Who's required to use these sensors is a question of policy. The defence sensors are really strong and have proven to be effective. I think what's important is that it's not the only layer of defence. The sensors are a layer you put on top of the cyber-defences you already have.
Out of the 119 organizations that don't have to use it, you're right that about 64% of them are. They've opted in and seen the value.
One of the gaps that we've highlighted is exactly this. Having this fragmented approach to cyber-defences puts the government somewhat at risk. Any good cyber-defence is about having as many people as possible feeding it. If everyone reports potential phishing attacks, all you're doing is improving and bolstering the defences. If the whole federal family partook in it, we would improve the defences of the Government of Canada's networks and systems.
