This legislation is part of an ensemble of legislation, but I would point out to you that companies already take a number of steps to protect their systems. They do so in collaboration with their own service providers, with third parties and with the Canadian centre for cybersecurity, which is a good partner of the private sector specifically on critical infrastructure.
I would also point out that Bill C-8, which received royal assent late yesterday, imposes a number of obligations on federal critical infrastructure owners, including cybersecurity and in relation to third parties. I think we need to look at it in totality in terms of what is done in the private sector and the obligations they have in regard to other pieces of legislation, but also, it is their responsibility.
We know that companies do this. They want to protect their systems because it's good for them and it's good for their customers. They are all constantly patching whether or not this legislation exists. As this legislation gets implemented and there are discussions with the government in terms of the regulations and ministerial orders, again, the legislation allows ESPs to say, “I can't do that because it introduces a systemic vulnerability.”
There are a number of safeguards in the legislation but also in totality in terms of obligations that apply to a number of providers.