
Industrial facility security essentials: Canada guide
By Michael Law · Industrial Real Estate Broker, Lennard Commercial Realty

TL;DR:
- Canadian industrial facilities must implement six core security controls, including a site-specific Threat and Risk Assessment and incident response plan, to establish a strong security baseline. Effective security design involves detailed threat analysis, perimeter hardening, access control, surveillance, and proper integration with safety procedures, while site selection and lease terms significantly influence long-term security costs and effectiveness. Regulatory compliance varies by sector, with mandatory breach reporting, security plans, and standards like CSA Z246.1:21, all requiring ongoing review and adaptation.
Every Canadian industrial facility needs six controls in place before anything else: a site-specific Threat and Risk Assessment (TRA), perimeter hardening, electronic access control, surveillance with monitored alarm response, operational technology (OT) network segmentation, and a documented incident response plan that satisfies applicable regulatory reporting timelines. Get those six right and you have a defensible baseline. Everything else builds on them.
Immediate actions for the initial days:
- Commission a site-specific TRA covering physical, insider, criminal, and cyber-physical threats
- Audit and repair perimeter fencing, lighting, and vehicle entry points
- Implement electronic badging and visitor management at all controlled entrances
- Segment OT/ICS networks from corporate IT and enforce multi-factor authentication (MFA) for any remote access
- Establish a written incident response plan with escalation contacts for local police, the RCMP, and the Canada Energy Regulator (CER) where applicable
- Confirm whether your site handles controlled goods or explosives and initiate the required security plan under the Controlled Goods Program or Natural Resources Canada
- Schedule a control-room or alarm-monitoring review to confirm SOPs are current
- Book a regulatory review against CSA Z246.1:21 if you operate in the petroleum or natural gas sector
TL;DR — Canadian mandatory items: Controlled Goods Program registrants must report security breaches within three days of discovery and maintain a site-specific security plan. Energy operators regulated by the CER must maintain a security management programme aligned with CSA Z246.1:21. Quick contacts: local police or RCMP for physical security incidents and suspicious activity; CER (cer-rec.gc.ca) for energy facility security concerns.
Table of Contents
- Why industrial security is different from commercial security
- How to run a TRA and build a site-specific security plan
- How do you design an effective industrial perimeter?
- What access control and contractor management actually require
- Surveillance, monitoring, and control-room operations
- Integrating security with safety, emergency preparedness, and incident response
- How should you protect OT and ICS systems from cyber-physical threats?
- Policies, training, maintenance, and periodic testing
- What are the key Canadian regulatory standards for industrial security?
- How do you choose a security integrator or vendor?
- How site selection and lease terms affect your long-term security costs
- Canadian vendors and solution categories: who does what
- What does a realistic security implementation timeline look like?
- Key takeaways
- Why the property decision is the security decision
- Security-aware site selection and lease advisory in the GTA
- Useful sources and further reading
- FAQ
Why industrial security is different from commercial security
A downtown office building and a Brampton distribution centre both need locks and cameras. The comparison stops there.
Industrial sites combine high-value assets, hazardous materials, and OT systems that control physical processes. A breach is not just a theft; it can trigger a safety incident, an environmental release, or a production shutdown that costs far more than whatever was stolen. That reality forces security to balance three things simultaneously: protecting people, protecting assets, and keeping operations running.
Several factors make industrial security genuinely harder than commercial security. Large yards with multiple vehicle entrances create perimeter lengths that are expensive to monitor continuously. Contractor churn means dozens of unfamiliar faces on site every week, each carrying tools and credentials that are difficult to verify in real time. Hazardous materials, including hydrocarbons, explosives, and industrial chemicals, raise the consequence of any breach from a property crime to a potential public safety event. And 24/7 operations mean there is no quiet period when security can be relaxed or systems taken offline for maintenance without careful coordination.
In the GTA specifically, proximity to emergency services varies sharply between a site in central Mississauga and one in a rural fringe area near Caledon or Barrie. Municipal response times, local zoning restrictions on fencing height and lighting intensity, and the density of neighbouring industrial users all influence what a realistic security design looks like. A site adjacent to a busy rail corridor or a major 400-series highway faces a different threat profile than a fenced campus in a single-tenant industrial park. Security design has to account for those local realities, not just generic best practice.
How to run a TRA and build a site-specific security plan
Start with a documented TRA. Every investment decision, every technology choice, and every policy flows from it. Without a TRA, you are guessing at priorities and almost certainly over-spending in some areas while leaving genuine gaps elsewhere.
The RCMP’s Operational Physical Security Guide is explicit: physical, procedural, and technological controls must be supported by a TRA that identifies vulnerabilities specific to your site. A generic template is not a TRA.
TRA steps:
- Threat identification — Consider insider threats, criminal activity (theft, vandalism, trespass), terrorism or extremism where applicable, and cyber-physical attacks targeting OT systems.
The TRA produces two deliverables: a risk register and a site-specific security plan. The security plan should cover physical controls, access procedures, surveillance architecture, incident response, and regulatory reporting obligations. Distribute it only to personnel who need it. Security plans are sensitive documents and should be reviewed at least annually and after any significant security incident.
Pro Tip: Include operations, HSE, and real-estate stakeholders in the TRA team from day one. The RCMP recommends multidisciplinary teams that include security officials, health and safety experts, and real property managers — because a control that blocks a fire exit or slows a forklift route will be bypassed the moment it creates a problem.
How do you design an effective industrial perimeter?
An effective perimeter combines passive hardening, deterrence, and active detection. Passive hardening means fencing, bollards, and vehicle barriers that physically stop or delay an intruder. Deterrence means lighting and signage that make a site look monitored and difficult to approach undetected. Active detection means sensors and cameras that alert your team when something is happening.
Perimeter design essentials:
- Install perimeter fencing appropriate to the threat level: chain-link with barbed wire for standard industrial sites, anti-climb or palisade fencing for higher-risk assets
- Use fibre-optic or accelerometer-based fence sensors to detect cutting or climbing attempts without excessive false positives from wind or wildlife
- Design controlled vehicle entrances with inspection bays that preserve logistics flow — a security checkpoint that backs up truck queues onto a public road creates its own operational and safety problem
- Install hostile vehicle mitigation (HVM) measures such as rated bollards or concrete barriers at pedestrian entrances and building facades where vehicle-borne threats are credible
- Light all perimeter zones to a minimum standard that supports camera performance at night; dark zones are where incidents happen
- Use perimeter analytics cameras with video analytics to flag loitering, fence approaches, or vehicle stops in restricted zones, and tune detection zones carefully to reduce nuisance alarms
For large yards, consider layered buffers: an outer perimeter that detects approach, an inner perimeter around the building or high-value asset cluster, and a tertiary control around the most sensitive areas such as server rooms, chemical storage, or explosives magazines. Sensor type matters by zone. Fence sensors work well along straight perimeter runs. Perimeter analytics cameras handle irregular yard areas and loading dock approaches. Microwave or infrared beam detectors suit narrow chokepoints. After your TRA, engage a specialist perimeter sensor integrator to design the detection layer — the technology choices depend on site geometry, vegetation, traffic patterns, and the specific threat scenarios your TRA identified.
Pro Tip: False alarms are the single biggest reason monitoring staff stop responding to alerts seriously. Budget for sensor calibration and a 30-day tuning period after installation before you go live with full alarm response protocols.

What access control and contractor management actually require
Combine electronic access control with strong personnel controls and contractor oversight. The technology is the easy part. The hard part is the process discipline that makes it work.
Access control checklist:
- Deploy credential-based badging (smart card or mobile credential) at all controlled entry points, including vehicle gates
- Implement visitor management with pre-registration, photo ID verification, and a site briefing before access is granted
- Apply two-person rules for access to sensitive areas such as server rooms, chemical stores, and explosives magazines
- Maintain a key control plan for any physical keys still in use, with a signed-out log and regular audits
- Conduct background screening for staff with access to controlled goods or explosives, as required under the Controlled Goods Program and Natural Resources Canada explosives licensing
Contractor management — four steps:
- Onboard every contractor through a formal site induction that covers emergency procedures, restricted zones, and reporting obligations before they set foot on site.
- Issue time-limited credentials that expire automatically at the end of the contract or work order period.
- Define work zones in the access control system so a contractor credentialled for the loading dock cannot badge into the server room.
- Assign a site supervisor or escort for contractors working in high-risk areas, and log their entry and exit times.
One area that gets overlooked in lease negotiations: your lease should specify that third-party vendors and contractors operating on the property must meet the tenant’s screening and access control requirements. If your landlord controls common-area access or shares the site with another tenant, that shared access arrangement is a security gap unless the lease addresses it explicitly. The site selection process matters here — a single-tenant fenced campus gives you full control; a multi-tenant park does not.
Surveillance, monitoring, and control-room operations
Cameras and analytics must be mission-designed. Coverage of choke points, asset clusters, and ingress routes with clear SOPs for monitoring and response is the baseline. A camera pointed at the wrong angle, or footage that nobody is watching, is not a security control.
System design essentials:
- Cover all perimeter entry points, loading docks, parking areas, and internal high-value zones with overlapping camera fields
- Select camera specifications (resolution, low-light performance, lens focal length) based on the specific detection task at each location, not a single spec across the site
- Set video retention periods to meet operational and legal requirements — a minimum of 30 days is common for industrial sites, though specific incidents may require longer preservation
- Comply with Canadian privacy law: post visible signage notifying individuals of video surveillance, limit camera coverage to areas where there is a legitimate security purpose, and restrict access to footage to authorised personnel
Control-room operations:
| Function | Requirement |
|---|---|
| Alarm triage | Written SOP with response priority levels and escalation contacts |
| Logging | Time-stamped audit trail of all alarms, responses, and access events |
| Escalation | Defined thresholds for escalating to site security, operations management, and local police or RCMP |
| Evidence handling | Chain-of-custody procedure for footage and access logs used in investigations |
| Shift handover | Documented handover checklist covering active alarms, open incidents, and system status |

Evidence handling deserves specific attention. When a security incident leads to a police investigation or regulatory inquiry, footage and access logs become evidence. Establish a chain-of-custody procedure before you need it: who can export footage, how it is stored, and how it is transferred to police or investigators without compromising integrity.
Integrating security with safety, emergency preparedness, and incident response
Security must be embedded in emergency preparedness and drill cycles. A security response that conflicts with an evacuation route, or a lockdown procedure that traps workers near a hazardous material release, is worse than no security response at all.
Integration checklist:
- Align security incident command with the site’s emergency response structure so there is one clear authority during a combined safety-security event
- Run joint training exercises with HSE at least annually, covering scenarios where a security incident triggers a safety response (intruder near chemical storage, vehicle incursion near a process unit)
- Map evacuation routes against security zone boundaries and resolve any conflicts before an emergency makes them apparent
- Pre-position hazardous material response information so that first responders arriving at a security incident have immediate access to site safety data
Sequencing drills and notifications:
- Conduct a tabletop exercise with security, HSE, and operations leadership to test the incident command structure before a live drill.
- Run a live drill that combines a security scenario with an emergency response activation, and debrief within 48 hours.
- Document post-incident review findings and assign corrective actions with owners and deadlines.
- Notify regulators within required timelines: controlled goods breaches within three days; CER-regulated facilities per their security management programme requirements.
Pro Tip: Pre-agree evidence-sharing and operational handover points with local fire, police, and RCMP before an incident. A memorandum of understanding or a pre-incident plan filed with the local fire department takes an hour to arrange and saves critical time when something actually happens.
How should you protect OT and ICS systems from cyber-physical threats?
Treat OT as a distinct, high-priority domain. Isolate it from corporate networks and enforce strict remote access controls. An OT compromise at an industrial facility is not a data breach — it is a potential loss of physical control over equipment, processes, or safety systems.
The Canadian Centre for Cyber Security is direct: OT and ICS components should be isolated from the internet and corporate networks using network zoning, with MFA and secure administrative workstations required wherever remote access cannot be eliminated.
Concrete OT controls:
- Segment OT networks from corporate IT using firewalls and defined security zones; air-gap where operationally feasible
- Enforce MFA for all remote administration sessions into OT environments
- Use dedicated, hardened administrative workstations for OT management — never manage OT systems from a general-purpose laptop connected to the corporate network
- Vet and document all remote maintenance processes, including third-party vendor access, with time-limited credentials and session logging
- Maintain OT-specific logging separate from IT logs, with offline backups that cannot be encrypted by ransomware affecting the corporate network
- Test manual control modes for critical functions at least annually so operators can maintain safe operations if digital controls are compromised
Develop an OT-specific incident response plan that covers detection, containment, recovery, and regulatory notification. The plan should name who has authority to isolate an OT segment during an active incident, because that decision has immediate operational consequences and cannot wait for a committee meeting.
Policies, training, maintenance, and periodic testing
Documented policies plus scheduled training and maintenance are the backbone of continuous security. Technology degrades, staff turn over, and threats evolve. Without a maintenance and testing cadence, a security programme that was effective on day one will have silent gaps within 18 months.
Maintenance schedule framework:
- Daily: Control-room staff verify alarm system status, review overnight access logs for anomalies, and confirm camera feeds are active.
- Monthly: Functional test of intrusion detection sensors, perimeter lighting, and access control readers at a sample of locations; document results.
- Quarterly: Full camera system audit including image quality, retention settings, and coverage gaps; review and update visitor and contractor access lists.
- Annually: Full TRA review, security plan update, refresher training for all staff with security responsibilities, and a tabletop or live exercise.
Training essentials:
- All staff: site security awareness, how to report suspicious activity, and what to do during a lockdown or evacuation
- Security and control-room staff: alarm triage SOPs, evidence handling, escalation procedures, and use of force policy where applicable
- Supervisors and managers: incident command roles, regulatory reporting obligations, and media/communications protocols during a security event
Pro Tip: Treat the security plan as a restricted document. Limit distribution to personnel who genuinely need it, number copies, and log who holds each copy. A security plan that circulates freely is a reconnaissance tool for anyone planning a breach.
The annual review is not optional. Canadian guidance calls for security plans to be living documents reviewed at least annually and after any security incident. If your site has had a significant change — new tenant, new process, new contractor population, or a nearby incident — trigger an unscheduled review rather than waiting for the calendar.
What are the key Canadian regulatory standards for industrial security?
The mandatory Canadian framework depends on your sector and the materials you handle. There is no single universal standard, but several obligations apply broadly.
Regulatory obligations by category:
- Controlled Goods Program (CGP): Registrants must develop a site-specific security plan and report potential security breaches within three days of discovery. The plan must cover access controls, personnel screening, and breach response procedures.
- Explosives licensing (Natural Resources Canada): Licence holders must submit a site-specific Security Plan that assesses threats, details protective measures, and specifies reporting and incident response procedures.
- CSA Z246.1:21: The mandated baseline for security management programmes in the petroleum and natural gas sector, covering design, construction, operation, and abandonment phases. Operators regulated by the CER must align their programmes with this standard.
- Canada Energy Regulator (CER): The CER inspects and audits regulated companies to confirm security management programmes are in place. Companies must identify risks and maintain prevention and response strategies. The CER provides contact options for reporting suspicious activity at energy facilities.
- Contract Security Program (CSP): Federal contractors handling classified or protected information must meet work-site security requirements set by Public Services and Procurement Canada, including physical security inspections.
When to escalate and to whom:
- Suspicious activity near a regulated energy facility: contact the CER and local police
- Theft or breach involving controlled goods: report to the CGP within three days and notify local police
- Explosives theft or loss: immediate notification to Natural Resources Canada and local police or RCMP
- Active physical security threat: local police first, RCMP for national security dimensions
Keep a regulatory contact sheet in your incident response plan and update it annually. Regulators change contact details; a stale phone number during an incident is a real problem.
How do you choose a security integrator or vendor?
Select vendors against capability, references, operational experience with industrial or energy assets, and post-installation support. A vendor who excels at retail loss prevention is not the right choice for a petrochemical facility.
Procurement checklist:
- Verified certifications relevant to the work (e.g., ASIS CPP for consultants, manufacturer certifications for system integrators)
- Documented references from industrial or energy sector clients in Canada, with contact details you can actually call
- Adequate insurance and clear liability terms covering both installation errors and ongoing system failures
- Service-level agreements (SLAs) that specify response times for critical system failures — “next business day” is not acceptable for a 24/7 monitored alarm system
- Spare parts availability and a documented maintenance offering for the system lifecycle
- For system vendors: a clear software update and patch management practice, including how OT-adjacent systems are updated without disrupting operations
Questions to include in your RFP:
- Provide three references from industrial clients in Canada where you installed a comparable system. May we contact them?
- What is your documented response time for a critical system failure at a 24/7 monitored site?
- How do you manage software updates for systems connected to or adjacent to OT networks?
- What is your process for handing over system documentation, as-built drawings, and credentials at project completion?
- Who holds the encryption keys and administrative credentials for the system after installation?
Red flags to watch for: no industrial references, vague or unwritten SLAs, inability to explain their software update practice, and any vendor who proposes a proprietary system with no documented migration path.
| Evaluation category | What to look for | Red flag |
|---|---|---|
| Certifications | ASIS CPP, manufacturer certs, relevant trade licences | No verifiable credentials |
| Industrial references | Named Canadian industrial clients, contactable | References only from commercial or retail sectors |
| OT experience | Documented OT-adjacent installations, network zoning knowledge | No OT experience, treats IT and OT as identical |
| SLA terms | Written, specific response times for critical failures | Verbal commitments only, “best efforts” language |
| Post-installation support | Maintenance contract, spare parts, update schedule | Project-only engagement, no ongoing support offered |
How site selection and lease terms affect your long-term security costs
Site selection and lease negotiation are security decisions. The property you choose today determines what security controls are feasible, how much they cost, and who pays for them for the duration of your occupancy.
Real-estate security checklist:
- Proximity to emergency services: a site more than 10 minutes from the nearest fire station or police detachment carries a higher consequence rating for any incident
- Shared access agreements: a shared truck court or common area entrance means your security perimeter depends on another tenant’s compliance
- Fencing responsibilities: confirm in the lease who is responsible for perimeter fencing maintenance and upgrades, and whether the landlord’s consent is required for security improvements
- Rooftop and yard control: confirm whether you have exclusive control of the roof (for antenna or camera mounting) and the yard (for lighting and barrier installation)
- Loading dock sightlines: a dock that cannot be observed from a control room or guard post is a persistent vulnerability
- Neighbour risk: an adjacent tenant handling hazardous materials or attracting high-value cargo theft activity raises your site’s threat profile
Pro Tip: Negotiate security-specific lease clauses before you sign. Include the landlord’s obligation to maintain common-area lighting and fencing, your right to install security upgrades without unreasonable consent delays, and a requirement that contractors working in common areas meet your site’s screening standards. These clauses cost nothing to negotiate and can save significant money and conflict later.
When evaluating GTA industrial properties, the difference between a single-tenant fenced campus in Vaughan and a multi-tenant park in Brampton is not just operational — it is a security architecture question. Shared yards increase coordination costs, shared entrances complicate access control, and a landlord who controls the perimeter gate controls your security posture. Planning industrial relocations in the GTA with security requirements as a primary filter, not an afterthought, consistently produces better outcomes and lower long-term costs.
Michael Law | Lennard Commercial works with occupiers across the GTA to evaluate sites against operational and security criteria before lease execution, not after.
Canadian vendors and solution categories: who does what
Use vendor categories, not endorsements. The right vendor depends on your TRA findings, your site type, and the specific gap you are filling.
Vendor categories and engagement triggers:
- Guard and monitoring services: — for 24/7 control-room monitoring, mobile patrol, and on-site guard services, GardaWorld and Securitas Canada both operate nationally with industrial sector programmes. Engage them when your TRA identifies a need for human response capability that technology alone cannot provide.
- OT/ICS security consultants: — engage after a TRA identifies OT risk or following a cyber-physical incident. These are specialists distinct from general IT security firms — confirm they have documented OT experience in your sector.
When to call authorities:
Pro Tip: A ULC-listed central monitoring station is not optional for insured industrial facilities in Canada — most commercial property insurers require it as a condition of coverage. Confirm your monitoring provider’s ULC listing before you assume your alarm system satisfies your insurance policy.
What does a realistic security implementation timeline look like?
A realistic implementation runs in five phases. The timeline varies by site size and complexity, but the phase sequence is consistent.
Implementation phases:
- Assessment (weeks 1–6): TRA, site survey, regulatory review, and gap analysis against applicable standards. Deliverable: risk register and security plan draft.
- Design (weeks 4–10): System architecture, vendor RFP, and design drawings. Overlaps with assessment to compress the schedule.
- Procurement (weeks 8–16): Tender, vendor selection, contract execution, and equipment lead times. Long-lead items (rated bollards, specialised sensors) can extend this phase.
- Installation and civil works (weeks 12–28): Fencing, cabling, camera and sensor mounting, access control hardware, and control-room fit-out. Civil works for vehicle barriers or inspection bays are typically the critical path.
- Commissioning and training (weeks 24–32): System integration testing, alarm tuning, staff training, and handover. Do not compress this phase — a poorly tuned system generates false alarms that undermine the entire programme.
Typical durations by site size:
- Small industrial site (under 50,000 sq ft, single tenant, standard threat): 4–6 months from TRA to commissioning
- Medium site (50,000–200,000 sq ft, moderate complexity, some OT): 6–10 months
- Large or high-criticality site (over 200,000 sq ft, OT integration, energy or controlled goods): 10–18 months
Primary cost drivers:
- OT integration complexity: connecting security systems to OT networks without introducing new vulnerabilities requires specialist engineering and adds cost
- Site civil works: trenching for cable runs, concrete for barriers, and fencing upgrades are often the largest single cost item on a retrofit
- Sensor density: perimeter sensor coverage per linear metre is a direct cost multiplier; TRA findings should drive density decisions, not a uniform specification
- Control-room staffing: 24/7 human monitoring is a recurring operating cost that often exceeds the capital cost of the technology within three years
- Recurring monitoring fees: ULC-listed central station monitoring, software licences, and maintenance contracts are ongoing costs that should be modelled over the full lease term
Lease terms affect schedule directly. If your landlord’s consent is required for civil works, budget four to eight weeks for approval. If the site is occupied during installation, coordinate work windows with operations to avoid disrupting production or creating safety hazards.
Key takeaways
A site-specific TRA is the non-negotiable starting point for every Canadian industrial security programme — it drives all investment, prioritisation, and regulatory compliance decisions.
| Point | Details |
|---|---|
| TRA drives everything | Commission a documented TRA before spending on technology; it determines what controls are actually needed. |
| OT isolation is urgent | Segment OT/ICS from corporate networks and enforce MFA for remote access — a compromise here is an operational emergency, not just a data breach. |
| Canadian compliance is sector-specific | Controlled goods registrants report breaches within three days; energy operators align with CSA Z246.1:21; explosives sites submit a site-specific Security Plan to Natural Resources Canada. |
| Maintenance and testing sustain effectiveness | Annual TRA reviews, monthly sensor tests, and quarterly camera audits prevent silent degradation of security controls over time. |
| Michael Law | Lennard Commercial |
Why the property decision is the security decision
The conventional wisdom in industrial security focuses almost entirely on technology: cameras, sensors, access control systems. That is understandable. Technology is visible, measurable, and easy to budget. What gets far less attention is the upstream decision that determines whether any of that technology can actually work: the property itself.
A site with a shared truck court, a landlord-controlled perimeter gate, and a lease that requires consent for any structural modification is a security problem before a single camera is installed. The tenant who signs that lease and then tries to build a serious security programme will spend more, achieve less, and fight their landlord for the duration of their occupancy. Conversely, a single-tenant fenced campus with a lease that assigns fencing maintenance to the landlord and grants the tenant unrestricted rights to install security infrastructure is a fundamentally different starting position.
This is not a theoretical concern. In the GTA’s tight industrial market, tenants are often under pressure to move quickly and accept lease terms that were not designed with security in mind. The loading dock that cannot be observed from the guard post, the shared entrance that a neighbouring tenant props open, the rooftop that the landlord controls — these are not problems you solve with a better camera. They are problems you negotiate out of before you sign, or live with for the term of your lease.
The sites that carry persistent perimeter risk — high-visibility locations on arterial roads, properties adjacent to rail corridors, multi-tenant parks with open yards — are not necessarily bad choices. But they require a different security design and a higher ongoing cost. Knowing that before you commit is the difference between a security programme that fits your budget and one that perpetually exceeds it.
For GTA occupiers with security as a material requirement, the Toronto industrial market offers options across a wide range of configurations. The work is in identifying which ones actually support the security posture your operations require.
Security-aware site selection and lease advisory in the GTA
Michael Law | Lennard Commercial works with industrial occupiers across the GTA who need more than a floor plan and a rental rate. For tenants where security is a material operational requirement — controlled goods handlers, logistics operators, manufacturers with sensitive processes, cold storage facilities — the site selection and lease negotiation process needs to account for perimeter control, shared access arrangements, landlord consent rights, and the long-term cost of security upgrades.

The practical difference: evaluating a shortlist of properties against a security checklist before offers are made, negotiating lease clauses that protect your right to install and upgrade security infrastructure, and flagging shared-site arrangements that will complicate your access control programme. That work happens at the front end of a transaction, where it costs nothing extra and changes the outcome significantly.
If you are selecting a new facility, renewing a lease, or evaluating a portfolio of GTA industrial properties with security requirements in mind, connect with Michael Law | Lennard Commercial to discuss your site criteria.
Useful sources and further reading
The following Canadian primary sources should be your first stop for regulatory guidance. Keep the links current in your security plan and assign someone to check for updates annually.
- Controlled Goods Program — Security Plan Guideline — mandatory reading for any site handling controlled goods; covers plan requirements, breach reporting timelines, and distribution controls.
- Natural Resources Canada — Explosives Security Plan Guideline: required for explosives licence holders; details the components of a compliant site-specific Security Plan.
- CSA Z246.1:21 — Security Management for Petroleum and Natural Gas Industry Systems: the baseline standard for energy sector security management programmes; purchase through CSA Group.
- RCMP Operational Physical Security Guide (GCPSG-010-2022) — the federal government’s primary reference for TRA methodology, multidisciplinary security teams, and physical security control selection.
- Canadian Centre for Cyber Security — Security Considerations for Critical Infrastructure (ITSAP.10.100) — OT/ICS isolation guidance, MFA requirements, and incident response planning for cyber-physical threats.
Which source to consult by topic:
Keep your security plan restricted, numbered, and logged. Schedule the next annual review before you close this one.
FAQ
What is a Threat and Risk Assessment (TRA) for an industrial facility?
A TRA is a structured analysis that identifies assets, threats, vulnerabilities, and consequences specific to your site, then ranks risks to drive investment and control decisions. The RCMP’s Operational Physical Security Guide sets out the methodology Canadian federal facilities use, and it applies equally well to private industrial sites.
Which Canadian regulations apply to industrial facility security?
The applicable rules depend on your sector: Controlled Goods Program registrants must maintain a site security plan and report breaches within three days; explosives licence holders must submit a site-specific Security Plan to Natural Resources Canada; petroleum and natural gas operators must align with CSA Z246.1:21 under CER oversight.
How often should an industrial security plan be reviewed?
At minimum annually, and after any significant security incident or material change to the site, operations, or threat environment. Canadian guidance treats the security plan as a living document, not a one-time submission.
What OT security controls does the Canadian Centre for Cyber Security recommend?
The Canadian Centre for Cyber Security recommends isolating OT and ICS systems from corporate networks and the internet using network zoning, enforcing MFA for any remote access, using dedicated administrative workstations, and maintaining OT-specific incident response plans with offline backups.
How does site selection affect industrial security costs in the GTA?
The property configuration, lease terms, and shared-access arrangements you accept at signing directly determine what security controls are feasible and who pays for them. Single-tenant fenced campuses with unrestricted upgrade rights cost less to secure over a lease term than multi-tenant parks with shared entrances and landlord consent requirements for structural changes.
Recommended
About Michael Law
Managing Partner and Industrial Real Estate Broker at Lennard Commercial Realty. Representing tenants and landlords across Toronto and the GTA for 15+ years. Michael specializes in GTA industrial real estate — connect with Toronto's leading industrial broker at mlawrealestate.com/industrial-broker-toronto.


