9diat des cyberincidents devrait \u00eatre r\u00e9vis\u00e9e. Les obligations de d\u00e9claration ne devraient pas d\u00e9tourner les exploitants d'infrastructures essentielles de leurs efforts d'intervention et de r\u00e9tablissement pendant et apr\u00e8s les incidents. Les exigences en mati\u00e8re de rapports doivent \u00eatre bien d\u00e9finies et coh\u00e9rentes, et le calendrier de production des rapports doit \u00eatre suffisamment souple pour permettre l'utilisation efficace des ressources limit\u00e9es pendant l'intervention et la reprise en cas d'incident.</p>\n<p data-HoCid=\"8213759\" data-originallang=\"en\">Toujours au sujet des exigences en mati\u00e8re de d\u00e9claration, les objectifs de la loi seraient mieux servis si une protection juridique pour les exploitants \u00e9tait incluse. Les dispositions d'exon\u00e9ration sont un \u00e9l\u00e9ment important de la promotion de l'\u00e9change de renseignements entre l'industrie et le gouvernement, de la mise en \u0153uvre r\u00e9ussie des nouvelles exigences en mati\u00e8re de d\u00e9claration et de la promotion de l'\u00e9change volontaire de renseignements.</p>\n<p data-HoCid=\"8213760\" data-originallang=\"en\">Le dernier aspect que je veux aborder est l'effet non voulu du projet de loi sur la collaboration actuelle entre l'industrie et le gouvernement. L'imposition d'exigences obligatoires pourrait entra\u00eener un refroidissement des relations de l'industrie avec les minist\u00e8res et organismes gouvernementaux. En l'absence de mesures de protection appropri\u00e9es, les juristes conseilleront probablement aux exploitants de ne partager que l'information n\u00e9cessaire pour se conformer \u00e0 la loi, et rien de plus. </p>\n<p data-HoCid=\"8213761\" data-originallang=\"en\">Cela irait \u00e0 l'encontre des objectifs du projet de loi, mais il y a deux ou trois choses que vous pourriez faire pour att\u00e9nuer ces risques. Premi\u00e8rement, il faut \u00e9tablir des limites claires quant \u00e0 la fa\u00e7on dont le gouvernement peut utiliser les renseignements recueillis aux termes de cette loi. Plusieurs dispositions du projet de loi permettraient l'\u00e9change de renseignements entre un \u00e9ventail de personnes et d'entit\u00e9s, mais ne limitent pas explicitement la fa\u00e7on dont les destinataires utiliseront les renseignements recueillis.</p>\n<p data-HoCid=\"8213762\" data-originallang=\"en\">Deuxi\u00e8mement, le cybercentre devrait \u00eatre exclu de la loi et exempt\u00e9 de l'obligation de d\u00e9clarer \u00e0 d'autres entit\u00e9s les renseignements obtenus en vertu de la loi. Les exploitants d'infrastructures essentielles entretiennent actuellement une relation de collaboration positive avec le cybercentre. Cela repose sur la conviction que ce dernier ne divulgue pas les renseignements des exploitants aux organismes de r\u00e9glementation, aux organismes d'application de la loi ou \u00e0 d'autres minist\u00e8res. Il est essentiel de prot\u00e9ger le cybercentre contre les obligations de partage de l'information pour maintenir cette relation de collaboration.</p>\n<p data-HoCid=\"8213763\" data-originallang=\"fr\">De nombreux autres aspects du projet de loi <a data-HoCid=\"11862853\" href=\"/bills/44-1/C-26/\" title=\"An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts\">C\u201126</a> m\u00e9riteraient \u00e9galement qu'on s'y attarde, mais c'est tout le temps de parole dont je dispose ce matin.</p>\n<p data-HoCid=\"8213764\" data-originallang=\"fr\"> Cependant, je vous encourage \u00e0 consulter notre m\u00e9moire, qui contient 14 recommandations sur la mani\u00e8re d'am\u00e9liorer le projet de loi C\u201126.</p>\n<p data-HoCid=\"8213765\" data-originallang=\"fr\">Merci beaucoup.</p>"
    },
    "url": "/committees/public-safety/44-1/93/francis-bradley-1/",
    "politician_url": null,
    "politician_membership_url": null,
    "procedural": false,
    "source_id": "12566129",
    "document_url": "/committees/public-safety/44-1/93/",
    "related": {
        "document_speeches_url": "/speeches/?document=%2Fcommittees%2Fpublic-safety%2F44-1%2F93%2F"
    }
}