In May, the Canadian Security Intelligence Service (CSIS) released its annual report warning Canadians about the threats facing our country. One of us served as Director of CSIS for seven years. The other spent five years working with Canada’s leading CEOs to defend against the threats CSIS identifies. This report confirms what we’ve witnessed firsthand: Canada’s openness, one of its greatest economic strengths, is being systematically turned against us.
For decades, Canada’s openness powered its prosperity. We attracted world-class talent, integrated into global supply chains, and built research partnerships that let a relatively small economy punch well above its weight. But the world has changed.
Today, business leaders operate in a landscape where economic and geopolitical interests are increasingly intertwined. Nations are competing to secure critical technologies, dominate emerging industries, and reduce dependence on strategic rivals. Canada, for all its advantages, has been slow to respond.
Meanwhile, adversarial nation-states—including the People’s Republic of China (PRC), Russia, and Iran—are already taking advantage. They have concluded that the fastest route to the top runs through countries like ours, and that stealing or disrupting what we have built is easier than developing it themselves. So, they recruit insiders at our organizations, exploit our partnerships, and turn our own supply chains and research networks against us.
Consider a few examples.
Last year, CSIS warned that entities linked to the PRC government or the Chinese Communist Party (CCP) organized pitch competitions targeting a handful of Canada’s most promising start-ups. These events offered entrepreneurs the opportunity to share sensitive business information in exchange for exposure and funding opportunities. But in the process, they increased the risk of their intellectual property falling into the wrong hands and being used to help a foreign adversary.
In 2022, Ukraine’s security service disassembled a downed Shahed drone that Russia had used to strike civilian targets and reportedly discovered satellite navigation antennas manufactured by a Canadian company. Though the company claimed it does not sell to Russia, Iran, or any sanctioned entity, it is suspected that the components were purposely diverted through distributors using front companies.
Even Prime Minister Mark Carney's Major Projects initiative—designed to accelerate nationally significant infrastructure in the energy, critical minerals, and defence sectors—is under threat. CSIS Director Dan Rogers recently acknowledged that his agency had pivoted to support this effort, driven by growing concerns over foreign control and influence over projects the government has deemed critical to Canada’s future. Such access, he warned, could be used to facilitate espionage or to manipulate and disrupt our critical infrastructure.
Let us be clear: we are not arguing for Canada’s retreat. Our national interest demands global engagement, including with nations whose governments have a record of targeting Canadian organizations. So, what must change?
First, awareness. Canadian businesses need a better understanding of how these nations operate, how they choose targets, and how their tactics, techniques, and procedures evolve over time. That is how they can begin to identify risk before it materializes.
Second, accountability. When security lives at the margins of an organization, the people making the biggest decisions can often be the least informed. Boards and executives need to internalize and then prioritize security as a strategic imperative.
Third, consistency. Businesses cannot build durable security programs if the legal and regulatory frameworks they operate within work against them. Too often, organizations that do the right thing find themselves penalized for it.
Last month, a labour arbitrator struck down key elements of a security-screening program used by Ontario’s largest electricity transmitter and distributor, ruling it intrusive and unreasonable. The program was implemented over a decade earlier, after both CSIS and the Royal Canadian Mounted Police warned the utility that a co-op student it employed had been actively recruiting for ISIS. In the years since, the program had successfully identified and blocked several high-risk hires, including five individuals linked to PRC and Russian state actors. A program that worked, in other words, was ruled unlawful.
That sends a contradictory message to every Canadian organization building out its security capabilities: you have to protect yourself, but you have to figure out how on your own, and you’d better not get it wrong.
Moving forward, Canada cannot just wish away the new realities of economic competition. Nor can we afford to keep discovering our vulnerabilities after the fact. But if government and the private sector align on awareness, accountability, and consistency, Canada can protect both its prosperity and its security without sacrificing the openness that built them.
David Vigneault is Chief Intelligence Officer at Strider Technologies and former Director of the Canadian Security Intelligence Service. Trevor Neiman is Canadian Country Manager and International Associate General Counsel at Strider Technologies and former Vice President of Policy and General Counsel at the Business Council of Canada.
