What comes first when cybersecurity never ends?

Rob Antonishen, director of cybersecurity and compliance at B.C. Hydro, outlines how the utility manages cyber risk amid legacy systems and regulatory demands. He prioritizes protection for the most exposed assets, integrates security into operational technology design, and emphasizes storytelling…

When asked what a typical week looks like for B.C. Hydro’s cybersecurity team, Rob Antonishen, the director of cybersecurity and compliance, says it’s a mix of meetings and emails. The bulk of those meetings focus on deciding which cyber risks the utility can accept and which must be mitigated immediately. With many of B.C. Hydro’s systems older than 30 years, not every legacy platform can be upgraded to meet modern security best practices, so Antonishen and his team must choose where to apply the most stringent controls first.

Legacy Systems and Regulatory Pressure

B.C. Hydro operates under a mandatory cybersecurity framework that applies to all North American power systems. The framework, which became permanent on January 1 2026 after a two‑year pilot, sets a baseline of requirements that the utility must meet. Antonishen stresses that compliance is a starting point, not the ceiling, for cybersecurity. “These regulatory requirements are the low bar,” he says. “They are not the ceiling when it comes to cybersecurity controls.”

In a recent session with one of the utility’s operational technology (OT) groups, Antonishen emphasized that meeting the minimum standards is only the beginning of the job. The real challenge lies in deciding which legacy systems—some dating back more than three decades—need the most robust protection. The most critical and exposed assets are prioritized, while systems that already have adequate controls can tolerate a higher level of risk.

Integrating Security into OT Design

Antonishen, a licensed professional engineer, is pushing for cybersecurity to be embedded in OT design from the outset. Traditionally, OT design has focused on reliability and safety, with engineers building systems to withstand equipment failures and extreme weather. “We have to design our systems to deal with somebody with malicious intent,” he says. The Canadian Centre for Cyber Security’s guidance on protecting OT highlights that personal safety and process reliability should precede data security in design considerations.

Recent incidents, such as a water facility where an attacker tampered with pressure values, illustrate why OT must account for intentional sabotage. The federal government’s alerts warn that any control system exposed to the internet becomes a potential target. By integrating security controls early, B.C. Hydro aims to reduce the attack surface and prevent disruptions that could affect communities.

Adapting to an Evolving Threat Landscape

For years, B.C. Hydro maintained a heightened state of cyber alert, driven by global events such as wars, ransomware campaigns, and the rapid evolution of attack techniques. Antonishen notes that the organization no longer expects the threat level to decline. Instead, the precautions that were once considered extraordinary have become part of the baseline operations.

Artificial intelligence has added a new dimension to the threat environment. Attackers now use AI to discover vulnerabilities and adapt their tactics in real time. “They can react to what your security controls are doing. They can pivot. They can shift,” Antonishen explains. To keep pace, B.C. Hydro employs AI‑powered security tools that sift through vast amounts of data to flag genuine threats, helping the team focus on high‑impact incidents.

Communicating Risk to the Board

Board members are more interested in the business impact of cyber incidents than in technical metrics. Antonishen therefore tailors his communication to highlight how security actions protect customer trust and business continuity. A recent example involved the takedown of fake B.C. Hydro billing sites. While the technical team viewed the operation as routine, Antonishen presented it to the board as a safeguard that maintained customer confidence.

Effective storytelling—using narratives and analogies—helps bridge the gap between technical teams and executive leadership. By framing cybersecurity achievements in terms of business outcomes, the director ensures that board members understand the value of proactive security investments.

Supporting Staff Well‑Being

The workload in cybersecurity is relentless, with threats coming from technology, geopolitics, vendor relationships, and supply chain risk. Antonishen acknowledges that the field attracts individuals who are driven to finish the job, but he also stresses the importance of preventing burnout. The team regularly checks in on staff mental health, encourages time off, and monitors for signs of overwork.

Antonishen’s own experience with burnout—stemming from overwork—has made him particularly vigilant about protecting his team’s well‑being. “I can’t afford for them to wear themselves out,” he says. By fostering an environment that values balance, B.C. Hydro hopes to retain talent and maintain operational resilience.

What’s Next for B.C. Hydro?

As the utility continues to modernize its infrastructure, the focus will remain on prioritizing protection for the most vulnerable systems while integrating security into new OT designs. The evolving threat landscape, especially the rise of AI‑driven attacks, will keep the cybersecurity team on its toes. Meanwhile, Antonishen will continue to translate technical safeguards into business‑relevant narratives for the board, ensuring that cybersecurity remains a strategic priority rather than a compliance checkbox.

With the 2026 Canadian CIO Awards announced for October 1 in Toronto, Antonishen’s work as a finalist for CISO of the Year underscores the critical role of cybersecurity leadership in today’s power sector.

Why it matters

B.C. Hydro’s approach illustrates how utilities with aging infrastructure can balance regulatory compliance, risk prioritization, and staff well‑being while adapting to an evolving cyber threat landscape.

Key points

  • Legacy systems require selective protection, not blanket upgrades
  • Compliance sets a minimum bar; real security goes beyond it
  • Security must be built into OT design from the start
  • AI is reshaping both attack tactics and defense tools
  • Effective communication turns technical work into business value
  • Staff well‑being is essential to sustain long‑term cybersecurity efforts

Frequently asked questions

What does B.C. Hydro’s cybersecurity framework require?

The framework mandates compliance with North American power system cybersecurity standards and the B.C. Utilities Commission’s permanent cybersecurity framework for public utilities.

How does B.C. Hydro prioritize which systems to protect?

They assess exposure and criticality, focusing first on the most vulnerable and essential assets while allowing higher risk tolerance for systems already protected by other controls.

Why is AI important in B.C. Hydro’s security strategy?

AI helps filter noise, identify real threats, and adapt to evolving attack patterns, enabling the team to focus on high‑impact incidents.

Reporting drawn from

More from World

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com