A system considered operationally stable can be placed under heightened surveillance overnight, with no advance warning. That is the reminder from an incident that occurred in the Maritimes in March 2024, whose technical details have not been made public.
Key points
- Drinking water infrastructure in New Brunswick and Nova Scotia was placed under heightened monitoring in March 2024.
- The exact nature of the attack has not been publicly confirmed, based on information available to date.
- The industrial control systems that run water treatment are increasingly connected to conventional IT networks.
- This incident does not directly affect Quebec, but it illustrates a risk relevant to any organization managing essential infrastructure.
What do we actually know about this incident?
Based on available information, drinking water infrastructure in New Brunswick and Nova Scotia was placed under heightened monitoring in March 2024 following a cyberattack. No official confirmation has specified the exact nature of the attack or its origin, and no group has been publicly identified as responsible for the incident.
This silence around technical details is not unusual when essential infrastructure is involved: response teams generally avoid releasing information that could be useful to malicious actors while a response is underway. For an organization following this kind of news, the main lesson is not the missing detail, but the fact that a system considered operationally stable had to be placed under heightened monitoring without warning.
Why is drinking water infrastructure a target?
Water treatment plants rely on SCADA-type industrial control systems that are increasingly connected to conventional IT networks, which widens their exposure. Their essential nature makes them attractive to an attacker, since even a limited disruption has a direct impact on the population served.
This observation extends well beyond the water sector. Any organization that links operational equipment, production lines, building systems, logistics, access control, to its office network creates a point of contact between two historically separate worlds, often with less monitoring than on conventional IT systems. The Canadian Centre for Cyber Security recommends treating these convergence zones as a priority in any security approach, regardless of an organization’s size.
What does this change for a Quebec SMB or nonprofit?
Few SMBs manage a drinking water network, but many operate connected equipment (cameras, heating systems, payment terminals, access control) without considering it part of their digital footprint. This incident is a reminder that any equipment connected to the network becomes a potential entry point, regardless of the organization’s industry.
In Quebec, an organization that experiences an incident affecting personal information has specific obligations under the Act respecting the protection of personal information in the private sector, including keeping a register of confidentiality incidents and, depending on the circumstances, notifying the Commission d’accès à l’information (Quebec’s access-to-information oversight body). These obligations exist regardless of the nature of the incident described here, and they apply whether the affected equipment is a workstation, an industrial system, or a connected device.
How can an organization reduce this kind of exposure?
There is no absolute protection against a cyberattack, but several recognized measures significantly reduce exposure: mapping connected equipment, isolating operational systems from the office network, restricting remote access, and keeping security patches up to date on a regular schedule.
The Canadian Centre for Cyber Security offers a list of baseline controls designed specifically for small and medium organizations, which generally do not have a dedicated security team. These controls are not meant to eliminate risk, which is impossible, but to make an intrusion significantly harder and to limit the damage if one occurs anyway. Be wary of any pitch that claims to offer complete protection or zero risk: no credible provider can make that claim.
FAQ
Can an SMB be affected by the same kind of incident as a drinking water network?
The technical scenario differs by sector, but the underlying principle is the same: as soon as operational equipment, whether a water treatment system, a surveillance camera, or a point-of-sale terminal, communicates with an IT network, it becomes a potential target. SMBs and nonprofits are rarely targeted for their profile, but often because they represent easier access than a larger, better-protected organization. An organization’s size does not shield it; it mainly changes the likelihood and nature of an attack, not whether one can occur.
What must a Quebec organization do in the event of an incident affecting personal information?
The Act respecting the protection of personal information in the private sector requires Quebec organizations to keep a register of confidentiality incidents, whether or not they are reported externally. When an incident poses a risk of serious harm to the individuals concerned, notifying the Commission d’accès à l’information and the affected individuals becomes mandatory. These obligations apply regardless of the type of system affected, whether a customer database or a connected operational device. They govern the response after the fact; they do not replace upstream prevention measures.
Does isolating operational systems from the office network eliminate the risk?
No, and any promise to that effect should be treated with caution. Network segmentation is a recognized measure that significantly reduces exposure by limiting how an incident spreads from one system to another, but it is only one element among several. An organization must also govern remote access, keep security patches current, train staff, and maintain an incident response plan. There is no absolute protection in cybersecurity; the realistic goal is to make an attack harder to carry out and faster to detect, not to guarantee it will never happen.
Sources
- Réseau d’Information Municipale, via Google News · press, 2026
- Canadian Centre for Cyber Security: baseline cyber security controls for small and medium organizations · baseline reference controls
- Commission d’accès à l’information du Québec · obligations, incident register and notification
Source: Réseau d’Information Municipale · https://news.google.com/rss/articles/CBMixgFBVV95cUxOWi1PcTJqUWFXWFY2SlJiUU9qTEpEU2J0bXE0M01BZW5ZU3FzNkVYUnM5X3oxYmVTdi1xS19RdUdNU09pbk00SVFaenNLeEZ4Wm5NNmhSWm1NS3QxTWVwMVdXd01pTXRZVk9nSDFoZzZuMEF0eEZhczVVNXh5MUVwYW9kWG81UmtfWGRpWFVtZjV5RGxoNkFOUzd5VXlUSjkxMG14TGI1Nmt4Mzk0RnREaWxEWE4zT0N4U3d2cnRTSTFXQ1ZpUkE?oc=5