Evidence of meeting #22 for Public Accounts in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was cyber.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Hayes  Deputy Auditor General, Office of the Auditor General
Rochon  Chief Information Officer of Canada, Treasury Board Secretariat
Jones  President, Shared Services Canada
Xavier  Chief, Communications Security Establishment
Tea-Duncan  Chief Information Security Officer of the Government of Canada, Treasury Board Secretariat
Goulet  Principal, Office of the Auditor General
Gupta  Head, Canadian Centre for Cyber Security, Communications Security Establishment

11:25 a.m.

Conservative

Stephanie Kusie Conservative Calgary Midnapore, AB

That's not very efficient or effective if you can't impose—

11:25 a.m.

Conservative

The Chair Conservative John Williamson

Ms. Kusie, I'm afraid that is your time. We will certainly come back to you.

Stephanie Kusie Conservative Calgary Midnapore, AB

Thank you, Chair.

11:25 a.m.

Conservative

The Chair Conservative John Williamson

Next is Ms. Yip.

You have the floor for six minutes, please.

Jean Yip Liberal Scarborough—Agincourt, ON

Thank you. Happy new year.

Thank you to our witnesses for coming in on a slight snow day here in Ottawa. I'll just note that Toronto has 45 centimetres of snow. It's rare that we out-snow Ottawa.

Voices

Oh, oh!

Jean Yip Liberal Scarborough—Agincourt, ON

I'm going to direct this question to all three organizations. How is your organization working on improving collaboration among all three of you? What steps have you taken that will help to protect Canadian national security?

Mr. Jones, would you like to go first?

11:25 a.m.

President, Shared Services Canada

Scott Jones

Sure. Thank you for the question.

I think there are a few areas where we're making progress.

The first thing is that there's been a base of collaboration for over a decade as we've built up this robust system of defences, and those are relationships. As much as I'm supposed to be leading a technology organization, effective cyber-response is about building those relationships and the trust, because a lot of times it's a judgment call until you know for certain. That is the first thing.

The second piece is that we are exercising. Mr. Rochon talked about the purple team and some of the other pieces that have been put in place lately as exercises. One of the consequences of having a robust defence mechanism is that.... When I first started working on cybersecurity with Mr. Gupta about 14 or 15 years ago, we were having incidents happening every day that we were responding to. Now our systems take care of a lot of these things proactively, and these big incidents that we've talked about don't happen often. You have to continue to practise so that those muscles stay able to work.

Those are a couple of the things we're doing.

The third thing is that in every single incident there's always something that we can learn from. We do a full after-action review that's led by my colleagues at Treasury Board. I'll let them speak to this, but that's very important. Even when it goes very well, what could have been done better? What could have been done more quickly? What could we learn from this?

There always has to be one, and sadly, with cybersecurity, there usually is a first victim. Our goal together is to make sure there's never a second.

11:30 a.m.

Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

Maybe I can elaborate.

It is indeed a team game. As Madame Xavier pointed out in her opening remarks, there's no one entity in cybersecurity. We form a tripartite in terms of protecting systems across the federal enterprise.

At Treasury Board Secretariat, we put in place rules. Indeed, we've promulgated a cybersecurity enterprise strategy for the federal government. We provide advice and guidance. Also, as Mr. Jones just alluded to, we have a Government of Canada security event management plan that is indeed followed, so that when there's a critical incident we understand roles, responsibilities, etc.

As the Auditor General pointed out, there are some shortcomings with regard to that coordination. Despite the fact that we meet regularly and we're constantly coordinating, there are certain things that we can do better. Last May, we put in place for the first time a simulation exercise at the executive level, touching several departments and agencies. Drawing from the lessons learned from that exercise, we're going to be updating our security event management plan, among other things. We also keep our policies and our strategy evergreen. We learn, as Mr. Jones just pointed out, from any critical incident.

In terms of our coordination efforts, they go from managing the policies to the direction and the guidelines. It's also a partnership with every department and agency. Each has to have a designated person responsible for cybersecurity and for making sure that they understand and interpret our rules and are putting them in place.

Mr. Jones and his organization are responsible for connections to the Internet and all of the infrastructure side of things. Then we have the special sauce, if you will, of the cybersecurity centre led by Mr. Gupta, which, above and beyond putting in place sensors, is doing all sorts of monitoring and connecting with the rest of the Communications Security Establishment to make sure we stay on top of the threat.

11:30 a.m.

Chief, Communications Security Establishment

Caroline Xavier

The only other thing I would add is the fact that, as I said earlier in my remarks, all that we do to provide advice, guidance and direction is definitely fed from an intelligence perspective. That is helpful, in addition to the learnings we are taking from all incidents that are occurring. As a learning organization, we strive to always do better. As was mentioned by Scott, we continue to apply those learnings. I would also add that as a tripartite, and in the way in which government has organized us in the cyber-defence space, we are the envy of many in terms of how this functions.

This is why I'm pleased about the fact that we have the sensors that we have to be able to be automated and be able to act on our behalf 24-7. We can then dive deeper into them when major incidents happen.

Jean Yip Liberal Scarborough—Agincourt, ON

Why are we the envy of others?

11:30 a.m.

Chief, Communications Security Establishment

Caroline Xavier

It is primarily because of the fact that Shared Services Canada does a great job of coordinating all that it does with regard to providing a centralized service to many of our government departments. Anybody getting the shared services is then protected by the sensors, because that is part of the standard rollout when it comes to working for the Government of Canada and the Government of Canada systems that Scott Jones protects.

Scott, feel free to add more there. We've heard that, for example, the U.K. Parliament has touted the Government of Canada's world-class sensor system as one of the sensors it recognizes as being world-class.

11:30 a.m.

Conservative

The Chair Conservative John Williamson

Thank you, Ms. Yip.

That's about your time. I'll give you a few extra seconds next time.

Mr. Lemire, good morning. You have the floor for six minutes.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

Thank you, Mr. Chair.

I would like to take this opportunity to wish you a very happy 2026. I believe it will be a very promising year for the public accounts. At least, we hope so.

Thank you to all the witnesses for your participation, and I apologize for the delay. Parliament sometimes calls on us. It’s part of our job.

I would first like to mention that the Royal Canadian Mounted Police, Public Safety Canada, Global Affairs Canada, the Financial Transactions and Reports Analysis Centre of Canada, and the Canadian Centre for Cyber Security issued a notice on July 16, 2025, stating that hostile agents deployed by the North Korean government could pose as information technology workers.

Ms. Kelly Hutchinson, a digital government and procurement strategist with the Compass Rose Group in Ottawa, pointed out that the North Korea case was just a drop in the ocean of this problem.

For his part, Aaron Shull, research director at the Centre for International Governance Innovation, pointed out that Canada’s reliance on outsourced labour from abroad, coupled with inconsistent security and identity checks, could create real avenues of attack by gaining access to sensitive data, thereby enabling espionage. He even mentioned the possibility of inserting malicious code into government systems and software.

Ms. Xavier, from the Communications Security Establishment, I would like to know your thoughts on the comments made by Ms. Hutchinson and Mr. Shull. Does outsourced labour abroad constitute a risk that should be thoroughly analyzed in a cybersecurity strategy?

11:35 a.m.

Chief, Communications Security Establishment

Caroline Xavier

Thank you for the question.

It is important to emphasize, as we did in our cyber-threat assessment published in October 2024, that we recognize that we face cyber-threats from states. One of the states that was named is China, but we also named the Democratic People’s Republic of Korea in our assessment, as well as Russia and others.

So, yes, we support the advisory that was issued, because it was issued in collaboration with us and the Communications Security Establishment, which includes the Canadian Centre for Cyber Security. This type of advisory is a way for us to ensure that we are all on the same page and that we can provide good advice and guidance so that the Canadian government can be prepared.

However, when we issue such an advisory, it is not just to protect the government. We also want to ensure that Canadians and critical infrastructure operators are aware. When it comes to cyber-threats, it is not just the government that is targeted when someone wants to harm Canada.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

Obviously, we are very vulnerable to the United States, and signing an agreement with China to import Chinese vehicles is not going to help us keep our data at home.

That said, my next question is for Mr. Rochon or Mr. Jones.

The government hires many self-employed workers and contractors. Ms. Hutchinson’s question is an interesting one. What is the government doing to authenticate individuals and ensure that they are who they say they are, in an era where identity fraud is facilitated by deepfakes and other tools? What measures have you put in place?

11:35 a.m.

Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

We have implemented security measures. Subcontractors must be authorized to work for the federal government. They go through different levels of verification depending on what they will have access to. There are rules in place to justify and certify their presence.

In short, the problem is that the threat will always be present. It is impossible to guarantee at all times that we have covered everything, so we put rules in place. We have implemented a mandatory course that all public servants must take each year. We have implemented a vulnerability management program where we are looking at the risks and following up on them. We have set up both a red and blue team of various cybersecurity professionals, as I mentioned.

Ms. Tea‑Duncan, would you like to elaborate on these points?

Po Tea-Duncan Chief Information Security Officer of the Government of Canada, Treasury Board Secretariat

Thank you for the question.

The purple team allows us to effectively test in advance some of the techniques of bad actors. It helps us to put in place the right detection and protective measures to make sure that we are all staying ahead of the cyber-threats.

Part of the policy on government security ensures that departments and agencies are putting in place the right baseline security controls. Cybersecurity is all about layers of controls—such as cyber-sensors that are put in place on end points in the network—but it's also about the protection of data within our information systems. That's outlined under the policy on government security.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

One of the things we realize about front companies is that companies claim to be indigenous, but ultimately they are not. Because of subcontractors, you never know who is actually doing the work, especially when it is sent to India or other countries to be done at low cost. You realize that you are extremely vulnerable. We send them our data. Is there a mechanism to ensure that the work is done by people from Canada, in Canada? Does this exist, or is it acceptable for gateways to be provided all over the world?

11:40 a.m.

Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

That’s an interesting and difficult question.

Each department and deputy minister is responsible for determining how to implement its programs. At the Treasury Board Secretariat, we are putting guidelines in place so that they are aware that risks exist. We need to look at the nature of the work and the systems they will have access to. If they have access to systems, that’s where we, who are here before you today, have a role to play. There are also issues from the perspective of equipment supply chains.

For all these things, we have rules in place, as well as procedures for follow-up. Ultimately, it’s also a team effort in the sense that each department must ensure that it follows our rules, and we must be aware of access to our systems and the nature of the work done by these departments.

Sébastien Lemire Bloc Abitibi—Témiscamingue, QC

Thank you, Mr. Rochon.

11:40 a.m.

Conservative

The Chair Conservative John Williamson

Thank you very much, Mr. Lemire.

We will now begin the second round of questions.

It consists of five members with various times.

Mr. Deltell, you have the floor for five minutes.

11:40 a.m.

Conservative

Gérard Deltell Conservative Louis-Saint-Laurent—Akiawenhrahk, QC

Thank you very much, Mr. Chair.

Good morning to all my colleagues.

Happy new year 2026 to everyone here and, of course, to all Canadians who follow our work.

Ladies and gentlemen, thank you very much for being here and thank you very much for serving our country, your country, in a situation as delicate as cybersecurity.

Mr. Chair, we Conservatives have very serious concerns about cybersecurity, particularly with regard to the Beijing regime. My colleague Mrs. Kusie, who is a career diplomat, shared her personal story earlier. I have been spared so far, as perhaps many people here have, but no one is ever safe from this.

Ms. Xavier, in response to my colleague Mr. Lemire’s question, you mentioned cyber-attacks and cyber-threats from states. Spontaneously, the first country you identified was the Beijing regime. Could you tell us more about that?

11:40 a.m.

Chief, Communications Security Establishment

Caroline Xavier

Thank you for the question.

I did not necessarily mention the Beijing regime first on purpose. I just wanted to mention that in our cyber-threat assessment published in the autumn of 2024, which is valid for two years, we clearly stated that we see certain states taking an interest in Canada. Yes, we name China, but we also name other actors such as Iran and Russia, among others.

With regard to our assessment of cyber-threats at the time, we certainly said that China is indeed a very sophisticated and capable actor. However, that does not always mean that, even if it is a Chinese actor, it is necessarily linked to the state. We know that there are also cyber-criminals. In fact, in the same publication, we said that the actions of cyber-criminals are also significant in terms of cyber-threats to Canada and around the world.

We have published several other documents in which we have said that we have seen actors. This is part of what we do to try to ensure that Canada and critical infrastructure are aware of how to protect themselves.

11:40 a.m.

Conservative

Gérard Deltell Conservative Louis-Saint-Laurent—Akiawenhrahk, QC

As you said, there are actors, but they are not necessarily linked to the state. However, when we talk about a totalitarian state, it is difficult to view these actors as autonomous. Rather, we see them as actors directly linked to the state, particularly the Beijing regime. You may have noticed that I am careful not to identify the country so as not to stigmatize Canadians who come from that country. For us, the problem is the Beijing regime, not its citizens.

In this regard, I cannot ignore the fact that on this side of the House, we are very concerned about the Prime Minister’s visit to the Beijing regime last week. All of our grievances and contentious issues regarding security and human rights seem to have evaporated. That is unfortunate, and we are very concerned about this approach. That is a political point of view, and I have no right to question you on that.

Mr. Rochon, earlier, in response to a question from a colleague, you said that it was a team effort. You have three entities here in Canada, namely the Communications Security Establishment, Shared Services Canada and the Treasury Board Secretariat.

Mr. Goulet, do you feel that these three entities work in coordination or in isolation? This is not a question of blame, but rather one of efficiency. With technology evolving at breakneck speed, do you feel that improvements could be made to ensure that information is shared more widely?