Back to Blog
Industry Specific
4 min read

Alberta Regulation 84/2024: Cyber Requirements for AER-Regulated Operators

A documented cyber security programme, IT/OT separation and AER enforcement powers that reach as far as ordering a facility shutdown.

GuardsArm Team

Security Experts

September 25, 2026

Alberta Regulation 84/2024 cyber security requirements

Alberta energy operators now sit under an enforceable cyber security regulation rather than sector guidance. Regulation 84/2024 requires AER-regulated operators to run a documented cyber security programme aligned to CSA Z246.1, and gives the Alberta Energy Regulator audit powers and enforcement options that extend to ordering a facility to stop operating until it complies.

For an industry where an outage is measured in barrels, an enforcement power aimed at operations rather than at the balance sheet changes the calculus.

Enforceable, not guidance
AER audits, orders and licence exposure
Shutdown is on the table
Enforcement aimed at operations, not just fines
CSA Z246.1 is the anchor
With IEC 62443 and NIST SP 800-82 alongside

What the programme must contain

The requirements track CSA Z246.1 and land on a familiar set of controls, with the emphasis firmly on operational technology.

What Regulation 84/2024 requires of the programmeEnvironment separation and boundary protection, asset inventory, tested backups, least privilege, recurring awareness training, and OT-specific incident response and continuity planning.IT/OT separation and boundary protectionIncluding governed remote accessAuthorised hardware and software inventoryDiscovered, monitored, maintainedBackup, restoration and recovery testingTested, not merely configuredLeast privilege and acceptable useAdministrative and user rights constrainedRecurring security awareness trainingOn a defined cadence, evidencedOT incident response and continuity plansSpecific to the control environment
Ordinary controls, applied to an estate where the ordinary methods do not fit.

Each of those is ordinary security practice. What makes this regulation demanding is that it applies them to an estate where the ordinary methods do not work.


IT/OT separation is the core of it

Boundary protection between the corporate network and the control environment, with governed remote access, is the requirement that carries the most weight and the most work.

RequirementWhat it means on a real site
Environment separationControl systems on their own segments, not a flat plant network
Boundary protectionEnforced, inspected traffic between IT and OT — not a shared switch
Remote access controlBrokered, authenticated, time-boxed and recorded
Asset inventoryEvery controller, HMI and engineering workstation, discovered not assumed

Vendor remote access is the recurring finding. Control system suppliers commonly hold persistent tunnels into plant equipment, installed at commissioning, shared between support engineers and frequently unlogged. Under this regulation that arrangement is not defensible. See third-party remote access — the pattern is identical outside healthcare.


The awareness requirement has a specific cadence

Security awareness training for all personnel on a defined recurring basis is named explicitly. Operators running ad-hoc or onboarding-only training will not satisfy it; the obligation is periodic and evidenced.

Evidence the cadence, not the intent
A training policy stating that staff are trained is not evidence. Attendance records with dates, covering all personnel including contractors and control room staff on shift patterns, are what an audit will ask for.

Enforcement is operational, not just financial

The AER can audit an operator's programme, order that a programme be implemented, and in serious cases require a facility to stop operating until compliance is achieved. Licence standing is exposed.

That shifts where this sits internally. A financial penalty is a matter for finance and legal; a shutdown order is a matter for operations and the executive. Operators that have briefed their leadership on the enforcement mechanism, rather than on the control list, generally get the programme resourced.


How this interacts with federal obligations

Pipeline operators may also be designated under the federal Critical Cyber Systems Protection Act, which adds incident reporting to the Communications Security Establishment and compliance with binding cyber security directions.

The two regimes overlap substantially on programme content. Build the programme once, against CSA Z246.1 with IEC 62443 and NIST SP 800-82 as supporting references, and map it to both sets of obligations rather than maintaining parallel documentation.


Where to start

Produce the OT asset inventory. Nothing else in the regulation — segmentation, patching decisions, monitoring, recovery testing — can be evidenced without it, and passive discovery on a control network will typically find equipment that no existing register lists.


What an AER audit will want to see

The regulation asks for a programme. An audit asks for evidence that the programme operates. Those are different artefacts, and operators who have only the first tend to fail on the second.

RequirementDocumentEvidence it runs
ProgrammeThe programme itself, with review datesMinutes or records of the review
Asset inventoryThe registerDiscovery output and a reconciliation date
SeparationNetwork architecture diagramFirewall rule review, tested boundary
Remote accessAccess policySession records and current account list
BackupsBackup designA restoration test report with a date and result
TrainingCurriculumAttendance records covering all personnel
Incident responseThe OT planAn exercise report, not just the plan

The right-hand column is where programmes fail. A backup design with no restoration test, or an incident plan never exercised, satisfies the paperwork and not the regulation. See backup testing and tabletop exercises.

GuardsArm assesses OT environments and builds programmes for Alberta energy operators. See Alberta Regulation 84/2024 services and OT and ICS security, or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.