What critical infrastructure means in Canada
Public Safety Canada's strategy defines critical infrastructure broadly as processes, systems, facilities, technologies, networks, assets, and services essential to the health, safety, security, or economic well-being of Canadians and the effective functioning of government. It organizes the landscape into ten sectors: energy and utilities; finance; food; government; health; information and communication technology; manufacturing; safety; transportation; and water. The framework is all-hazards and shared across public and private responsibilities. Sources: Public Safety Canada (opens in a new tab) Public Safety Canada (opens in a new tab)
A category label does not make every facility nationally critical. Assessment depends on the service, affected population, geographic concentration, alternatives, time, and perspective. A local road, school, retail fuel site, or municipal facility may be essential in an incident without being represented as a national critical asset. Good analysis states the scope and avoids turning a generic point-of-interest dataset into an authoritative inventory. Source: Public Safety Canada (opens in a new tab)
Likelihood, exposure, and consequence are different
An outage model may estimate the chance that a defined location or region experiences an interruption. A consequence assessment asks what happens if it does. A hospital or water facility near the forecast area does not, by its presence alone, increase wind loading, tree contact, or equipment failure. It changes how serious the interruption could be and which coordination questions deserve attention. Mixing those axes can distort both model training and operational prioritization.
A qualitative likelihood-by-consequence matrix can be useful when each input remains visible. High likelihood with modest consequence may justify routine readiness; lower likelihood with severe consequence may still justify a watch or contingency review. Confidence in the data is another dimension. Missing asset, backup, or provider data should not be interpreted as low consequence. Duration and recoverability also matter because a brief, well-supported transfer differs from a prolonged multi-service disruption. Source: Public Safety Canada (opens in a new tab)
Evidence: Conceptual Illustration
Keep physical likelihood and consequence separate
Explain qualitative review priorities without implying critical assets make faults more likely.
Scroll horizontally or use the arrow keys to compare every column.
| Outage likelihood | Consequence | Illustrative review posture |
|---|---|---|
| Lower | Lower | Routine monitoring; retain uncertainty |
| Higher | Lower | Operational readiness proportional to forecast evidence |
| Lower | Higher | Contingency and continuity review may still be warranted |
| Higher | Higher | Coordinated review with source, confidence, duration, and access visible |
Explain qualitative review priorities without implying critical assets make faults more likely.
Direct, indirect, and cascading impacts
Direct impact is the immediate loss or degradation of service at an affected facility or network. Indirect impact reaches customers, suppliers, staff, or communities that depend on it. Cascading impact occurs when disruption propagates through dependencies: electricity affects telecom or water, telecom affects payment and logistics, fuel affects generators and transport, and access affects repair and staffing. The sequence can also loop, with one degraded service slowing restoration of another. Sources: Government of Canada-led assessment (opens in a new tab) Public Safety Canada (opens in a new tab)
Dependency diagrams should remain generalized in public. Their purpose is to reveal categories of reliance and possible coordination needs, not to publish the exact topology, vulnerability, or failure threshold of a real facility. Local emergency and utility teams may maintain more detailed protected information under their own authority. Public educational content should help readers understand the relationship while preserving that boundary. Source: Public Safety Canada (opens in a new tab)
Evidence: Observed Public Data
How a local interruption can propagate
Show dependency categories described in Canadian infrastructure guidance.
-
Electricity
Initial interruption
Duration and affected load vary
-
Telecom
Communications pressure
Coordination, payments, monitoring may depend on power
-
Water / fuel
Pumping and supply pressure
Backup and logistics introduce new dependencies
-
Health / safety
Service consequence
Staff, access, supplies, and alternatives matter
Source-derived dependency categories; not the topology of a real facility or region.
Figure sources: Government of Canada-led assessment (2021) (opens in a new tab) Public Safety Canada (opens in a new tab)
Duration, redundancy, backup power, access, and population served
Backup generation can reduce immediate consequence, but the phrase 'has a generator' is not enough. Capacity, transfer equipment, maintenance, test history, fuel supply, runtime, load priority, ventilation, and staffing all influence continuity. A service may also depend on off-site telecom, water, transport, or suppliers. These details change and may be sensitive, so a public model should not infer or expose them without authorization. Sources: Public Safety Canada (opens in a new tab) Public Safety Canada (opens in a new tab)
Substitutability asks whether another facility, route, communication path, or supply can deliver the service. Geographic concentration asks whether several dependencies can be affected by the same event. Population served and vulnerable populations shape social consequence. Access conditions influence whether staff, fuel, or repairs can arrive. These factors can be represented as review prompts even when a numeric score would imply more precision than the data supports. Source: Public Safety Canada (opens in a new tab)
Geographic exposure and service-area context
A weather or outage-risk polygon can overlap an essential-service location, but point proximity alone does not define dependency or service impact. A water plant may serve a distant community; a telecom facility may have network redundancy; a transport closure can constrain a repair route without losing electric supply at the mapped point. GIS should connect geometry to a stated question rather than treat every nearby feature as equivalent.
Aggregation can make public analysis both safer and more honest. A map may show counts by broad category or generalized service areas instead of exact sensitive coordinates. It should display source, date, coverage, and whether the data is authoritative, open, inferred, or schematic. An incomplete public dataset cannot support a claim that no critical service exists where no point is shown. Source: Public Safety Canada (opens in a new tab)
Prioritization and restoration context
Utilities and emergency managers can consider public safety, essential services, customers affected, system topology, repair complexity, access, weather, and available resources. A critical-infrastructure overlay can support a watchlist or coordination conversation. It is not a restoration promise, and it cannot determine the electrical sequence without authoritative network and field information. Source: BC Hydro (opens in a new tab)
BC Hydro publishes one example of restoration priorities, beginning with hazards and critical services before equipment serving larger groups and then smaller or individual outages. Other utilities and incidents may differ. Even within one event, crews can work in parallel, switching can restore some customers before repairs, and safety or access can change the order. Public articles should qualify examples rather than imply guaranteed entitlement. Source: BC Hydro (opens in a new tab)
Data sensitivity, privacy, aggregation, and security
Some infrastructure locations are public and already widely known; that does not make detailed vulnerability, backup runtime, dependency topology, control systems, capacity, or access constraints appropriate for republication. A map built for public education should use the minimum detail needed to explain risk. It should avoid combining open fragments into an operational vulnerability profile and should follow the owning organization's security and privacy rules. Source: Public Safety Canada (opens in a new tab)
Account data needs another boundary. User-saved locations and private portfolios should remain scoped to the authorized account and should not be used to create public asset maps. Aggregated counts need disclosure controls when small numbers could identify a protected facility. Data-source documentation can describe categories, provenance, update cadence, and known gaps without publishing secrets or sensitive coordinates. Source: Public Safety Canada (opens in a new tab)
Evidence: Observed Public Data
Public explanation versus protected operations
Apply the minimum-detail principle to infrastructure and account data.
Scroll horizontally or use the arrow keys to compare every column.
| Appropriate public context | Keep protected / authorized |
|---|---|
| Generalized sectors and aggregated service areas | Exact sensitive coordinates and topology |
| Source, date, coverage, and known gaps | Vulnerability, capacity, and failure thresholds |
| Qualitative dependency categories | Backup runtime, fuel plans, control details |
| Public preparedness relationships | Private saved locations and account portfolios |
Apply the minimum-detail principle to infrastructure and account data.
Figure source: Public Safety Canada (2010-07-01) (opens in a new tab)
How GeoGridIQ can connect probability and consequence
A GeoGridIQ workflow can place a separately estimated outage probability beside generalized consequence indicators, data freshness, and evidence quality. The display should show which axis raised the review priority. A hospital category may raise consequence without changing physical probability; a strong weather/vegetation signal may raise probability without proving severe consequence. Operators can then review authoritative local information under their procedures.
The product should not call an open asset layer complete, infer backup-generator state, expose dependency details, or promise restoration priority. Current forecast status also matters: if region, horizon, artifact, batch, or freshness gates fail, no critical-infrastructure overlay should make the unavailable forecast appear trusted. The safer alternative is a static preparedness layer or an explicit unavailable state with current timestamps and limitations. Source: GeoGridIQ
A consequence-aware planning checklist
Start with the decision and geography. Identify the essential service category, authoritative owner, population or service dependence, duration sensitivity, alternatives, backup assumptions, access constraints, and downstream dependencies. Record the source and review date for each fact. Keep unknown fields unknown and separate public from protected details. Then combine the consequence review with an independently sourced hazard or outage-risk state. Source: Public Safety Canada (opens in a new tab)
During and after an event, validate which services were affected, how dependencies behaved, whether backup arrangements operated as assumed, and which public data was missing or stale. That learning can improve future checklists without publishing protected detail. Consequence analysis is most useful when it creates a shared set of questions before disruption—not when it produces a dramatic but unverifiable score. Source: Public Safety Canada (opens in a new tab)
Scope and safeguards
Limitations and responsible use
- Public asset datasets may be incomplete, stale, generalized, or inappropriate for operational use.
- Backup-power, redundancy, capacity, and dependency information is often unavailable or protected.
- Criticality and restoration procedures change by jurisdiction, owner, event, and time.
- A consequence overlay does not validate or repair an unavailable outage forecast.
Frequently asked questions
Questions this article answers
What counts as critical infrastructure?
Canada identifies ten sectors, but an individual asset's criticality depends on its function, consequences, scale, alternatives, and assessment perspective.
Does critical-infrastructure proximity increase outage probability?
Not by itself. It changes potential consequence and review priority, not necessarily the physical chance of failure.
What is cascading infrastructure risk?
It is disruption that propagates because one service depends on another, such as water pumping, telecom, or fuel logistics depending on electricity.
How does backup generation change risk?
It may reduce immediate consequence, but capacity, transfer, maintenance, fuel, runtime, load, access, and other dependencies still matter.
Why should some locations be aggregated or protected?
Exact locations and operational details can expose security, vulnerability, privacy, or continuity information beyond what public education requires.
Evidence register
Sources
Sources were reviewed on . Mutable sources are rechecked on the article review schedule.
-
I1 Public Safety Canada. National Strategy for Critical Infrastructure (opens in a new tab). 2009.
-
I2 Public Safety Canada. Current critical-infrastructure overview (opens in a new tab).
-
I3 Public Safety Canada. Risk Management Guide for Critical Infrastructure Sectors (opens in a new tab). 2010-07-01.
-
I4 Public Safety Canada. Canada's Critical Infrastructure (opens in a new tab).
-
C2 Government of Canada-led assessment. Canada in a Changing Climate — National Issues, Chapter 2 (opens in a new tab). 2021.
-
O3 BC Hydro. How power is restored (opens in a new tab).
-
GGI_MODEL_STATUS GeoGridIQ. Protected-artifact safety and runtime availability audit.