Sure. Thank you for the question.
I think there are a few areas where we're making progress.
The first thing is that there's been a base of collaboration for over a decade as we've built up this robust system of defences, and those are relationships. As much as I'm supposed to be leading a technology organization, effective cyber-response is about building those relationships and the trust, because a lot of times it's a judgment call until you know for certain. That is the first thing.
The second piece is that we are exercising. Mr. Rochon talked about the purple team and some of the other pieces that have been put in place lately as exercises. One of the consequences of having a robust defence mechanism is that.... When I first started working on cybersecurity with Mr. Gupta about 14 or 15 years ago, we were having incidents happening every day that we were responding to. Now our systems take care of a lot of these things proactively, and these big incidents that we've talked about don't happen often. You have to continue to practise so that those muscles stay able to work.
Those are a couple of the things we're doing.
The third thing is that in every single incident there's always something that we can learn from. We do a full after-action review that's led by my colleagues at Treasury Board. I'll let them speak to this, but that's very important. Even when it goes very well, what could have been done better? What could have been done more quickly? What could we learn from this?
There always has to be one, and sadly, with cybersecurity, there usually is a first victim. Our goal together is to make sure there's never a second.
