Photo by: Seaman Donald Freeman
by Anthony Ofongo
August 2026
Table of Contents
- Introduction
- The Geopolitical Stakes for Canada
- Canada's Cyber-Defence Ecosystem
- The Gap that Moving Target Defence Addresses
- Operationalizing Moving Target Defence in Canada
- Policy Recommendations
- Strategic Autonomy Through Domestic Capability
- Conclusion
- About the Author
- Canadian Global Affairs Institute
Introduction
The age of cyber-conflict as a theoretical concern is over. It ended somewhere between a hospital in Newfoundland and a gas field in the Persian Gulf. On 30 October 2021, healthcare workers across Newfoundland and Labrador arrived at work to find their systems locked and their screens dark. The Hive ransomware group had spent more than two weeks moving through the provincial health network before deploying its payload. The results were catastrophic by any peacetime standard: thousands of surgeries and procedures were cancelled, parts of the health system were forced back on to paper records, the personal health records of more than 58,000 patients and employees were exposed, and the recovery bill reached at least $16 million. Cyber-security experts described it as the worst cyber-attack in Canadian history. The attack was not attributed to a conventional military unit, but to what is best understood as an organized criminal ransomware enterprise: a cyber-crime operation that functions like a business by infiltrating networks, stealing or locking data, and demanding payment for restoration or non-disclosure. In this case, that criminal model exposed weaknesses in a public system that proved far more vulnerable than its administrators had assumed.
Three years later, the stakes have grown exponentially. As of March 2026, the United States and Israel are engaged in active military operations against Iran under the designation Operation Epic Fury, and US National Cyber Director Sean Cairncross stated on 19 March 2026 that American cyber-capabilities were playing a “critical component” role in the war. Energy infrastructure across the Persian Gulf has been targeted by Iran, and Iranian facilities on the South Pars gas field have been struck. The opening phase of the war also included cyber-enabled efforts to disrupt communications infrastructure near key Iranian state institutions.
Iran, for its part, is prosecuting a responsive cyber-campaign through a doctrine of deliberate decentralization. Even as the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security have sustained severe physical damage from US and Israeli strikes, Iran’s cyber-capabilities have not been decapitated. They have been dispersed. Proxy hacktivist groups have claimed compromises of industrial control systems across Israel, Poland, Turkey, Jordan and Gulf states. In March 2026, there was a significant cyber-attack on Stryker, a Fortune 500 Michigan-based medical device company, evidence that Iran retains high-end offensive capability and can impose psychological and operational costs far from the battlefield.
Meanwhile, Beijing is watching. The People’s Republic of China has maintained public restraint on the Iran war while almost certainly using it as a real-time intelligence collection opportunity, studying American and Israeli cyber-performance, tactics and vulnerabilities for future conflict modelling, particularly in the context of any future confrontation over Taiwan. Russia has also benefited from the opportunity to burden already stretched Western cyber-defenders through opportunistic cyber-activity.
While Canada is not a combatant in Operation Epic Fury, it is not insulated from the strategic lessons of the conflict. For a Five Eyes ally such as Canada, the significance of the Iran conflict reveals lessons about the contemporary role of cyber-operations in alliance politics, infrastructure vulnerability and geopolitical signalling. A Canadian Centre for Cyber Security bulletin issued on 28 February 2026 urged Canadian critical infrastructure operators and other potentially affected entities to remain vigilant amid the escalation, while noting broader risks of cyber-enabled information operations, harassment and espionage linked to the conflict environment.
Overall, Canada faces an increasingly complex and dangerous cyber-threat environment. State-sponsored actors, ransomware enterprises and AI-enhanced offensive operations are targeting Canadian critical infrastructure, government systems and research institutions with growing frequency and sophistication. Canada’s federal government has built a layered cyber-defence ecosystem that already includes meaningful prevention, detection and active cyber-operation capabilities, supported by a wide range of departments and agencies. However, the persistence of advanced adversaries, their capacity to evade established sensors, and the operational dwell time observed in recent intrusions point to a specific capability gap that current measures only partially address. In response to these challenges, this article argues that Canada should make Moving Target Defence a deliberate, federally coordinated element of its cyber-defence ecosystem, operationalized through existing institutions rather than through new bodies that duplicate ongoing work.
The Geopolitical Stakes for Canada
Canada’s geopolitical situation demands particular clarity on this point. Canada is a liberal democracy embedded within a set of overlapping security alliances, primarily the Five Eyes intelligence partnership, NATO and NORAD, the bilateral Canada-US defence relationship, that are directly implicated in the war now unfolding in the Middle East and the broader strategic competition with China and Russia. Sean Cairncross stressed that Five Eyes collaboration, including Canada, “underpins so much of global events in this space,” while emphasizing the growing importance of trusted technology ecosystems and interoperable cyber-coordination among allies. The geopolitical implications of Beijing’s quiet observation of Operation Epic Fury deserve particular attention. China is monitoring current US cyber-operations, studying performance, identifying gaps and building models for future conflict scenarios, most acutely a possible confrontation over Taiwan.
Russian cyber-operations in Ukraine and across Europe further underscore the broader strategic significance of contemporary cyber-conflict. As Reuters reported on the Kyivstar intrusion, Russian-linked hackers were inside Ukraine’s largest telecom provider for months before a December 2023 attack that disrupted communications for millions of users, while Ukrainian officials said they had thwarted more than 4,500 major cyber-attacks on government bodies and critical infrastructure in the previous year. The wider European dimension is equally important: the UK government and the National Cyber Security Centre concluded that Russia was almost certainly responsible for the Viasat cyber-attack launched just before the 2022 invasion, an operation that had spillover effects across Europe. Taken together, these cases show that cyber-operations are not confined to a single battlefield, but can be used to degrade civilian infrastructure, shape regional insecurity and project coercive power well beyond the immediate theatre of war.
Every vulnerability Canada presents, every gap in its critical infrastructure protection, and every federal department that has not deployed the government’s own recommended cyber-security tools creates information value for adversaries such as China and Russia which are engaged in long-horizon strategic reconnaissance across allied systems. Canada’s cyber-resilience is not separable from the collective resilience of the Western alliance. It is a constituent part of it.
This is not an abstract proposition. The National Cyber Threat Assessment 2025-2026 identifies the People’s Republic of China as the most sophisticated and active cyber-threat facing Canada, while also warning that state-sponsored actors are very likely targeting critical infrastructure networks in Canada and allied countries in order to pre-position for possible future disruptive or destructive cyber-operations. Canada is not on the periphery of the global cyber-conflict. It sits at its centre.
Cyber-deterrence is inherently difficult in the digital domain because adversaries exploit existing vulnerabilities, operate through uncertainty and capitalize on asymmetries that often leave defenders responding after systems have already been penetrated, as Libicki (2009) explains. For that reason, a credible national cyber-posture cannot rest on punishment alone. It must also reduce exposure, harden critical systems and strengthen the capacity of institutions to absorb and recover from disruption. Effective deterrence in cyber-space therefore depends as much on denial and resilience as on retaliation, a point also underscored by Nye (2017). For Canada, this is not a technical matter at the margins of policy. It is a strategic imperative tied directly to economic stability, public trust and national security. A more resilient cyber-posture, supported by adaptive defensive measures and stronger protection of critical infrastructure, should therefore be treated as a core responsibility of statecraft rather than a secondary function of IT administration.
Canada's Cyber-Defence Ecosystem
Canada’s federal cyber-defence ecosystem is more substantial than is often acknowledged in public commentary. The Communications Security Establishment (CSE) is the technical authority for cyber-security and information assurance and conducts both defensive and active cyber-operations under its statutory mandate. The Canadian Centre for Cyber Security, housed within the CSE, serves as the operational interface for federal departments, critical infrastructure operators and other partners. The CSE’s network and host-based sensors function as both preventive and detection controls, blocking trillions of suspicious events annually before they reach federal systems.
Cyber-defence in the federal government is not the work of the CSE and the Canadian Centre for Cyber Security alone. The Department of National Defence and the Canadian Armed Forces (CAF), through Canadian Armed Forces Cyber Command, conduct military cyber-operations and contribute to the defence of military networks and missions. The Treasury Board of Canada Secretariat sets enterprise information technology and cyber-security policy for federal departments. Shared Services Canada operates and protects much of the underlying federal information technology estate. Public Safety Canada and the Royal Canadian Mounted Police (RCMP) lead on cyber-crime coordination and enforcement. Innovation, Science and Economic Development Canada supports the broader cyber-security innovation ecosystem, and Defence Research and Development Canada (DRDC) provides the federal government’s primary defence and security research capability.
This ecosystem is therefore layered, with overlapping mandates that include prevention, detection, response, intelligence, military operations, law enforcement and research and development. Canada also conducts active cyber-operations through the CSE and the CAF when authorized, which means Canada is not purely reactive in posture. The relevant policy question is not whether Canada has cyber-defence capabilities, but whether the existing ecosystem is configured to address a specific and growing class of adversary tradecraft: the ability of sophisticated actors to operate inside networks for extended periods without triggering the controls already in place.
The Gap that Moving Target Defence Addresses
Even within a layered defence-in-depth model, advanced adversaries continue to gain access and maintain operational presence in sensitive networks. The 2021 Newfoundland health network attack is a clear illustration. A provincial forensic investigation found that the Hive ransomware enterprise had been active inside the network from 15 October and only deployed ransomware on 30 October, after gaining access through compromised credentials and moving laterally with elevated administrative privileges. A 2024 Global Affairs Canada intrusion likewise showed how long an intrusion can remain operationally significant before remote access is shut down to contain the incident. These cases do not show that Canada has no defences. They show that even with defence-in-depth in place, the operational window between initial access and containment can remain large.
This is the specific problem that Moving Target Defence addresses. Moving Target Defence is a proactive form of cyber-defence that continuously changes aspects of a system’s configuration and attack surface so that adversaries face greater uncertainty and fewer opportunities for successful intrusion. It does not replace prevention or detection. It augments them by reducing the operational value of any foothold an adversary manages to establish. By altering elements such as network paths, host configurations, addressing and software diversity on a continuous basis, Moving Target Defence shortens the useful lifespan of reconnaissance, complicates lateral movement, and increases the cost and risk of remaining inside a system long enough to achieve mission objectives.
This type of cyber-defence would not have prevented the intrusions described above. It would, however, materially reduce the dwell-time value of intrusions of this kind, meaning the period during which an adversary, having entered a network, can map systems, escalate privileges, and prepare a final action. For a country with the federal information technology footprint, allied exposure and critical infrastructure dependencies that Canada has, reducing dwell-time value is itself a meaningful national security gain.
Operationalizing Moving Target Defence in Canada
Canada does not require new institutions to adopt Moving Target Defence. It needs to better use the institutions it already possesses. A credible federal pathway can be built across four existing nodes of the cyber-defence ecosystem.
Research and capability development through Defence Research and Development Canada. DRDC, not the Canadian Centre for Cyber Security, is the federal entity equipped to conduct and coordinate cyber-defence research at scale. A focused federal Moving Target Defence research program led by DRDC, in collaboration with CSE technical experts and Canadian universities, would allow Canada to evaluate Moving Target Defence techniques against realistic threat models and develop deployment guidance suited to federal environments.
Deployment within federal systems through Shared Services Canada. Because Shared Services Canada operates a substantial portion of the federal information technology estate, any meaningful federal Moving Target Defence deployment must be designed with and through Shared Services Canada. A staged pilot project in selected federal environments, governed jointly by the CSE and Shared Services Canada, would allow controlled evaluation before broader adoption.
Risk guidance and benchmarking through the Canadian Centre for Cyber Security. The Canadian Centre for Cyber Security is well placed to publish baseline guidance on Moving Target Defence applicability, integration with existing controls, and resilience benchmarks, in the same way it publishes guidance on other defensive practices. This positions the centre in its actual role of advice and benchmarking rather than asking it to perform research it is not structured to perform.
Operational integration through Canadian Armed Forces Cyber Command and the Communications Security Establishment. Because Canada already conducts active cyber-operations, Moving Target Defence adoption should be considered explicitly in the context of those operations as part of a layered defensive posture, not as a separate program. Integration with CAF Cyber Command and the CSE ensures that Moving Target Defence adoption is informed by current operational realities.
Policy Recommendations
The following four recommendations are narrowly focused on operationalizing Moving Target Defence within Canada’s existing cyber-defence ecosystem.
- Establish a federal Moving Target Defence pilot program through Shared Services Canada and Defence Research and Development Canada. The pilot should be jointly governed by the CSE and Shared Services Canada, with research support from DRDC, and risk guidance from the Canadian Centre for Cyber Security. The objective should be measurable reductions in adversary dwell-time value in selected federal environments, with results published in unclassified summary form to support broader adoption.
- Fund Moving Target Defence innovation through existing federal innovation programs. Rather than creating a new fund, Canada should use Innovation for Defence Excellence and Security and Innovative Solutions Canada to support Canadian researchers and firms developing Moving Target Defence-relevant capabilities. These programs already exist for this purpose, and expanding their cyber-defence focus is faster and more credible than building new institutions.
- Use Bill C-8 as the lever for critical infrastructure adoption. Bill C-8 provides a legislative pathway to introduce binding cyber-security obligations on federally regulated critical infrastructure operators. Where appropriate, Canada should use that pathway to require risk-based adoption of adaptive defensive measures, including Moving Target Defence, in sectors most exposed to advanced persistent threats. This approach uses legislation already in motion rather than creating new statutory mechanisms.
- Introduce annual federal Moving Target Defence readiness reporting through the Treasury Board Secretariat. The Treasury Board Secretariat sets enterprise information technology and cyber-security policy across federal departments and is best placed to require annual reporting on Moving Target Defence pilot results, adoption metrics and integration with defence in depth. Public reporting in summary form would support transparency and parliamentary oversight without creating duplicative structures.
Strategic Autonomy Through Domestic Capability
Canada’s interest in Moving Target Defence is not only technical. It is strategic. Canada operates in a Five Eyes environment where allied cooperation remains essential and should remain so. At the same time, the policy direction of major allies can shift, and the operational availability of foreign-developed cyber-capabilities cannot always be assumed. Strategic autonomy in cyber-defence does not mean disengagement from allies. It means ensuring that Canada has enough domestic capability, domestic expertise and domestic governance to defend its critical systems and make sovereign decisions in periods of allied recalibration. Adopting Moving Target Defence through Canadian institutions, supported by Canadian research and industry, is a concrete way to advance that autonomy without weakening interoperability.
Conclusion
Canada’s cyber-defence ecosystem is more developed than is often acknowledged. The Communications Security Establishment and the Canadian Centre for Cyber Security provide both preventive and detection capability, Canadian Armed Forces Cyber Command and the Communications Security Establishment conduct active cyber-operations, and the Treasury Board Secretariat, Shared Services Canada, Public Safety Canada, the Royal Canadian Mounted Police, Innovation, Science and Economic Development Canada, and Defence Research and Development Canada play significant supporting roles. The remaining problem is not the absence of cyber-defence capability, but the operational reality that advanced adversaries can still establish footholds, dwell inside systems, and act before containment is complete. Moving Target Defence addresses that specific gap. Operationalizing it through existing Canadian institutions, funded through existing federal innovation programs, anchored in Bill C-8 where appropriate, and reported through the Treasury Board Secretariat, would strengthen Canada’s cyber-defence posture without duplicating work already under way. It would also give Canada something it currently lacks: a clear, focused and distinctly Canadian contribution to the next phase of allied cyber-defence innovation.
About the Author
Dr. Anthony Ofongo is a postdoctoral researcher at the University of Calgary’s Faculty of Law, where he teaches and researches topics related to cybersecurity law, foreign interference, and national security policy in Canada.
Canadian Global Affairs Institute
The Canadian Global Affairs Institute focuses on the entire range of Canada’s international relations in all its forms including trade investment and international capacity building. Successor to the Canadian Defence and Foreign Affairs Institute (CDFAI, which was established in 2001), the Institute works to inform Canadians about the importance of having a respected and influential voice in those parts of the globe where Canada has significant interests due to trade and investment, origins of Canada’s population, geographic security (and especially security of North America in conjunction with the United States), social development, or the peace and freedom of allied nations. The Institute aims to demonstrate to Canadians the importance of comprehensive foreign, defence and trade policies which both express our values and represent our interests.
The Institute was created to bridge the gap between what Canadians need to know about Canadian international activities and what they do know. Historically Canadians have tended to look abroad out of a search for markets because Canada depends heavily on foreign trade. In the modern post-Cold War world, however, global security and stability have become the bedrocks of global commerce and the free movement of people, goods and ideas across international boundaries. Canada has striven to open the world since the 1930s and was a driving factor behind the adoption of the main structures which underpin globalization such as the International Monetary Fund, the World Bank, the World Trade Organization and emerging free trade networks connecting dozens of international economies. The Canadian Global Affairs Institute recognizes Canada’s contribution to a globalized world and aims to inform Canadians about Canada’s role in that process and the connection between globalization and security.
In all its activities the Institute is a charitable, non-partisan, non-advocacy organization that provides a platform for a variety of viewpoints. It is supported financially by the contributions of individuals, foundations, and corporations. Conclusions or opinions expressed in Institute publications and programs are those of the author(s) and do not necessarily reflect the views of Institute staff, fellows, directors, advisors or any individuals or organizations that provide financial support to, or collaborate with, the Institute.

Showing 1 reaction