A recent report by the federal auditor general has highlighted concerning deficiencies in the federal government’s response to a rising number of perilous cyberattacks. The audit, presented in the House of Commons, unveiled inadequate coordination among agencies responsible for safeguarding the government’s IT systems during cyber assaults, leading to prolonged access to personal information by attackers in some instances.
The audit emphasized that these cybersecurity defense gaps compromise the government’s ability to safeguard critical data and manage cyber risks effectively. While key agencies like the Treasury Board of Canada Secretariat, Communications Security Establishment Canada (CSE), and Shared Services Canada possess the necessary tools to shield government networks from cyber threats, not all departments are utilizing recommended security measures.
Statistics from the audit reveal relentless cyber assaults on government infrastructure, with CSE thwarting approximately 2.4 trillion suspicious cybersecurity events from April 2023 to March 2024. Similarly, Shared Services Canada intercepted around 6.6 trillion suspicious events from October 2023 to September 2024. Despite these defensive efforts, successful attacks have occurred, causing substantial losses and disruptions.
The report highlighted the inconsistent application of cybersecurity tools across federal organizations, with some failing to deploy essential defense mechanisms. While CSE and Shared Services Canada offer critical cybersecurity services, not all departments are mandated to use them, leading to varying levels of protection and awareness of cyber threats.
Moreover, lapses in coordination during cyber incidents were noted, resulting in delayed responses and inadequate information sharing among key cyber defense agencies. These deficiencies increase the risk of personal data breaches and hinder the government’s ability to swiftly counter cyber threats.
The audit recommended a reassessment of cybersecurity incident management practices by key departments, urging enhanced coordination and information sharing to bolster cyber defense capabilities. Despite ongoing efforts to address these gaps, the completion of crucial projects aimed at enhancing cybersecurity remains pending, underscoring the need for sustained vigilance and investment in cybersecurity measures to uphold public trust and safeguard critical government systems.
