The House of Commons Standing Committee on Public Accounts met to study the cybersecurity of government networks and systems, based on the fall 2025 reports of the Auditor General of Canada. Appearing were Andrew Hayes (Deputy Auditor General) and Jean Goulet (Principal) from the Office of the Auditor General; Dominic Rochon (Chief Information Officer of Canada) and Po Tea-Duncan (Chief Information Security Officer) from the Treasury Board Secretariat; Scott Jones (President) from Shared Services Canada; and Caroline Xavier (Chief) and Rajiv Gupta (Head, Canadian Centre for Cyber Security) from the Communications Security Establishment.
Andrew Hayes stated that the audit found gaps in cybersecurity defence services, monitoring, and response during active attacks, noting that only 42% of federal organizations are required to use defence services, which undermines the government's ability to protect critical information. He highlighted that poor coordination delayed the response during a major attack two years ago, and that a lack of a comprehensive inventory of IT devices risks an inability to respond quickly to the changing cybersecurity landscape.
Dominic Rochon said the Treasury Board Secretariat welcomes the Auditor General's recommendations and is working with partners to implement them, including ensuring federal organizations install cyber-defence sensors on all endpoints and improving incident management coordination. He noted that budget 2024 provided $11.1 million for a whole-of-government cybersecurity strategy, including a purple team to proactively test security gaps, and that the government regularly reviews its Cybersecurity Event Management Plan through tabletop exercises.
Scott Jones stated that Shared Services Canada blocks about 6.5 trillion cyber-threats annually and is working to provide connectivity and security services to 43 small departments by March 2027. He noted that the endpoint visibility, awareness, and security (EVAS) project, which was delayed, has turned a corner with over 36,000 deployments since July 2025, and that a contract for a security information and event management system is on track for early 2026.
Caroline Xavier said the Communications Security Establishment produced over 3,300 foreign intelligence reports and responded to over 2,500 cyber-incidents in 2024-25, and that its cyber-defence sensors program provides real-time detection of malicious activity. She welcomed the Auditor General's recommendations and said CSE is working with partners to expand sensor deployment and refine incident response protocols, emphasizing that cybersecurity is a shared responsibility.
Po Tea-Duncan explained that the purple team proactively tests controls as a preventative measure, and that guidelines on vulnerability management help departments identify and mitigate vulnerabilities. She noted that the Treasury Board Secretariat is working with partners to help departments prioritize which vulnerabilities to address within the ecosystem.
Rajiv Gupta said the Canadian Centre for Cyber Security tracks threat actors globally and uses intelligence to stay ahead of evolving threats, including through innovation workshops and collaboration with Five Eyes partners. He noted that AI is democratizing cyber capabilities, and that the centre provides advice and guidance on securing AI and connected devices, including electric vehicles.
Jean Goulet stated that the audit observed a high level of co-operation among the three entities, but that there is room for improvement, particularly regarding delayed projects important for cybersecurity. He did not disagree with any other witness.
The committee debated the implications of the Prime Minister's recent announcement of a Canada-China strategic partnership, with Conservative members expressing concern about cybersecurity risks from Chinese state actors and the import of Chinese electric vehicles. Liberal members emphasized the need to diversify trade while maintaining robust cybersecurity, and noted that the Auditor General found the government's cybersecurity strategy to be sound and comprehensive. No motions or votes were recorded.
AI-generated summary — may contain errors; verify against the official evidence.