Â鶹´«Ã½

Skip to main content

Security committee finds gaps in federal cyberdefences that place vital data at risk

Chair David McGuinty speaks about the Annual Report of the National Security and Intelligence Committee of Parliamentarians during a news conference in Ottaw on April 9, 2019. THE CANADIAN PRESS/Adrian Wyld Chair David McGuinty speaks about the Annual Report of the National Security and Intelligence Committee of Parliamentarians during a news conference in Ottaw on April 9, 2019. THE CANADIAN PRESS/Adrian Wyld
Share
OTTAWA -

The committee of MPs and senators which oversees federal security policy has uncovered gaps in Canada's cyberdefences that could leave many agencies vulnerable to state-sponsored hackers from countries like China and Russia.

In a new report, the National Security and Intelligence Committee of Parliamentarians says cyberthreats to government systems and networks are a significant risk to Canada's security and government operations.

It points to Beijing and Moscow as the most sophisticated cyberthreat actors targeting the government, while Iran and North Korea have moderately advanced capabilities and pose less of a danger.

The committee says although nation states represent the most highly developed threats, any player with malicious intent and sophisticated capabilities puts the government's data and the integrity of its electronic infrastructure at risk.

The report concludes the federal government has built a strong cyberdefence system to counter this threat over the last decade.

However, it is weakened by the inconsistent application of policies and use of cyberdefence services across government.

The report, tabled in Parliament late Monday, is a redacted version of a classified document submitted to Prime Minister Justin Trudeau last August.

Governments are highly attractive targets for cyberattacks, the report says.

"The federal government holds enormous amounts of data about Canadians, Canadian businesses and innovative sectors such as universities and research institutes. Cyber compromises of this data could reveal sensitive personal information of Canadians and sap the vitality of individual companies and of the economy."

The government also manages foreign, trade and security relations through electronic infrastructures that, if compromised, could damage federal policies and undermine Canada's vital interests, the report adds.

It provides new details about the sweeping nature of an early attack by a Chinese state-sponsored attacker that served as a "wake-up call" for the federal government.

Between August 2010 and August 2011, China targeted 31 departments, with eight suffering severe compromises. Information losses were considerable, including email communications of senior government officials and mass theft of information from several departments, such as briefing notes, strategy documents, secret material, and password and file system data.

The report also reveals new information about a debilitating 2014 attack on the National Research Council, saying a Chinese state-sponsored actor used its access to the network to steal more than 40,000 files.

"The theft included intellectual property and advanced research and proprietary business information from NRC's partners. China also leveraged its access to the NRC network to infiltrate a number of government organizations."

It cost more than $100 million to deal with the problem.

Three organizations, the Treasury Board of Canada Secretariat, Shared Services Canada and the Communications Security Establishment, work closely together -- and with other government departments -- on federal cyberdefences, the report says.

Ideally under the system, government networks fall within a single electronic perimeter with a handful of access points to the internet that are monitored by sophisticated sensors capable of detecting and blocking known threats.

Departments should continually update and patch their devices and systems under the co-ordinated direction, advice and guidance of the three organizations, the report adds.

However, the current cyberdefence system "has not yet achieved this ideal."

The key weaknesses include:

-- Treasury Board policies relevant to cyberdefence are not applied equally to departments and agencies, creating gaps in protecting government networks from cyberattack;

-- Crown corporations are known targets of state actors, but are not subject to Treasury Board cyber-related directives or policies and are not obligated to obtain cyberdefence services from the government, placing their data at risk; and

-- Cyberdefence services are provided inconsistently, meaning, for instance, many agencies do not benefit from Shared Services Canada's full complement of assistance.

"The threat posed by these gaps is clear," the report says. "The data of organizations not protected by the government cyber defence framework is at significant risk."

Moreover, unprotected organizations potentially act "as a weak link" in the government's defences by maintaining electronic connectivity to organizations within the cyberdefence framework, creating risks for the government as a whole.

In responses included in the report, the government agreed with the committee's various recommendations to address the deficiencies.

This report by The Canadian Press was first published Feb. 15, 2022.

IN DEPTH

Opinion

opinion

opinion Don Martin: Gusher of Liberal spending won't put out the fire in this dumpster

A Hail Mary rehash of the greatest hits from the Trudeau government’s three-week travelling pony-show, the 2024 federal budget takes aim at reversing the party’s popularity plunge in the under-40 set, writes political columnist Don Martin. But will it work before the next election?

opinion

opinion Don Martin: How a beer break may have doomed the carbon tax hike

When the Liberal government chopped a planned beer excise tax hike to two per cent from 4.5 per cent and froze future increases until after the next election, says political columnist Don Martin, it almost guaranteed a similar carbon tax move in the offing.

CTVNews.ca Top Stories

An Edmonton man says he was in the wrong place at the wrong time when he was injured by members of the Edmonton Police Service last year.

BREAKING

BREAKING

The brother of a 27-year-old man who was fatally shot in Scarborough over the weekend has been arrested and charged in connection with his death, say police.

Local Spotlight

Cole Haas is more than just an avid fan of the F.W. Johnson Wildcats football team. He's a fixture on the sidelines, a source of encouragement, and a beloved member of the team.

Getting a photograph of a rainbow? Common. Getting a photo of a lightning strike? Rare. Getting a photo of both at the same time? Extremely rare, but it happened to a Manitoba photographer this week.

An anonymous business owner paid off the mortgage for a New Brunswick not-for-profit.

They say a dog is a man’s best friend. In the case of Darren Cropper, from Bonfield, Ont., his three-year-old Siberian husky and golden retriever mix named Bear literally saved his life.

A growing group of brides and wedding photographers from across the province say they have been taken for tens of thousands of dollars by a Barrie, Ont. wedding photographer.

Paleontologists from the Royal B.C. Museum have uncovered "a trove of extraordinary fossils" high in the mountains of northern B.C., the museum announced Thursday.

The search for a missing ancient 28-year-old chocolate donkey ended with a tragic discovery Wednesday.

The Royal Canadian Mounted Police is celebrating an important milestone in the organization's history: 50 years since the first women joined the force.

It's been a whirlwind of joyful events for a northern Ontario couple who just welcomed a baby into their family and won the $70 million Lotto Max jackpot last month.

Stay Connected