A recent report from the federal auditor general highlighted significant deficiencies in the federal government’s response to the escalating number of harmful cyberattacks. The report, presented in the House of Commons, exposed inadequate coordination among agencies responsible for safeguarding the government’s IT systems during cyber assaults, leading to delays that facilitated unauthorized access to personal data.
According to the audit, the three key agencies overseeing cyber defense—Treasury Board of Canada Secretariat, Communications Security Establishment Canada (CSE), and Shared Services Canada—possessed the necessary tools to shield government networks from cyber threats. However, Auditor General Karen Hogan noted that not all departments, agencies, and Crown corporations were utilizing the available cybersecurity services, indicating shortcomings in collaboration and information sharing during cyber incidents.
The audit revealed that CSE thwarted approximately 2.4 trillion suspicious cybersecurity events between April 2023 and March 2024, while Shared Services Canada intercepted around 6.6 trillion suspicious events from October 2023 to September 2024. Despite these efforts, notable breaches occurred in the past. For instance, a breach at the National Research Council Canada in 2014 resulted in substantial intellectual property loss and incurred an estimated $100 million in remediation costs.
The report highlighted inconsistencies in the adoption of cybersecurity tools across federal organizations, with some entities failing to fully leverage critical services. While CSE’s sensors were deployed by all mandated organizations, a notable percentage did not utilize Shared Services Canada’s secure internet connection. This uneven utilization of cybersecurity services hindered the government’s ability to promptly detect and counter cyber threats effectively.
Moreover, the audit underscored deficiencies in inter-agency coordination during cyber incidents, leading to delays in responding to security breaches and potential data compromises. Inadequate protocols for information sharing between agencies prolonged response times, allowing attackers extended access to sensitive information. The report recommended a reassessment of cybersecurity incident management practices by the relevant departments to enhance response efficiency.
Shared Services Canada and CSE were also criticized for lacking comprehensive inventories of government IT devices, hindering efforts to assess vulnerabilities and mitigate cyber risks effectively. Despite ongoing initiatives to address these gaps, the completion timeline for inventory management remains uncertain. In response, officials emphasized their commitment to investing in advanced monitoring and threat detection capabilities to bolster cybersecurity measures and ensure public trust in government institutions.
CSE’s warnings regarding sophisticated cyber threats from countries like China, Russia, Iran, North Korea, and India underscore the pressing need for robust cybersecurity measures to safeguard critical government information and infrastructure.
