Recommendations
RECOMMENDATION 1:
All levels of government prioritize cyber security education in their cyber security strategies. To achieve this, the federal government should enable and fund:
Cyber security skills training programs, in collaboration with the provinces, territories and municipalities, to assist businesses with their cyber security needs;
Three national centres of excellence in cyber security research in order to promote basic research in the science of cyber security at the university level and to encourage Canadians to pursue education and careers in cyber security-related fields, with the goal of doubling the number of graduates with cyber security expertise in the next four years; and
A national cyber literacy program, led by the Canadian Centre for Cyber Security, to educate consumers and businesses on how to become cyber resilient. The program should promote awareness of the importance of cyber security needs at the junior and senior high school levels and encourage further education in science, technology, engineering and mathematics programs.
RECOMMENDATION 2:
The federal government develop standards to protect consumers, businesses and governments from threats related to the Internet of Things devices.
RECOMMENDATION 3:
The federal government develop a rapid and responsive national cyber security information sharing framework and make any necessary legislative changes to the Privacy Act and the Personal Information Protection and Electronic Documents Act to allow information sharing about cyber threats within the private sector and between the private sector, government and relevant international organizations.
RECOMMENDATION 4:
The federal government identify any deficiencies in information sharing and determine how law enforcement agencies can be provided with the necessary tools to actively and quickly share information and work with other jurisdictions in the prosecution of cyber criminals.
RECOMMENDATION 5:
The federal government develop a consistent set of leading cyber security standards that are harmonized with the highest international standards and would apply to all entities participating in critical infrastructure sectors.
RECOMMENDATION 6:
The federal government provide incentives for all businesses, particularly those in critical infrastructure sectors, to improve their cyber security practices, such as allowing accelerated capital cost allowance deductions to companies under the Income Tax Act for investments in cyber security.
RECOMMENDATION 7:
The federal government modernize Canada’s privacy legislation to take into account emerging cyber security concerns and international standards. It should provide the Office of the Privacy Commissioner with new resources to carry out its mandate and provide the Commissioner the power to make orders and impose fines against companies that have failed to take adequate measures to protect customers’ personal information.
RECOMMENDATION 8:
The federal government create a new federal minister of cyber security. This minister would be responsible for cyber security policy, including the national cyber security strategy, and have oversight over the new Canadian Centre for Cyber Security and the National Cybercrime Coordination Unit.
Until the minister of cyber security is created, the person designated as the federal lead for cyber security should report directly to the Prime Minister on these matters.
Lastly, the Prime Minister should table an annual report to Parliament on issues related to Canada’s cyber security strategy.
RECOMMENDATION 9:
The federal government create a federal expert task force on cyber security to provide recommendations regarding the national cyber security strategy that would establish Canada as a global leader in cyber security.
RECOMMENDATION 10:
The federal government require its departments and agencies to report privacy breaches to the Office of the Privacy Commissioner.
and
The federal government continue to implement best practices for the federal public service to ensure that properly secured devices are used to protect sensitive information.
Fredericton, October 29, 2018 – Cyber criminals from around the world have already preyed on millions of Canadians, leaching money and intimate, personal data that will live on the internet forever.
Meanwhile, Canada’s critical infrastructure is vulnerable to attack thanks to an absence of cyber security standards and a lack of co-ordinated information sharing.
In the face of these real and rising online threats, the federal government has offered only timid responses. And police confess they’re mostly powerless.
It’s long past time to protect Canadians from online predators, the Senate Committee on Banking, Trade and Commerce said in a report released Monday.
The report, called cyber assault: it should keep you up at night, provides a stark analysis of the dangers lurking online — and 10 recommendations to keep Canadians safe.
For example, Canadians have little recourse when businesses do not take adequate steps to safeguard their personal information. The Office of the Privacy Commissioner of Canada, which is responsible for protecting privacy rights, does not have the power to make companies comply with privacy legislation, or to impose fines when companies breach these laws. This must change.
Education is the best way to keep safe. That’s why the committee is urging the government to prioritize cyber security education as part of its national cyber security strategy. The committee also recommends that the government create a new minister for cyber security to coordinate security efforts across all levels of government and to help Canadians hold the federal government to account.
Cyber crime threatens Canadians’ finances, the economy and national security.
It should keep you up at night.
Quick Facts
- Over 10 million Canadians were victims of cyber crime in 2017 alone.
- Cyber criminals have successfully breached the systems of large companies holding Canadians’ sensitive personal data, including major banks and telecommunications, social media and ride-sharing companies.
- Three out of five Canadians have four or more internet-connected devices in their homes, which can act as conduits for cyber criminals.
Quotes
“This epidemic of criminal acts has already affected millions of Canadians and threatens our national security. The problem is only going to get worse if the government does not make a full-throated commitment to stamp out this serious and growing problem. We can no longer afford to delay — Canadians are waiting for someone to help them.”
- Senator Doug Black, Chair of the committee.
“The theft of personal information is a violation. Parents become terrified that photos of their children might be used to slake the thirst of online degenerates. People’s credit ratings can be damaged in an instant. You can lock your doors, but the internet is a gateway for criminals to invade your home. The government must provide Canadians with the tools and resources to protect themselves.”
- Senator Carolyn Stewart Olsen, Deputy Chair of the committee.
Associated Links
- Read the report, cyber assault: it should keep you up at night.
- Follow the committee on social media using the hashtag #BANC.
- Sign up for the Senate’s eNewsletter.
For more information, please contact:
Sonia Noreau
Public Relations Officer
Communications Directorate
Senate of Canada
613-614-1180 | sonia.noreau@sen.parl.gc.ca
Multimedia and Quiz
Senators Doug Black, QC (committee chair), Carolyn Stewart Olsen (committee deputy chair), Percy Mockler (finance committee chair) and Dr. Ali Ghorbani (Director of the Canadian Institute for Cybersecurity) discuss the Committee on Banking, Trade and Commerce’s report on cyber security in front of an engaged audience of post-grad students at the University of New Brunswick.



Take our quiz below:
1. TRUE OR FALSE? In 2017, the number of Canadian victims of cybercrime topped 10 million.
True:approximately 10.14 million Canadians were victims of cybercrime. DYK? In 2017, 978 million adults in 20 countries fell victim to cybercrime.
Source: https://www.symantec.com/content/dam/symantec/docs/about/2017-ncsir-global-results-en.pdf
2. TRUE OR FALSE? Ten per cent of companies worldwide have not performed a cyber security risk assessment in the past two years.
True: DYK? While 54% of companies have conducted a general fraud risk assessment, only 30% have cybersecurity response plans.
Source: https://www.pwc.com/gx/en/forensics/global-economic-crime-and-fraud-survey-2018.pdf
3. TRUE OR FALSE: In 2016, the average number of records breached surpassed 20,000.
True: The average number of records breached in 2016 was 20,456. DYK? The Ponemon Institute surveyed 24 companies across all sectors and noted the average cost of a data breach to a company is $6 million and $258 per record breached.
Source: Scott Smith, Director, Intellectual Property and Innovation Policy, The Canadian Chamber of Commerce, Evidence: BANC, March 1, 2018.
4. TRUE OR FALSE? Most Canadian businesses report cyber security incidents to law enforcement agencies.
False: Only about 10% of businesses impacted by a cyber security incident reported it to law enforcement in 2017. According to StatsCan, of those that did report, 79% were in relation to stolen money or a ransom payment and 56% were related to the theft of personal or financial information.
Source: https://www150.statcan.gc.ca/n1/daily-quotidien/181015/dq181015a-eng.htm
5. TRUE OR FALSE? in 2016, the majority of CEOs believed cyber security posed a threat to their company’s growth prospect.
True : The actual percentage of CEOs who believed cyber security poses a threat to their company’s growth is 61%.
Source: PwC 2016 Global CEO survey https://www.pwc.com/gx/en/ceo-survey/2016/landing-page/pwc-19th-annual-global-ceo-survey.pdf
Senators who participated in this study
Jean-Guy Dagenais
CSG - Quebec (Victoria)
Joseph A. Day
Non-affiliated - New Brunswick (Saint John-Kennebecasis)
Colin Deacon
CSG - Nova Scotia
Pierrette Ringuette
ISG - New Brunswick
Scott Tannas
CSG - Alberta
Pamela Wallin
CSG - Saskatchewan
Howard Wetston
ISG - Ontario
David Tkachuk
C - Saskatchewan
Carolyn Stewart Olsen
C - New Brunswick
Ex-officio members of the committee: The Honourable Senators Peter Harder, P.C., Diane Bellemare, Grant Mitchell, Larry W. Smith, Yonah Martin, Joseph A. Day, Terry M. Mercer, Yuen Pau Woo and Raymonde Saint-Germain.
Other senators who have participated in the study: The Honourable Senators Pierre-Hugues Boisvenu, Larry W. Campbell, Claude Carignan, P.C., Tobias Enverga, Jr., Stephen Greene, Michael L. MacDonald, Ghislain Maltais, Elizabeth Marshall, Paul J. Massicotte, Lucie Moncion and Betty Unger.
