News

CSE Annual Report Maps Canada's Digital Frontline

CSE's 2025-26 annual report details Canada's digital defence priorities, research partnerships and threats to critical infrastructure.

Filed byClaire Bergeron
Published
Read time11 minutes
CSE Annual Report Maps Canada's Digital Frontline

Tech Forum reports on the Communications Security Establishment Canada’s (CSE) latest annual report, a comprehensive, unclassified summary of its activities and strategic priorities for the 2025-2026 period. The report covers April 1, 2025, to March 31, 2026, and presents a detailed snapshot of Canada’s digital defence posture, research partnerships, and governance mechanisms at a moment of rapid technological disruption and geopolitical tension. The release underscores how Canada’s digital frontline of defence is evolving to address threats to critical infrastructure, government networks, and democratic processes. The information comes from CSE’s own annual publication, together with the government’s accompanying materials, which frame the year as a period of growth, expanded collaboration, and enhanced accountability. This year’s report marks a turning point as Canada’s defence and security investments translate into expanded capabilities and stronger resilience across the public and private sectors. (cse-cst.gc.ca)

The document not only chronicles a year of expansion and modernization but also situates CSE’s work within a broader geopolitical and technological landscape. The Chief’s message and ministerial foreword emphasize a shift toward greater integration across intelligence, cyber operations, and national security policy, aligning with Canada’s defence investments and alliance commitments. The report also highlights how Canada’s NATO benchmarks and the Five Eyes alliance shape operational priorities, while foregrounding the need to protect critical infrastructure through proactive cyber defence and threat intelligence. For readers tracking technology and market trends, the CSE annual report provides concrete metrics on workforce growth, incident response, and research partnerships that illuminate how national-scale cyber resilience translates into everyday digital security for Canadians. (cse-cst.gc.ca)

What Happened

Announcement and Period Covered

The CSE annual report for 2025-2026 is presented as an unclassified summary of the agency’s activities over a defined fiscal-year window. The document specifies that the reporting period runs from April 1, 2025, to March 31, 2026, and frames “this year” in the context of that period. This framing is essential for readers evaluating year-over-year progress, governance, and outcomes. The report’s forward-looking emphasis also notes ongoing expansion and transformation in response to a rapidly evolving threat landscape. In short, the key facts center on an official government publication detailing public-facing outcomes and governance for the 2025-2026 period. (cse-cst.gc.ca)

Key Facts and Highlights from 2025-2026

The 2025-2026 highlights section of the CSE annual report enumerates several core outcomes that are useful for understanding the agency’s operational tempo and strategic focus:

  • Workforce growth and composition:

    • Total workforce: 4,178 employees, including both indeterminate and term personnel as well as casual staff. The year saw an 8.1% increase in headcount (a rise of 337 employees). Attrition remained relatively low at 2.8%. Diversity and representation metrics show women at 33.9%, persons with disability at 14.1%, racialized persons at 17.9%, Indigenous persons at 2.6%, and 2SLGBTQIA+ representation at 6.4%. These figures reflect ongoing efforts to build a more inclusive, capable workforce in a context of expanding cyber operations and research. (cse-cst.gc.ca)
  • Alerts, incidents, and cyber operations:

    • The Cyber Centre’s early warning and incident response activities continued to expand in scale, with more than 3,200 cyber incidents recorded across government and critical infrastructure sectors in 2025-2026. This level of activity underscores the intensity of today’s cyber threat environment and the importance of rapid detection, protection, and response capabilities. (cse-cst.gc.ca)
    • The National Cyber Threat Notification System (NCTNS) delivered more than 97,000 notifications during the year, reaching organizations across the country and providing early warning of cyber threats. On average, roughly 450 organizations were notified each week, with 1,363 organizations subscribed to the service as of this reporting period. These numbers illustrate Canada’s commitment to proactive cyber hygiene and information sharing as a national security priority. (cse-cst.gc.ca)
    • The Cyber Centre also issued 67 pre-ransomware notifications to Canadian organizations identified as potential targets, helping to prevent or mitigate ransomware incidents before they escalate. This initiative reflects an increasingly proactive stance on cyber threat prevention and interagency collaboration. (cse-cst.gc.ca)
  • Governance, policy, and oversight:

    • As of March 31, 2026, six Ministerial Orders were in effect for CSE, reflecting the government’s ongoing authorization framework for foreign cyber operations, information handling, and critical infrastructure protection. The presence of these orders underscores the formal governance surrounding sensitive activities and the importance of oversight in a complex threat environment. (cse-cst.gc.ca)
    • External oversight and audit activities remained a central pillar of accountability. In 2025-2026, CSE participated in 26 external reviews and contributed to 24 briefings for review bodies, answering 454 questions. These statistics highlight a robust process for transparency and continuous improvement, even as the agency expands its capabilities. (cse-cst.gc.ca)
  • Operational tempo and capabilities:

    • The 2025-2026 highlights also show ongoing expansion in mission-critical capabilities, with greater integration across foreign signals intelligence, cyber security, and cyber operations. The throughline—greater integration—emphasizes the shift toward a more cohesive, end-to-end approach to national security in the digital domain. The report notes investments and partnerships designed to accelerate capability development and broaden impact. (cse-cst.gc.ca)
  • Research, partnerships, and education:

    • The report emphasizes mobilizing research and partnerships to safeguard Canada’s future, including advances in mission-critical capabilities through research, education, and public outreach. The Canadian Centre for Cyber Security and other partners collaborate on threat intelligence and practical guidance for industry and government, reflecting a whole-of-society approach to cyber resilience. (cse-cst.gc.ca)
  • Notable programmatic milestones:

    • A notable program reference is “One CSE: The Collection” Season 2, which launched in January 2026. This iteration builds on earlier efforts to communicate CSE’s mission, culture, and capabilities and to foster transparency and public engagement. The initiative is part of broader workforce and partnership development designed to sustain capabilities over time. (cse-cst.gc.ca)
  • Contextual leadership statements:

    • The report includes messages from leadership and ministers that frame the year within broader policy objectives, including Canada’s NATO defence-spending targets and national security strategy objectives. These sections help readers understand how CSE’s activities tie to national priorities and international cooperation. (cse-cst.gc.ca)

Timeline at a Glance: Key Dates and Milestones

  • April 1, 2025 – March 31, 2026: The official reporting period for the 2025-2026 CSE annual report. This window frames the year’s activities, including threat detection, response, research, and governance updates. (cse-cst.gc.ca)
  • January 2026: Launch of One CSE: The Collection, Season 2, marking continued public-facing engagement and outreach as part of internal culture and external collaboration initiatives. (cse-cst.gc.ca)
  • March 31, 2026: End of the reporting period for the 2025-2026 annual report; completion of a year of growth and transformation, as reflected in workforce expansion and governance enhancements. (cse-cst.gc.ca)

Section 1 of the CSE annual report lays out a precise set of facts and numbers that illuminate how Canada’s cyber posture is evolving in real time. The document’s emphasis on quantifiable metrics—workforce growth, incident counts, threat notifications, and governance activities—gives readers a rigorous basis for assessing national cyber resilience and the scale of strategic investment. The 2024-2025 annual report release adds a complementary set of numbers from the prior year, providing a historical baseline for comparison and trend assessment. In 2024-2025, for example, the report highlighted 3,385 foreign intelligence reports, 2,561 cyber security incidents, seven major unclassified threat assessments, and total authorities just over $1 billion, along with a workforce of 3,841 employees. These figures help frame the 2025-2026 year as part of a broader trajectory of expansion and capability building. (canada.ca)

Why It Matters

Strategic Context and National Security Benefits

The CSE annual report is more than a ledger of activities; it is a strategic signal about how Canada plans to defend its digital frontiers in a volatile global environment. The throughline of greater integration—connecting foreign signals intelligence, cyber security, and cyber operations—reflects an intentional shift toward end-to-end capability development. This approach matters because it translates into more coherent decision support for government partners, stronger resilience for critical infrastructure, and more robust guidance for industry and academia. The ministerial foreword and leadership messages emphasize NATO benchmarks and Five Eyes collaboration, illustrating how Canada situates its cyber posture within a trusted international architecture. For technology and market observers, these shifts point to a more predictable, policy-aligned environment for cyber security investments, research collaborations, and public-private partnerships. (cse-cst.gc.ca)

Implications for Technology Markets and Public-Private Collaboration

The scale of incidents and alerts captured in the year highlights the continuing rise of cyber threats and the corresponding demand for defence-grade cyber capabilities. The Cyber Centre’s role in responding to thousands of incidents and issuing tens of thousands of early warnings suggests that enterprises across sectors face a dynamic threat landscape requiring ongoing investment in detection, response, and resilience. The NCTNS notifications—nearly 97,000 in the year—demonstrate a mature, scalable information-sharing infrastructure designed to accelerate incident awareness and collective defense. For technology vendors, system integrators, and service providers, these developments create opportunities in managed security services, threat intelligence, and risk-assessment tooling, while also underscoring the importance of standards, transparency, and independent oversight to sustain trust. (cse-cst.gc.ca)

Workforce and Diversity as a Capacity Signal

The 2025-2026 highlights show significant workforce growth alongside a sustained emphasis on diversity and inclusion. With 4,178 employees and an 8.1% year-over-year increase, CSE is expanding its capacity to innovate, secure, and operate at scale. Diversity metrics—33.9% women, 14.1% persons with disability, 17.9% racialized, 2.6% Indigenous, and 6.4% 2SLGBTQIA+—signal a deliberate effort to build a workforce that reflects and understands Canada’s broader demographic tapestry. This is relevant to market observers because it aligns with global trends toward inclusive tech workplaces and can influence recruitment, talent development, and partnerships in cyber security research and operations. (cse-cst.gc.ca)

Governance and Accountability as Market Confidence Signals

External oversight and accountability are central to how the CSE annual report frames trust in national security institutions. The numbers around external reviews, ministerial orders, and compliance activity demonstrate that Canada maintains an active governance regime around sensitive operations and information handling. For readers evaluating risk, policy risk, or the regulatory climate for cyber security work, these sections of the report offer a concrete basis for understanding how public institutions balance security imperatives with transparency and accountability. (cse-cst.gc.ca)

Real-World Impacts on Canadians and Critical Infrastructure

The report’s emphasis on protecting critical infrastructure, defending democracy, and supporting allied partners translates into tangible outcomes for Canadians. While the document presents high-level metrics, the underlying message is clear: Canada is investing in capabilities that reduce vulnerability, improve threat information sharing, and accelerate the adoption of practical cyber security guidance across sectors. The inclusion of alliances with NATO and Five Eyes partners reinforces the idea that protect-and-defend strategies are increasingly collaborative and international in scope, which has implications for supply chains, cross-border data flows, and joint research initiatives. The public-facing nature of these disclosures helps inform policymakers, industry stakeholders, and researchers about the direction and pace of Canada’s cyber security evolution. (cse-cst.gc.ca)

Quotes and Expert Framing

The CSE annual report includes leadership reflections that underscore continuity and adaptation in a shifting threat landscape. For example, the ministerial foreword and chief’s message highlight the ongoing expansion of capabilities, the importance of partnerships, and the drive to translate investments into action. These framing elements provide context for readers seeking to interpret the numbers within the broader policy environment and strategic outlook. Quoted passages from these sections help ground the data in real-world leadership perspectives and connect technical progress with national policy priorities. (cse-cst.gc.ca)

What’s Next

Roadmap, Timelines, and Immediate Milestones

Looking ahead, the CSE annual report points to continued growth and transformation as part of Canada’s cyber security strategy. The organization indicates a path toward sustaining a larger workforce, maintaining rigorous governance, and deepening partnerships with industry, academia, and government partners. The 2025-2026 highlights indicate that Canada’s investments in digital defence are not static; rather, they are part of an ongoing program to scale capabilities, improve resilience, and respond to emergent threats. The ongoing rollout of governance mechanisms, including ministerial orders and enhanced compliance programs, suggests a continuing emphasis on accountability as the foundation for expanded operational capacity. (cse-cst.gc.ca)

Public Engagement and Transparency Initiatives

With initiatives like One CSE and Season 2 of The Collection, the agency signals a commitment to transparency and public engagement as it grows. These outreach efforts serve dual purposes: they help demystify intelligence and cyber operations for the public and stakeholders, and they create channels for feedback, collaboration, and knowledge sharing. For readers and markets watching technology policy, these initiatives indicate a shift toward more accessible, dialogue-based governance around sensitive national security work. (cse-cst.gc.ca)

What to Watch For in the Near Term

  • Further workforce expansion and diversification activities as Canada sustains growth in cyber defence and digital infrastructure protection.
  • Enhanced public-facing programs and educational outreach designed to broaden cybersecurity awareness and resilience across sectors.
  • Ongoing collaboration with international partners, including NATO and the Five Eyes community, to align standards, share threat intelligence, and coordinate responses to cyber threats that transcend borders.
  • Continued oversight, audits, and independent reviews that validate how CSE implements its mandate while balancing transparency with operational security.

These elements are likely to influence procurement, research funding, and corporate partnerships in the technology and security ecosystems. Observers should monitor government announcements, annual report updates, and CSE’s public engagement channels for the latest information on policy changes, program milestones, and new collaborative initiatives. (cse-cst.gc.ca)

Closing

The CSE annual report for 2025-2026 presents a portrait of Canada’s digital defence posture grounded in data and disciplined governance. The year’s numbers—workforce expansion, incident response scale, threat notifications, and governance activity—paint a picture of a national security apparatus that is growing in both capacity and accountability, while remaining tightly integrated with international partners and industry stakeholders. As Canada continues to invest in cyber resilience, readers can expect ongoing updates, detailed disclosures, and deeper collaboration across sectors aimed at safeguarding Canada’s digital infrastructure and democratic processes. For ongoing coverage, Tech Forum will follow CSE’s public disclosures, government announcements, and independent reviews to bring readers timely, data-driven analysis of how these developments unfold and what they mean for technology and market trends in Canada. (cse-cst.gc.ca)

About the author

Claire Bergeron

**Claire Bergeron** is a Montreal-based contributor to *Tech Forum* covering design, brand identity and digital culture, with a particular interest in how classroom policy shapes what audiences can actually read.