Ron Lloyd BETWEEN INTENT AND OUTCOMES

Home / Published Work / Empowering Defence in the Digital Age

POLICY PAPERCGAI, TRIPLE HELIXMAY 2025

Empowering Defence in the Digital Age

Why the barriers to Defence's digital ambitions sit outside Defence's own authorities

Defence & National Security Digital Government & Procurement Security & Assurance

SYNOPSIS

The most significant challenge facing the Canadian Armed Forces is leveraging digital technologies to its advantage. No matter what platforms and combat capabilities Canada acquires, they will not be optimized without the digital tools to enable pan domain command and control. This paper makes the case that the vast majority of the barriers preventing that sit outside Defence's own authorities, responsibilities and accountabilities. It works through the government-wide instruments that bind Defence, ITSG-33, the cloud security profiles, the administrative and operational data distinction, and the absence of Zero Trust and data centric security from the framework, and shows that Canada's cyber security posture is not only sub-optimal but costs roughly a half billion dollar premium relative to peers. It argues that Defence should have its own digital policy framework, and makes six recommendations.

“It is completely unrealistic to believe that Canada, and specifically defence, can function as a 21st century digital enterprise on a 20th century digital policy foundation.”

From the paper, page 2

KEY FINDINGS

  1. 1

    The barriers sit outside Defence's own authorities. Despite some policy exemptions in recognition of its unique requirements, Defence still complies with numerous government-wide policies that do not reflect or support military needs. Defence's digital progress is therefore a direct reflection of the Government of Canada's ability to realize its own digital ambitions, and an aggregated approach to policy, infrastructure and requirements does not serve the unique needs of the CAF.

  2. 2

    The posture is sub-optimal and Canadians pay a premium for it. A comparative study of ten national cyber security strategies ranked Canada ninth. Drawing on the government's own Enterprise Cyber Security Strategy, the paper places Canada's posture in the bottom or second bottom of the four tiers of the NIST Cyber Security Framework 2.0, on which Canada based its own 2025 strategy. A 2018 Shared Services Canada sponsored Gartner study found SSC's network and security model 19 per cent, or $427 million, more costly than peers. The paper puts the premium at roughly half a billion dollars.

  3. 3

    The framework the strategy rests on is obsolete. The Enterprise Cyber Security Strategy anchors its execution to ITSG-33, released in 2012 and last updated in 2015. Neither Zero Trust nor data centric security is referenced in it, even though the United States has mandated Zero Trust by executive order and Australia, New Zealand and the United Kingdom have all issued direction on it.

  4. 4

    The control profiles carry substantially more than allied equivalents. Canada's Protected B profile has 436 controls against NIST moderate's 257, and Secret 516 against NIST high's 339, roughly 180 additional controls for baselines described as equivalent. The cloud profiles repeat the pattern: Canada's low baseline has 253 controls against FedRAMP low's 156, and once supply chain controls are counted requires 108 more; PBMM has 357 against FedRAMP Moderate's 323, with 80 controls that do not map across at all.

  5. 5

    The administrative and operational data distinction does not survive contact with Defence. The paper calls it “an overly simplistic and a foolish characterization”. Data that is administrative to a policy maker is operational to a practitioner. Since Defence owns the national security risk, the paper argues it should own the risk of where it hosts its data, rather than having that approved by departments delivering against goals that have nothing to do with national security.

  6. 6

    Accountability without the corresponding authority is not accountability. Defence carries responsibility for the national defence and security of the nation, but many of the authorities governing its digital environment reside elsewhere. The paper concludes that the current accountability framework, “characterized by split accountabilities, unclear and often contradictory policies essentially delivers no accountability at all”, leaving Defence accountable for outcomes without control over many of the decisions required to produce them.

RECOMMENDATIONS

The paper makes six recommendations.

1. Review the digital policy suiteIn recognition of the pace of digital technology and the uniqueness of the Defence digital enterprise, review the current digital policy suite so that Defence domain specific policy can respect the government position while focussing on defence needs at pace and at scale.
2. Remove the ambiguity in responsibilitiesRevisit the responsibility sections of the digital policies to remove the ambiguity that exists between departments, CSE, SSC and Treasury Board. If Treasury Board is to provide strategic direction, that should be the lens through which its responsibilities are articulated.
3. Adopt a new classification frameworkOfficial (Official: Sensitive), Secret and Top Secret. In the interim, convene a government and industry working group to review the Protected B and Secret profiles in ITSG-33 and the CCCS Low and Medium cloud profiles, and report to TBS.
4. Update the Enterprise Cyber Security StrategyReflect the govern function as depicted in NIST CSF 2.0; direct CSE to draft a Government of Canada information security manual as the authoritative document for line departments; and direct departments to develop Zero Trust plans.
5. Amend the definition of cyber securityAdopt the Schatz et al. definition, validated with the author in 2025, which frames cyber security around security risk management and recognizes that it is about protecting users, not just data.
6. Address the misperceptions about cloudHave the Canadian Centre for Cyber Security publish a white paper for senior executives, along the lines of the United Kingdom's Security benefits of a good cloud service (November 2020).

WHERE THIS FITS

Added September 2026

The first three papers examined government-wide instruments and the behaviour they produce. This one applied that analysis to a single institution that cannot opt out of any of it. Defence carries the national security risk but holds few of the authorities that determine how it may use its own data, and the paper follows that mismatch through classification, cloud, control profiles and the accountability framework. It is also the paper that introduced the argument for a Defence specific digital policy framework, which the later work develops into a broader account of institutional architecture.

SINCE PUBLICATION

What has changed, and where the argument went

UPDATE · SEPTEMBER 2026

WHAT HAS CHANGED

  • On 1 April 2026 the Cyber Centre's ITSP.10.033-01, a medium impact security and privacy control profile, superseded Annex 4A Profile 1, the Protected B profile this paper examined. Its controls are drawn from the Cyber Centre's own catalogue, ITSP.10.033.
  • The 436 control Protected B comparison in Finding 4 therefore describes the baseline as it stood when the paper was published, not the current profile.
  • ITSP.10.033-01 supersedes only the Protected B profile. It does not replace the Secret profile, Annex 4A Profile 3, on which the paper's 516 control comparison rests.

Source: Canadian Centre for Cyber Security, ITSP.10.033-01, effective 1 April 2026.

HOW THE THINKING HAS DEVELOPED

This paper moved the analysis from individual policies and programs to the relationship between accountability and authority. Defence could be held responsible for national security outcomes while many of the policy, infrastructure and security decisions affecting those outcomes rested elsewhere. Later work developed that observation into a broader institutional architecture argument: outcomes depend not only on who is accountable, but on whether authorities, resources and decision rights are aligned sufficiently to allow institutions to execute.

The paper's rejection of a clean boundary between administrative and operational data also foreshadowed the later iC2 argument. Institutional systems that appear administrative in peacetime can become operationally consequential when they are required to generate, sustain, adapt or regenerate military capability.

ABOUT THE AUTHOR

Vice-Admiral (Ret'd) Ron Lloyd was the 35th Commander of the Royal Canadian Navy and is a Fellow of the Canadian Global Affairs Institute. Transparency →