Canadian Security Showcase
Sessions
Registration and Networking
7:30 AM - 8:30 AM (60 mins)
Welcome from Public Sector Network
8:30 AM - 8:40 AM (10 mins)
Welcome from Chair
8:40 AM - 8:50 AM (10 mins)
Securing Canada in 2026: Priorities for a Whole-of-Government Approach
8:50 AM - 9:10 AM (20 mins)
Canada's security environment is under simultaneous pressure from threats to borders, critical infrastructure, and democratic institutions, while the federal government is being asked to deliver more at speed. This session will give you the shared operating picture for 2026 and the priority decisions you need to make in the next 12 to 18 months to strengthen national resilience across physical and digital domains.
- Align on national priorities and what they mean for operational focus across public safety, intelligence, border, and cyber
- Ground your planning in Public Safety Canada's 2026–27 priorities: border integrity, threat detection, law enforcement capability, and emergency management
- Connect security decisions to sovereignty measures in the Spring Economic Update, including strengthening domestic capability in critical sectors
- Strengthen democratic resilience by understanding the latest signals on foreign interference and influence-transparency measures
- Accelerate collaboration without duplication by clarifying where coordination is essential vs where agencies should act independently
Protecting Canada's most critical systems: detection, response, and resilience in high-consequence environments
9:10 AM - 9:30 AM (20 mins)
Federal departments, public safety agencies, and critical infrastructure operators are navigating a threat environment that is faster, more targeted, and harder to contain than it was two years ago. This session will show you what effective detection and response looks like in practice for high-consequence government environments, so your team can reduce dwell time, close capability gaps, and respond with greater confidence.
- Identify the detection gaps that matter most in federal and public safety environments and the practical controls that close them
- Strengthen response capacity by building playbooks and escalation pathways aligned to Canada's Federal Cyber Incident Response Plan
- Reduce dwell time by applying threat detection patterns proven in environments operating at national security classification levels
- Improve operational resilience by integrating detection and response tooling into your existing security operations without adding complexity
Public Safety in an Era of Complex Risk: Tackling Cybercrime, Foreign Interference, and Organized Threat
9:30 AM - 9:50 AM (20 mins)
Canada’s public safety environment is increasingly shaped by blended threats across cybercrime, online fraud, foreign interference, and border-enabled organized crime. This session will share the RCMP’s operational perspective on what readiness looks like in 2026: detecting risks earlier, disrupting threats faster, and responding under pressure through clear escalation pathways, trusted information-sharing, and cross-jurisdiction collaboration.
- Understand how complex threats are converging across mandates
- Clarify what practical readiness means for detection, disruption, and response
- Strengthen collaboration and information-sharing across jurisdictions
- Identify the capabilities and escalation pathways agencies should prioritize in 2026
Readiness Through Collaboration: Detect, Disrupt, and Respond Across Mandates
9:50 AM - 10:20 AM (30 mins)
Threat actors are moving faster, blending tactics across physical and digital domains, and exploiting seams between mandates. This moderated plenary stress-tests what readiness actually means in 2026—and focuses on the practical operating model leaders need to collaborate without duplication or compromise.
- Identify the fastest-moving risk areas across people, process, technology, and geopolitics and what they mean for your mandate
- Understand what new authorities and legislative changes mean for operational readiness and cross-mandate coordination in practice
- Align on the shared threat set Public Safety Canada is prioritizing: critical infrastructure, espionage, terrorism, organized crime, and foreign interference
- Define readiness in measurable terms: capabilities, thresholds, and response expectations your teams can execute against
- Agree on collaboration patterns that work, including roles, decision rights, and escalation paths, and identify where they are currently breaking down
Morning Networking Break
10:20 AM - 10:50 AM (30 mins)
Incident Readiness in Practice: Escalation, Coordination, and Response Across Canada’s Cyber Defense Architecture
10:50 AM - 11:10 AM (20 mins)
Severe cyber incidents test more than technical response — they test executive decision-making, coordination, continuity, and trust under pressure. This session will examine what turns an incident into a “severe” event, how escalation is initiated, and how initiatives like CIREN and the Federal Cyber Incident Response Plan are shaping Canada’s approach to coordinated response across critical infrastructure and high-consequence environments.
- Understand what distinguishes a severe incident and when escalation should begin
- Clarify the executive decision points that matter most: containment, continuity, disclosure, and recovery
- Explore how CIREN and the Federal Cyber Incident Response Plan support coordinated response
- Identify recovery lessons and coordination patterns that build real readiness across critical infrastructure
Foreign interference, community safety, and democratic resilience: from monitoring to response
11:10 AM - 11:30 AM (20 mins)
Foreign actors are targeting Canadian communities, democratic processes, and public institutions faster than traditional monitoring approaches can track. This session will demonstrate how purpose-built intelligence and threat detection capabilities close the gap between signal and response, so agencies can act decisively when foreign interference intersects with community safety and democratic integrity.
- Apply AI-driven open-source intelligence and real-time threat monitoring to surface foreign influence activity across digital, physical, and social domains
- Understand how to operationalize FITAA obligations with automated monitoring workflows that reduce manual effort and accelerate escalation
- Integrate intelligence platforms to support coordinated response across CSIS, RCMP, and Public Safety Canada without creating new data silos
- Build proportionate, auditable response frameworks that act on threat signals while protecting civil liberties and community trust
Protecting Canada's Critical Infrastructure: How Asset Owners and Government Are Managing Risk Across Essential Systems
11:30 AM - 12:00 PM (30 mins)
Canada's critical infrastructure owners are navigating a threat environment that is simultaneously physical and digital, and the gap between policy frameworks and operational reality is where the exposure lives. This session will examine how sector operators are working with government to assess risk, close capability gaps, and build the resilience that national security depends on.
- Assess the real risk picture facing Canada's critical infrastructure sectors: where physical and cyber threats converge and what that means for operators and government partners alike
- Strengthen the government-to-operator relationship by understanding what effective information sharing, regulatory expectations, and joint response look like in practice
- Apply lessons from recent incidents to identify the most common failure points in critical infrastructure protection programs before they become national security events
- Build a sector-specific resilience baseline that satisfies both operational continuity requirements and the national security obligations that flow from being designated critical infrastructure
Zero trust networks in practice: micro-segmentation, workload isolation, and eliminating implicit trust in GC environments
12:00 PM - 12:20 PM (20 mins)
Most federal networks still operate on implicit trust; once inside the perimeter, lateral movement is too easy. This session will demonstrate what eliminating that implicit trust looks like at the network and workload layer in a real GC environment, so your team can contain the blast radius of any compromise without rebuilding your entire architecture.
- Apply micro-segmentation to control east-west traffic in federal environments, preventing lateral movement between systems that have no business communicating
- Implement workload isolation patterns for hybrid and multi-cloud GC environments that enforce least-privilege connectivity without creating operational bottlenecks
- Apply a phased segmentation approach that protects the highest-value targets first without requiring a full network redesign
- Integrate zero trust network controls with existing GC perimeter security investments rather than replacing them
- Measure network trust posture with the visibility and policy enforcement metrics that satisfy both operations teams and security auditors
Networking Lunch
12:20 PM - 1:20 PM (60 mins)
Interactive Roundtables
1:20 PM - 2:20 PM (60 mins)
Pick your topic. Pull up a seat and join a 60-minute interactive discussion with your government peers. Facilitated by an industry expert, you'll share challenges and swap practical approaches within the topic area. Take this opportunity to benchmark what good looks like, pressure-test ideas, and workshop next steps together.
Roundtable One - AI Frontier: Harnessing GenAI and Delivering Trustworthy Public Service Delivery
Roundtable Two - Continuing the Conversation: Securing Canada’s Critical Infrastructure – Embedding Mission-Critical Cyber Defence
Roundtable Three - Stay Ahead of the Threat: Operationalizing Real-Time Intelligence for Government
Roundtable Four - Sharing and Operationalizing Data
Roundtable Five - Staying Left of Boom to Reduce Canada's Threat Risk Profile
Prevention to response: building integrated public safety operations
2:20 PM - 2:50 PM (30 mins)
When threats escalate quickly, fragmented operations cost time, and time is the most expensive resource in public safety. This session will focus on the practical operating model for integrated operations, so you can improve information sharing, joint readiness, and coordinated response across prevention, disruption, and the current IMVE threat environment.
- Identify what is blocking integration across decision rights, data sharing, tooling, and culture, and how leading teams are unblocking it
- Improve coordination across federal, provincial, territorial, and Indigenous partners for emergency readiness and response
- Strengthen joint operations readiness with clearer roles, escalation pathways, and shared situational awareness
- Respond faster under pressure by aligning on what good looks like across prevention, disruption, and incident response
AI-powered security operations: scaling your SOC without scaling your headcount
2:50 PM - 3:10 PM (20 mins)
Federal security operations teams are expected to do more with the same people: more alerts, more complexity, more accountability, while the analyst talent pipeline stays constrained. This session will show you how AI is changing the economics of government Security Operations Centre (SOC) operations, automating the repetitive work that burns out analysts and freeing human judgment for the investigations that actually need it.
- Reduce the time analysts spend on routine alert enrichment, context gathering, and case documentation through AI-assisted investigation
- Automate high-volume, low-complexity event handling at machine speed, surfacing only genuine escalations for analyst review
- Apply an analyst augmentation model that improves junior analyst output without requiring senior analyst oversight at every step
- Build a governance and human-in-the-loop framework that enables security leadership to trust AI-driven decisions in a government accountability environment
- Define a realistic adoption roadmap: where AI delivers value fastest in a federal SOC, and what to avoid in the first 12 months
Protecting Digital Government at Scale: Zero Trust, Identity, and Secure Access in Practice
3:10 PM - 3:40 PM (30 mins)
As federal agencies modernize services, platforms, and mission-critical systems, the challenge is no longer just defending the perimeter, instead it is governing access across users, devices, applications, APIs, cloud environments, and partners. This session will explore how you can apply zero trust, identity governance, and secure-by-design principles to protect sensitive systems and data while enabling trusted digital delivery at scale.
- Strengthen access governance across staff, partners, privileged users, service accounts, applications, and APIs
- Apply zero trust principles in practical phases across networks, cloud environments, shared platforms, and legacy systems
- Reduce risk from over-privileged access, non-human identities, third-party connections, and unmanaged application pathways
- Improve auditability and accountability with clearer ownership, continuous verification, and risk-based access decisions
- Build secure digital services that protect sensitive data without slowing modernization or user access
What Canada is building: capability investments reshaping national security in 2026–27
3:40 PM - 4:00 PM (20 mins)
Closing Remarks
4:00 PM - 4:10 PM (10 mins)