Your report mentions the multifactor authentication and industry best practices, which you just discussed right now. As you also discussed, the CRA was unable to provide details of every confirmed breach that it had reported, due to limitations of the tracking system—I'm reading that from the report. Also, somehow, attackers were successful in bypassing the authentication process to access...and the CRA was not able to explain that.
It's not just that there's a problem. They don't even know how to fix the problem. The Liberals frequently lecture Canadians about misinformation, cybersecurity and digital trust. What message does this send to Canadians about the federal government's own competence at protecting sensitive data?
