Evidence of meeting #9 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was meetings.

A recording is available from Parliament.

On the agenda

Members speaking

Before the committee

Walshe  Associate Head, Canadian Centre for Cyber Security, Communications Security Establishment
Arbour  Director General, Telecommunications and Internet Policy Branch, Department of Industry
Gibson  Director, Cyber Protection Policy Division, Department of Public Safety and Emergency Preparedness
Couillard  Director General, Cyber Partnerships, Canadian Centre for Cyber Security, Communications Security Establishment
MacSween  Director General, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

The Chair Liberal Jean-Yves Duclos

Once again, welcome to the four senior officials who were kind enough to stay with us for the second hour. We have two other witnesses, Bridget Walshe, associate head, Canadian centre for cyber security, and Daniel Couillard, director general, cyber partnerships, Canadian centre for cyber security.

As I understand it, Ms. Walshe, you are the only one giving a presentation, so the floor is yours. You have five minutes.

Bridget Walshe Associate Head, Canadian Centre for Cyber Security, Communications Security Establishment

Thank you, Mr. Chair.

Good afternoon, Chair and members of the committee. Thank you for inviting us today to discuss Bill C-8, an act respecting cybersecurity, amending the Telecommunications Act and making consequential amendments to other acts.

My name is Bridget Walshe. I am the associate head of the Canadian centre for cybersecurity—also known as the cyber centre—within the Communications Security Establishment Canada. I'm joined by my colleague Daniel Couillard, director general of partnerships and risk mitigation.

The Canadian centre for cyber security is Canada's technical authority on cybersecurity. We lead the government’s federal response to cybersecurity events and serve as a unified source of expert advice.

We're pleased to be here today to discuss Canada's cyber-threat landscape and the importance of cybersecurity in the context of Bill C-8.

I want to begin with a simple truth: Our world has never been more connected. From the smart phones in our pockets to the satellites orbiting above us, technology has woven itself into the very fabric of our daily lives. It powers our communications, our economies, our health care systems and even our democracies, but with this unprecedented connectivity and reliance on technology, we are exposing ourselves to its vulnerabilities. Whether it's the risk of state-sponsored cyber-threats, the exploitation of aging computer systems or the misuse of artificial intelligence, this interconnection brings with it a complex web of challenges that touch every sector and every Canadian.

Today, threat actors can bypass traditional foreign interference and espionage methods by deploying sophisticated malicious activities with unprecedented reach, all from the comfort of their home. In fact, through cybercrime-as-a-service platforms, with a few strokes on a keyboard, anyone with the means can quickly conduct large-scale campaigns that steal sensitive data, disrupt or deny services and influence public discourse.

As outlined in our 2025-26 national cyber-threat assessment, we are increasingly concerned about the enduring resilience of global cybercrime, as adversaries refine their methods, embrace new technologies and collaborate to expand their reach. I have a copy of the threat assessment report with me today available for committee members.

The evolving threat environment requires thoughtful and forward-looking measures. Strengthening Canada's cyber-defence capabilities is essential, but so is fostering meaningful collaboration between government and industry. By working together, we can move toward a more proactive approach to threat mitigation. To support this, a comprehensive incident reporting framework would help ensure that Canada remains responsive and resilient in the face of increasingly sophisticated cyber-threats.

Bill C‑8 builds on its predecessor, Bill C‑26, to advance Canada’s comprehensive, whole-of-society approach to cybersecurity.

Although CSE will gain no new authorities, this legislation will provide the government with tools and authorities to enhance cyber-defences and protect critical infrastructure. It will establish a regulatory framework for baseline cybersecurity of critical industry sectors, facilitating information sharing with the cyber centre and allowing regulators to seek CSE advice and guidance.

Bill C-8 underscores the importance of mandatory incident reporting by reinforcing the cyber centre's role in helping organizations resolve incidents and improving our collective ability to detect, respond to and prevent cyber-threats through sharing of cyber-threat information.

Incident reporting helps us to understand what transpired, share threat indicators and strengthen our defences. The information the cyber centre would receive from designated operators under Bill C‑8 is strictly technical, focusing on indicators of compromise and exploited vulnerabilities.

In closing, let me leave you with this. Cybersecurity is a shared responsibility. If there's one lesson we've learned in cybersecurity, it is that no single entity, whether an agency, a government or a company, can succeed alone.

The Chair Liberal Jean-Yves Duclos

Thank you, Ms. Walshe.

Now we'll turn to Mr. Lloyd for six minutes.

12:15 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Thank you, Chair.

Thank you to the witnesses. We had you for an hour just before this. It was in camera. We asked some good questions and we got some answers. In the interest of transparency, I'm going to re-ask similar questions and hope that we can get the same answers.

I noted that under the CSIS Act, for threat reduction measures, you have to get a warrant from the Federal Court in order to move forward. It's not clear under this legislation whether the government would need a warrant to move forward with the actions they're giving themselves the power to do. Why is that?

Andre Arbour Director General, Telecommunications and Internet Policy Branch, Department of Industry

The powers under Bill C-8 concern the ongoing regulation in terms of the security of underlying infrastructure.

In the instance of telecommunications, it's Bell's network infrastructure. They do not engage with certain charter rights or privacy considerations in that context. Similarly, that's how telecommunications operators are currently regulated. For instance, in the allocation of spectrum licences that are necessary to run their wireless networks, that's currently an authority under the Minister of Industry and there's no need for judicial oversight.

12:15 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

We talked about a specified person in the previous hour, and you told me that they're a legal entity, not necessarily a natural person.

There's a concern that.... When you have legislation that's written to say that the minister has the authority to order the telecoms to cease providing services to a specified person, there's a fear that we're talking about individual Canadians. If you believe that an individual Canadian is a threat to the telecommunications system—they're degrading the system, disrupting the system or manipulating the system—why is there no requirement for a warrant in that case?

12:15 p.m.

Director General, Telecommunications and Internet Policy Branch, Department of Industry

Andre Arbour

If I understand the question correctly, regarding the authority to withdraw services from an entity, in that context, first of all, the authorities are scoped in terms of needing to protect the Canadian telecommunications system. That means the individual commentary of Canadians or their ongoing traffic online is not germane to that in practical terms. That would be in the context, for instance, of a distributed denial of service attack, which is like flooding a network and essentially preventing the operation of it for other Canadians.

The use of that authority needs to be reasonably necessary to advance the stated goal. It can't just be on a whim. It needs to actually be tied to the gravity of the threat in question. We are dealing with circumstances where time is of the essence. These are services that Canadians rely on for life and death—to be able to call 911 or things of that nature—so there are considerations about being able to move quickly.

12:15 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Why the secrecy? Why are there secrecy provisions provided in this?

12:20 p.m.

Director General, Telecommunications and Internet Policy Branch, Department of Industry

Andre Arbour

Generally speaking, the secrecy provisions are both not necessary and not operationalizable. When we're dealing with equipment that applies to all telecom carriers, 99.9% of the time we'll be going out with a public consultation with rules, and we want everyone to know the rules of the road.

There can be some specific circumstances where, for instance, an operator has a vulnerability in their network—it's very specific—where disclosing that vulnerability would essentially invite hackers to flood the zone while that operator is trying to get that under control. That's the use case for the confidential order-making provision.

It does include oversight—for instance, notification requirements to NSIRA and NSICOP so that they have line of sight and can ensure that the power is being used appropriately. It's also subject to annual reports to Parliament.

Even though—

12:20 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Is there an opportunity for judicial review if somebody feels that these decisions are infringing on their charter rights?

12:20 p.m.

Director General, Telecommunications and Internet Policy Branch, Department of Industry

Andre Arbour

Certainly anyone can go to the courts with an application of judicial review and—

Dane Lloyd Conservative Parkland, AB

What if it's secret, if they've been ordered not to say anything? How would they go to the courts?

12:20 p.m.

Director General, Telecommunications and Internet Policy Branch, Department of Industry

Andre Arbour

We still need to consult the affected parties. That's a provision of the bill, and it's also a bedrock provision of administrative law.

The entity affected still needs to have the opportunity to make their case about how the order may affect them, and they can go to the court. There is also, again, the notification to review bodies and the annual report to Parliament, which, even if it doesn't disclose the detailed nature of the order, still needs to describe the activities, as well as their necessity.

12:20 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Is there a time limit on those things? It says specified time.

12:20 p.m.

Director General, Telecommunications and Internet Policy Branch, Department of Industry

Andre Arbour

We have 90 days to notify NSIRA and NSICOP, and the report to Parliament is tabled annually.

12:20 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Thanks.

The Chair Liberal Jean-Yves Duclos

Thank you, MP Lloyd, for these good questions.

Let me turn now to MP Acan for six minutes.

Sima Acan Liberal Oakville West, ON

Thank you, Mr. Chair.

Thank you for being with us today.

I was going to ask this of Ms. Walshe, but Mr. Arbour and Mr. MacSween can contribute to the answers.

Canadian companies have been using offshoring, development outside of Canada. The critical cyber systems protection act part of Bill C-8 establishes a fundamental requirement for designated operators who manage vital services such as telecommunications, banking and energy to mitigate supply chain and third party risks.

If, so far, development is being offshored, the responsibility should still be on the Canadian company that ordered the development, and they should scan and verify the product they receive before they deploy it to production.

How does placing the explicit responsibility on Canadian companies, the designated operators, to establish and maintain comprehensive cybersecurity programs, including steps to identify and manage risk associated with the designated operator supply chain and its use of third party products and services, ensure compliance with high Canadian security standards, regardless of the physical location of the development or of the support team?

Kelly-Anne Gibson Director, Cyber Protection Policy Division, Department of Public Safety and Emergency Preparedness

I think this gets to a really important aspect of the bill. As you say, the obligation is on the designated operator to make sure that any third party services or products they use are up to a reasonable standard to mitigate those risks.

The way this would work is that the designated operator would have a cybersecurity program in place. They would have a plan for how they mitigate those risks, which means they would have a plan for how they would assess the various services and products that they might contract to be used in their networks.

There's advice and guidance that comes from the cyber centre, and they can use that advice and guidance to understand how best to identify the products and services that will maintain the safety and integrity of their network.

One element of this that will help the cybersecurity ecosystem writ large is that it means that companies that are selling their products and services to critical infrastructure will have to make sure that their products are secure by design and that they're not rushing to market and fixing potential flaws after the fact.

Sima Acan Liberal Oakville West, ON

Thank you.

In addition to the general risk mitigation, foreign state actors and entities from high-risk countries pose direct threats to our national security.

How do the expanded emergency powers granted to the Governor in Council under part I of the Telecommunications Act—specifically the power under the proposed new section 15.1 to “prohibit a telecommunications service provider from using all products and services provided by a specified person” and to direct their removal—provide the government with the precise and necessary tool to safeguard the Canadian telecommunications system against interference, manipulation, disruption or degradation?

12:25 p.m.

Director General, Telecommunications and Internet Policy Branch, Department of Industry

Andre Arbour

There are products and services that can be under the control of a hostile adversary, either in terms of the producer of those products and services being subject to extrajudicial oversight or in terms of other means by which they could be used to infiltrate Canadian infrastructure.

In that context, especially given that software is increasingly important, risk mitigation may not be possible in using that equipment or service. Therefore, the authority in question gives the government the ability to restrict its use entirely or to have it removed from the Canadian telecommunications system.

Sima Acan Liberal Oakville West, ON

Thank you very much.

Considering the scenario where foreign support teams remotely access the runtime environments, it is critical that they adhere to the same mandatory security posture as Canadian employees, ensuring competitive fairness across the sector.

Since designated operators must integrate steps into their cybersecurity programs to protect critical cyber systems from being compromised, how does the implementation of mandatory security standards and risk mitigation measures address the concern that companies utilizing international supply chains might otherwise gain an unfair economic advantage by circumventing necessary domestic cybersecurity costs?

12:25 p.m.

Director, Cyber Protection Policy Division, Department of Public Safety and Emergency Preparedness

Kelly-Anne Gibson

If I understand the question, you're asking how a company would manage the financial aspect of having to mitigate these risks and whether it puts them at a competitive disadvantage. Is that right?

Sima Acan Liberal Oakville West, ON

That's correct.

12:25 p.m.

Director, Cyber Protection Policy Division, Department of Public Safety and Emergency Preparedness

Kelly-Anne Gibson

The bill itself does not directly address that. However, what we have looked at, in the context of this bill, is trying to ensure that we create a cybersecure environment in a way that does not put undue burden on industry. In this particular case, having a cybersecure environment is important because the bigger risk is an incident. One incident can outweigh years of profits and, frankly, can incur so much damage that it would eclipse the expense of trying to keep the environment secure from the get-go.

The bill does not address this directly, but it is meant to protect the Canadian economy and the industries themselves in that way, just because the threat and the cost of a cybersecurity incident are so high, if it were to materialize.