Inside Canada’s Cyber Defence: What the CSE’s 2025-2026 Annual Report Actually Shows

Contents

The Headline Numbers

The Communications Security Establishment Canada (CSE) has released its 2025–2026 Annual Report, covering activities between April 2025 and March 2026, and the numbers paint a picture of an agency stretched across an increasingly active threat landscape.

Over that twelve-month period, the Canadian Centre for Cyber Security responded to more than 3,200 cyber security incidents affecting federal institutions and critical infrastructure, while CSE produced 3,976 foreign intelligence reports to inform the government about foreign-based threats and global events.

That’s roughly nine incidents a day requiring a response from the Cyber Centre — and that figure only counts what reached the level of a formal incident response, not the much larger volume of attempted intrusions filtered out earlier in the pipeline.

3,200+Cyber incidents responded to

3,976Foreign intelligence reports produced

995Advisories issued

25Alerts issued

97,000+National Threat Notification alerts

1,363Subscribed organizations

10Major ransomware groups actioned

1,772Supply chain risk assessments

13Ministerial Authorizations received

What the Cyber Centre Actually Did With Those Incidents

The scale of activity beneath the headline number is worth unpacking. Alongside incident response, the Cyber Centre issued 25 alerts, 995 advisories, and over 97,000 National Cyber Threat Notification System alerts to 1,363 subscribed organizations — a notification system that appears to be functioning as an early-warning network across Canada’s public and private critical infrastructure operators, well beyond the incidents CSE handles directly.

The agency also went on the offensive in a more targeted way: CSE took action against 10 of the most significant ransomware groups causing harm to Canada and its allies, and conducted 1,772 supply chain risk assessments to identify vulnerabilities before they could be exploited rather than after. Supply chain risk has become a recurring theme in CSE’s public threat assessments, reflecting a broader shift in how the agency frames the problem — not just “who is attacking us” but “which vendors and dependencies make us attackable in the first place.”

On the intelligence-gathering side, oversight is built into the picture: CSE received a total of 13 Ministerial Authorizations in the past year, including four related to foreign cyber operations — the legal mechanism under the Communications Security Establishment Act that permits CSE’s more sensitive activities, subject to ministerial sign-off and independent review.

The Threat Picture Behind the Numbers

CSE’s companion document, the National Cyber Threat Assessment 2025–2026, gives more texture to why the incident count is climbing. The assessment identifies five converging trends shaping the threat environment.

Five converging trends — National Cyber Threat Assessment 2025–26

NEW ERA OF CYBER VULNERABILITY

01AI amplifying cyberspace threats

02Tradecraft evolving to evade detection

03Non-state actors adding unpredictability

04Vendor concentration, systemic risk

05Dual-use commercial services exploited

The assessment concludes that Canada has entered a “new era of cyber vulnerability,” where cyber incidents now have cascading and disruptive effects on the daily lives of Canadians — rather than remaining confined to isolated IT departments.

Ransomware in particular is singled out as the most consequential threat to critical infrastructure, with the Cyber Centre forecasting that the ransomware ecosystem will keep fragmenting as affiliates break off from established groups to run independent operations — making the threat harder to disrupt through any single law enforcement action.

State-sponsored activity adds another layer. CSE’s broader public reporting has repeatedly flagged the People’s Republic of China’s cyber program as the most sophisticated and active state threat facing Canada, alongside Russian and Iranian operations aimed at destabilization and coercion respectively — context that helps explain why a domestic incident-response number like “3,200” sits inside a much larger geopolitical picture.

A Coordination Push, Not Just a Bigger Budget

One of the more structurally significant developments in the report isn’t a statistic at all — it’s an agreement. In fall 2025, provincial, territorial, and federal governments signed the Canadian Cybersecurity Collaboration Agreement, aimed at strengthening pan-Canadian coordination by enabling more efficient sharing of cyber security information, expertise, and tools across jurisdictions.

Historically, one of the harder problems in national cyber defence isn’t detecting threats — it’s getting that detection to travel fast enough between a federal agency, a provincial government, and a municipal utility before an incident spreads. This agreement, along with CSE’s ongoing Federal-Provincial-Territorial Heads of Cyber Roundtable, is a direct attempt to close that gap.

CSE also flagged its role securing major events during the reporting period:

Milan Cortina 2026Cyber support for the Winter Olympic Games

G7 Summit — Kananaskis51st G7 Summit, hosted in Alberta

A reminder that high-profile international events have become standard-issue targets for state and criminal cyber actors alike, and now require dedicated cyber posture planning the same way physical security does.

Why This Matters Beyond Ottawa

For organizations outside government — hospitals, utilities, financial institutions, and private companies that make up Canada’s “critical infrastructure” designation — this report functions as an indirect risk signal. When the agency responsible for defending federal systems logs incident numbers climbing and explicitly warns of a “new era of cyber vulnerability,” it’s a reasonable proxy for what private-sector security teams should expect to be dealing with as well, particularly given how frequently ransomware crews and state-linked actors move between government and commercial targets using the same tooling and access-broker networks.

The practical takeaway from CSE’s own data: the agencies best equipped to catch and contain incidents quickly are the ones plugged into shared notification systems like the one that pushed out 97,000 alerts this year — not the ones waiting to discover a breach on their own. As the new Canadian Cybersecurity Collaboration Agreement rolls out, expect more organizations, especially at the provincial and municipal level, to get pulled into that same information-sharing net.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *