Thank you, Mr. Chair.
I'm pleased to speak about the Auditor General's performance audit of the cybersecurity of government networks and systems, which is report 5 of her fall 2025 reports.
I'm pleased to appear today with my colleagues from Shared Services Canada, the Communications Security Establishment, the Office of the Auditor General and, in particular, Po Tea-Duncan from my office, the Government of Canada's chief information security officer.
Mr. Chair, protecting the government's IT infrastructure from vulnerabilities and responding to cybersecurity threats is critical to protecting Canadians' data and the services the Government of Canada provides them. As Canadians increasingly access government programs and services online, network security is more important than ever.
The Treasury Board of Canada Secretariat is named in two of the recommendations in the audit. The first such recommendation is that TBS, in consultation with the Communications Security Establishment, ensure that federal organizations implement the Communications Security Establishment's cyber-defence sensors on all their IT endpoint devices so that their associated vulnerabilities can be identified and remediated.
The second recommendation is that Treasury Board Secretariat, Shared Services Canada and the Communications Security Establishment re-evaluate their cybersecurity incident management practices to enable better coordination and timely access to required critical information when responding to cybersecurity incidents affecting federal organizations.
The government is committed to reducing cybersecurity risks in order to protect its systems and, consequently, Canadians’ information, and to ensuring the continued delivery of secure and reliable digital services. The Treasury Board Secretariat welcomes the Auditor General’s recommendations and will continue to work with Shared Services Canada and Communications Security Establishment Canada to implement them.
With regard to evaluating our cybersecurity incident management practices to improve the rapid communication of critical information, the Treasury Board Secretariat, in collaboration with its partners, regularly reviews our operational framework, the Government of Canada Cybersecurity Event Management Plan.
The lessons learned from cyber simulation exercises, also known as “tabletop exercises”, enable the TBS to identify improvements that are then applied to the plan to ensure its effectiveness.
The Government of Canada, like all public and private sector organizations, faces ongoing and evolving cyber-threats. To maintain a strong cyber-defence posture, the Treasury Board Secretariat, in consultation with Communications Security Establishment Canada, will work with federal organizations to ensure that the centre’s defence sensors are installed on all endpoints, whether they are devices, servers or workstations.
We will achieve this in part through a tool that quickly identifies information technology endpoints where no sensors are deployed. This will enable us to subsequently detect, assess and prioritize vulnerabilities to be addressed on IT devices on government networks.
Of note, Mr. Chair, to enhance the government's cybersecurity, budget 2024 provided $11.1 million over three years, starting in 2024-25, for the Treasury Board Secretariat to begin implementing a whole-of-government cybersecurity strategy. This included measures to support the rapid identification, assessment and management of vulnerabilities across the enterprise, the formation of a purple team that will emulate techniques used by malicious threat actors to proactively test and audit any security gaps, and the creation of a program to improve cyber-assurance and risk evaluation for the Government of Canada enterprise.
Network cybersecurity is vital for the government to protect Canadians' data and services, ensure national security, maintain economic prosperity and uphold public trust in an increasingly digital world. We agree with the Auditor General's recommendations and, along with our partners, are taking action to address her concerns.
Thank you. Following my colleagues' opening remarks, I will welcome the committee members' questions.
