Taking a quick step back, the legislation would not apply to every single electronic service provider from day one. For an electronic service provider to be covered by the legislation, either it would have to be covered as a core provider through the regulation, or it would need to be identified through a ministerial order...to develop any capability that is mandated by the regulation or the ministerial order. The legislation is not intended to introduce vulnerabilities into systems. We don't refer to back doors. We don't believe it creates back doors. I think there's a letter from the CSE that was shared with the community on some of these points.
Whether or not it's in this legislation as it currently stands, it is the responsibility of companies to protect their cybersecurity. They do it every day. Attacks happen. We had testimony from my colleagues at the service: No system is 100% protected from cyber breaches. I think we all know this from what we see every day. Companies are well positioned to defend their systems.
This legislation has safeguards to prevent new vulnerabilities from being introduced into systems.
