System Brief // NA-ONE-NETWORK-TWO-CLOCKS-2026-09-27
One Network. Two Clocks.
Desmond Otieno Odhiambo · ClearGlass Intelligence · Burlington, Ontario · 27 September 2026
North America is already one attack surface. Most companies still run two security programs taped together. Identity, SaaS, and AI agents ignore the border. Regulation does not.
Most Canada–US operators do not have a North American security program. They have a Canadian policy binder, a US contract appendix, a shared Microsoft tenant, and an incident channel that starts with “who do we call first?”
ClearGlassInc’s position is simple: treat Canada and the United States as one technical estate with two legal clocks. Design the estate so you can answer four questions under pressure, in either jurisdiction.
- What changed?
- Who changed it?
- Where did the data sit when it changed?
- Which reporting clock started, and at what time?
If those answers live in screenshots and memory, you do not have a program. You have a hope.
The real problem is not more compliance
Mapping NIST to CIS to CMMC to CPCSC is necessary. It is not the work. The work is that the production system is already transnational, while the evidence system is still national.
Canada now has a real federal cyber statute. Bill C-8 received Royal Assent in mid-June 2026. Part 1 amended the Telecommunications Act immediately. Part 2 enacted the Critical Cyber Systems Protection Act. Designated-operator duties wait on in-force orders. Build evidence before a designation order compresses the clock.
US reporting clocks are already written. CIRCIA requires covered entities to report substantial incidents to CISA within 72 hours and ransomware payments within 24 hours. CISA targeted a September 2026 final rule after earlier misses. As of 27 September 2026, treat CISA.gov/CIRCIA and the Federal Register as the live source.
Add PIPEDA accountability for cross-border processing, Quebec Law 25, Ontario PHIPA, CPCSC Canadian storage for safeguarded defence contract data, and a CMMC program that suspended Phase II third-party certification on 13 July 2026 while leaving NIST SP 800-171 / DFARS 252.204-7012 obligations in force.
Canada still has no comprehensive federal AI statute. Bill C-27, including AIDA, died at prorogation in January 2025. Waiting for a Canadian AI Act is not a control.
What North American means in production
| Shape | What it looks like | Where programs break |
|---|---|---|
| Canadian operator, US customers | Ontario company on Microsoft 365 and US-east cloud | PIPEDA comparable-protection and foreign-access notice; vendor AI training clauses |
| US operator, Canadian users | US SaaS with a Toronto office or Canadian user base | PIPEDA applies to Canadian personal information even if the company thinks it is US-only |
| Dual-entity group | Two legal entities, one identity plane | Contracts say segregation; Entra groups and admin roles say otherwise |
| Defence or critical-systems supplier | Canadian shop in a US prime supply chain, or the reverse | CPCSC residency versus CMMC portability; CLOUD Act residual risk |
Four planes, one evidence chain
1. Identity plane
Most board-level incidents in this region still start with identity. For a Canada–US estate, identity work is not “turn on MFA.” It is one source of truth for workforce, vendors, and agents; privileged roles treated as production systems; Conditional Access that encodes where and why; joiner-mover-leaver automation; and written rules for non-human identities.
If you cannot list every account that can move Canadian personal information into a US model or ticket queue, you do not have cross-border control. See Services & Engagements.
2. Residency and transfer plane
PIPEDA does not ban US processing. It keeps the Canadian organization accountable for comparable protection. CPCSC, unlike CMMC, has been described as requiring safeguarded contract data to stay in Canada. The operating requirement is a living data-flow map: systems, regions, subprocessors, AI tools, training clauses, and support-access paths.
3. Autonomy plane
In a dual-jurisdiction company, an ungoverned agent is a cross-border disclosure device with a friendly UI. Inventory models and agents. Bound data classes and tools. Require human approval for external send, privilege change, production deploy, and legal filing. Retain prompts, outputs, and tool calls as business records. See Artemis 2040.
4. Incident and evidence plane
| Clock | Trigger | Destination |
|---|---|---|
| PIPEDA | Real risk of significant harm | OPC + individuals, as soon as feasible |
| CCSPA | When designated and in force | CSE + sector regulator |
| CIRCIA | When final and applicable | CISA 72 hours / 24 hours for payment |
Companion pieces: You Do Not Have a North American Security Program · Dual-clock runbook · CPCSC vs CMMC.
What good looks like in 90 days
Days 1–15 — Estate truth. Inventory identity, data classes, AI tools, regions, and decision-makers.
Days 16–45 — Reduce obvious exposure. Harden Entra ID and Windows. Kill standing privilege. Close orphaned guests. Brake AI tools that see client data. Write the dual-clock ledger.
Days 46–90 — Make it replayable. Logging that survives the incident. A residency register legal and engineering both accept. One cross-border identity tabletop. A board paper in plain language.
What to do this week
- Start with a read-only Security Quick-Audit (CAD $249).
- If the estate is a Microsoft problem, use the M365 + Windows Hardening Sprint (from CAD $2,500).
- For the operating-model conversation, see pricing and engagements.
The border is a legal fact. It is not a network boundary. Design accordingly.