CCN Report NNs division.pdf

24State of OT Report 2025
How to Establish a CCSPA-Compliant Cybersecurity Program for Critical Cyber Systems by Sandeep Lota, Presented by Nozomi Networks
After a long and winding legislative journey, Canada is poised to pass its first major cybersecurity bill designed to protect both telecommunications and critical infra- structure. If passed later this year, the second part of Bill C-8 will enact the Critical Cyber Systems Protection Act (CCSPA) which, among other things, requires designat- ed operators in key industries to establish a cybersecurity program for their critical cyber systems. As consequential as the CCSPA is, the impetus for Bill C-8 (and its pre- decessor, Bill C-26) lies in the first part, which amends the Telecommunications Act to allow the government to prohibit the use of products or services that pose a threat to
Canada’s telecommunications system. This article will focus on helping designated operators in key industries meet the CCSPA requirements.
Background: From C-26 to C-8
On June 18, 2025, the Canadian Minister of Public Safety introduced into Parliament Bill C-8, An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts. The bill resurrects Bill C-26, which passed the Senate in December 2024 but died on the order paper when Parliament
https://www.linkedin.com/in/sandman007/ https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/first-reading https://www.parl.ca/DocumentViewer/en/44-1/bill/C-26/first-reading https://www.nozominetworks.com/
25State of OT Report 2025
was prorogued in January 2025 after a drafting error. Reintroduced six months later as Bill C-8, the new bill is nearly identical to the original version, except for a few updates to procedural requirements. As such, it is expected to pass quickly.
Overview of the CCSPA
The CCSPA establishes a framework to protect cyber sys- tems that support services vital to Canada’s national securi- ty and public safety, imposing cybersecurity obligations on key sectors such as:
• Telecommunications services
• Interprovincial or international pipeline and power line systems
• Nuclear energy systems
• Transportation systems within the legislative authority of Parliament
• Banking systems
• Clearing and settlement systems
Designated operators in these industries must:
• Establish a cybersecurity program for their critical cyber systems
• Mitigate supply-chain and third-party risks
• Report cybersecurity incidents above a certain threshold
• Comply with cybersecurity orders
• Follow information disclosure and confidentiality rules
• Keep records of their cybersecurity program and any cybersecurity incidents
Penalties for non-compliance are up to $1 million for indi- viduals or $15 million in any other case.
Getting Started: NIST CSF 2.0 and IEC 62443
The core obligation in the CCSPA is establishing a cyberse- curity program for critical cyber systems. If you’re starting from scratch and are unfamiliar with how securing opera- tional technology (OT) and Internet of Things (IoT) devices differs from traditional IT tools and methods, this may be a heavy lift. Two leading cybersecurity frameworks provide trusted guidance: the NIST Cybersecurity Framework (CSF) 2.0 and IEC 62443, which are often used in conjunction.
Many CISOs are already familiar with NIST CSF, which was originally designed to help critical infrastructure organi- zations manage IT cyber risk. Developed by the National Institute of Standards and Technology in the U.S. and adopted globally, it offers a broad, flexible approach that is easy to implement and provides a clear path to matu- rity. The original framework outlines five core functions: Identify, Protect, Detect, Respond and Recover. Updated in 2024, version 2.0 added a sixth core function, Govern, with significant emphasis on OT, IoT and supply chain risk.
Developed by the International Society of Automation, IEC 62443 is a widely recognized standard for industrial cybersecurity. Part 2-1-2009 provides detailed guidance on establishing a high-quality industrial automation and con- trol systems (IACS) security program.
The Four Steps to Establishing a Compliant Cybersecurity Program
The CCSPA outlines four steps designated operators must include in their cybersecurity program:
• Identify and manage any organizational cybersecurity risks, including those associated with supply chain and third-parties
• Protect its critical cyber systems from being compromised
• Detect any cybersecurity incidents that affect or could affect these systems
• Minimize the impact of cybersecurity incidents
The CCSPA also includes a fifth requirement: to comply with any additional measures prescribed by future regula- tion, a catchall that remains undefined until those regula- tions are published. The other four requirements form the foundation of any cybersecurity program, though formal approaches to managing supply chain and third-party risks have only matured in recent years.
Let’s consider each step separately.
1. IDENTIFY AND MANAGE CYBERSECURITY RISKS
Before you can manage risk, you need to know what’s connected to your network and what it’s talking to. For des- ignated operators, that means maintaining an automated inventory of all IT, IoT and OT assets, continuously updated with details on asset behavior and known vulnerabilities. In complex environments where unplanned downtime isn’t tolerated, creating a complete asset inventory will likely require a variety of sensors and discovery methods to build
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat https://www.nozominetworks.com/
26State of OT Report 2025
detailed asset profiles, ideally enriched using artificial intel- ligence (AI).
These capabilities will give you the asset and network visibility needed to identify and manage risk in your environment:
• A variety of sensor types, including network, endpoint and wireless, to monitor your entire environment
• Active and passive discovery techniques, with remote collectors to cover hard-to-reach and unmanned locations
• Deep packet inspection (DPI) and comprehensive OT, IoT and IT protocol fluency to analyze network traffic and understand behavior
• An AI engine that learns from millions of monitored assets to fill gaps about identical devices across environ- ments and improve inventory accuracy.
Enlisting AI to enrich device profiles may sound like a nice- to-have, but it’s a potent one. According to the SANS 2024 State of ICS/OT Cybersecurity, AI adoption among defend- ers is still nascent, with only 10% of respondents using AI in both enterprise IT and OT networks. That percentage is likely to surge as security teams begin to realize they must keep up with their adversaries, who are using AI to increase the sophistication and velocity of their operations.
Assessing and Prioritizing Risk
A complete asset inventory makes it easy to identify risk; the harder part is assessing its potential impact and know- ing what to prioritize. Unlike IT cybersecurity, OT asset risk entails more than vulnerabilities. Patches (assuming they exist) must often be delayed until the next maintenance window. You must consider both cyber and operational risk down to the process variable level. When a pressure value spikes, you don’t know if it is due to malicious tampering or operator error until the incident has been investigated. In an OT network, every component is part of a larger process, so risk is interconnected. Most importantly, the stakes are higher, failures can endanger people and harm the environment.
When looking at your OT asset risk, it’s essential to iden- tify which assets pose the greatest risk, whether by zone, site, vendor, or any other relevant category. You should be able to drill down to understand what makes them risky and what you can do about it. That’s where automated risk scoring comes in. For OT devices, risk scores must account for more than just vulnerability risk but also:
• Alert risk: Measures how frequently the asset triggers security alerts. Higher volumes of confirmed or cor- related alerts indicate increased exposure or likelihood of compromise.
• Communication risk: Evaluates what an asset communi- cates with and how. If the asset connects to untrusted or internet-facing systems, traverses network boundaries, or engages in unexpected or unauthorized traffic patterns, it’s risky. DPI and protocol behavior analysis can uncover such risk.
• Device risk: Considers the device’s inherent character- istics, such as its role (PLC, HMI, etc.), OS type, patch levels and known vulnerabilities. An unpatched legacy device running outdated firmware is risky.
• Asset criticality: Reflects how important the asset is to operational continuity and safety. This is typically defined by the organization (crown jewel assets, for example) and takes into account the asset’s function within an industrial control system.
• Compensating controls: Policies and protections (net- work segmentation, endpoint monitoring, access con- trol, etc.) in place that reduce the asset’s effective risk. These controls may limit exposure, shorten response times or both.
Many cybersecurity platforms calculate multifactor risk scores, but if you’re going to rely on them, you want to be able to customize the weight of each factor to reflect how your organization assigns risk. Risk scores help cut through the noise so your security team can zero in on the assets that matter the most. The right platform doesn’t just calcu- late scores, it prioritizes them and gives clear guidance on which fixes will reduce the most risk.
Managing Supply Chain and Third-Party Risk
The CCSPA specifically obliges designated operators to manage supply chain and third-party risk, but doing so re- mains a challenge. A comprehensive asset inventory should include not only the asset itself but also its OS, end-of-sale and end-of-support dates, firmware version, and all soft- ware components, including open-source. Software bills of material (SBOMs) are the definitive source of information for managing supply chain and third-party product risk. As they become mandatory and more widespread, scanning SBOMs to pinpoint assets with vulnerable components will become easier. Leveraging AI to enrich asset profiles with complete information helps identify assets with high-risk components and determine whether to remediate or isolate them, making it the most effective course of action.
https://www.nozominetworks.com/
27State of OT Report 2025
2. PROTECT CRITICAL CYBER SYSTEMS FROM BEING COMPROMISED
Network segmentation is fundamental to protecting critical cyber systems. With full network visibility, a well-defined segmentation architecture can efficiently break down large, flat networks into secure, manageable zones organized by function, criticality or geography, making policy enforce- ment much easier. If a threat actor gains access to one segment, they’re prevented from pivoting to other sensitive areas, for example, from an HVAC system to a PLC that contorls turbine operations.
Converged networks are the norm today, and critical infrastructure is no exception. Separating IT, IoT and OT networks should be the norm. Yet, recent surveys show that 50% to 75% of cyberattacks targeting OT systems originated in IT networks. Too often, unwanted com- munication links go unchecked under the assumption that these networks are separated when they are not. Attackers know this.
Yes, converged machines, devices and controllers must talk to each other to make operations more efficient, but those communications must be tightly controlled. The Purdue Model facilitates proper segmentation in industrial environments.
Although not originally designed as a cybersecurity frame- work, the Purdue Model has become the de facto reference architecture for segmenting process control networks. Widely adopted by OT engineers, it logically separates functions across five levels, with physical functions (equip- ment) at Level 0 and business functions (IT) at Level 4. To reduce risk, direct communication between Levels 3 and 4, such as a SCADA historian sending data to an enterprise resource planning system, is blocked by firewalls. Instead, all data exchanges must pass through a demilitarized zone (DMZ) at Level 3.5.
Beyond segmentation, isolation is often appropriate for assets including:
• Certain legacy controllers that make easy targets for adversaries
• Safety critical systems that, if compromised, could cause human or environmental damage
• Crown jewel assets such as primary SCADA servers, his- torian databases and central DCS controllers that could result in a full process compromise if breached
3. DETECT ANY CYBERSECURITY INCIDENTS THAT MAY AFFECT CRITICAL CYBER SYSTEMS
Detecting cyber incidents requires continuous monitoring, performed by the same sensors used to maintain an accu- rate asset inventory. As mentioned earlier, you must be able to detect both cybersecurity threats and operational anoma- lies, because until investigated, you don’t know which it is. Comprehensive risk monitoring combines rule-based threat detection with behavior-based anomaly detection.
Rule-based Threat Detection
Rule-based detection is efficient for detecting threats where the indicators are easily observable and identifiable. This method can also be used to detect known, non-malicious anomalies, such as spikes in resource usage or an unexpect- ed surge in traffic.
Signature-based detection (a subset of rule-based detec- tion) is a fast, efficient way to detect malicious activity or unauthorized access. It works by using predefined rules to identify known attack patterns and matching them against a database of threats. An OT/IoT-focused threat intelligence feed helps ensure your sensors can detect the latest vulner- ability signatures as well as emerging malware and indica- tors of compromise (IOCs).
Behavior-based Anomaly Detection
Operational anomalies and unknown threats, including zero-day attacks, can’t be detected using rules. The best way to detect these threats is through continuous monitor- ing. DPI parses industrial protocols and compares current behavior against a baseline. AI and machine learning help establish these baselines and alert on deviations. To reduce nuisance alerts, thresholds must be set to filter out benign anomalous activity.
4. MINIMIZE THE IMPACT OF CYBERSECURITY INCIDENTS AFFECTING CRITICAL CYBER SYSTEMS
With a complete and accurate asset inventory, thoughtful network segmentation, and robust threat and anomaly detec- tion, you will be well positioned to minimize the impact of cybersecurity incidents in your environment, including multi- stage attacks. More is more: the greater the variety of sensors you deploy (network, endpoint, wireless), and the broader the monitoring techniques and intelligence sources you use (passive DPI, selective active querying), the more quickly you can detect suspicious events and cut response time.
Even so, response actions should be deliberate and risk- calculated. Don’t expect to cut and paste incident response plans from IT templates. In OT environments, safety and
https://www.nozominetworks.com/
28State of OT Report 2025
wireless signals, endpoint activity, behavior baselines and threat intelligence. This centralization streamlines risk management across sites and regions. One of AI’s greatest strengths for defenders is automation, sorting and correlat- ing data, prioritizing critical threats, adding context, and recommending next steps.
Founded in 1937, Air Canada is the country’s largest airline. It operates hubs in Toronto, Montreal, and Vancouver. Its fleet of more than 400 aircrafts serves 222 destinations across six continents.
When Bill C-26 (the precursor to Bill-8) was introduced in Parliament in 2022, the airline’s legal team evaluated it to determine the impact it would have on the company as a transportation provider. Their evaluation quickly went to the board of directors, who agreed that the cybersecurity legislation was coming, and the company needed to prepare for it. Even though Bill C-26 never passed, that’s when Air Canada began to build their program — starting with no OT security and only a vague definition of what OT assets they had.
The program consisted of four components:
• A governance model to guide how the security team would communicate with senior leadership and other stake- holders, from the network team to cargo managers to maintenance crews
• An asset inventory strategy to identi- fy all OT assets and assess their risk
• An OT reference architecture for de- signing, securing and managing their networks
• Incident response plans tailored for OT
To identify the right asset inventory solution, the team conducted a three- month proof-of-value (POV), with several vendors competing apples-to-apples in critical environments that rely heavily on OT, such as hangers and cargo areas. The visibility gained from this exercise led to a key decision: categorize OT assets into two verticals. The first covers airplane control systems, including all support systems unique to aircraft. The second covers automation systems, such as safety locks, video cameras, HVAC, fire suppression, and other smart-build- ing technologies common in airports.
During the unusually long POV, the team was able to thoroughly vet each ven- dor’s solution and approach, picking up valuable insights that accelerated the ac- tual implementation once a vendor was selected. In just four months, the airline deployed 35 security sensors across its operations in Canada, with more to go. Local sensors perform asset discov- ery, vulnerability analysis, and threat monitoring. All telemetry is then sent to the cloud for centralized monitoring, AI- powered threat analysis, profile enrich- ment, and risk prioritization.
The OT security team still has plenty of work ahead of them, but with Bill C-8 still pending, Air Canada has a solid jumpstart on addressing not only the CCSPA’s requirements but the compa- ny’s internal goals for securing its critical cyber systems.
How Bill C-26 Shaped Air Canada’s Approach to Risk Management
process continuity take priority. That’s why responses must be tightly coordinated with engineering and safety teams, who often are the better source for response tactics involv- ing containment or shutdown steps.
An AI-powered cloud platform can significantly reduce workload by consolidating data from network traffic,
Level Up Your Critical Cyber System Security to Manage Enterprise Risk
The CCSPA is enabling legislation. As such, it establishes a broad frame- work, with details to be filled in by regulations after its passage. Ahead of those specifics, designated operators should be rolling up their sleeves and getting to work.
For CISOs, this means incorporating often-overlooked industrial control systems in your enterprise risk strat- egy. As CISOs increasingly assume responsibility for OT and IoT security, even those with mature IT cyberse- curity programs are realizing a gap: they no longer have the cyber ma- turity they thought they did without developing a cybersecurity program tailored to these assets.
The OT/IoT cyber maturity curve be- gins with asset inventory and advanc- es through network segmentation, intrusion detection, and ultimately risk management. The CCSPA aims high, targeting not only risk manage- ment but supply chain and third-party risk oversight. The best advice? Start where you are, and keep going.
In his current role as Global Field CTO at
Nozomi Networks, Sandeep Lota enables the
success of Nozomi’s sales and channel force
and is both a leader and expert in executing
complex design and systems engineering
configurations. Having spent the first decade
of his career working on the operations and
project teams for global energy super-giants;
Sandeep gained a powerful knowledge base
of IT & OT principals which have been the
foundation of his success.
https://www.nozominetworks.com/ https://www.linkedin.com/in/sandman007/
Download the report
See why Nozomi Networks is a Customers' Choice in the 2025 Gartner® Voice of the Customer for CPS Protection Platforms
A Customers' Choice
https://www.nozominetworks.com/gartner-voice-of-the-customer-cps https://www.nozominetworks.com/