It goes to one of the earlier questions in terms of whether the barriers are legal or whether they are logistical and financial. Mr. Jones adequately answered it earlier, saying there's a little bit of both.
There's a barrier in that we can impose our rules on those entities that fall under the Financial Administration Act's schedules I and II. Schedule III falls outside of our authorities. As a result, we cannot mandate Crown corporations to use CSE sensors or, indeed, to use SSC services. However, on a voluntary basis, we have reached out to all of these entities. We're looking for them to adopt our cybersecurity practices, because, of course, they're world-leading and why wouldn't you? As a result, little by little we've started to address that gap. That deals with the legal side of things.
On the logistical and financial side of things, again, as Mr. Jones pointed out, we need to understand exactly what the Internet presence is and what the technological presence is of some of these organizations and how they are set up. If they then want us to protect them, what happens if an incident occurs with one of those organizations? It costs time, effort and resources. We need to put in place the appropriate cost recovery mechanisms in order to ensure that we're able to address them.
