On July 13, the NSA, CISA, the FBI and sixteen other agencies across thirteen countries, including the Canadian Centre for Cyber Security, published a joint advisory (AA26-194A) attributing a decade-long campaign against poorly configured and end-of-life network devices in critical sectors to Center 16 of Russia's FSB. Six sectors are named most at risk: communications, the defence industrial base, energy, financial services, government services and healthcare.
Four weeks earlier, on June 15, Bill C-8 received royal assent in Ottawa, enacting the Critical Cyber Systems Protection Act. Read together, the two documents tell Canadian critical infrastructure operators something simple: the threat is active and documented, and preparedness is about to stop being good practice and become a legal obligation.
A campaign with no malware
What makes advisory AA26-194A remarkable is how ordinary the described techniques are. No sophisticated implant, no zero-day: FSB actors scan the internet for SNMP agents that accept default community strings, then send SNMP requests that order the device to copy its own configuration and exfiltrate it over TFTP to servers they control. Occasionally they exploit a Cisco Smart Install flaw known since 2018 (CVE-2018-0171), or end-of-life devices that will never see another patch.
The stolen configuration files then yield passwords stored in weak formats, addressing schemes and filtering rules: everything needed to come back later, quietly, with legitimate access.
Two points deserve a risk owner's attention.
- It is a silent attack by design. No malware to detect, spoofed source addresses, traffic that looks like routine network administration. Most organizations would see nothing.
- Every exploited failure is a known control. Disable Smart Install, move to SNMPv3, restrict administration to an out-of-band management network, block TFTP and SNMP at the edge, replace end-of-life devices: the advisory asks for nothing exotic. It asks for discipline and a current inventory, which is to say real external attack surface management.
What Bill C-8 changes
The Critical Cyber Systems Protection Act targets designated operators in four federally regulated sectors: finance, telecommunications, energy and transportation. Three of those four also appear on the FSB's priority target list according to the joint advisory. The Act is not yet fully in force, its regulations are still to come, but its architecture is known.
- A mandatory cybersecurity program. Identify risks, protect critical cyber systems, detect incidents, minimize their impact. Legal analyses point to a 90-day deadline after designation to establish it.
- Mandatory incident reporting to the Canadian Centre for Cyber Security, within a timeframe to be set by regulation (analyses point to 72 hours at most), then to the sector regulator.
- Supply chain risk management, to be addressed as soon as risks are identified.
- Binding government directions, and administrative penalties of up to 15 million dollars per violation for an organization, with each day counting as a separate violation, plus potential personal liability for directors and officers.
Put the two documents side by side and the finding becomes concrete: a configuration exfiltration over SNMP, exactly what the advisory describes, is precisely the kind of incident that will become reportable within hours once the Act is in force. It is also the kind of incident most operators would not detect today.
The preparation window
Bill C-8's obligations do not yet have a coming-into-force date: operators have a preparation window of unknown length. Designation, when it comes, may arrive with short deadlines. The rational move is to build the program now against the joint advisory's mitigation list, which explicitly cites the Canadian Centre for Cyber Security's own publications.
- Inventory your network devices, including the ones nobody administers anymore. An end-of-life router reachable from the internet is exactly the target described.
- Harden management protocols: SNMPv3, strong passwords in modern storage formats, out-of-band management access, TFTP, Smart Install and SNMP blocked at the network edge.
- Detect the silent scenario: alerts on inbound SNMP requests targeting sensitive identifiers and on local-account logins to network devices cost little and cover precisely this campaign.
- Document everything. Under C-8, the regulator's question will not be "are you secure" but "show me your program, your identified risks and your evidence." Cyber risk mapping becomes a regulatory deliverable, not just an internal tool.
The board question
For the board of a critical infrastructure operator, the question has changed in nature. Yesterday: "are we exposed to this campaign?" Tomorrow, under C-8: "if this incident happened tonight, would we detect it, report it on time, and demonstrate to the regulator that our program was serious?" With per-day penalties and personal liability for directors, the gap between those two questions is now measured in dollars and careers.
Where FortaRisks comes in
FortaRisks, a Canadian integrated risk management platform, helps operators prepare on both sides of the equation: external attack surface management continuously discovers exposed devices, including the ones that fell out of inventory, and the Compliance module turns cybersecurity program requirements into measured, prioritized, documented gaps ready to present to a board or a regulator. For a first free snapshot, our cyber risk score takes a few minutes.