Thank you, Mr. Arbour.
Ms. Walshe, we haven't talked about the impact of cyber-threats and ransomware attacks. Currently, what is the financial toll on Canadians?
Evidence of meeting #9 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was meetings.
A recording is available from Parliament.
Liberal
Marianne Dandurand Liberal Compton—Stanstead, QC
Thank you, Mr. Arbour.
Ms. Walshe, we haven't talked about the impact of cyber-threats and ransomware attacks. Currently, what is the financial toll on Canadians?
Associate Head, Canadian Centre for Cyber Security, Communications Security Establishment
Thank you very much for the question.
I will answer in English.
It's difficult to measure the impact that cybercrime has on Canadian organizations, for a few reasons, but we know that the impact is large.
From a financial perspective, we do know that Canadian organizations make payments to crimeware groups that total in the hundreds of millions of dollars, but not all of those figures are reported to us. To understand the complete impact.... We have incomplete information.
We also know that it's not just the impact of a payment that somebody makes to a criminal that has a financial cost to an organization. It's also the loss in productivity and the recovery from those attacks that are quite expensive.
Those sorts of figures are also difficult to understand because those are things that a private enterprise may disclose as part of its public reporting or that may be kept private, so it's difficult to say.
Liberal
The Chair Liberal Jean-Yves Duclos
Thank you, Ms. Walshe. That's all the time Ms. Dandurand has.
Mrs. DeBellefeuille, you may go ahead for two and a half minutes.
Bloc
Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC
Thank you, Mr. Chair.
I commend you, Mr. Arbour, for answering questions in French. It's always a bit disappointing when senior officials aren't proficient in both official languages. As a francophone, I must tell you how happy it makes me to hear you answering questions in French. It shows that you are fluent.
I have a short question about providers. You mentioned big providers like Bell. However, many small businesses are involved in bringing high-speed Internet to small, rural communities. Where I'm from, for example, we have Targo and the co-op CSUR.
Do you think those small providers are equipped to meet the requirements in Bill C‑8? Can they afford it? Are there any plans to provide them with support?
October 28th, 2025 / 12:45 p.m.
Director General, Telecommunications and Internet Policy Branch, Department of Industry
The Department of Industry is used to working with small telecommunications service providers. One of our objectives is to support these types of operators to promote competition within sectors and expand networks in rural and remote areas. It's important for us to establish rules that match the skills of service providers of all sizes, even small businesses.
For example, during the spectrum auction, we set rules specific to small service providers. The same goes for the implementation of this bill. For example, in our consultations, we take into consideration the time needed to achieve the objective of a regulation based on the size of the supplier. The large players have a certain level of systematic risk compared to a small provider that serves 500 consumers.
Liberal
The Chair Liberal Jean-Yves Duclos
Thank you. I'm sorry, Mrs. DeBellefeuille, but your time is already up.
Mr. Lloyd, you have the floor for five minutes.
Conservative
Dane Lloyd Conservative Parkland, AB
Thank you.
There have been some groups, such as the Canadian Civil Liberties Association, that have talked about encryption standards. There's a fear that this legislation will give unprecedented powers to break encryptions.
Is there anything specific in this bill that deals with encryption-breaking powers?
Director General, Telecommunications and Internet Policy Branch, Department of Industry
There isn't a specific provision governing encryption; however, the ability to break encryption for the purpose of surveillance is out of the scope of the powers here.
Being able to access individual information for the purpose of law enforcement is certainly an important issue. It's a very hotly discussed topic. We've seen it in Bill C-2, for instance. It is deliberately out of the scope of this bill. For instance, breaking encryption does not advance the protection of telecommunications network infrastructure. It has nothing to do with that.
Conservative
Dane Lloyd Conservative Parkland, AB
Thank you for that clarification.
I think the argument that has been advanced.... I apologize to these organizations if I've mislabelled their argument. They talk about the wording that the minister can order the telecoms “to do anything, or refrain from doing anything”, and they're saying that's a very broad power that could lead to the breaking of encryption.
Can you describe why that power has been worded like that? I even thought to myself that this seems like very interesting wording to use, “to do anything, or refrain from doing anything”. It seems very broad.
Director General, Telecommunications and Internet Policy Branch, Department of Industry
The wording is meant to capture the range of risks to the telecom infrastructure that can exist. For instance, one may want to tell a service provider that they cannot use a particular product or a service in their network, or that they need to take some positive action to protect their network.
A bedrock principle of statutory interpretation is that you need to look at the bill as a whole. For instance, the policy objective, at the outset, sets the overall scoping. There are additional requirements—for instance, that the order-making power needs to be reasonable to the gravity of the threat, etc. Those all still apply and structure the government's ability to act.
Conservative
Dane Lloyd Conservative Parkland, AB
Thank you.
We've talked about personal data. You've said it's outside the scope of this. We've gone over that. However, the intelligence commissioner has stated in testimony that this power of the minister to ask the telecoms to do something or refrain from doing something could give them the ability to ask telecom providers to provide the private information of Canadians. I believe the Privacy Commissioner has also raised this concern.
Can you elaborate on those concerns? Is that a concern, and if not, why not?
Director General, Telecommunications and Internet Policy Branch, Department of Industry
The information collection authority in part 1 is modelled on the existing section 37 of the Telecommunications Act, which has been in place for decades without incident. It's just carried forward, because it needs to be applied to the new security network protection authorities. It is still structured within the scope of what can be done to protect the Canadian telecom system, and not to advance general security or law enforcement aims. It is still limited to the order-making authorities and the protection of Canadian telecom systems. It cannot be used to advance a generalized fishing expedition or investigation into personal information.
Conservative
Dane Lloyd Conservative Parkland, AB
Thank you.
Finally, how is it determined that the minister's decision, under this power, is reasonable? Who determines if it's a reasonable thing that the minister has done?
Director General, Telecommunications and Internet Policy Branch, Department of Industry
First, there is consultation on the rules. We are required to take into consideration what those views are. There are notification and transparency requirements after the fact. Then, ultimately, all decisions of the minister are reviewable by the courts. The telecom operators are not shy to go to the courts. They are well resourced and frequently make use of that avenue.
Liberal
Liberal
Ali Ehsassi Liberal Willowdale, ON
Thank you, Mr. Chair.
Thank you, witnesses, for your very comprehensive responses.
Does this legislation now make it mandatory for all these operators to report every single breach they may experience?
Colin MacSween Director General, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness
The mandatory reporting requirement appears in part 2 of the act. The answer to your question is no. The intention there is that the legislation will set out the requirement for mandatory reporting, and then the regulations will define exactly what that looks like.
I mentioned earlier that we have had some discussions with Five Eyes counterparts about what their mandatory regimes look like. Those have been specifically on the threshold for reporting. Our colleagues from the cyber centre certainly aren't interested in receiving information on every single cyber-incident. A lot of those are day-to-day things everybody experiences that we have good traction on. What we want to understand is when there's an incident that has a certain level of significance. That's what we want reported to the cyber centre.
Liberal
Ali Ehsassi Liberal Willowdale, ON
Thank you.
Then there's the mention of AMPs in this legislation. Do we have any sense yet of what the highest administrative monetary penalties would be?
Director, Cyber Protection Policy Division, Department of Public Safety and Emergency Preparedness
Yes. It's in the bill. I'm sorry, but I don't remember the exact number. I can tell you that because this is a cross-sectoral framework and different industries have different thresholds, it's set high, but it will be set within a range that is typical for the industry being regulated.
Liberal
Ali Ehsassi Liberal Willowdale, ON
Thank you very much.
I have one last question, if I may. In the information you've provided to us, it says, “Cyber incidents cost Canada’s economy $5 billion annually, with Canadian businesses paying nearly $7 million per data breach.” Could you just roughly tell us why these data breaches cost companies so much? Are these attempts to pay customers because there have been privacy breaches? Why is it so large?
Director, Cyber Protection Policy Division, Department of Public Safety and Emergency Preparedness
There are a number of factors.
If you have a breach, a cyber-incident, your data can be compromised, so the first thing that happens is that you have to figure out what has been compromised. That can be incredibly expensive, because you have to bring in experts to understand what exactly is going on with your network. What's been compromised, and what's potentially been exfiltrated?
Then, you have to start putting in place remedies, and not only from the technical perspective. You also have to start looking at your regulatory responsibilities. Are you now not in compliance? There are privacy laws that are going to come into play, such as PIPEDA, the Privacy Act and all those types of things. There are notifications. There are lawyers and breach coaches who get involved. The costs mount.
The other piece, which is a little more intangible, is simply the reputational cost. Often, these will eventually become public, and you potentially begin losing customers. That's how the costs start multiplying very quickly.
Associate Head, Canadian Centre for Cyber Security, Communications Security Establishment
I might add to that a little bit.
From a technical perspective, it's the enormous expense that's paid, as my colleague pointed out, to remediate the situation immediately, but it's also the enormous cost of rebuilding and the losses in revenue that a business may have while that rebuilding occurs. We know that there's a huge cost incurred, not just in the immediate aftermath of the incident but also in rebuilding the technology to get back up and running.
Liberal
The Chair Liberal Jean-Yves Duclos
Thank you so much.
Witnesses, I want to thank all six of you for being here. We're grateful not only for your presence, but also for your preparation for this important meeting. We hope you have a great day.
I invite committee members to stay for a few moments while we finish this meeting.
Mr. Ramsay, the floor is yours.
Liberal
Jacques Ramsay Liberal La Prairie—Atateken, QC
I'd like to propose two motions.
The first one relates to Bill C-12:
That, in relation to the study of Bill C-12:
The committee invite members to submit witness lists to the clerk of the committee no later than October 29, 2025, at 5:00 p.m.;
That's tomorrow.
That the committee schedule four meetings to hear from witnesses; invite the Minister of Public Safety to appear and invite relevant officials;
And that the committee conduct clause-by-clause consideration of the bill after the conclusion of witness testimony on the fourth meeting, and that the committee does not adjourn until clause-by-clause has completed.
That's the first motion.
Liberal