Evidence of meeting #22 for Public Accounts in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was cyber.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Hayes  Deputy Auditor General, Office of the Auditor General
Rochon  Chief Information Officer of Canada, Treasury Board Secretariat
Jones  President, Shared Services Canada
Xavier  Chief, Communications Security Establishment
Tea-Duncan  Chief Information Security Officer of the Government of Canada, Treasury Board Secretariat
Goulet  Principal, Office of the Auditor General
Gupta  Head, Canadian Centre for Cyber Security, Communications Security Establishment

Jean Goulet Principal, Office of the Auditor General

Thank you for the question.

I can say without hesitation that we observed a very high level of co-operation between the entities. That said, it doesn't mean there's no room for improvement. We mention this in our report, particularly with regard to various projects that were delayed but are nonetheless very important for the country's cybersecurity needs. The three entities definitely co-operate well with each other.

11:45 a.m.

Conservative

Gérard Deltell Conservative Louis-Saint-Laurent—Akiawenhrahk, QC

Mr. Rochon, what do you think could be improved? What other entities could be improved to ensure that you are more effective?

January 26th, 2026 / 11:45 a.m.

Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

Thank you for the question.

I'll start by saying that improvements can always be made, especially when it comes to information sharing.

We have highly skilled people working in all three organizations. We don't always think to bring everyone together to solve the problem. Under our policies, if an incident occurs in any department, the Canadian Centre for Cyber Security is immediately notified. From there, it will launch its investigation. I think improvements need to be made to bring everyone together so that we are all aware. There are also issues we haven't mentioned yet today with respect to access to privacy. If personal information is incorporated, the Privacy Commissioner must absolutely be brought back into the equation. It's a matter of honing those responses, conducting exercises to ensure that everyone understands their role and responsibilities and that everyone works together.

11:45 a.m.

Conservative

The Chair Conservative John Williamson

Thank you very much.

Mr. Osborne, you have the floor for five minutes, please.

Tom Osborne Liberal Cape Spear, NL

Thank you, Mr. Chair.

I think we need to keep the fact that canola farmers or fisher people in Atlantic Canada can trade with a country separate from cybersecurity. I'm not sure the two are connected. We do need to strengthen not only cybersecurity but economic trade.

I think this is the first time I've ever uttered the words.... There was a security threat in Newfoundland and Labrador against the Newfoundland and Labrador Health Services. I was the chair of the cabinet committee on that, so I have some understanding, but this is the first time I've ever said that publicly, because we were advised never to say it. As parliamentarians, we're probably a target for bad actors. I will say that there are bad actors, both nation-states and very well-organized organizations, that profit.

Keeping in mind the balance between the public's right to know what's happening and our nation's security, I think we have to be careful in the questions we ask here, because the work that you undertake is very serious business. We do need to ensure that we address the weak links.

I have two questions. Mr. Rochon, I'll direct this question at you.

With regard to the purple team, how are we ensuring that this group of professionals is able to stay ahead of a system that changes very quickly—hour by hour, maybe minute by minute, as quickly as we put defences in place to protect our information security and our cybersecurity measures—as bad actors are working to try to get around those measures?

11:50 a.m.

Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

Therein lies the rub. The challenge that we have on a daily basis is staying ahead of the sophisticated threat actors.

One of the members today mentioned artificial intelligence. As much as we're excited about the use of artificial intelligence for good, you could imagine that malicious actors are going to be using artificial intelligence for bad.

I'd like to distinguish between the purple team...which is still very much in pilot project format. It's something that we've just launched. We were relying on departments and agencies to self-report that they had put in place all the measures and defences that we've advocated in our policies and our cyber strategy and our vulnerability programs, etc. The purple team is going in without a department or an agency knowing about it, checking in on them and seeing if those defences are actually up to snuff. We do so in partnership with Shared Services Canada and the CSE, of course, which have the expertise and understand where those vulnerabilities might be. As those things come to light, we are able to test and discover those gaps further.

To your question specifically about how we stay ahead of the sophistication, I think that would be better suited for my colleague, Mr. Gupta, who I think releases annually or every two years the cyber-threat report. CSE is constantly looking at the sophistication that's occurring and is tailoring their services and their defences and their sensor work to counter that.

Rajiv Gupta Head, Canadian Centre for Cyber Security, Communications Security Establishment

Actually staying ahead of the threat is very important to us. It does change all the time, and as we lock down certain areas, other areas become the target of threat actors. That's exactly what we see on a daily basis. To stay ahead of the groups, yes, we have the purple team. Treasury Board brings in first-class industry experts to come in and see if we detect them and if others detect them as well, which is an important exercise.

The chief mentioned earlier the collaboration right across CSE and with our Five Eyes partners. We are tracking threat actors right around the globe all the time, trying to figure out what their next techniques are going to be and what exploitation efforts they're going to conduct, and we are implementing defences for this.

We host innovation workshops with the best in industry right across Canada and around the world. For example, GeekWeek, which is hosted annually, includes members of critical infrastructure—banks, telcos, etc.—as well as security companies and cloud service providers. We all come and try to figure out what those next challenges will be.

We do this on the classified side as well, with basically the best cyber-defenders in the world trying to figure out what those threats are and how we can circumvent them. It's intelligence-informed, definitely, and staying at the latest edge of technology in being able to find threats that are out there from a threat intelligence perspective, but it's also building the latest technologies as well.

You mentioned AI. It's very important for us to put out advice and guidance on how to secure AI and how organizations can safety adopt AI, but we also make extensive use of AI internally as well, making sure that we can scale, just as threat actors are scaling as well.

We're on the edge for technology development, but we're also consuming threat intelligence from ourselves, from commercial entities and from our partners to make sure that we understand what's there. We may still find some gaps and subsequently find something new, because that's the world. It's changing all the time.

11:50 a.m.

Conservative

The Chair Conservative John Williamson

Thank you very much.

That was your time, Mr. Osborne. I believe we'll come back to you later.

Mr. Lemire, you have the floor for two and a half minutes.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

Thank you, Mr. Chair.

In her many reports, the Auditor General highlighted the massive use of subcontractors in IT, who can access sensitive information without the required security clearances or training. Ottawa spends nearly $1 billion a year on IT services. In 2022, the number of IT subcontractors was around seven. So I think there's a huge vulnerability there.

Mr. Jones, you might be the best person to answer my question, but obviously any of you can answer.

I think we are quite vulnerable to foreign interference. We would need security guarantees. What are the security guarantees required by the government? Are checks done so that companies to whom you award a contract have the work done by people from that company, and not by subcontractors? How are you going to adapt your methods for awarding contracts to avoid using foreign workers located in countries at risk, with which there are diplomatic tensions? As the world order changes, the list of countries we can trust is quite limited.

11:55 a.m.

President, Shared Services Canada

Scott Jones

Thank you for the question.

I can only speak to the hiring of subcontractors and contractors by Shared Services Canada.

First, to access the Shared Services Canada system, you have to get an account from us. So we have to verify the identity of the individuals who will have access to our systems and our information.

Second, we are constantly evaluating the systems for verification, and for keeping and securing information, so that individuals can only access the information they need to do their job.

Our own security processes apply before giving an account or an ID card to access our facilities, but also to verify someone's identity and the country in which that person works.

Finally, there is also the procurement process. The contract contains clauses that require information, as well as security clearances related to Public Services and Procurement Canada's security program.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

Thank you very much.

11:55 a.m.

Conservative

The Chair Conservative John Williamson

Thank you very much.

Up next is Mr. Kuruc.

You have the floor for five minutes, please.

11:55 a.m.

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

Hello, everybody.

Thank you for coming today, and happy new year.

My first question would be for Ms. Caroline Xavier.

In an earlier quote in a document, you said, “the rise of AI-enabled cyber threats poses significant challenges to our democratic process.” What countries would you identify as bad actors for that?

11:55 a.m.

Chief, Communications Security Establishment

Caroline Xavier

I believe the quote you are referring to is from our document on threats to the democratic process. Almost every two years we put out a publication called “Cyber Threats to Canada's Democratic Process,” where we assess what we learn from a global perspective and what are the threats that could be of concern, especially if there is going to be a general, municipal or provincial election. We look at it purely in terms of the cyber-threat activity targeting these elections. In general, we tend to see action such as DDoS attacks, mis- and disinformation, manipulation of online systems and things of that nature.

11:55 a.m.

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

I'm sorry, but I have limited time.

Are you saying that it's global and there are no specific countries that you would pinpoint?

11:55 a.m.

Chief, Communications Security Establishment

Caroline Xavier

What I was going to say is that in “Cyber Threats to Canada's Democratic Process” we have highlighted that Russia and China have the most cyber-threat activity attributed to them in terms of targeting foreign elections. It is important to note that this is on a global stage.

11:55 a.m.

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

Thank you very much. I appreciate your answer.

My next question is for Mr. Gupta.

You were quoted as saying, “Malicious actors are increasingly leveraging AI to enhance the scale and sophistication of their activities—including those that threaten our democratic institutions.” Could I get your expert opinion on which countries those would be?

11:55 a.m.

Head, Canadian Centre for Cyber Security, Communications Security Establishment

Rajiv Gupta

I would refer to the exact same document that the chief mentioned, “Cyber Threats to Canada's Democratic Process”. That's from a democratic perspective. At the same time, AI is democratizing this capability, and I think that more and more countries will continue to stand up the ability because it's easier for countries to take advantage.

11:55 a.m.

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

Would you agree with the chief, then, that China and Russia would probably be the two main...amongst others, obviously?

I fully respect that it is a global issue, but I'm trying to pinpoint a few things. As Conservatives, our party has always had concerns about these issues. I want to commend you both for doing a great job, first and foremost. Now, as the Prime Minister looks to make new trade deals, it seems he's aggressively moving very quickly towards China. More importantly, it's China, but for more important communication methods, let's call it the Chinese Communist Party. That's the real concern, as opposed to China and Chinese people. It's the Communist Party that governs that country.

As a Conservative, I and many of my colleagues here are advised not to use things like TikTok, which 99% of MPs don't use for security reasons, which I'm sure you know all too well. Canadians can't buy Huawei phones. The previous government addressed that, and I agreed with that.

Now there's a big concern about Chinese EVs. Not only will it be a threat to the auto sector in Ontario, but also on a security level, Mr. Gupta, how do you feel...and what would you address? Is there a threat in bringing 50,000 Chinese EVs into our market?

Noon

Head, Canadian Centre for Cyber Security, Communications Security Establishment

Rajiv Gupta

From a security perspective, EVs are similar to other technology platforms. We've given out advice and guidance in terms of the increasing digitalization of critical infrastructure in general. I think that's something we need to keep a view on right across the board, because everything is becoming connected to the Internet.

With respect to EVs, we have supply chain guidance, and we have national cyber-threat assessments. We have all those things that we publish regularly on our website, and we continue to communicate these threats to Canadians. The supply chain is in one of the documents we have there as well. We also have advice and guidance as to secure communications of vehicles that we post as well. There is all that advice and guidance. I think it was mentioned earlier that you need layered defences, but you need to understand exactly what situation you're actually deploying the technologies in and what mitigations you put in place. We recommend.... For applications that are perhaps not as secure as you'd be considering, there are mitigations you can put in place, such as turning off Bluetooth and doing different sorts of things, so—

Noon

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

Would there be a heightened risk, though? We can't use TikTok and Huawei, and some of our journalists and MPs have to use burner phones when they go to visit the Chinese Communist Party. Is there a higher threat in those EVs, or is it standard?

Noon

Head, Canadian Centre for Cyber Security, Communications Security Establishment

Rajiv Gupta

Right across the board, we assess risk as a number of different elements. Part of it is the supply chain, so you do look at the laws of nations as it comes in, you look at technology and the quality and implementation of software, and then you look at legal and reputational risks as well. That's our typical assessment of products. Putting all those things together gives you a general risk. You'll have products that are developed in certain ways that will have vulnerabilities based on technical deficiencies. You'll have—

Noon

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

But the same is—

Noon

Conservative

The Chair Conservative John Williamson

Thank you. That is the time, I'm afraid, Mr. Kuruc.

Noon

Conservative

Ned Kuruc Conservative Hamilton East—Stoney Creek, ON

Thank you very much. I appreciate your answers.