Good morning, everyone.
I now call the meeting to order.
Welcome back from the Christmas recess. I hope everyone is rested and ready to go.
The weather is not getting us down too much, although I understand it's worse in Toronto.
Evidence of meeting #22 for Public Accounts in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was cyber.
A video is available from Parliament.
Conservative
The Chair Conservative John Williamson
Good morning, everyone.
I now call the meeting to order.
Welcome back from the Christmas recess. I hope everyone is rested and ready to go.
The weather is not getting us down too much, although I understand it's worse in Toronto.
Liberal
Conservative
The Chair Conservative John Williamson
Welcome to meeting number 22 of the House of Commons Standing Committee on Public Accounts.
Today's meeting is taking place in a hybrid format, pursuant to the Standing Orders. Members are attending in person in the room and remotely by using the Zoom application.
I want to thank all of our witnesses for coming here in person today.
Before I begin, I would like to remind participants of the following points. Please wait until I recognize you by name before speaking. Comments should be addressed through the chair—well, that's more if we have a debate of any sort.
Pursuant to Standing Order 108(3)(g), the committee will begin consideration of the cybersecurity of government networks and systems, taken from the fall 2025 reports of the Auditor General of Canada and referred to the committee on Tuesday, October 21, 2025.
Let me introduce the witnesses I just thanked for coming in today despite the ugly weather.
From the Office of the Auditor General, we have Andrew Hayes, deputy auditor general, along with Jean Goulet, principal. It's nice to see you.
From the Treasury Board Secretariat, we have Dominic Rochon, chief information officer of Canada, and Po Tea-Duncan, the chief information security officer of the Government of Canada. It's nice to see you as well.
From Shared Services Canada, we have Scott Jones, president. It's good to see you again, Mr. Jones. We also have Patrice Nadeau, senior assistant deputy minister, connectivity and security services branch. It's nice to see you as well.
From the Communications Security Establishment, we have Caroline Xavier, chief. It's nice to see you again. We also have Rajiv Gupta, head of the Canadian centre for cybersecurity.
Thank you all for coming in today. I suspect we'll be using the full two hours, given the number of esteemed witnesses we have here today. Each unit department will have five minutes.
Mr. Hayes, I'll get you to open things up for five minutes, please.
Andrew Hayes Deputy Auditor General, Office of the Auditor General
Good morning, Mr. Chair.
Thank you for the opportunity to appear before the committee today to discuss our report on cybersecurity of government networks and systems, which was tabled on October 21, 2025.
I’d like to begin by recognizing that we are meeting on the traditional, unceded territory of the Algonquin Anishinabe people.
With me today is Jean Goulet, the principal director who was responsible for the audit.
The central responsibility for protecting government information technology systems and operations is shared by the Treasury Board of Canada Secretariat, Communications Security Establishment Canada, and Shared Services Canada. These organizations work together and with departments and agencies to prevent data theft and limit disruptions to systems that deliver programs and services to Canadians. We found that while the government had tools in place to protect and defend its networks and systems against cyber-threats, there were gaps in cybersecurity defence services, monitoring and response during active attacks.
Only 42% of federal organizations are required, by Treasury Board policy, to use the cybersecurity defence services offered by Shared Services and the Communications Security Establishment. Others have opted in, but this inconsistent use of services undermines the federal government’s ability to protect critical information and manage risks.
We also found that coordination among the three organizations was too slow during active cyber-attacks. For example, poor coordination delayed the government's response during a major attack two years ago. This extended the time during which the attacker had access to public servants' personal information.
Protecting federal networks and systems also requires analyzing the potential vulnerabilities of all government IT devices, including laptops, smart phones, and servers. We found that Shared Services and the Communications Security Establishment did not have a comprehensive inventory of all government devices. Without up-to-date information, the federal government risks being unable to quickly respond to a changing cybersecurity landscape.
Malicious actions, external events, and attacks targeting the Canadian government’s digital systems are frequent and more sophisticated. A coordinated and comprehensive approach to the government’s cybersecurity posture, better collaboration and a current inventory of IT devices are key to safeguarding Canadians’ information.
Mr. Chair, this concludes my opening remarks. We would be pleased to answer any questions the committee may have.
Thank you.
Conservative
The Chair Conservative John Williamson
Thank you very much, Mr. Hayes.
Mr. Rochon, you have the floor for five minutes.
Dominic Rochon Chief Information Officer of Canada, Treasury Board Secretariat
Thank you, Mr. Chair.
I'm pleased to speak about the Auditor General's performance audit of the cybersecurity of government networks and systems, which is report 5 of her fall 2025 reports.
I'm pleased to appear today with my colleagues from Shared Services Canada, the Communications Security Establishment, the Office of the Auditor General and, in particular, Po Tea-Duncan from my office, the Government of Canada's chief information security officer.
Mr. Chair, protecting the government's IT infrastructure from vulnerabilities and responding to cybersecurity threats is critical to protecting Canadians' data and the services the Government of Canada provides them. As Canadians increasingly access government programs and services online, network security is more important than ever.
The Treasury Board of Canada Secretariat is named in two of the recommendations in the audit. The first such recommendation is that TBS, in consultation with the Communications Security Establishment, ensure that federal organizations implement the Communications Security Establishment's cyber-defence sensors on all their IT endpoint devices so that their associated vulnerabilities can be identified and remediated.
The second recommendation is that Treasury Board Secretariat, Shared Services Canada and the Communications Security Establishment re-evaluate their cybersecurity incident management practices to enable better coordination and timely access to required critical information when responding to cybersecurity incidents affecting federal organizations.
The government is committed to reducing cybersecurity risks in order to protect its systems and, consequently, Canadians’ information, and to ensuring the continued delivery of secure and reliable digital services. The Treasury Board Secretariat welcomes the Auditor General’s recommendations and will continue to work with Shared Services Canada and Communications Security Establishment Canada to implement them.
With regard to evaluating our cybersecurity incident management practices to improve the rapid communication of critical information, the Treasury Board Secretariat, in collaboration with its partners, regularly reviews our operational framework, the Government of Canada Cybersecurity Event Management Plan.
The lessons learned from cyber simulation exercises, also known as “tabletop exercises”, enable the TBS to identify improvements that are then applied to the plan to ensure its effectiveness.
The Government of Canada, like all public and private sector organizations, faces ongoing and evolving cyber-threats. To maintain a strong cyber-defence posture, the Treasury Board Secretariat, in consultation with Communications Security Establishment Canada, will work with federal organizations to ensure that the centre’s defence sensors are installed on all endpoints, whether they are devices, servers or workstations.
We will achieve this in part through a tool that quickly identifies information technology endpoints where no sensors are deployed. This will enable us to subsequently detect, assess and prioritize vulnerabilities to be addressed on IT devices on government networks.
Of note, Mr. Chair, to enhance the government's cybersecurity, budget 2024 provided $11.1 million over three years, starting in 2024-25, for the Treasury Board Secretariat to begin implementing a whole-of-government cybersecurity strategy. This included measures to support the rapid identification, assessment and management of vulnerabilities across the enterprise, the formation of a purple team that will emulate techniques used by malicious threat actors to proactively test and audit any security gaps, and the creation of a program to improve cyber-assurance and risk evaluation for the Government of Canada enterprise.
Network cybersecurity is vital for the government to protect Canadians' data and services, ensure national security, maintain economic prosperity and uphold public trust in an increasingly digital world. We agree with the Auditor General's recommendations and, along with our partners, are taking action to address her concerns.
Thank you. Following my colleagues' opening remarks, I will welcome the committee members' questions.
Conservative
The Chair Conservative John Williamson
Thank you very much.
Up next is Mr. Jones, please, for five minutes.
Scott Jones President, Shared Services Canada
Thank you, Mr. Chair, for the opportunity to discuss the Auditor General’s Report on the Cyber Security of Government Networks and Systems.
Before we begin, I would like to acknowledge that we are on the traditional, unceded territory of the Algonquin Anishinabe people. I’m here today with Patrice Nadeau, senior assistant deputy minister for SSC's Connectivity and Security Services Branch.
Shared Services Canada, or SSC, welcomes the Auditor General’s findings and is working to address the issues raised. It’s important to underline that the Auditor General found that the government had tools in place to protect and defend its networks and that the government’s cybersecurity plan was sound and comprehensive.
As the provider of IT services to departments and agencies, SSC plays a pivotal role in this work.
Indeed, SSC blocks about 6.5 trillion cyber-threats annually, which is an average of 18 billion a day. This ensures the uninterrupted operation of government services. We do that through a state-of-the-art enterprise infrastructure and modern commercial cybersecurity solutions that defend government systems against a wide range of cyber-threats. SSC uses multiple layers of defence and prevention, including firewalls, network defences, anti-denial of service measures, anti-virus and anti-malware tools, encryption, virtual private networking and robust identification on authentication services.
We have an excellent partnership with our colleagues at the Treasury Board Secretariat and the Communications Security Establishment. This collaboration is absolutely vital, as the Auditor General underscored, and we continue to improve it. We regularly conduct post-mortems on cyber events to identify ways we can always do better. Together, SSC and CSE's Canadian centre for cybersecurity provide sophisticated cyber-defences that go beyond commercial capabilities. Our work offers one of the most sophisticated cyber-defences in the world.
Cybersecurity is a space that is evolving fast, and we work continuously to keep on top of it. That said, there is more to do, as the Auditor General rightfully underscored. We share the Auditor General's concerns about organizations that are outside of SSC's enterprise internet service. As the threat environment changes rapidly, that is a model that clearly needs to evolve. This is why SSC is now working to provide connectivity and security services to 43 small departments and agencies. It is on track to complete this work by the end of March 2027.
The Auditor General also highlighted a project called endpoint visibility, awareness and security, or EVAS for short. This is one of the tools SSC is adding to its cybersecurity environment. EVAS will automatically identify network-connected endpoints, such as desktops and servers, and verify that they meet security requirements. Unlike our semi-manual service system, EVAS is automated and enables real-time vulnerability and impact assessments. EVAS will also provide automated response to cyber events. While there were delays to this project, our organization has learned a number of lessons. This project has turned a corner and, since implementation began in July 2025, over 36,000 deployments have been completed.
The Auditor General also highlighted our project to develop a security information and event management system, or SIEM for short. I want to assure you that we are on track to award a competitive contract for this project in early 2026. Further, SSC is currently operating an interim SIEM capability, which allows SSC and our partners at the Canadian centre for cybersecurity to manage priority needs and supports an effective response to cyber-threats.
Since SSC's creation, we have shifted the government's business model from one that is siloed and decentralized to a government-wide enterprise approach. This not only reduces costs but strengthens overall security Government of Canada-wide. It is easier to monitor, patch and fix one system than 45 separate ones—and it is easier to invest in one system than in 45 separate ones.
We are not done. SSC is streamlining the management of devices and software by centralizing procurement and operations. This achieves considerable efficiencies and reduces the potential for inconsistencies in security policies. We're also continuing to reduce duplication by replacing additional siloed back-office tools with standard, government-wide tools. Legacy systems are also more vulnerable to cyber-threats, as was pointed out in another Auditor General review. Moving off legacy systems improves our cybersecurity posture.
In short, everything we do to consolidate and modernize IT systems is essential to improving cybersecurity.
Reports from the Auditor General are also an important tool to hold us accountable and allow us to improve our operations. Cybersecurity is an evolving field with actors that don’t follow our rules. Continuous improvements are key to protecting the GC’s IT systems.
Thank you for the opportunity to speak on this important file, and I look forward to answering your questions.
Thank you.
Conservative
The Chair Conservative John Williamson
Thank you, Mr. Jones.
Ms. Xavier, you now have the floor for five minutes.
Caroline Xavier Chief, Communications Security Establishment
Thank you.
Good morning, Mr. Chair and members of the committee.
Thank you for inviting me to appear today to discuss the Auditor General of Canada’s report on the Cyber Security of Government Networks and Systems.
As mentioned, my name is Caroline Xavier, and I am the chief of the Communications Security Establishment, also known as CSE.
I'm joined today by Rajiv Gupta, head of the Canadian centre for cybersecurity, also known as the cyber centre, which forms an integral part of CSE.
We are pleased to appear alongside our colleagues from the Treasury Board Secretariat and Shared Services Canada, with whom we work closely on cybersecurity.
Today I will provide a brief overview of CSE and our cyber centre, and then share how we are responding to an increasingly complex threat landscape, one that includes cyber-threats, risks to economic security, violent extremism, foreign interference, disinformation campaigns and more.
Before we begin, I want to acknowledge that we are on the traditional unceded territory of the Algonquin Anishinabe nation. We acknowledge that this nation has been on this land since time immemorial.
CSE is one of Canada’s key security and intelligence agencies, and a stand-alone agency reporting to the Minister of National Defence.
As part of our mission, we provide vital foreign signals intelligence on a wide range of threats to help the Government of Canada make informed decisions and safeguard Canada's interests, while strictly following Canadian law and privacy standards. We also defend Government of Canada networks and systems of national importance against malicious cyber activity targeting Canada's digital infrastructure.
Through the cyber centre, we serve as the national and technical authority for cybersecurity, providing a single, trusted source of expert advice and guidance for Canadians and organizations across the country. By integrating cybersecurity, signals intelligence and foreign cyber-operations, CSE is uniquely positioned to strengthen Canada's overall defence and security.
The integrity of Canada's cyberspace is foundational to our country's future. It underpins our digital economy, protects personal safety, and strengthens national resilience.
In 2024-25, CSE produced more than 3,300 foreign intelligence reports and responded to over 2,500 cyber-incidents affecting federal institutions and critical infrastructure partners. We also issued over 330 pre-ransomware notifications to more than 300 Canadian organizations, early warnings that helped prevent serious harm.
As the threat landscape evolves, so do we. Our world-recognized cyber-defence sensors program provides real-time detection of malicious cyber activity across Government of Canada networks and cloud environments. This program is available to all federal departments and agencies, and to Crown corporations upon request. It enables our experts to block and neutralize threats before they cause harm.
While many federal organizations manage their own IT infrastructure, they can leverage CSE's sensors program and the cyber centre's expert guidance to strengthen their defences. Today, most federal institutions use at least one of our sensors. We also continue to deepen our engagement with Crown corporations, critical infrastructure operators, and provincial and territorial partners.
CSE welcomes the Auditor General's report and supports its recommendations, particularly those aimed at strengthening sensor deployment and improving incident management coordination. As my colleagues have highlighted, we are working closely together to expand the deployment of cyber-defence sensors across federal networks and refine incident response protocols.
These efforts build on significant progress already made to modernize and secure the digital systems that deliver essential services for Canadians. Cybersecurity is a shared responsibility, and collaboration remains at the heart of our approach.
Mr. Chair and members of the committee, the threat environment is dynamic, but our commitment is unwavering. Together with our partners, we will continue to protect Government of Canada systems, Canada’s critical infrastructure and digital systems, ensuring Canadians can rely on secure and trusted services.
Thank you once again for the opportunity to appear before this committee.
We welcome your questions and look forward to continued dialogue.
Thank you.
Conservative
The Chair Conservative John Williamson
Thank you, all, very much.
We'll now begin our first round of questions, which will consist of three members with six minutes each.
Ms. Kusie, you'll kick us off this year. Thank you.
January 26th, 2026 / 11:20 a.m.
Conservative
Stephanie Kusie Conservative Calgary Midnapore, AB
Earlier this month, the Prime Minister announced a new Canada-China strategic partnership. On many fronts, this concerns me, but specific to this meeting, I'm concerned about Canada's cybersecurity and the protection of our private information.
In 2024, I was informed by IPAC through the FBI that I had been the target of a cyber-attack orchestrated by the PRC. I had been targeted because of my status as a member of Parliament. As the Canadian government begins a new economic relationship with the PRC, I'm concerned with how our government assesses these new strategic partnerships with non-democracies on the world stage.
Madame Xavier, can you please share with this committee what measures your agencies and departments are taking to ensure cybersecurity and the protection of sensitive data as we enter new agreements with governments like the PRC?
Chief, Communications Security Establishment
As mentioned in my opening remarks, CSE holds multiple mandates within one agency, one being the foreign intelligence collection that we do, to be able to ensure that decision-makers have the information they require to make decisions. That is something we've been doing for almost 80 years. The other part of our mandate is the cybersecurity or cyber-defence part of our mandate, and one other part of our mandate is the foreign cyber-operations mandate. Having all those elements within one agency really helps us to ensure that what we learn from foreign intelligence data collection can be used in the defence of Canada and vice versa. All the billions of incidents that we protect against in the defence of Canada allow us to learn about threat actors who maybe have potential interests in Canada. That then feeds what we can do on the foreign intelligence part of the mandate. In addition to that, in foreign cyber-operations, we're able to take actions in cyberspace, in the foreign cyberspace, to ensure that we continue to protect Canada.
We operate under cabinet-approved intelligence priorities that are reviewed on a regular basis. As it is now, our mandate includes protecting Canada's critical infrastructure and democratic institutions. Whether they are nation states or cybercriminals, that is part of the mandate that we operate on a regular basis, 24-7, 365 days a year. We remain committed to being able to ensure that we do our jobs effectively. I am pleased and proud of the fact that we lead an organization that puts out world-class cyber-defence. The work that we do together with our partners both at Treasury Board and SSC allows us to continue to protect Government of Canada systems.
Conservative
Stephanie Kusie Conservative Calgary Midnapore, AB
Thank you very much for that extensive answer.
You mentioned that you have protected against billions of negative interactions, negative interceptions; however, it is apparent to me, from the experience I had as well as that of several other members of Parliament, that the most cunning of evil operators are still able to penetrate the system, which is very concerning to me.
You mentioned the implication of other decision-makers. Are there ministers who have given you direction specifically, and who would those ministers be, please?
Chief, Communications Security Establishment
Again, thank you for the opportunity to clarify.
Our intelligence priorities are driven by the cabinet of the Government of Canada. Our intelligence—
Conservative
Chief, Communications Security Establishment
The full cabinet endorses the intelligence priorities of the Government of Canada—
Conservative
Chief, Communications Security Establishment
The full cabinet provides the direction, led by the Prime Minister of the country. As a result, we've published the intelligence priorities so Canadians have an opportunity to understand the priorities we have. The priorities are fairly broad, and we are able to work to those priorities in the work we do.
Conservative
Stephanie Kusie Conservative Calgary Midnapore, AB
Thank you very much, Madame Xavier. I'm not getting a lot of good, clear information in terms of what those priorities are and how they're implemented, but thank you.
Mr. Hayes, your report from October is not the first to focus on cybersecurity. As the importance of technology continues to grow, I'm sure it will not be the last, unfortunately.
Do you believe that hostile actors like the PRC could attempt to act on the security gaps that you mentioned within this report?
Deputy Auditor General, Office of the Auditor General
There's no doubt that the government faces attacks every day. Indeed, they're stopping billions and trillions every year. I think the message from our report is that vigilance and rigour need to be at the top of the mind of every government organization.
To us, one of the big findings in our report is that not every federal organization is required to use the services that Shared Services Canada and the Communications Security Establishment Canada provide. That is, in our view, a missed opportunity.
Conservative
Stephanie Kusie Conservative Calgary Midnapore, AB
Thank you for that.
Monsieur Rochon, over the past year, the government has placed a focus on artificial intelligence and the use of it both within and outside of government. With AI comes a world of opportunity, but also a world of unknowns.
How can Canadians be confident that their confidential information will be secure and private if your department can't even get federal organizations to follow the existing rules and policies surrounding cybersecurity?
Chief Information Officer of Canada, Treasury Board Secretariat
Thank you for the question, Mr. Chair.
Let me just say that the challenge remains that.... The Financial Administration Act, section 7, grants Treasury Board authority to apply general administrative policies, such as the policy on government security and the policy on service in digital. Those policies are applicable to departments and agencies that fall according to a certain schedule. That's how the legislative framework is set up and, therefore, we cannot impose on agents of Parliament or Crown corporations—