Climate Risk Solutions

November 29, 2023

Policy Tools to Induce Cyber Resilience among Critical Infrastructure Owners and Operators

August 2023

Jason Thistlethwaite
Daniel Henstra
Sandra Biskupovic

Ensuring the cyber resilience of critical infrastructure (CI) systems is a high priority. Although awareness of the benefits of cyber resilience is growing, implementation of its tenets at a scale and precision necessary to effectively counter cyber threats is unlikely without government intervention. This paper documents policy instruments used in Canada and other countries to strengthen cyber resilience by engaging different governing resources, including authority (e.g., regulation), information (e.g., disclosure), the public treasury (e.g., subsidies) and organizational capacity (e.g., procurement). The research found that Canada has not yet engaged the full spectrum of policy instruments, has prioritized some aspects of cyber resilience over others, and lacks a meaningful assessment of the effectiveness of policy efforts to induce cyber resilience among CI operators.

Read