From: Montreal Gazette

By Jordan Press

OTTAWA — No matter where the pieces of a new federal email system is built or  developed, any commercial product will come with vulnerabilities that could  allow hackers to find a way into the government’s systems, Canada’s top cyber  spies say.

High-ranking officials in the Communications Security Establishment, the  government’s ultra-secretive cyber-security agency, told a Senate committee  Monday that it will help evaluate every piece of hardware that will go into the  government’s new email system.

The department responsible for the system, Shared Services Canada, has  already invoked national security provisions for the purchase of the system that  will service more than 40 of the government’s heaviest IT-dependent departments.  As part of the contract, first put out over the summer and updated late last  week, the government will have the right to evaluate every company and person  involved in the project, and the system must be made in Canada.

Under questioning from Conservative Senator Daniel Lang, the head of IT  security for the cyber-intelligence agency suggested that buying local was not a  surefire bet that the system will be safe from foreign threats.

“All commercial products have some vulnerability in them,” said Toni Moffa,  deputy chief at CSE. “As we find those vulnerabilities we find ways…to mitigate  some of those vulnerabilities.”

Senators on the national defence committee were not only interested in  defending the federal government’s systems, but whether CSE and the military  were also ready to fight battles online with whatever digital weapons were at  their disposal. A general in charge of cyber defence wouldn’t say much, and the  head of CSE said his agency wouldn’t target Canadians at home or overseas.

“I’m an intelligence agency…and I have a mandate to protect the government of  Canada’s networks from people who are trying to infiltrate it,” John Forster  said. “I don’t look at my mandate in terms of defence and offence. My job is can  I protect those networks. … I don’t have an offensive mandate.”

Protecting the federal government’s systems from Internet-based attacks has  become a bigger concern in recent years as the number of threats from cyberspace  increase. The federal auditor general’s review of the government’s  cyber-security strategy and capabilities pointed out some holes in passing  information around government agencies involved in protecting networks and  systems. Progress has been made, the auditor general said, but government  agencies were concerned they wouldn’t be able to keep up with ever-evolving  threats.

“The greatest challenge for all of us in this space is to continue to keep up  our skills and abilities and investment in the technology we need to stay  ahead,” Forster said. “That’s what our people do constantly. It’s not a  static space. Things we see today you wouldn’t have seen five years ago.”

The Canadian Forces is currently revamping the way it looks at defending the  country and finding the right people for the jobs, said Brig.-Gen. Greg  Loos, who oversees the Canadian Forces’ cyber-security evolution.

The change in culture and the way the military approaches modern warfare  could take years to fully implement, Loos said. He said the military is trying  to use existing staff and structures to respond to issues in the short-term  while long-term problems are worked out.

“You’re absolutely right. Time is pressing on us,” Loos said. “Realistically,  the (human resources) piece of it is likely to be the most challenging.”

Forster said recruiting the best digital defence experts in the world means  he has to compete against the Googles and Facebooks of the work, which, he said,  can offer more in terms of salaries and benefits.

“I’d say we’re in good shape. it’s certainly a challenge for all of the  agencies,” Forster said. “You’re looking for some of the brightest people.”

Loos was more guarded when it came to weaponizing cyberspace, and whether the  Canadian Forces uses hacking, malware or other digital attack options to cause  damage against a foe. How or if governments weaponize cyberspace is an issue  security experts say challenges policy makers who have not yet fully dealt with  the issue.

“This domain is absolutely one we have to competently act in,” Loos said. “We  have to ensure that we’ve retained the ability to continue to use the cyber  environment for the purposes to support operations at a minimum. … But I can’t  really speak much beyond that.”