Good morning, Mr. Chair.
Thank you for the opportunity to appear before the committee today to discuss our report on cybersecurity of government networks and systems, which was tabled on October 21, 2025.
I’d like to begin by recognizing that we are meeting on the traditional, unceded territory of the Algonquin Anishinabe people.
With me today is Jean Goulet, the principal director who was responsible for the audit.
The central responsibility for protecting government information technology systems and operations is shared by the Treasury Board of Canada Secretariat, Communications Security Establishment Canada, and Shared Services Canada. These organizations work together and with departments and agencies to prevent data theft and limit disruptions to systems that deliver programs and services to Canadians. We found that while the government had tools in place to protect and defend its networks and systems against cyber-threats, there were gaps in cybersecurity defence services, monitoring and response during active attacks.
Only 42% of federal organizations are required, by Treasury Board policy, to use the cybersecurity defence services offered by Shared Services and the Communications Security Establishment. Others have opted in, but this inconsistent use of services undermines the federal government’s ability to protect critical information and manage risks.
We also found that coordination among the three organizations was too slow during active cyber-attacks. For example, poor coordination delayed the government's response during a major attack two years ago. This extended the time during which the attacker had access to public servants' personal information.
Protecting federal networks and systems also requires analyzing the potential vulnerabilities of all government IT devices, including laptops, smart phones, and servers. We found that Shared Services and the Communications Security Establishment did not have a comprehensive inventory of all government devices. Without up-to-date information, the federal government risks being unable to quickly respond to a changing cybersecurity landscape.
Malicious actions, external events, and attacks targeting the Canadian government’s digital systems are frequent and more sophisticated. A coordinated and comprehensive approach to the government’s cybersecurity posture, better collaboration and a current inventory of IT devices are key to safeguarding Canadians’ information.
Mr. Chair, this concludes my opening remarks. We would be pleased to answer any questions the committee may have.
Thank you.
