“Fed Auditor General Report Reveals Cyber Defense Failures”

Share

A recent report from the federal auditor general highlighted significant deficiencies in the federal government’s response to the escalating number of cyberattacks. The report, presented in the House of Commons, revealed that coordination among agencies responsible for safeguarding government IT systems was lacking during active attacks, leading to prolonged access to personal information by attackers.

According to the audit, the three key agencies tasked with cyber defense, including the Treasury Board of Canada Secretariat, Communications Security Establishment Canada (CSE), and Shared Services Canada, had the necessary tools to protect government networks from cyber threats. However, Auditor General Karen Hogan emphasized that not all departments and agencies were utilizing the recommended cybersecurity measures, indicating gaps in coordination and information sharing during attacks.

The audit unveiled that CSE’s sensors intercepted approximately 2.4 trillion suspicious cybersecurity events from April 2023 to March 2024, while Shared Services Canada thwarted around 6.6 trillion suspicious events from October 2023 to September 2024. Despite these efforts, successful cyber breaches have occurred in the past, such as the breach at the National Research Council Canada in 2014, costing the government millions of dollars.

The report also highlighted inconsistencies in the adoption of cybersecurity tools across federal organizations. While CSE’s sensors were deployed by all required organizations, only 26% were utilizing Shared Services Canada’s secure connection service. The report emphasized that this inconsistent utilization of cybersecurity services hinders the government’s ability to detect and defend against cyber threats effectively.

Furthermore, the audit identified delays in information sharing and coordination during cyberattacks, leading to extended periods of unauthorized access to sensitive information. The report recommended a reevaluation of cybersecurity incident management practices by the relevant departments. It also pointed out the lack of complete inventories of government IT devices by Shared Services Canada and CSE, highlighting vulnerabilities that could be exploited in cyberattacks.

In response to the audit findings, government officials emphasized the importance of cybersecurity as a national priority and pledged to enhance monitoring and threat detection capabilities. CSE has repeatedly warned about the cyberthreat posed by countries like China, Russia, Iran, North Korea, and India, underscoring the ongoing challenges faced by Canada in combating cyber threats.

Read more

Local News