Thank you.
Good morning, Mr. Chair and members of the committee.
Thank you for inviting me to appear today to discuss the Auditor General of Canada’s report on the Cyber Security of Government Networks and Systems.
As mentioned, my name is Caroline Xavier, and I am the chief of the Communications Security Establishment, also known as CSE.
I'm joined today by Rajiv Gupta, head of the Canadian centre for cybersecurity, also known as the cyber centre, which forms an integral part of CSE.
We are pleased to appear alongside our colleagues from the Treasury Board Secretariat and Shared Services Canada, with whom we work closely on cybersecurity.
Today I will provide a brief overview of CSE and our cyber centre, and then share how we are responding to an increasingly complex threat landscape, one that includes cyber-threats, risks to economic security, violent extremism, foreign interference, disinformation campaigns and more.
Before we begin, I want to acknowledge that we are on the traditional unceded territory of the Algonquin Anishinabe nation. We acknowledge that this nation has been on this land since time immemorial.
CSE is one of Canada’s key security and intelligence agencies, and a stand-alone agency reporting to the Minister of National Defence.
As part of our mission, we provide vital foreign signals intelligence on a wide range of threats to help the Government of Canada make informed decisions and safeguard Canada's interests, while strictly following Canadian law and privacy standards. We also defend Government of Canada networks and systems of national importance against malicious cyber activity targeting Canada's digital infrastructure.
Through the cyber centre, we serve as the national and technical authority for cybersecurity, providing a single, trusted source of expert advice and guidance for Canadians and organizations across the country. By integrating cybersecurity, signals intelligence and foreign cyber-operations, CSE is uniquely positioned to strengthen Canada's overall defence and security.
The integrity of Canada's cyberspace is foundational to our country's future. It underpins our digital economy, protects personal safety, and strengthens national resilience.
In 2024-25, CSE produced more than 3,300 foreign intelligence reports and responded to over 2,500 cyber-incidents affecting federal institutions and critical infrastructure partners. We also issued over 330 pre-ransomware notifications to more than 300 Canadian organizations, early warnings that helped prevent serious harm.
As the threat landscape evolves, so do we. Our world-recognized cyber-defence sensors program provides real-time detection of malicious cyber activity across Government of Canada networks and cloud environments. This program is available to all federal departments and agencies, and to Crown corporations upon request. It enables our experts to block and neutralize threats before they cause harm.
While many federal organizations manage their own IT infrastructure, they can leverage CSE's sensors program and the cyber centre's expert guidance to strengthen their defences. Today, most federal institutions use at least one of our sensors. We also continue to deepen our engagement with Crown corporations, critical infrastructure operators, and provincial and territorial partners.
CSE welcomes the Auditor General's report and supports its recommendations, particularly those aimed at strengthening sensor deployment and improving incident management coordination. As my colleagues have highlighted, we are working closely together to expand the deployment of cyber-defence sensors across federal networks and refine incident response protocols.
These efforts build on significant progress already made to modernize and secure the digital systems that deliver essential services for Canadians. Cybersecurity is a shared responsibility, and collaboration remains at the heart of our approach.
Mr. Chair and members of the committee, the threat environment is dynamic, but our commitment is unwavering. Together with our partners, we will continue to protect Government of Canada systems, Canada’s critical infrastructure and digital systems, ensuring Canadians can rely on secure and trusted services.
Thank you once again for the opportunity to appear before this committee.
We welcome your questions and look forward to continued dialogue.
Thank you.
