We have implemented security measures. Subcontractors must be authorized to work for the federal government. They go through different levels of verification depending on what they will have access to. There are rules in place to justify and certify their presence.
In short, the problem is that the threat will always be present. It is impossible to guarantee at all times that we have covered everything, so we put rules in place. We have implemented a mandatory course that all public servants must take each year. We have implemented a vulnerability management program where we are looking at the risks and following up on them. We have set up both a red and blue team of various cybersecurity professionals, as I mentioned.
Ms. Tea‑Duncan, would you like to elaborate on these points?
