Evidence of meeting #22 for Public Accounts in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was cyber.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Hayes  Deputy Auditor General, Office of the Auditor General
Rochon  Chief Information Officer of Canada, Treasury Board Secretariat
Jones  President, Shared Services Canada
Xavier  Chief, Communications Security Establishment
Tea-Duncan  Chief Information Security Officer of the Government of Canada, Treasury Board Secretariat
Goulet  Principal, Office of the Auditor General
Gupta  Head, Canadian Centre for Cyber Security, Communications Security Establishment

Noon

Conservative

The Chair Conservative John Williamson

Up next is Ms. Tesser Derksen. You have the floor for five minutes, please.

Noon

Liberal

Kristina Tesser Derksen Liberal Milton East—Halton Hills South, ON

Thank you so much, Mr. Chair.

Welcome, everyone. It's great to be back.

I certainly take my colleagues' concerns to heart with respect to trade agreements with foreign countries. I know it's not anything new. I know the Conservative government back in 2014 under Stephen Harper negotiated the FIPA with China without any public debate, and quite quietly and efficiently.

It's something that's been brewing for a long time. It's something we have to keep our minds to if we're going to diversify our trade. It's something that I'm glad we have a team like you in place to help guide us through.

Getting back to the report, I want to note the staggering numbers. That's really what caught my eye at the start. We're talking about trillions of different interactions from a cybersecurity perspective. I want to maybe have you comment on the levels of threat, because I know not all of them are actual attacks. I presume many of them are innocuous, not to make light of cybersecurity threats. Could one of you—whoever feels best placed to answer—just comment on the hierarchy of characterization of the threats? There are incidents, events and then attacks.

Noon

Head, Canadian Centre for Cyber Security, Communications Security Establishment

Rajiv Gupta

Sure, I can begin.

The internet “weather” is active. You're being hit non-stop by reconnaissance. This is basically the equivalent of people coming by and wiggling your doorknobs and trying your windows. That is happening non-stop—millions of times a second. That's just so you're aware of that. Mr. Jones talked about some of the protections in terms of blocking that initial set of reconnaissance, as we call it—basically those doorknob turnings or window checks. Those are happening non-stop, so those blocks happen. Those are in the trillions.

There are the protections that we have in terms of known threats. For anything that we know about that's a threat, we actually put in blocks to try to block those things from happening. That gets into billions of blocks, as well.

Then there will be other threats that actually get through. They run through analytics. We start to find out that this thing plus this thing plus this thing makes it look suspicious and worrisome. What do we have to do with that? Then you're into tens of thousands. Some of that is actually handled by automated analytics that block things as we're sleeping, 24-7.

Within our security operations centre, which is tier two for the Government of Canada, we're looking at close to 180 different departments. From all of that automated machinery that's happening and blocking millions of things a day, we get down to maybe a few hundred alerts that actually have to be looked at by humans. We look at those and triage them. Then, every single day, if we look at 1,100 incidents for the Government of Canada, we have about six or seven of those that turn legit.

Every single day, we're actually working on real, legit incidents with our partners here, as a team. When you say that cybersecurity is a team sport.... We see each other too often—weekends, evenings, all the time. Every single day, there are about six or seven things that we're actively chasing that become legit incidents. They are typically mitigated, but sometimes they go further than others and we have to work hard together to be able to prevent them.

12:05 p.m.

President, Shared Services Canada

Scott Jones

Perhaps I could just jump onto what Rajiv said.

We're not used to calling each other “Mr.” and “Ms.”, because we've worked together so closely for the last 20 years.

Pat can talk about this in a little more detail, but there isn't a minute that goes by when there's not a government department under a denial-of-service attack. Pat's team right now will be mitigating that with our automated defences. You almost never notice them because of the defences and what we've layered in.

As we go through, this is where we talk about the best available commercial defences. Shared Services Canada is responsible for deploying that, making sure we maintain that, keeping it up to date and continually modernizing the commercial side of things. When it gets past those—there are threat actors that are able to get past that—that's when we turn to our colleagues at the Canadian centre for cybersecurity and the Communications Security Establishment.

That's what I would say is the “secret sauce” of the Government of Canada. It's the fact that we have this continuum. It is not separate things. It goes together. I think one of the key points in the Auditor General's report is that you bring this together and you bring a comprehensive approach to cybersecurity. Not a minute goes by when we are not suffering some sort of denial-of-service attack from all around the world.

Kristina Tesser Derksen Liberal Milton East—Halton Hills South, ON

Thank you so much. You're quite right. I noted that in the Auditor General's report, the strategy was found to be “sound and comprehensive”. Congratulations on that.

I believe, though, that the critique from the Auditor General is that we have these tools and systems in place, but the uptake from all organizations is not 100%. I want to move into a question surrounding that.

Are there policy obstacles to these departments taking advantage of these tools? Is it a logistical issue? I know there might be a perception that it might infringe on the independence of a particular agency. Could you comment a little more on that? How can we resolve that issue?

12:05 p.m.

President, Shared Services Canada

Scott Jones

Absolutely. Thank you for the question.

I think the first thing is that the Shared Services Canada mandate is specified in an order in council. There are 44 departments that must use our service, particularly on connectivity. That is then optionally provided to a number of other entities, including, if they wish, Crown corporations and others.

As you rightly noted, there are organizations that have opted out, for independence. Primarily, if you look at the judicial branch.... The parliamentary branch has also opted out of Shared Services Canada, for reasons of independence, as you pointed out. They've done other things to compensate for that, but those were the primary things.

Many departments have chosen not to come with SSC. There are a few reasons. Number one is that it does cost more. If you're just going to run standard, commercial Internet access, the commercial defences we've layered on cost money. If you run without those, you're running at risk, but you've made a choice. You might not be able to afford it. That's what the investment in the small departments and agencies is seeking to overcome. It's funding so that they can come on to the sensors that they couldn't have afforded without that type of thing.

It is not a mandatory service. It is an optional service for most departments and agencies that they get to make a choice about. My department works on cost recovery, so they have to be able to pay the bill.

12:05 p.m.

Conservative

The Chair Conservative John Williamson

Thank you very much.

It is my intention to get through another two full rounds. That will give the government two additional slots and give the opposition two additional slots for each round.

The Bloc Québécois will also have two turns for questions.

Mrs. Kusie, you have the floor for five minutes.

12:05 p.m.

Conservative

Stephanie Kusie Conservative Calgary Midnapore, AB

Thank you very much, Mr. Chair.

I'll start by saying that I'm very concerned that this government refers to any cyber-attack as innocuous. This is the security of our nation that is further compromised. I'm very concerned in terms of the new level of the relationship being delivered by this Prime Minister. That's very concerning to me.

Continuing with that, APT31, which hacked parliamentarians, was linked to China's intelligence service, as I indicated in the first round. In light of this finding, how can the CSE provide a guarantee that intelligence shared with China will not compromise Canadian cyber-defence security?

12:05 p.m.

Chief, Communications Security Establishment

Caroline Xavier

First of all, it's important to recognize that no matter what amount of cyber-defence we put in place—and we have some great-quality defence in place—we can never guarantee zero cyber-incidents. Working in cyber-defence is a team sport. It's one that we're doing with all the people at this table, but in addition, an individual role has to be played when one is doing what needs to be done to protect oneself.

There is no intelligence sharing under way with regard to the CCP or the PRC. We work on a global stage with many intelligence entities as well as international bodies. That is part of what we do in the cyber-defence space because it is so important to learn from others how cyber-defence works.

I won't speak to the intent of the Prime Minister. I'll leave that for you all to discuss with him directly. I would say, though, that the role CSE plays in terms of foreign intelligence collection is very important. Particularly, when decisions are made by government, it could be informed in terms of the intent of others.

Those are the insights we provide in the work we do, in addition to all the learning from the many incidents that happen on a global scale and all the sharing we do with international bodies, including the Five Eyes, and it's the way we function, both domestically and internationally.

12:10 p.m.

Conservative

Stephanie Kusie Conservative Calgary Midnapore, AB

Thank you very much for that response.

I'll also add that former prime minister Harper had the capacity to manage our relationship to the south, a capacity that the current Prime Minister does not have. That's why he's been forced to kowtow to dictators around the world. I just want to make that very clear. Harper had the capacity to manage that relationship. This Prime Minister does not, and that's why he's forced into the hands of dictators, as we have seen throughout this week.

Can you confirm whether any technology produced by Beijing state-owned companies, as my colleague alluded to, will be blocked from being embedded into the Canadian cybersecurity operations? I'm talking about the daily ones as well, of course.

12:10 p.m.

Chief, Communications Security Establishment

Caroline Xavier

As has been mentioned by my colleagues, part of the work we do is to ensure that any tools we use in the cyber-defence of Canada are tools that we trust and that minimize any of the vulnerabilities we're concerned about. They go through rigorous testing, rigorous assessments, and as part of the procurement contracts, we outline clear conditions that must exist.

No matter what products we will use, no matter which country they will come from, this forms the basis of the work that's required to be done, especially if we at CSE are going to use them, because we want to ensure that we continue to keep our systems secure. Therefore, it matters to pay attention to the supply chain, as mentioned earlier, and to pay attention to who the potential contractors are. They still have to undergo a very rigorous process when it comes to security, personnel security, especially if they're going to work for, and be employed by, the Communications Security Establishment.

12:10 p.m.

Conservative

Stephanie Kusie Conservative Calgary Midnapore, AB

Thank you.

Every one of these 20,000 EVs will be evaluated for potential malware. Is this what I'm hearing?

12:10 p.m.

Chief, Communications Security Establishment

Caroline Xavier

This is not what I'm saying, Mr. Chair. The question asked was about whether or not we are assessing anything that's going to be used by the Communications Security Establishment. My answer to that is yes. We make sure to assess that.

I would add that, as part of the community you see at this table, our jobs will be to ensure that we give our best advice to government when it comes to whatever systems they are going to use. The other thing I would add is that we work with critical infrastructure sectors, including the transportation sector, and they are the ones who will give the advice, I assume, to the government as to the best way to do the implementation of any electric vehicles.

We have advice out, as Mr. Gupta said earlier, with regard to connected devices, and we stand behind that advice. We'll continue to learn and to improve our advice as we become more informed. This is where Bill C-8 is really important, because one of the sectors in that is the transportation sector. If that bill passes, then we'll have a better understanding of what the vulnerabilities are.

In the meantime, we continue to work and to build really great relationships with the transportation sector, and we have governance bodies that allow us to better understand what's going on there.

12:10 p.m.

Conservative

The Chair Conservative John Williamson

Thank you very much. That is the time.

Next, we go back to Ms. Yip.

You have the floor for five minutes, please.

Jean Yip Liberal Scarborough—Agincourt, ON

Thank you.

We'll just say that Mr. Harper was not negotiating with President Trump. Prime Minister Carney is a pragmatist, and he's able to see that our economy really needs to be diversified.

Now I go back to the report. I'd like to ask questions of Mr. Jones and Ms. Xavier. This is in regard to the AG's report indicating that there was not a comprehensive, up-to-date inventory of all government IT devices—such as laptops, smart phones and servers—and that, while Shared Services Canada began to work to address this in 2017, the project has not been completed and is expected to continue until, at least, 2027. Why is this important, and why is it taking so long?

12:15 p.m.

President, Shared Services Canada

Scott Jones

I'll start. Thank you for the question.

I think it's important to note the complex environment we operate in—as I was discussing during one of the last questions—which is the complexity of the number of departments that are involved. A number of entities are responsible for managing their own inventory of goods. The other piece is that, when Shared Services was created, it was a mishmash of technology that was thrown together and handed over to this new agency, saying, “Figure it out.”

The agency didn't invest in its tooling at the beginning. There wasn't money to do that. Really, the money was to just keep it running and hope we could do that. We managed to make some good progress in things like cyber-defence with our colleagues at CSE. That is why EVAS is back on track. We had to work with the vendor. There are some things around needing to make sure the software and the packages we bought were working securely. The pandemic did delay the procurement process.

At the same time, this is a space where the market is evolving very quickly, so we have shifted from a very static project management process that is long-term to a very agile project delivery process that is about rolling out minimum viable product quickly to accelerate that. That's why we've gone from zero deployments to 35,000 desktops so far. It will be at 87,000 desktops by the end of this year, so it's starting to fill that gap. However, there are over 100 departments and agencies we have to work with. That is one of the complicating factors.

The second piece, for us, is how we make sure that information is available to those departments so they can see what their users have. It is an environment that.... There are very few organizations in the world that work the way we do, because of the vertical silos. Mr. Rochon was talking about the authorities, but then we have this horizontal organization that does infrastructure, so there are things we have to work with the vendors on. Those have all been overcome now.

Now it is about—not to trivialize this—lather, rinse, repeat: Get the deployment, get into the department, get it deployed, move to the next one and get it deployed, and do that on a priority basis to get that visibility.

12:15 p.m.

Chief, Communications Security Establishment

Caroline Xavier

I don't know whether I have much more to add to what Scott Jones has already shared.

We are working hand-in-glove. With regard to the recommendation the OAG provided related to identifying a new platform, this is work we're doing in conjunction with our Treasury Board and Shared Services colleagues. We will, though, even without the platform, continue to at least provide a minimum viable product, as was mentioned by Scott.

Dom mentioned earlier the importance of continuing to build the relationships through tabletop exercises. That's really where it matters. It doesn't matter what systems you have, ultimately, in physically tracking these things if we're not doing a good job of ensuring that we're keeping that communication channel open, which is very much what we've worked on, improved and learned from, in terms of the OAG's report.

Jean Yip Liberal Scarborough—Agincourt, ON

What are the biggest barriers for your organizations to having cybersecurity defence sensors on all the devices?

12:15 p.m.

Chief, Communications Security Establishment

Caroline Xavier

I don't know whether the Treasury Board wants to take that one. There aren't any barriers....

12:15 p.m.

Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

It goes to one of the earlier questions in terms of whether the barriers are legal or whether they are logistical and financial. Mr. Jones adequately answered it earlier, saying there's a little bit of both.

There's a barrier in that we can impose our rules on those entities that fall under the Financial Administration Act's schedules I and II. Schedule III falls outside of our authorities. As a result, we cannot mandate Crown corporations to use CSE sensors or, indeed, to use SSC services. However, on a voluntary basis, we have reached out to all of these entities. We're looking for them to adopt our cybersecurity practices, because, of course, they're world-leading and why wouldn't you? As a result, little by little we've started to address that gap. That deals with the legal side of things.

On the logistical and financial side of things, again, as Mr. Jones pointed out, we need to understand exactly what the Internet presence is and what the technological presence is of some of these organizations and how they are set up. If they then want us to protect them, what happens if an incident occurs with one of those organizations? It costs time, effort and resources. We need to put in place the appropriate cost recovery mechanisms in order to ensure that we're able to address them.

12:20 p.m.

Conservative

The Chair Conservative John Williamson

Thank you very much.

Mr. Lemire, you have the floor for two and a half minutes.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

Thank you, Mr. Chair.

Ms. Xavier, during the Prime Minister's trip to China last week or about 10 days ago, journalists were asked not to bring their phone, but to use a temporary phone and throw it away afterwards to make sure it wouldn't be used.

When we parliamentarians travel, security checks are a given. Often, we are loaned another device to ensure that the foreign country cannot access our data and all the information we have access to as members of Parliament.

During that trip to China, an agreement was reached to import Chinese electric vehicles. I could pick up my parliamentary phone and connect to the Bluetooth network of a Chinese electric vehicle. Would you recommend I avoid doing so? Would I be putting Parliament's strategic data at risk for the benefit of the Chinese government?

12:20 p.m.

Chief, Communications Security Establishment

Caroline Xavier

Thank you for the question.

It's a bit difficult to give a concrete answer, because those are hypothetical questions. What I would generally say, like my—

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

It's like the TikTok app, which the government asked us to delete from our phones. I've never used that app, but the government still asked me to delete it. We're also talking about Huawei phones, which were banned, and wireless networks. So it's really not hypothetical.

January 26th, 2026 / 12:20 p.m.

Chief, Communications Security Establishment

Caroline Xavier

Indeed, but what I was going to add is that, for the examples you mentioned—whether it's TikTok or another application—we at the Canadian Centre for Cyber Security always recommend that people pay attention to all the privacy laws of the country in which they travel. That's what we're talking about.

You specifically mentioned Beijing and China. That said, regardless of where people travel, our advice is to always pay attention to local laws. We have to ask ourselves what they are, whether we're comfortable with the laws and the networks on which data will circulate, because we don't have control over all the telecommunications networks around the world.

So it's a personal question that someone has to ask themselves when travelling, to make sure they understand the laws, problems or challenges that exist—