Three recommendations made to BC Hydro in assessing cybersecurity risks, maintaining an inventory of its hardware and software components, and implementing detection mechanisms
OFFICE OF THE AUDITOR GENERAL : We found that BC Hydro is effectively managing cybersecurity risk by detecting and responding to cybersecurity incidents on the parts of its electric power system covered by mandatory reliability standards — standards which are accepted across Canada and the U.S. But components that don’t fall under the mandatory standards may be vulnerable to cybersecurity threats and should be monitored. The components that BC Hydro isn’t looking at—generally equipment of lower power capacity—may allow cybersecurity incidents to cause localized outages and, in aggregate, could have a large effect on the overall power system. Cybersecurity is no longer only about prevention, but also about quickly detecting and responding to attacks. A strong capability for cybersecurity monitoring and response is fundamental to good cybersecurity practice. We focused on how BC Hydro is managing the cybersecurity risks to its industrial contr...