TL;DR: Canada’s Bill C-8 shifts critical infrastructure cybersecurity toward continuous, evidence-based resilience rather than periodic compliance checks, according to Horizons.ai’s whitepaper. That changes the practitioner problem from documenting controls to proving exploitable paths are closed and remediation actually holds.
NHIMG editorial — based on content published by Horizons.ai: Meeting Canada’s Bill C-8 Cybersecurity Requirements with NodeZero®
Questions worth separating out
Q: How should critical infrastructure teams validate cybersecurity controls under Bill C-8?
A: They should validate controls against realistic attack paths, not just against policy checklists.
Q: Why do periodic assessments fall short for continuous resilience requirements?
A: Periodic assessments only show control status at one moment, while attack paths change continuously.
Q: What should IAM teams look for when identity is part of resilience testing?
A: They should focus on standing privilege, excessive token scope, third-party trust, and stale access that can be chained into critical system access.
Practitioner guidance
- Map critical attack paths across identity and infrastructure Identify the paths most likely to reach critical systems, including privileged accounts, third-party connections, cloud permissions, and exposed services.
- Replace one-time assessment evidence with continuous verification Require post-remediation testing that confirms the exploit path is actually closed.
- Build audit evidence from exploitable risk reduction Document which attack paths were tested, which controls blocked them, and what changed after remediation.
What's in the full article
Horizons.ai's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The full CCSPA obligation breakdown and how each requirement maps to operational security work
- The Hack. Fix. Verify. Repeat. methodology applied to continuous autonomous validation
- Environment-specific guidance for internal, external, cloud, identity, Kubernetes, and web application testing
- The evidence model for showing remediation effectiveness to regulators and internal stakeholders
👉 Read Horizons.ai's whitepaper on Bill C-8 and continuous cyber resilience →
Bill C-8 and continuous validation: what changes for critical systems?
Explore further
Continuous validation is becoming a governance requirement, not a niche testing preference. Bill C-8 reflects a broader shift in which critical infrastructure operators are expected to prove resilience, not simply assert it. That matters because evidence-based security changes how boards, regulators, and operators judge control effectiveness. For identity programmes, the same expectation applies to access and privilege boundaries. Practitioners should treat validation as part of governance evidence, not an optional security exercise.
A question worth separating out:
Q: Who is accountable if remediation looks complete but the attack path still exists?
A: Accountability sits with the programme owner who accepted remediation without verifying the outcome. In evidence-based resilience models, a closed ticket is not the same as a closed risk. Governance teams, security operations, and control owners should share responsibility for proving that the exploit path is gone before declaring success.
👉 Read our full editorial: Bill C-8 pushes critical systems toward continuous cyber evidence