
Alberta Regulation 84/2024: Cyber Requirements for AER-Regulated Operators
A documented cyber security programme, IT/OT separation and AER enforcement powers that reach as far as ordering a facility shutdown.
GuardsArm Team
Security Experts

Alberta energy operators now sit under an enforceable cyber security regulation rather than sector guidance. Regulation 84/2024 requires AER-regulated operators to run a documented cyber security programme aligned to CSA Z246.1, and gives the Alberta Energy Regulator audit powers and enforcement options that extend to ordering a facility to stop operating until it complies.
For an industry where an outage is measured in barrels, an enforcement power aimed at operations rather than at the balance sheet changes the calculus.
What the programme must contain
The requirements track CSA Z246.1 and land on a familiar set of controls, with the emphasis firmly on operational technology.
Each of those is ordinary security practice. What makes this regulation demanding is that it applies them to an estate where the ordinary methods do not work.
IT/OT separation is the core of it
Boundary protection between the corporate network and the control environment, with governed remote access, is the requirement that carries the most weight and the most work.
| Requirement | What it means on a real site |
|---|---|
| Environment separation | Control systems on their own segments, not a flat plant network |
| Boundary protection | Enforced, inspected traffic between IT and OT — not a shared switch |
| Remote access control | Brokered, authenticated, time-boxed and recorded |
| Asset inventory | Every controller, HMI and engineering workstation, discovered not assumed |
Vendor remote access is the recurring finding. Control system suppliers commonly hold persistent tunnels into plant equipment, installed at commissioning, shared between support engineers and frequently unlogged. Under this regulation that arrangement is not defensible. See third-party remote access — the pattern is identical outside healthcare.
The awareness requirement has a specific cadence
Security awareness training for all personnel on a defined recurring basis is named explicitly. Operators running ad-hoc or onboarding-only training will not satisfy it; the obligation is periodic and evidenced.
Enforcement is operational, not just financial
The AER can audit an operator's programme, order that a programme be implemented, and in serious cases require a facility to stop operating until compliance is achieved. Licence standing is exposed.
That shifts where this sits internally. A financial penalty is a matter for finance and legal; a shutdown order is a matter for operations and the executive. Operators that have briefed their leadership on the enforcement mechanism, rather than on the control list, generally get the programme resourced.
How this interacts with federal obligations
Pipeline operators may also be designated under the federal Critical Cyber Systems Protection Act, which adds incident reporting to the Communications Security Establishment and compliance with binding cyber security directions.
The two regimes overlap substantially on programme content. Build the programme once, against CSA Z246.1 with IEC 62443 and NIST SP 800-82 as supporting references, and map it to both sets of obligations rather than maintaining parallel documentation.
Where to start
Produce the OT asset inventory. Nothing else in the regulation — segmentation, patching decisions, monitoring, recovery testing — can be evidenced without it, and passive discovery on a control network will typically find equipment that no existing register lists.
What an AER audit will want to see
The regulation asks for a programme. An audit asks for evidence that the programme operates. Those are different artefacts, and operators who have only the first tend to fail on the second.
| Requirement | Document | Evidence it runs |
|---|---|---|
| Programme | The programme itself, with review dates | Minutes or records of the review |
| Asset inventory | The register | Discovery output and a reconciliation date |
| Separation | Network architecture diagram | Firewall rule review, tested boundary |
| Remote access | Access policy | Session records and current account list |
| Backups | Backup design | A restoration test report with a date and result |
| Training | Curriculum | Attendance records covering all personnel |
| Incident response | The OT plan | An exercise report, not just the plan |
The right-hand column is where programmes fail. A backup design with no restoration test, or an incident plan never exercised, satisfies the paperwork and not the regulation. See backup testing and tabletop exercises.
GuardsArm assesses OT environments and builds programmes for Alberta energy operators. See Alberta Regulation 84/2024 services and OT and ICS security, or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


