Action Item 9. Examine ways to improve the collection and analysis of suspicious cybercrime incidents involving Canada’s critical infrastructure and other vital cyber systems. Links to operational framework: P1; O1; O2; O3; E3; E5 Sucess Indicators Planned Timeline Ongoing. - Improve the collection and analysis of suspicious and possibly criminal cyber incidents occurring at critical infrastructure facilities and other vital cyber operations in Canada. - Engage Canada’s critical infrastructure and vital cyber systems community to inform of suspected cybercrime threats and ways to address them. Description: Cybercrime poses serious threats to Canada’s critical infrastructure and other vital cyber systems, such as those in energy, telecommunications and financial sectors. Critical infrastructure systems may include Internet-facing components, potentially leaving them vulnerable to malicious software and other cybercrime threats. The impact of these threats to critical infrastructure and other vital cyber systems may vary, ranging from industrial espionage, to data extraction and theft of intellectual property or trade secrets, to more disruptive tactics involving system compromises. These threats are growing in sophistication and volume, and require greater collaboration between law enforcement and other public and private sector stakeholders. To address this requirement, the RCMP will examine ways to improve its collection and analysis of suspicious cybercrime incidents involving Canada’s critical infrastructure and other vital cyber systems. This initiative will consider the RCMP National Critical Infrastructure Team (NCIT) and its analysis of cybercrime threats to critical infrastructure and other vital cyber systems. This initiative will also involve law enforcement collaboration with Canada’s critical infrastructure community, such as the National Cross Sector Forum and sector-specific briefings. Notably, the NCIT examines physical and cyber threats to Canada’s critical infrastructure, and collaborates with law enforcement, public and private sector stakeholders to ensure a common understanding of the criminal threats and risks surrounding Canada’s critical infrastructure, including those in the cyber realm. Ongoing. 10. Improve the intake and triage - Improve ability to obtain and of reported cybercrime incidents. disseminate information on cybercrime incidents to operational areas. Links to operational framework: - Improve situational awareness on suspected cybercrime activity in P1; O1; O2; O3; E3; E5 Canada. Description: The RCMP anticipates that domestic and international cybercrime incidents will require a greater ability to intake and triage requests for law enforcement assistance, improve situational awareness on cybercrime activities in Canada and disseminate information on cybercrime incidents to RCMP jurisdictions and other Canadian police services. To address this requirement, the RCMP will examine ways to improve its intake and triage functions for reported incidents of suspected cybercrime activities. This initiative will focus on examining RCMP operational areas that facilitate intake and triage functions for domestic criminal investigations and foreign law enforcement requests for assistance, including the RCMP Federal Policing Operational Information Management Intake Unit and INTERPOL Ottawa. 16 Royal Canadian Mounted Police Cybercrime Strategy

Select target paragraph3