The House of Commons Standing Committee on Public Safety and National Security met to study Bill C-8, an act respecting cybersecurity and amending the Telecommunications Act. Appearing were Bridget Walshe, Associate Head of the Canadian Centre for Cyber Security; Andre Arbour, Director General of the Telecommunications and Internet Policy Branch at the Department of Industry; Kelly-Anne Gibson, Director of the Cyber Protection Policy Division at the Department of Public Safety and Emergency Preparedness; Daniel Couillard, Director General of Cyber Partnerships at the Canadian Centre for Cyber Security; and Colin MacSween, Director General of the National Cyber Security Directorate at the Department of Public Safety and Emergency Preparedness.
Bridget Walshe described the evolving cyber-threat landscape, including state-sponsored threats and cybercrime-as-a-service platforms, and stressed that cybersecurity requires collaboration across government and industry. She noted that Bill C-8 builds on Bill C-26 to establish a regulatory framework for baseline cybersecurity of critical sectors, with mandatory incident reporting to the cyber centre focused on technical indicators of compromise, and that CSE gains no new authorities under the bill.
Andre Arbour explained that the minister's powers under part 1 of the bill are scoped to protecting the telecommunications system, not individual speech or data, and that orders must be reasonable relative to the threat. He noted that the authority to withdraw services targets entities like those conducting distributed denial of service attacks, not individual Canadians, and that safeguards include consultation requirements, notification to NSIRA and NSICOP, annual reports to Parliament, and judicial review. He disagreed with concerns that the broad wording "to do anything, or refrain from doing anything" could enable encryption-breaking, stating that such actions are out of scope and that the bill explicitly prohibits intercepting private communications.
Kelly-Anne Gibson said that designated operators under part 2 are responsible for managing supply chain and third-party risks through their cybersecurity programs, using guidance from the cyber centre. She noted that the bill does not directly address competitive fairness but that a secure environment protects the economy, and that penalties are set high but within industry-typical ranges. She confirmed that civil liberties organizations were consulted and their submissions considered.
Daniel Couillard added that the cyber centre has strong working relationships with provinces and territories, sharing threat information regularly, and that mandatory reporting under Bill C-8 will improve the centre's ability to identify threats and notify affected entities. He noted that over 1,400 incidents were reported voluntarily in 2024-25.
Colin MacSween clarified that mandatory reporting under part 2 will not require reporting every breach; regulations will define a threshold for significant incidents, informed by discussions with Five Eyes counterparts.
The committee debated and then agreed on a motion for the study of Bill C-12, setting a witness list deadline of November 3, 2025, scheduling four meetings for witness testimony, and beginning clause-by-clause consideration at a fifth meeting without limiting the number of meetings needed to complete it.
AI-generated summary — may contain errors; verify against the official evidence.